What’s the Difference Between CPS 234 vs ISO 27001

Ajay Unni
Ajay Unni CEO,StickmanCyber
October 8, 2026 8 min read

The threat of cybercrime for businesses cannot be understated, cybercrime in the past decade has seen a sharp increase, causing significant financial and reputational damage to businesses in Australia and all around the world. This threat has led to businesses choosing to prioritise uplifting their information security. To meet this need there are several frameworks and standards that help businesses create or enhance their cybersecurity program that covers all facets of their information security. ISO 27001 and APRA CPS 234 are two such examples, each designed to meet a particular set of needs. So what are their differences? Before we can delve into their differences it is important to understand what each of them is and the purpose they serve.

What is ISO 27001?

ISO 27001 is a globally recognised standard for information security. It allows for your business to equip itself with a risk-based approach to information security that is internationally accepted as best practice.

One of the key ways it achieves this is through the introduction of an Information Security Management System. An ISMS assists businesses in identifying, assessing, mitigating, and managing the risks involved in managing corporate information. Implementing an Information Security Management System is one of the most important methods of securing your organisation’s intellectual property, financial data, and third-party or employee information.

An ISMS is a combination of processes and policies that help you identify, manage, and protect your sensitive data against external threats. The ISMS’s main objective is to make sure that the confidentiality, integrity, and availability of your company’s data and information are maintained.

Why is ISO 27001 important?

Achieving ISO 27001 certification proves to your customers and partners that your business is committed to achieving an international standard of information security. The certification helps towards improving the trust customers are comfortable putting into your business and is a huge differentiating factor amongst competitors.

Lock Down Your Cybersecurity & Compliance
Protect, Certify & Grow Your Business

Build resilient governance practices that can adapt and strengthen with evolving threats. Speak to an expert

What are the controls of ISO 27001?

ISO 27001 takes a risk-based approach to information security. This approach requires organisations to identify risks that may be detrimental to information security and then select appropriate controls to mitigate them.

Those controls are outlined in Annex A of the Standard. ISO 27001:2013 listed 114 Annex A controls, divided into 14 control domains. The current edition, ISO/IEC 27001:2022, has 93 Annex A controls grouped into four themes, and ISO 27001:2013 certifications expired or were withdrawn when the transition period ended on 31 October 2025:

ThemeControlsExamples of what it covers
Organisational37Information security policies, roles, supplier relationships, incident management, business continuity and compliance
People8Screening, terms of employment, security awareness and training, and remote working
Physical14Physical perimeters and entry, equipment protection and storage media
Technological34Access and authentication, malware protection, backup, logging, network security and secure development

When checking for ISO 27001 compliance, certification auditors will take a look at controls under each theme.

What is APRA CPS 234?

To assist organisations in protecting themselves from cybercrime the Australian Prudential Regulation Authority (APRA) created a standard for information security management called APRA CPS 234, which has been in force since 1 July 2019. This standard is designed to help APRA-regulated entities increase their overall resilience towards information security incidents that can affect the confidentiality, integrity or availability of information assets.

The CPS 234 requires APRA-regulated entities to:

  1. Explicitly define roles and responsibilities of the board, senior management, governing bodies and other employees regarding information security.
  2. Create and maintain an information security capability that is adequate enough to deal with emerging threats and existing vulnerabilities, so that the organisation can continue to operate efficiently and effectively.
  3. Establish controls to protect information assets taking into consideration their individual criticality and sensitivity. Continue to evaluate these controls in a timely fashion so that improvements can be made so that they are always of a high standard.
  4. Report material information security incidents to APRA no later than 72 hours after becoming aware of them.

Why is APRA CPS 234 relevant today?

Cyber-attacks remain a persistent and costly threat, as malicious actors are getting more sophisticated and ingenious in their methods of compromising information assets of organisations. Organisations in the finance industry have become especially lucrative targets for these criminals due to the high amount of financial reward and access to personally identifiable information (PII) and protected health information (PHI) that these organisations hold.

This trend has been helped by lacklustre information security and an overreliance on the use of technology and third-party vendors by superannuation, banking and insurance companies, in an attempt to increase customer satisfaction and operational efficiency. In consequence, internal and external stakeholders have increased their expectations when it comes to securing information assets, as well as calling for an increase in importance given to promoting information security within the organisation as a whole.

CPS 234 can help APRA-regulated entities to reduce cyber risk and increase their overall cyber security posture by ensuring that their information security takes into account their vulnerabilities and threats. The CPS 234 also ensures that organisations give more attention to vendor risk management so that incidents involving third parties are reduced.

What kind of organisations does the APRA CPS 234 apply to?

CPS 234 applies to all APRA-regulated entities. These include:

  • Banks, credit unions and other authorised deposit-taking institutions (ADIs)
  • Superannuation funds (RSE licensees)
  • Life insurance companies
  • Friendly societies
  • General insurers
  • Non-operating holding companies
  • Private health insurers.

It is important to note that since 1 July 2020, CPS 234 has also applied in full to information assets managed by third parties: an APRA-regulated entity must assess the information security capability of any related party or third party that manages its information assets.

CPS 234 also applies to certain foreign entities, for their Australian branch operations. These include:

  • Foreign ADIs
  • Foreign general insurers (Category C insurers)
  • Eligible foreign life insurance companies

Are there any differences between CPS 234 and ISO 27001?

A key difference between the two standards is the way that they are enforced, on one hand, businesses can get ISO 27001 certification and are required to renew their certification every 3 years, with regular surveillance audits during this period. On the other hand, CPS 234 does not have a certification, instead, APRA has a range of formal and non-formal enforcement tools at their disposal. Non-formal approaches include working in cooperation with companies to identify and rectify problems before they threaten the ability of that company to meet its promises. However, APRA is prepared to take enforcement action when appropriate – including court-based action or directing companies to take or cease particular actions.

Another key distinction between the two standards is who they apply to, while ISO 27001 is globally recognised, APRA created the CPS 234 standard to meet the growing need for cybersecurity uplift amongst businesses in the financial services industry, therefore it is a requirement that is specific to APRA regulated entities, whereas ISO 27001 is a much broader information security standard that is more thorough and applies to business across industries, regardless of size, type and location.

In conclusion, apart from the two differences outlined above it is difficult to compare the two standards as they both are designed to uplift an organisation’s information security. CPS 234 does not require ISO 27001 certification, but many of its requirements overlap with the clauses and controls outlined in the ISO 27001 standard. Therefore businesses that are already certified to ISO 27001 generally have an easier time meeting the requirements outlined in CPS 234.

How can StickmanCyber help?

Whether you are looking to achieve ISO 27001:2022 certification or need help meeting APRA CPS 234’s key requirements, StickmanCyber is here to help. We have worked with organisations across Australia and New Zealand since 2006, and our consultants are certified as ISO 27001 Lead Auditors and Lead Implementers.

The First Step is Crucial. Start with a Cybersecurity Assessment

Where are you at your cybersecurity maturity journey? Get an assessment of your current security posture and identify the gaps and challenges that you need to act upon. Start an assessment

Frequently asked questions

Does ISO 27001 certification mean an organisation complies with CPS 234?

No. ISO 27001 certification is useful evidence of a well-run information security management system, but on its own it does not demonstrate CPS 234 compliance. CPS 234 adds specific obligations, such as making the board ultimately responsible for information security, notifying APRA of material incidents within 72 hours and assessing the information security capability of third parties that manage information assets.

Is CPS 234 mandatory?

Yes, for APRA-regulated entities. CPS 234 is a binding prudential standard that has applied to Australian banks, insurers, private health insurers and superannuation trustees since 1 July 2019. ISO 27001, by contrast, is voluntary: organisations choose to be certified, often because customers, partners or tenders ask for it.

Does CPS 234 apply to third-party service providers?

Service providers are not regulated by APRA directly, but CPS 234 still reaches them. A regulated entity must assess the information security capability of any related party or third party that manages its information assets, and its internal audit function reviews the controls those parties maintain. Providers to Australian banks, insurers and super funds are therefore often asked to evidence their security controls.

How often must CPS 234 controls be tested?

CPS 234 does not set a fixed interval. It requires a systematic testing program whose nature and frequency match factors such as how quickly vulnerabilities and threats change, the criticality and sensitivity of the information assets and the consequences of an incident. Testing must be done by appropriately skilled and functionally independent specialists, and the program must be reviewed at least annually.

What happened to ISO 27001:2013 certificates?

The transition period to ISO/IEC 27001:2022 ended on 31 October 2025, and certificates issued against the 2013 edition expired or were withdrawn at that point. Organisations now certify to ISO/IEC 27001:2022, which ISO amended in 2024 to add climate action changes, and their Statement of Applicability must refer to the 93 Annex A controls of the 2022 edition.

How does CPS 230 relate to CPS 234?

APRA’s CPS 230 Operational Risk Management took effect on 1 July 2025 and sets updated requirements for operational risk, business continuity and service provider management. It sits alongside CPS 234 rather than replacing it: CPS 234 still governs information security, while CPS 230 covers the wider resilience of critical operations, including material service providers.

Ajay Unni

Ajay Unni

CEO,StickmanCyber Ajay Unni is CEO of StickmanCyber, leading the team in delivering cybersecurity, risk, and compliance solutions. He holds a Master of IT and a Bachelor of Computer Science, is a PCI Qualified Security Assessor and Certified Information Systems Auditor, and has served as CREST Vice Chairman and a member of the NSW Government Cyber Security Taskforce. With over 25 years in the industry, Ajay is a sought-after voice on the Australian cyber threat landscape.

Master of IT B. Computer Science PCI Qualified Security Assessor Certified Information Systems Auditor (CISA) CREST Vice Chairman NSW Gov Cyber Security Taskforce

Cybersecurity As A Service for Australian Organisations

StickmanCyber helps mid-market businesses across Australia and New Zealand reduce cyber risk, strengthen compliance, and build security maturity without the cost and complexity of managing it all internally.

Combining experienced cybersecurity specialists with AI-powered delivery, StickmanCyber provides practical, Cyber Done support across risk assessments, compliance, remediation, and ongoing protection — acting as a trusted partner from strategy through to certification and beyond.

CREST Accredited PCI-DSS ISO 27001 Essential Eight Since 2006
Book a free consultation
Risk Assessment & Essential EightUnderstand your current maturity and gaps
Compliance & CertificationISO 27001, PCI DSS, SOC 2 and more
Penetration & VAPTFind gaps, strengthen controls, build resilience
24/7 Monitoring via StickSecureContinuous visibility across your environment

Recent Posts