Skip to content

Security & SOC4 min read

CPS 234 Control Testing: The Evidence APRA-Regulated Entities Need

CPS 234 control testing evidence: systematic testing, functional independence, penetration testing scope, raw artefacts, remediation, retest and escalation.

Share

Key takeaways

  • CPS 234 requires systematic control testing matched to threat, criticality, consequence and material change.
  • Tests need skilled, functionally independent specialists; program sufficiency reviewed annually or after change.
  • Pentests are one source: identity, endpoint, detection, cloud, backup and third-party controls need operating-effectiveness evidence too.
  • Evidence chain: control → raw output → finding → remediation ticket → retest → escalation.
  • Functional independence governs who runs the test; internal audit keeps its own review of control design and effectiveness.
  • CPS 230 covers operational resilience and material service providers, it does not mandate a 24/7 SOC.
On this page8 sections

CPS 234 compliance requires APRA-regulated entities to run a systematic control testing programme, not a yearly CPS 234 penetration testing PDF in isolation. This guide covers CPS 234 control testing evidence, what an independent audit or assurance function expects to see, and CPS 230 adjacency for operational resilience, without inventing mandates like a required 24/7 SOC. We are not the statutory auditor or IRAP assessor.

Where control testing sits in CPS 234

The wider standard covers Board responsibility, asset classification, incident management, third parties and internal audit review of control design and operating effectiveness. The CPS 234 compliance pillar owns the full obligation map.

Notification thresholds that shape evidence:

  • 72 hours: material information-security incident
  • 10 business days: material control weakness not remediated in a timely manner

When you rely on a third party's testing, CPS 234 requires assessing whether that testing is commensurate with the standard.

CPS 234 evidence chain from control through test, finding, remediation and retest

Penetration testing is evidence, not the whole program

Control areaUseful testKey artefact
Internet-facing appsExternal/web/API pentestScope, raw output, findings, retest
IdentityMFA bypass, privileged access reviewIdP/PAM config, auth logs
EndpointEDR validation, execution testPolicy, telemetry, containment
SIEM / detectionAdversary simulationRaw events, alert, analyst ticket
CloudConfig review, IAM path testCSPM export, remediation ticket
Backup / recoveryRestore exerciseRTO/RPO result, backup ACL evidence
Third partiesProvider assurance reviewSOC report, gap assessment, contract map

See threat-informed detection engineering and Splunk noise-first migration for detection evidence patterns.

APRA CPG 234 operating model

CPG 234 expects testing that validates design and operating effectiveness over time. A sufficient set of controls is normally tested at least annually; controls in untrusted environments are typically tested through the year.

Internet-facing critical apps: frequent scanning + periodic pentest

Privileged identity: recurring review as roles change

Backup and recovery: restore exercises on defined cadence

Third-party reliance: validate provider testing commensurate with CPS 234

The evidence chain assessors expect

  1. Control and asset in scope
  2. Test objective and method
  3. Tester identity, skills and functional independence statement
  4. Date and raw output (not summary-only)
  5. Result and finding severity
  6. Remediation owner and ticket
  7. Retest evidence or documented risk acceptance
  8. Management or Board escalation where required

Raw artefacts beat summary decks. SIEM logs, configuration exports and ticket trails should link to the control statement.

Who tests, and does CPS 234 require an independent audit?

CPS 234 requires testing by specialists who are appropriately skilled and functionally independent of the function that designed or operates the control. That is narrower than a CPS 234 independent audit in the statutory sense. It is an independence-of-tester requirement, not an instruction to appoint an external auditor for every test.

Separately, CPS 234 requires internal audit to review the design and operating effectiveness of information-security controls, including any testing performed by a related party or third party. Agree the independence model with risk and internal audit before the cycle starts, so evidence is not rejected after the testing is complete.

An external specialist can satisfy the functional-independence requirement for technical testing while internal audit retains its own review role. AiRAT delivers the technical testing side, we are not the statutory auditor.

CPS 230 adjacency (third-party risk)

CPS 230 covers operational resilience and material service providers. It does not mandate a 24/7 SOC unless another requirement applies. Keep CPS 234 assurance separate from operational-resilience narrative drift.

Remote engineering delivery is viable when access is controlled, session-logged and does not export bulk production data offshore without approval. See Australia residency.

Readiness checklist

  • Define control population and risk-tiered test calendar
  • Document functional independence model with internal audit
  • Ensure raw test outputs are retained and ticket-linked
  • Map escalation path for unremediated material weaknesses
  • Review third-party testing commensurate with reliance
  • Schedule annual sufficiency review of the testing programme

Limitations

Technical assurance guidance, not statutory audit, legal or APRA regulatory advice. Re-check CPS 234 and CPG 234 before board reporting.


Sources: APRA CPS 234, CPG 234, verified 8 August 2026.

Next step: Scope CPS 234 control testing · CPS 234 pillar · Pentest case study

CPS 234APRAControl TestingPenetration TestingCybersecurityAustralia

Written by

Anurag Sogani

Founder & Principal Engineer, AiRAT

Anurag leads AiRAT's platform engineering practice, shipping production SOC, XDR and agent-security systems for regulated enterprises across UAE, India, Singapore, Europe, Australia and the US. He writes from delivery work: the frameworks here come out of live programmes, not vendor decks.

Common questions

7 questions

Is this a complete CPS 234 compliance guide?

No. This article intentionally focuses on control-testing and penetration-testing evidence. The CPS 234 compliance pillar covers the full standard, including governance, assets, incidents, third parties and notifications.

What does CPS 234 require for control testing?

APRA requires a systematic program that tests information-security control effectiveness with nature and frequency matched to threat change, asset criticality, incident consequence, untrusted exposure and material change.

Does CPS 234 require penetration testing?

CPS 234 requires systematic control-effectiveness testing, not a single named test type. Penetration testing is useful evidence for relevant technical controls but should sit inside a broader assurance program.

Who should perform CPS 234 control testing?

CPS 234 says testing must be conducted by appropriately skilled and functionally independent specialists. The entity should define the independence model with risk/internal-audit stakeholders.

What evidence should be retained from a CPS 234 test?

Retain control/asset scope, test objective/method, tester, date, raw output, result, finding, owner, remediation ticket, retest evidence and escalation or risk acceptance where applicable.

How does CPS 234 apply to third-party service providers?

When information assets are managed by a related or third party and the entity relies on that party's testing, the entity must assess whether the nature and frequency of that testing is commensurate with CPS 234.

Does CPS 230 require a 24/7 SOC?

No. CPS 230 covers operational risk, continuity and service-provider risk; do not convert that into a claim that APRA mandates a 24/7 SOC unless another source or requirement applies.

Stay current

Engineering insights, when we publish them.

Production notes on AI, security, and data infrastructure. No marketing, only the pieces worth reading.

No spam. Unsubscribe anytime.

Get started

Leave your email - we'll reach out.

Share your work email and we'll follow up with a tailored note on security, AI, or data programmes - usually within one business day.

No spam. We only use your email to respond to this request.

Explore services →