What Does CPS 234 Compliance Cost for Financial Institutions in Australia?
Alexander Sverdlov
Security Analyst

Every APRA-regulated entity I have worked with eventually asks the same question about CPS 234: what is this going to cost us? It is a fair question, and it deserves a better answer than a single number. The honest truth is that CPS 234 compliance cost varies enormously depending on where you start, how complex your environment is, and how much of your infrastructure you have handed to third parties. A small mutual with a tidy cloud stack and a large bank with decades of legacy systems are not in the same universe.
What I can give you, drawn from running security assessments across 14 countries since 2013, is a clear map of what drives CPS 234 cost up and down, so you can budget realistically and avoid the two failure modes I see most often: spending heavily on tools that do not close your real gaps, and underspending on the testing and evidence that APRA actually reviews. No invented case studies, no fake dollar guarantees. Just the economics.
Why there is no single CPS 234 price tag
CPS 234 is deliberately outcome-based. APRA does not prescribe a product list or a spending level. The standard requires you to maintain an information security capability commensurate with the size and extent of the threats to your information assets. "Commensurate" is the operative word, and it is why cost scales with your risk profile rather than with a fixed tariff.
Three variables move the number more than anything else:
- Your starting maturity. An entity that already has MFA, logging, patching discipline, and documented policies is refining and evidencing. One starting from informal, undocumented controls is building. The gap between those two is the single biggest cost driver.
- Environment complexity. More systems, more legacy technology, more integrations, and more data all raise the effort to secure, test, and document.
- Third-party footprint. CPS 234 holds you accountable for information assets managed by third parties, so a heavy reliance on outsourced or cloud providers adds vendor assessment and contract work.
The real cost categories
Rather than quote fabricated figures, here is where CPS 234 budget genuinely goes. Get quotes against these categories from any provider and you will be able to compare like for like.
| Cost category | What you are paying for | What makes it cheaper |
|---|---|---|
| Gap assessment | Honest baseline of current controls versus CPS 234 | Existing documentation, a clearly scoped environment |
| Governance and policy | Board accountability, policy framework, reporting | Reusing an existing risk governance structure |
| Controls and tooling | MFA, encryption, logging, endpoint and patch management | Using cloud-native tooling you already pay for |
| Testing | Penetration testing, vulnerability assessment, detection testing | Right-sizing frequency to asset sensitivity |
| Internal audit | Independent review of control effectiveness | Competent in-house audit, or targeted external review |
| Ongoing operation | Monitoring, incident response readiness, evidence upkeep | Continuous evidence collection, a virtual CISO model |
1. Gap assessment
Almost every sensible CPS 234 programme starts here, and it is money well spent because it prevents you from buying controls you do not need or missing gaps you cannot see. A focused IT security audit against the standard tells you exactly where you stand. Skipping this step is how firms end up spending on shiny tooling while a basic access-control weakness sits unaddressed.
2. Governance and policy framework
CPS 234 requires board-level accountability and a policy framework proportionate to your exposures. If you already have a risk governance structure, extending it to information security is far cheaper than building governance from scratch. The cost here is mostly senior time and, where you lack an in-house security leader, the cost of someone competent to own the programme.
3. Controls and tooling
This is where budgets balloon if you are not disciplined. Identity and access management, encryption, logging and monitoring, endpoint protection, and patch management are the core. The mistake is assuming you must buy an expensive new platform for each. Most cloud providers already give you logging, access review, and configuration tooling you are paying for whether you use it or not. If your environment is cloud-based, our cloud security consulting focuses on getting these controls right with what you already own before recommending new spend.
4. Testing
CPS 234 explicitly requires systematic testing of control effectiveness, and this is a recurring cost, not a one-off. Regular penetration testing and ongoing vulnerability assessment are the backbone. The cost lever you control is frequency and depth: test your most sensitive, fastest-changing systems more often, and right-size the rest. Under-testing is a false saving, because APRA and your own internal audit will look for evidence that controls actually work.
5. Internal audit
The standard requires independent review of the design and operating effectiveness of your controls, including those held by third parties. If your internal audit function has genuine security competence, this cost is contained. If it does not, budget for a targeted independent assessment rather than pretending a generalist review satisfies the requirement.
6. Ongoing operation
CPS 234 is not a project with an end date. Monitoring, incident response readiness, evidence maintenance, and keeping controls current all continue year after year. This is where a fintech virtual CISO or virtual CISO model often works out cheaper than a full-time hire, because you get experienced leadership scaled to what a smaller regulated entity actually needs.
Cost by entity size, in relative terms
I will not attach invented dollar amounts to these, because anyone who quotes you a precise figure without seeing your environment is guessing. But the relative shape is reliable:
- Smaller entities (a small mutual, a focused insurer, a fintech ADI) with modern, mostly cloud infrastructure tend to have the lowest cost, provided they scope tightly and reuse cloud-native controls. Their main risk is under-resourcing governance and testing.
- Mid-sized entities carry more systems and more third-party relationships, so vendor risk management and testing scope grow. Complexity, not headcount, drives their cost.
- Large entities with legacy estates face the highest cost, dominated by securing and testing older systems and by the sheer breadth of assets to classify, control, and audit.
The pattern that matters: cost tracks complexity and legacy debt far more than it tracks company size. A lean, cloud-native firm can comply for a fraction of what a similarly sized firm with tangled legacy systems will spend.
Where firms waste money on CPS 234
- Buying tools before assessing gaps. Tooling bought without a gap assessment often addresses risks you did not have while missing ones you did.
- Over-scoping. Treating every system as equally critical spreads spend thin. Classification exists precisely so you can concentrate controls where they matter.
- Cheap, box-ticking testing. A superficial test that misses real weaknesses is worse than no test, because it creates false confidence and leaves you exposed when it counts.
- Ignoring third parties. Underinvesting in vendor assessment leaves a large slice of your regulated assets unmanaged, and APRA still holds you accountable.
- Treating it as one-and-done. Firms that do not budget for ongoing operation face a scramble every audit cycle, which costs more than steady maintenance.
How to keep CPS 234 cost under control
- Start with a gap assessment so every dollar afterwards targets a real weakness.
- Classify assets first, then concentrate spending on the critical and sensitive ones.
- Exhaust cloud-native and existing tooling before buying new platforms.
- Right-size testing frequency to asset sensitivity and rate of change.
- Map CPS 234 controls once and reuse them for overlapping obligations like CPS 230, the Privacy Act, and ISO 27001 through our ISO 27001 readiness work, rather than building parallel programmes.
- Use a virtual CISO for ongoing leadership if a full-time hire is not justified by your size.
The cost of not complying
It is worth putting the compliance spend in perspective. CPS 234 is enforceable, and the alternative to compliance is not zero cost. A material information security incident carries breach response costs, potential customer loss, and reportable obligations to APRA within 72 hours. A control weakness you cannot remediate in time must be reported within 10 business days. Regulatory attention, remediation under pressure, and reputational damage all cost far more than a well-run compliance programme. The right framing is not "how much does CPS 234 cost" but "how much cheaper is it than the incident it is designed to prevent."
Getting a real number for your situation
The only way to get an accurate cost for your entity is to have someone assess your actual environment against the standard. That is what we do at Atlant Security. I have personally led over 200 security assessments, and our approach to CPS 234 is to scope tightly, reuse what you already own, and put budget where your genuine risk sits rather than where a vendor wants to sell. If you want a clear, honest cost estimate and a plan to match, book a call and we will give you a fixed-scope proposal instead of a vague range.
Frequently Asked Questions
How much does CPS 234 compliance cost?
There is no single figure, because CPS 234 requires controls commensurate with your specific threats. Cost is driven by your starting maturity, environment complexity, and third-party footprint far more than by company size. The reliable way to get a real number is a gap assessment of your actual environment against the standard.
What is the biggest driver of CPS 234 cost?
Your starting maturity. An entity that already has MFA, logging, patching, and documented policies is mostly evidencing what it has, which is relatively inexpensive. One starting from informal, undocumented controls must build them first, which costs considerably more. Legacy system complexity is the second biggest driver.
Can we reduce cost by using tools we already have?
Usually, yes. Most cloud providers include logging, access review, and configuration tooling you are already paying for. Exhausting those, and reusing an existing risk governance structure, closes a large part of CPS 234 before you buy anything new. Assess gaps first so new spend targets real weaknesses.
Is CPS 234 a one-time or ongoing cost?
Ongoing. Testing, monitoring, incident response readiness, internal audit review, and evidence maintenance all recur. Budgeting only for an initial project leads to a costly scramble each cycle. A virtual CISO model often makes the ongoing cost more predictable and lower than a full-time hire for smaller entities.
Does third-party risk really add to the cost?
Yes. CPS 234 holds you accountable for information assets managed by related parties and third parties, and internal audit must review the effectiveness of controls those providers maintain. A heavy reliance on outsourced or cloud services adds vendor assessment and contract work that firms frequently underestimate.
Is compliance cheaper than a breach?
Almost always. A material incident brings response costs, customer loss, mandatory 72-hour reporting to APRA, and reputational damage, on top of the remediation you will have to fund under pressure. A steady, well-scoped compliance programme is far less expensive than absorbing the event it is designed to prevent.

Alexander Sverdlov
Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.