Prudential Standard CPS 234 Information Security (CPS 234) is a cross-industry standard issued by the Australian Prudential Regulation Authority (APRA), the statutory authority established in 1998 that supervises Australia’s banking, insurance, and superannuation sectors. CPS 234 commenced on 1 July 2019. Its purpose is to ensure that APRA-regulated entities can remain resilient against information security incidents, including cyberattacks, by maintaining an information security capability that matches the vulnerabilities and threats they face.
CPS 234 is principles-based and outcomes-focused rather than prescriptive. It does not hand entities a checklist of specific technologies. Instead, it requires them to maintain security controls, including authentication controls, that are commensurate with the sensitivity and criticality of their information assets. This proportionate approach is central to how the standard treats MFA: the strength of authentication is expected to rise with the sensitivity of what is being protected. The standard is supported by Prudential Practice Guide CPG 234 Information Security (CPG 234), which provides APRA’s guidance on how entities are expected to meet the requirements, including the role of authentication controls such as MFA.
CPS 234 is a legally binding prudential standard, so compliance is mandatory for APRA-regulated entities. It also connects to the broader APRA framework. Prudential Standard CPS 230 Operational Risk Management, which came into force on 1 July 2025, explicitly requires entities to meet the information security requirements of CPS 234 as part of managing technology risk. Information security and MFA are therefore part of a wider operational resilience obligation, not a standalone concern.
CPS 234 applies to all APRA-regulated entities across the banking, insurance, and superannuation industries. This includes:
CPS 234 also reaches third parties in practice. Where an APRA-regulated entity relies on a related party or third party to manage information assets, the entity remains responsible for ensuring that information security, including authentication controls, is maintained to the standard CPS 234 requires. This means service providers to APRA-regulated entities are effectively held to CPS 234 expectations through their contracts and their clients’ obligations.
A note for organizations outside Australia: CPS 234 is an Australian prudential standard, but it reaches offshore service providers that handle information assets for APRA-regulated entities. A technology provider, cloud service, or outsourced operations partner serving an Australian bank, insurer, or superannuation fund is expected to support that entity’s CPS 234 compliance, including its authentication requirements. Canadian and other international providers to the Australian financial sector should expect CPS 234 expectations to flow through their service agreements.
CPS 234 sets out a set of information security obligations covering governance, capability, controls, testing, and incident notification. The requirements most relevant to MFA concern the implementation of controls and the notification of control weaknesses. The table below maps them to their MFA relevance and how LoginTC supports them.
| CPS 234 Provision | Requirement | MFA Relevance | LoginTC Relevance |
|---|---|---|---|
| Paragraph 21 (controls) | Implement information security controls commensurate with the vulnerabilities, threats, criticality, and sensitivity of information assets | Mandatory, risk-based | MFA scaled to asset sensitivity across access points via RADIUS/LDAP/AD |
| CPG 234 (guidance): privileged access | Strengthened authentication for administrative or privileged access to sensitive or critical information assets | MFA expected | MFA for privileged and administrator accounts |
| CPG 234 (guidance): remote access | Strengthened authentication for remote access to systems and information assets | MFA expected | MFA for VPN, Windows logon, and remote desktop access |
| Paragraph 36 (notification) | Notify APRA of material information security control weaknesses | MFA coverage gaps can trigger notification | Coverage reporting and authentication logs for weakness assessment |
| Paragraph 27 (testing) | Test the effectiveness of information security controls through a systematic testing program | Authentication controls must be tested | Detailed logs and centralized visibility to support testing and assurance |
Paragraph 21 is the heart of the CPS 234 control obligation. It requires an APRA-regulated entity to implement information security controls to protect its information assets, and to do so in a way that is commensurate with the vulnerabilities and threats to those assets, and with their criticality and sensitivity. For authentication, this means the strength of the control is expected to scale with what it protects. Low-sensitivity systems may warrant standard controls, while sensitive or critical information assets warrant strengthened authentication such as MFA. APRA has stated directly that the use of MFA, and the strength of authentication controls, should be commensurate with the information being protected.
While CPS 234 sets the outcome, the Prudential Practice Guide CPG 234 gives APRA’s view on how to achieve it. CPG 234 identifies specific scenarios where strengthened authentication, such as MFA, is typically required to prevent false identification and unauthorized access. Two stand out:
APRA expects entities to review the coverage of MFA across their operating and technology environments against these expectations, and to close gaps where they exist.
CPS 234 includes a notification obligation that gives the MFA expectation real force. Under paragraph 36, an entity must notify APRA of a material information security control weakness that it expects it will not be able to remediate in a timely manner. APRA has stated that where gaps in MFA coverage have the potential to materially affect the entity or the interests of depositors, policyholders, beneficiaries, or other customers, it would consider this a material security control weakness requiring notification. In other words, an MFA coverage gap is not just a technical shortcoming; it can be a reportable regulatory matter.
Yes, in practice. CPS 234 does not name MFA as a universal mandate in the way some frameworks do, but it requires authentication controls commensurate with the sensitivity and criticality of the information being protected, and APRA has made clear that this means MFA for sensitive and critical access. APRA’s own guidance states that the use of MFA and the strength of authentication controls should be commensurate with the information being protected.
For the access scenarios APRA highlights, the expectation is unambiguous. CPG 234 identifies privileged and administrative access to sensitive or critical information assets, and remote access, as situations where strengthened authentication such as MFA is typically required. An APRA-regulated entity that left privileged or remote access to sensitive systems protected by a password alone would be operating below APRA’s stated expectations.
The notification obligation reinforces this. Because APRA treats material gaps in MFA coverage as a material security control weakness that must be reported under paragraph 36, the absence of MFA on sensitive access is not a private matter for the entity to weigh at leisure. It is something APRA expects to hear about. Through 2025, APRA repeatedly pressed regulated entities, and superannuation licensees in particular, to urgently uplift authentication controls following a series of cyber incidents affecting the sector, reinforcing that this is an active supervisory priority rather than a dormant expectation.
The practical bottom line is clear. If your entity holds sensitive or critical information assets and privileged or remote access to those assets is not protected by MFA, you are below APRA’s expectations, and the gap may be a reportable weakness. MFA on sensitive access is effectively required.
CPS 234 is a legally binding prudential standard, and a breach of a prudential standard is a breach of the law that established APRA’s powers. Unlike frameworks with fixed penalty schedules, APRA’s consequences come through its supervisory and enforcement toolkit rather than a set fine per violation.
APRA has a graduated range of enforcement options. These include issuing formal directions requiring an entity to take specific action, accepting or imposing enforceable undertakings, imposing additional conditions on an entity’s licence or authorization, requiring independent reviews at the entity’s expense, and applying additional capital requirements where risk management is found wanting. For the most serious cases, APRA can pursue disqualification of responsible individuals and other court-based remedies. The reputational consequence of APRA enforcement action in the Australian market is itself significant, given the scrutiny on financial institutions.
The notification regime is a distinctive feature. Under CPS 234, entities must notify APRA of material information security incidents within 72 hours, and of material control weaknesses, including material MFA coverage gaps, that they cannot remediate in a timely way. Failing to notify is itself a compliance failure. An entity that suffers a breach traceable to a known, unreported authentication weakness faces compounded regulatory exposure.
The risk is not hypothetical. The Australian financial sector, and the superannuation industry in particular, experienced cyber incidents involving credential compromise and authentication weaknesses that prompted direct APRA intervention through 2025. APRA’s public statements made clear that authentication control weaknesses represented a gap between its expectations and industry practice, and that it expected entities to act immediately upon identifying such weaknesses. For any APRA-regulated entity, credential-based attacks are precisely the threat that MFA is designed to counter.
CPS 234 requires controls commensurate with the sensitivity and criticality of information assets, so start by identifying and classifying those assets. Determine which systems and data are sensitive or critical, since these are where strengthened authentication is expected. This classification drives your MFA scope and provides the basis for demonstrating to APRA that your authentication controls are proportionate to what they protect.
APRA expects entities to review the coverage of MFA across their operating and technology environments. Map every privileged and administrative access path to sensitive or critical assets, and every remote access path into your environment, since these are the scenarios CPG 234 highlights. Identify where MFA is present and where gaps exist. This review is both a compliance activity and the input to your paragraph 36 assessment of whether any gap is a material weakness.
Choose an MFA solution that fits the systems Australian financial institutions run, which often include a mix of modern and legacy platforms. Look for support for RADIUS, LDAP, and Active Directory to cover the range of access points without replacing existing systems, and consider whether you need cloud, on-premises, or hybrid deployment based on your data handling and sovereignty requirements. Confirm the solution can secure privileged access and remote access, the two scenarios APRA emphasizes.
Deploy MFA first where APRA expects it most: privileged and administrative access to sensitive or critical information assets, and remote access. These carry the highest risk and are the clearest expectations in CPG 234. For privileged accounts especially, consider phishing-resistant methods such as FIDO2 security keys, which offer stronger protection against the credential theft attacks that have driven APRA’s recent focus on the sector.
Beyond the priority scenarios, extend MFA to close any coverage gaps that could materially affect the entity or its customers. Because a material gap can trigger a notification obligation, the goal is to eliminate gaps on sensitive access rather than leave them to be reported. Include third-party and service-provider access, since the entity remains responsible for information security even where a third party manages the asset.
CPS 234 requires entities to test the effectiveness of their information security controls through a systematic testing program. Test your MFA deployment the way an assessor would, confirming that privileged and remote access to sensitive assets cannot be reached without completing MFA, and that no bypass paths exist. Document the testing, since APRA expects assurance that controls are effective, not merely present.
Ensure your MFA solution generates detailed authentication logs that support incident detection and provide evidence of coverage. Strong logging helps you detect credential-based attacks quickly and supports the incident notification obligations under CPS 234, including the 72-hour incident notification timeline. Establish a process to assess whether any identified MFA gap is a material weakness requiring notification under paragraph 36, and review your coverage regularly as your environment changes.
LoginTC is well suited to the environments Australian financial institutions operate, where MFA needs to cover privileged and remote access across a mix of modern and legacy systems. LoginTC integrates through RADIUS, LDAP, and Active Directory, so banks, insurers, and superannuation licensees can enforce MFA across the access points CPS 234 emphasizes without replacing existing infrastructure.
For the privileged and remote access scenarios that CPG 234 highlights, LoginTC enforces MFA on administrator accounts, VPN and remote connections, Windows logon, and remote desktop access. It supports phishing-resistant factors such as FIDO2 security keys and hardware tokens, which are strong choices for the privileged access APRA is most concerned about and for the credential-based threats that have prompted its recent supervisory focus. Because CPS 234 expects authentication commensurate with asset sensitivity, LoginTC’s per-application and role-based policies let entities apply stronger authentication to their most critical systems.
For entities with data sovereignty requirements or a preference to keep authentication infrastructure within their own environment, LoginTC’s on-premises deployment option provides that control. Detailed authentication logs and centralized administration give compliance and risk teams visibility into MFA coverage, support the testing and assurance CPS 234 requires, and provide the evidence needed to assess whether any gap is a material weakness. This supports both the control and the notification sides of the standard.
Explore LoginTC for Finance | View All Connectors
CPS 234 requires authentication controls commensurate with the sensitivity and criticality of the information being protected, and APRA has stated that this means MFA for sensitive and critical access. Guidance in CPG 234 identifies privileged and administrative access to sensitive or critical information assets, and remote access, as scenarios where strengthened authentication such as MFA is typically required. While CPS 234 is principles-based rather than prescriptive, MFA on sensitive access is effectively required, and material gaps can be a reportable weakness.
CPS 234 applies to all APRA-regulated entities, including authorised deposit-taking institutions (banks, credit unions, building societies), general insurers, life insurers, private health insurers, superannuation (RSE) licensees, and non-operating holding companies. It also reaches service providers in practice, because a regulated entity remains responsible for information security even where a third party manages its information assets.
CPS 234 does not mandate a specific technology. It requires authentication strength commensurate with the sensitivity of the information protected. Acceptable methods include authenticator apps, hardware tokens, and FIDO2 security keys. For privileged access and other high-value scenarios, phishing-resistant methods such as FIDO2 keys are strongly preferred, particularly given APRA’s recent focus on credential-based attacks. SMS-based codes are weaker and are increasingly seen as insufficient for sensitive access.
APRA has stated that where gaps in MFA coverage have the potential to materially affect the entity or the interests of depositors, policyholders, beneficiaries, or other customers, it considers this a material security control weakness. Under paragraph 36 of CPS 234, a material control weakness that cannot be remediated in a timely manner must be notified to APRA. This makes closing material MFA gaps a regulatory priority, not just a technical improvement.
CPS 234 is APRA’s information security standard, focused on protecting information assets, including through authentication controls. CPS 230 Operational Risk Management, in force since 1 July 2025, is broader and focuses on operational resilience, critical operations, and service provider management. CPS 230 explicitly requires entities to meet the information security requirements of CPS 234 as part of managing technology risk, so the two operate together rather than in isolation.
CPS 234 is an Australian prudential standard, but it reaches offshore service providers that manage information assets for APRA-regulated entities. A cloud provider, technology vendor, or outsourced operations partner serving an Australian bank, insurer, or superannuation fund is expected to support that entity’s CPS 234 compliance, including its authentication requirements. International providers to the Australian financial sector should expect these expectations to flow through their contracts.
CPS 234 does not mandate a specific hosting location, but it does expect entities to manage information security risk, which can include data sovereignty considerations. Both cloud-based and on-premises LoginTC deployments can support CPS 234 compliance. For entities that prefer to keep authentication infrastructure within their own environment or within Australia, LoginTC’s on-premises option provides that control and can simplify sovereignty and evidence considerations.
Meeting CPS 234’s authentication expectations means covering privileged and remote access to your sensitive systems, scaling authentication strength to asset sensitivity, and being able to demonstrate coverage and effectiveness to APRA. With authentication controls under active supervisory focus, closing gaps quickly matters.
Our team helps Australian financial institutions and their service providers deploy MFA that meets APRA’s expectations across privileged and remote access, without disrupting operations. If you are reviewing your MFA coverage or responding to APRA’s focus on authentication controls, we are ready to help.