APRA CPS 234 MFA Requirements at a Glance

  • MFA is expected, scaled to risk: CPS 234 requires information security controls, including authentication, that are commensurate with the sensitivity and criticality of the information assets being protected.
  • APRA names where strong authentication is expected: Guidance in CPG 234 identifies privileged and administrative access to sensitive or critical information assets, and remote access, as scenarios where strengthened authentication such as MFA is typically required.
  • Gaps in MFA coverage can be a material weakness: Where MFA coverage gaps could materially affect the entity or its customers, APRA considers this a material security control weakness that must be notified under paragraph 36 of CPS 234.
  • It applies across banking, insurance, and superannuation: CPS 234 covers all APRA-regulated entities, including banks, insurers, private health insurers, and superannuation licensees.
  • Authentication is an active enforcement focus: Through 2025, APRA repeatedly pressed regulated entities, particularly superannuation licensees, to uplift authentication controls following cyber incidents.
  • Breaching a prudential standard is a breach of law: CPS 234 is legally binding, and APRA has a range of enforcement powers for non-compliance, from directions to licence conditions.

What is APRA CPS 234?

Prudential Standard CPS 234 Information Security (CPS 234) is a cross-industry standard issued by the Australian Prudential Regulation Authority (APRA), the statutory authority established in 1998 that supervises Australia’s banking, insurance, and superannuation sectors. CPS 234 commenced on 1 July 2019. Its purpose is to ensure that APRA-regulated entities can remain resilient against information security incidents, including cyberattacks, by maintaining an information security capability that matches the vulnerabilities and threats they face.
 
CPS 234 is principles-based and outcomes-focused rather than prescriptive. It does not hand entities a checklist of specific technologies. Instead, it requires them to maintain security controls, including authentication controls, that are commensurate with the sensitivity and criticality of their information assets. This proportionate approach is central to how the standard treats MFA: the strength of authentication is expected to rise with the sensitivity of what is being protected. The standard is supported by Prudential Practice Guide CPG 234 Information Security (CPG 234), which provides APRA’s guidance on how entities are expected to meet the requirements, including the role of authentication controls such as MFA.
 
CPS 234 is a legally binding prudential standard, so compliance is mandatory for APRA-regulated entities. It also connects to the broader APRA framework. Prudential Standard CPS 230 Operational Risk Management, which came into force on 1 July 2025, explicitly requires entities to meet the information security requirements of CPS 234 as part of managing technology risk. Information security and MFA are therefore part of a wider operational resilience obligation, not a standalone concern.

Who Does APRA CPS 234 Apply To?

CPS 234 applies to all APRA-regulated entities across the banking, insurance, and superannuation industries. This includes:

  • Authorised deposit-taking institutions (ADIs): Banks, credit unions, and building societies authorized to take deposits in Australia.
  • General insurers: Providers of general insurance products such as home, motor, and business insurance.
  • Life insurers: Providers of life insurance and related products, including friendly societies.
  • Private health insurers: Organizations providing private health insurance in Australia.
  • RSE licensees (superannuation): Licensees of registrable superannuation entities that manage Australians’ retirement savings.
  • Non-operating holding companies: Authorized or registered non-operating holding companies within regulated groups.

CPS 234 also reaches third parties in practice. Where an APRA-regulated entity relies on a related party or third party to manage information assets, the entity remains responsible for ensuring that information security, including authentication controls, is maintained to the standard CPS 234 requires. This means service providers to APRA-regulated entities are effectively held to CPS 234 expectations through their contracts and their clients’ obligations.
 
A note for organizations outside Australia: CPS 234 is an Australian prudential standard, but it reaches offshore service providers that handle information assets for APRA-regulated entities. A technology provider, cloud service, or outsourced operations partner serving an Australian bank, insurer, or superannuation fund is expected to support that entity’s CPS 234 compliance, including its authentication requirements. Canadian and other international providers to the Australian financial sector should expect CPS 234 expectations to flow through their service agreements.

What Are the APRA CPS 234 Requirements?

CPS 234 sets out a set of information security obligations covering governance, capability, controls, testing, and incident notification. The requirements most relevant to MFA concern the implementation of controls and the notification of control weaknesses. The table below maps them to their MFA relevance and how LoginTC supports them.
 

CPS 234 Provision Requirement MFA Relevance LoginTC Relevance
Paragraph 21 (controls) Implement information security controls commensurate with the vulnerabilities, threats, criticality, and sensitivity of information assets Mandatory, risk-based MFA scaled to asset sensitivity across access points via RADIUS/LDAP/AD
CPG 234 (guidance): privileged access Strengthened authentication for administrative or privileged access to sensitive or critical information assets MFA expected MFA for privileged and administrator accounts
CPG 234 (guidance): remote access Strengthened authentication for remote access to systems and information assets MFA expected MFA for VPN, Windows logon, and remote desktop access
Paragraph 36 (notification) Notify APRA of material information security control weaknesses MFA coverage gaps can trigger notification Coverage reporting and authentication logs for weakness assessment
Paragraph 27 (testing) Test the effectiveness of information security controls through a systematic testing program Authentication controls must be tested Detailed logs and centralized visibility to support testing and assurance

Paragraph 21: Controls Commensurate with Risk

Paragraph 21 is the heart of the CPS 234 control obligation. It requires an APRA-regulated entity to implement information security controls to protect its information assets, and to do so in a way that is commensurate with the vulnerabilities and threats to those assets, and with their criticality and sensitivity. For authentication, this means the strength of the control is expected to scale with what it protects. Low-sensitivity systems may warrant standard controls, while sensitive or critical information assets warrant strengthened authentication such as MFA. APRA has stated directly that the use of MFA, and the strength of authentication controls, should be commensurate with the information being protected.

CPG 234: Where Strengthened Authentication Is Expected

While CPS 234 sets the outcome, the Prudential Practice Guide CPG 234 gives APRA’s view on how to achieve it. CPG 234 identifies specific scenarios where strengthened authentication, such as MFA, is typically required to prevent false identification and unauthorized access. Two stand out:

  • Privileged and administrative access: Administrative or other privileged access to sensitive or critical information assets is a primary scenario where MFA is expected. Privileged accounts are high-value targets, and their compromise can affect an entire environment.
  • Remote access: Remote access to systems and information assets is the other scenario CPG 234 highlights. Access from outside the entity’s controlled environment carries elevated risk and warrants stronger authentication.

APRA expects entities to review the coverage of MFA across their operating and technology environments against these expectations, and to close gaps where they exist.

Paragraph 36: Material Control Weakness Notification

CPS 234 includes a notification obligation that gives the MFA expectation real force. Under paragraph 36, an entity must notify APRA of a material information security control weakness that it expects it will not be able to remediate in a timely manner. APRA has stated that where gaps in MFA coverage have the potential to materially affect the entity or the interests of depositors, policyholders, beneficiaries, or other customers, it would consider this a material security control weakness requiring notification. In other words, an MFA coverage gap is not just a technical shortcoming; it can be a reportable regulatory matter.

Is MFA Required by APRA CPS 234?

Yes, in practice. CPS 234 does not name MFA as a universal mandate in the way some frameworks do, but it requires authentication controls commensurate with the sensitivity and criticality of the information being protected, and APRA has made clear that this means MFA for sensitive and critical access. APRA’s own guidance states that the use of MFA and the strength of authentication controls should be commensurate with the information being protected.
 
For the access scenarios APRA highlights, the expectation is unambiguous. CPG 234 identifies privileged and administrative access to sensitive or critical information assets, and remote access, as situations where strengthened authentication such as MFA is typically required. An APRA-regulated entity that left privileged or remote access to sensitive systems protected by a password alone would be operating below APRA’s stated expectations.
 
The notification obligation reinforces this. Because APRA treats material gaps in MFA coverage as a material security control weakness that must be reported under paragraph 36, the absence of MFA on sensitive access is not a private matter for the entity to weigh at leisure. It is something APRA expects to hear about. Through 2025, APRA repeatedly pressed regulated entities, and superannuation licensees in particular, to urgently uplift authentication controls following a series of cyber incidents affecting the sector, reinforcing that this is an active supervisory priority rather than a dormant expectation.
 
The practical bottom line is clear. If your entity holds sensitive or critical information assets and privileged or remote access to those assets is not protected by MFA, you are below APRA’s expectations, and the gap may be a reportable weakness. MFA on sensitive access is effectively required.

Consequences of APRA CPS 234 Non-Compliance

CPS 234 is a legally binding prudential standard, and a breach of a prudential standard is a breach of the law that established APRA’s powers. Unlike frameworks with fixed penalty schedules, APRA’s consequences come through its supervisory and enforcement toolkit rather than a set fine per violation.
 
APRA has a graduated range of enforcement options. These include issuing formal directions requiring an entity to take specific action, accepting or imposing enforceable undertakings, imposing additional conditions on an entity’s licence or authorization, requiring independent reviews at the entity’s expense, and applying additional capital requirements where risk management is found wanting. For the most serious cases, APRA can pursue disqualification of responsible individuals and other court-based remedies. The reputational consequence of APRA enforcement action in the Australian market is itself significant, given the scrutiny on financial institutions.
 
The notification regime is a distinctive feature. Under CPS 234, entities must notify APRA of material information security incidents within 72 hours, and of material control weaknesses, including material MFA coverage gaps, that they cannot remediate in a timely way. Failing to notify is itself a compliance failure. An entity that suffers a breach traceable to a known, unreported authentication weakness faces compounded regulatory exposure.
 
The risk is not hypothetical. The Australian financial sector, and the superannuation industry in particular, experienced cyber incidents involving credential compromise and authentication weaknesses that prompted direct APRA intervention through 2025. APRA’s public statements made clear that authentication control weaknesses represented a gap between its expectations and industry practice, and that it expected entities to act immediately upon identifying such weaknesses. For any APRA-regulated entity, credential-based attacks are precisely the threat that MFA is designed to counter.

How to Implement MFA for APRA CPS 234 Compliance

1. Identify and Classify Your Information Assets

CPS 234 requires controls commensurate with the sensitivity and criticality of information assets, so start by identifying and classifying those assets. Determine which systems and data are sensitive or critical, since these are where strengthened authentication is expected. This classification drives your MFA scope and provides the basis for demonstrating to APRA that your authentication controls are proportionate to what they protect.

2. Review MFA Coverage Against APRA’s Expectations

APRA expects entities to review the coverage of MFA across their operating and technology environments. Map every privileged and administrative access path to sensitive or critical assets, and every remote access path into your environment, since these are the scenarios CPG 234 highlights. Identify where MFA is present and where gaps exist. This review is both a compliance activity and the input to your paragraph 36 assessment of whether any gap is a material weakness.

3. Select an MFA Solution Suited to Financial Infrastructure

Choose an MFA solution that fits the systems Australian financial institutions run, which often include a mix of modern and legacy platforms. Look for support for RADIUS, LDAP, and Active Directory to cover the range of access points without replacing existing systems, and consider whether you need cloud, on-premises, or hybrid deployment based on your data handling and sovereignty requirements. Confirm the solution can secure privileged access and remote access, the two scenarios APRA emphasizes.

4. Prioritize Privileged and Remote Access

Deploy MFA first where APRA expects it most: privileged and administrative access to sensitive or critical information assets, and remote access. These carry the highest risk and are the clearest expectations in CPG 234. For privileged accounts especially, consider phishing-resistant methods such as FIDO2 security keys, which offer stronger protection against the credential theft attacks that have driven APRA’s recent focus on the sector.

5. Extend Coverage to Close Material Gaps

Beyond the priority scenarios, extend MFA to close any coverage gaps that could materially affect the entity or its customers. Because a material gap can trigger a notification obligation, the goal is to eliminate gaps on sensitive access rather than leave them to be reported. Include third-party and service-provider access, since the entity remains responsible for information security even where a third party manages the asset.

6. Test the Effectiveness of Your Controls

CPS 234 requires entities to test the effectiveness of their information security controls through a systematic testing program. Test your MFA deployment the way an assessor would, confirming that privileged and remote access to sensitive assets cannot be reached without completing MFA, and that no bypass paths exist. Document the testing, since APRA expects assurance that controls are effective, not merely present.

7. Enable Logging and Prepare for Notification

Ensure your MFA solution generates detailed authentication logs that support incident detection and provide evidence of coverage. Strong logging helps you detect credential-based attacks quickly and supports the incident notification obligations under CPS 234, including the 72-hour incident notification timeline. Establish a process to assess whether any identified MFA gap is a material weakness requiring notification under paragraph 36, and review your coverage regularly as your environment changes.

APRA CPS 234 MFA Best Practices

  • Scale authentication to asset sensitivity: CPS 234 is built on proportionality. Apply the strongest authentication to your most sensitive and critical information assets, and be able to show how your control strength maps to asset classification.
  • Cover privileged and remote access first: These are the two scenarios APRA names explicitly in CPG 234. Ensure both are protected by MFA before extending to other access, since gaps here are the most likely to attract supervisory attention.
  • Prioritize phishing-resistant factors for privileged accounts: FIDO2 security keys and similar methods offer strong protection against the credential theft attacks that have driven APRA’s recent enforcement focus, and are well suited to high-value privileged access.
  • Treat MFA coverage gaps as a reportable risk: Because a material gap can require notification under paragraph 36, assess coverage gaps against their potential impact on the entity and customers, and close them rather than carry them.
  • Hold service providers to the same standard: The entity remains responsible for information security even where a third party manages the asset. Ensure third-party and outsourced access uses MFA and reflect the expectation in contracts.
  • Test and document, do not just deploy: CPS 234 requires testing the effectiveness of controls. Regularly test that MFA cannot be bypassed on sensitive access, and keep documentation that demonstrates both coverage and effectiveness to APRA.

How LoginTC Helps with APRA CPS 234 MFA Compliance

LoginTC is well suited to the environments Australian financial institutions operate, where MFA needs to cover privileged and remote access across a mix of modern and legacy systems. LoginTC integrates through RADIUS, LDAP, and Active Directory, so banks, insurers, and superannuation licensees can enforce MFA across the access points CPS 234 emphasizes without replacing existing infrastructure.
 
For the privileged and remote access scenarios that CPG 234 highlights, LoginTC enforces MFA on administrator accounts, VPN and remote connections, Windows logon, and remote desktop access. It supports phishing-resistant factors such as FIDO2 security keys and hardware tokens, which are strong choices for the privileged access APRA is most concerned about and for the credential-based threats that have prompted its recent supervisory focus. Because CPS 234 expects authentication commensurate with asset sensitivity, LoginTC’s per-application and role-based policies let entities apply stronger authentication to their most critical systems.
 
For entities with data sovereignty requirements or a preference to keep authentication infrastructure within their own environment, LoginTC’s on-premises deployment option provides that control. Detailed authentication logs and centralized administration give compliance and risk teams visibility into MFA coverage, support the testing and assurance CPS 234 requires, and provide the evidence needed to assess whether any gap is a material weakness. This supports both the control and the notification sides of the standard.
 
Explore LoginTC for Finance | View All Connectors

Frequently Asked Questions

Does APRA CPS 234 require MFA?

CPS 234 requires authentication controls commensurate with the sensitivity and criticality of the information being protected, and APRA has stated that this means MFA for sensitive and critical access. Guidance in CPG 234 identifies privileged and administrative access to sensitive or critical information assets, and remote access, as scenarios where strengthened authentication such as MFA is typically required. While CPS 234 is principles-based rather than prescriptive, MFA on sensitive access is effectively required, and material gaps can be a reportable weakness.

Who does APRA CPS 234 apply to?

CPS 234 applies to all APRA-regulated entities, including authorised deposit-taking institutions (banks, credit unions, building societies), general insurers, life insurers, private health insurers, superannuation (RSE) licensees, and non-operating holding companies. It also reaches service providers in practice, because a regulated entity remains responsible for information security even where a third party manages its information assets.

What types of MFA are acceptable under CPS 234?

CPS 234 does not mandate a specific technology. It requires authentication strength commensurate with the sensitivity of the information protected. Acceptable methods include authenticator apps, hardware tokens, and FIDO2 security keys. For privileged access and other high-value scenarios, phishing-resistant methods such as FIDO2 keys are strongly preferred, particularly given APRA’s recent focus on credential-based attacks. SMS-based codes are weaker and are increasingly seen as insufficient for sensitive access.

What happens if we have a gap in our MFA coverage?

APRA has stated that where gaps in MFA coverage have the potential to materially affect the entity or the interests of depositors, policyholders, beneficiaries, or other customers, it considers this a material security control weakness. Under paragraph 36 of CPS 234, a material control weakness that cannot be remediated in a timely manner must be notified to APRA. This makes closing material MFA gaps a regulatory priority, not just a technical improvement.

How does CPS 234 relate to CPS 230?

CPS 234 is APRA’s information security standard, focused on protecting information assets, including through authentication controls. CPS 230 Operational Risk Management, in force since 1 July 2025, is broader and focuses on operational resilience, critical operations, and service provider management. CPS 230 explicitly requires entities to meet the information security requirements of CPS 234 as part of managing technology risk, so the two operate together rather than in isolation.

Does APRA CPS 234 apply to organizations outside Australia?

CPS 234 is an Australian prudential standard, but it reaches offshore service providers that manage information assets for APRA-regulated entities. A cloud provider, technology vendor, or outsourced operations partner serving an Australian bank, insurer, or superannuation fund is expected to support that entity’s CPS 234 compliance, including its authentication requirements. International providers to the Australian financial sector should expect these expectations to flow through their contracts.

Does LoginTC need to be hosted in Australia to support CPS 234 compliance?

CPS 234 does not mandate a specific hosting location, but it does expect entities to manage information security risk, which can include data sovereignty considerations. Both cloud-based and on-premises LoginTC deployments can support CPS 234 compliance. For entities that prefer to keep authentication infrastructure within their own environment or within Australia, LoginTC’s on-premises option provides that control and can simplify sovereignty and evidence considerations.

Get a Free APRA CPS 234 MFA Strategy Session

Meeting CPS 234’s authentication expectations means covering privileged and remote access to your sensitive systems, scaling authentication strength to asset sensitivity, and being able to demonstrate coverage and effectiveness to APRA. With authentication controls under active supervisory focus, closing gaps quickly matters.
 
Our team helps Australian financial institutions and their service providers deploy MFA that meets APRA’s expectations across privileged and remote access, without disrupting operations. If you are reviewing your MFA coverage or responding to APRA’s focus on authentication controls, we are ready to help.
 


Start your free trial today. No credit card required.

Sign up and Go