Do superannuation trustees need to comply with APRA CPS 234 (Information Security)?
A computed answer from the Rules Mate applicability engine, with the exact condition, the outcome for every structure and size, and the primary source.
Short answer: Yes
Yes. This obligation applies to superannuation trustees whatever their structure or size. The deciding fact: RSE licensee — APRA-regulated.
The obligation in brief
Comply with APRA CPS 234 (Information Security). CPS 234 requires APRA-regulated entities (ADIs, insurers, RSE licensees) to clearly define information security-related roles, maintain capability, implement controls commensurate with vulnerabilities and threats, and notify APRA within 72 hours of a material information security incident.
Trigger: Being APRA-regulated.
Why superannuation trustees get a different answer
Rules Mate runs its applicability engine across 9 business structures and 6 size bands for each of the 35 industries it maps. For 32 of those industries the answer for "Comply with APRA CPS 234 (Information Security)" is no. Superannuation trustees is one of the 3 where the answer is different: yes.
The deciding fact for superannuation trustees: RSE licensee — APRA-regulated.
About the industry: Trustees of APRA-regulated super funds.
Compare a professional services (general) business with 6–19 employees structured as a Pty Ltd company: the obligation does not apply (Requires APRA regulation).
Answer by business structure and size
Each cell is the engine's outcome for a business in superannuation trustees with that structure and size, assuming it sells to consumers and small businesses and holds customer contact details. "Check" means the obligation turns on a fact the industry does not settle.
| Structure | No employees | 1–5 employees | 6–19 employees | 20–99 employees | 100–499 employees | 500+ employees |
|---|---|---|---|---|---|---|
| Sole trader | Yes | Yes | Yes | Yes | Yes | Yes |
| Partnership | Yes | Yes | Yes | Yes | Yes | Yes |
| Trust | Yes | Yes | Yes | Yes | Yes | Yes |
| Pty Ltd company | Yes | Yes | Yes | Yes | Yes | Yes |
| Public company | Yes | Yes | Yes | Yes | Yes | Yes |
| Not-for-profit (unregistered) | Yes | Yes | Yes | Yes | Yes | Yes |
| Registered charity | Yes | Yes | Yes | Yes | Yes | Yes |
| Super fund | Yes | Yes | Yes | Yes | Yes | Yes |
| Foreign company | Yes | Yes | Yes | Yes | Yes | Yes |
What the obligation requires
- When due
- Continuous; APRA notification within 72 hours of a material incident.
- Evidence to keep
- Information security policy, control testing, internal audit reports, incident notifications.
- Maximum penalty
- APRA enforcement actions including additional capital, licence conditions, directions
- Regulator
- APRA
- Jurisdiction
- Commonwealth (national)
Other obligations where superannuation trustees differ from the norm
- Annual YFYS performance test (MySuper + Choice): Yes
- Comply with APRA CPS 230 (Operational Risk Management): Yes
- Comply with Design and Distribution Obligations (DDO): Yes
- Comply with Financial Accountability Regime (FAR) accountability obligations: Yes
- Comply with SIS Act trustee covenants: Yes
- Design and Distribution Obligations (DDO) — RG 274: Yes
- All 15 answers for superannuation trustees
Other industries with a non-default answer
Questions
- Do superannuation trustees need to comply with APRA CPS 234 (Information Security)?
- Yes. This obligation applies to superannuation trustees whatever their structure or size. The deciding fact: RSE licensee — APRA-regulated.
- Is the answer the same for every industry?
- No. For 32 of the 35 industries Rules Mate maps, the answer is no. Superannuation trustees is one of 3 industries with a different answer.
Related
Sources
- APRA: official source
- Banking Act 1959
- Insurance Act 1973
- Life Insurance Act 1995
- Superannuation Industry (Supervision) Act 1993
- APRA guidance
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.