Skip to main content
Rules Mate

Who must comply with APRA CPS 234 (Information Security)?

The applicability test for Comply with APRA CPS 234 (Information Security) (APRA), computed across 35 industries, 9 business structures and 6 size bands.

Short answer: Some businesses

Applies when the business has APRA regulation.

What the obligation is

APRA-regulated entities must maintain information security capability commensurate with the size and extent of threats.

CPS 234 requires APRA-regulated entities (ADIs, insurers, RSE licensees) to clearly define information security-related roles, maintain capability, implement controls commensurate with vulnerabilities and threats, and notify APRA within 72 hours of a material information security incident.

The applicability test

Applies when the business has APRA regulation.

How the regulator frames it: All APRA-regulated entities.

What triggers it: Being APRA-regulated.

Jurisdiction: Commonwealth law, so the test is the same in every state and territory.

Which industries are in or out

Outcome across the 35 industries Rules Mate maps (3 of 35: yes; 32 of 35: no).

IndustryAnswer
Banks & ADIsYes
Superannuation trusteesYes
Private health insurersYes
No32 other industries

Business structure and size

Structure does not change the answer in the 3 industries it can reach: for every structure the answer is "yes".

Size does not change the answer in the 3 industries it can reach: at every size band the answer is "yes".

Worked examples

Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:

  • Pty Ltd company in banks & adis with 6–19 employees, turnover $1M–$3M: applies. ADI — APRA-regulated.
  • Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires APRA regulation.

Answers that bring it into scope

Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:

  • The business is regulated by APRA: it then applies (APRA-regulated).

What you must do, and when

When due
Continuous; APRA notification within 72 hours of a material incident.
Frequency
Ongoing
Evidence to keep
Information security policy, control testing, internal audit reports, incident notifications.
Status
Current
Priority
Critical

Penalty for not complying

Maximum penalty: APRA enforcement actions including additional capital, licence conditions, directions.

Audit or assurance level

Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.

Enforcement examples

Obligations with the same applicability test

What usually applies alongside it

Across the 1,890 business profiles Rules Mate evaluates, these obligations apply to most of the businesses this one applies to, and are far more common among them than among businesses generally:

Where it sits in the corpus

Rules Mate tracks 9 published obligations tagged "cyber", 4 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated critical priority, and is an ongoing duty.

Regulator, legislation and tools

Regulated by Australian Prudential Regulation Authority.

APRA: Prudential regulator of banks (ADIs), insurers (general, life, private health), and superannuation funds. Sets and enforces CPS standards including CPS 234 (information security) and CPS 230 (operational risk).

Banking Act 1959: Authorises APRA to regulate authorised deposit-taking institutions (banks, building societies, credit unions).

Insurance Act 1973: Prudential supervision of general insurers by APRA.

Life Insurance Act 1995: Prudential supervision of life insurers by APRA.

SIS Act: Federal supervision of superannuation.

Free tools that help with this obligation:

Questions

Who must comply with APRA CPS 234 (Information Security)?
Applies when the business has APRA regulation.
Do sole traders need to comply with APRA CPS 234 (Information Security)?
Yes. Looking in the 3 industries it can reach and every size band, the engine's answer for a sole trader is: yes.
Do businesses with 1–5 employees need to comply with APRA CPS 234 (Information Security)?
Yes (1–5 employees, turnover $100K–$1M).
When is "Comply with APRA CPS 234 (Information Security)" due?
Continuous; APRA notification within 72 hours of a material incident.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.