Back to Blog
Insights11 min read

CPS 234 vs NIST: Key Differences and Compliance Strategies

A

Alexander Sverdlov

Security Analyst

7/20/2026
CPS 234 vs NIST: Key Differences and Compliance Strategies

If you run security or technology at an APRA-regulated business in Australia, CPS 234 is not optional and NIST 800-53 is not required. Yet I keep meeting teams who treat the two as competing choices, or who bolt on NIST controls hoping it will somehow satisfy the regulator. Neither view is right. CPS 234 tells you what outcomes APRA expects. NIST 800-53 gives you a detailed, tested catalogue of controls you can use to actually achieve those outcomes. Used together, correctly, they save you rework and give an auditor far less to argue with.

I have run security assessments and readiness work across 14 countries since 2013, and the pattern is the same everywhere a principles-based regulation meets a control catalogue: people either under-implement because the regulation is vague, or over-implement because the catalogue is huge. This article walks through what each framework actually is, where they genuinely differ, how the control domains map to each other, and a practical strategy to satisfy CPS 234 while borrowing the parts of NIST 800-53 that are worth the effort.

What CPS 234 Actually Requires

CPS 234 is APRA's Prudential Standard on Information Security. It has applied to APRA-regulated entities since 1 July 2019 and covers authorised deposit-taking institutions, general and life insurers, private health insurers, and superannuation (RSE) licensees. It is principles-based, which means it describes required outcomes rather than prescribing specific technologies. The companion guidance, CPG 234, explains APRA's expectations in more detail but is not itself enforceable.

The core obligations are compact and worth knowing precisely:

  • Roles and responsibilities. The Board is ultimately accountable for information security. The standard requires you to clearly define the roles of the Board, senior management, governing bodies, and individuals.
  • Information security capability. You must maintain capability that is commensurate with the size and extent of threats to your information assets, and that enables the sound operation of the entity. Capability must scale with the potential consequences of a compromise.
  • Controls and testing. You must implement controls to protect information assets, and you must systematically test the effectiveness of those controls through a formal testing program. Testing frequency should reflect the rate of change of the environment and the criticality of the asset.
  • Third-party and related-party management. Where information assets are managed by a third party, you remain responsible. You must assess the third party's information security capability.
  • Incident notification. You must notify APRA no later than 72 hours after becoming aware of a material information security incident, and no later than 10 business days after identifying a material information security control weakness that you cannot remediate in a timely manner.

Notice what CPS 234 does not do. It does not tell you to use multi-factor authentication, or to encrypt data in transit, or to keep audit logs for a specific period. It expects you to reach a defensible security outcome and to be able to demonstrate it. That deliberate flexibility is exactly why many teams reach for a control catalogue like NIST 800-53 to fill in the "how."

What NIST 800-53 Actually Is

NIST Special Publication 800-53 is a catalogue of security and privacy controls maintained by the US National Institute of Standards and Technology. Revision 5, the current version, organises controls into 20 families and contains over 1,000 individual controls and control enhancements. It was written for US federal information systems, but it is used voluntarily worldwide because it is thorough, freely available, and mapped to many other standards.

The 20 control families in Revision 5 are: Access Control (AC), Awareness and Training (AT), Audit and Accountability (AU), Assessment, Authorization and Monitoring (CA), Configuration Management (CM), Contingency Planning (CP), Identification and Authentication (IA), Incident Response (IR), Maintenance (MA), Media Protection (MP), Physical and Environmental Protection (PE), Planning (PL), Program Management (PM), Personnel Security (PS), PII Processing and Transparency (PT), Risk Assessment (RA), System and Services Acquisition (SA), System and Communications Protection (SC), System and Information Integrity (SI), and Supply Chain Risk Management (SR). Revision 5 notably added the SR family for supply chain risk and the PT family for privacy, and it integrated privacy controls throughout rather than treating them separately.

Controls are grouped into baselines (documented in the companion SP 800-53B) for low, moderate, and high-impact systems, so you are not expected to apply all 1,000 controls to everything. The point is that NIST gives you specificity: named controls, defined parameters, and implementation guidance that a principles-based regulation deliberately leaves open.

The Real Differences

Stripped of the marketing, the differences come down to intent, structure, and enforceability. CPS 234 is a regulatory outcome you are legally required to meet in Australia. NIST 800-53 is a voluntary toolkit you can choose to implement. One tells you where to arrive; the other hands you a detailed map of how to get there.

AspectCPS 234NIST 800-53 Rev 5
TypeEnforceable prudential standardVoluntary control catalogue
IssuerAPRA (Australia)NIST (United States)
Who it bindsAPRA-regulated banks, insurers, super fundsUS federal systems; adopted voluntarily elsewhere
ApproachPrinciples-based, outcome-focusedPrescriptive, control-by-control
SizeConcise standard plus CPG 234 guidance20 families, 1,000+ controls and enhancements
Scaling mechanismCommensurate with size and threatLow / moderate / high baselines (800-53B)
Incident handlingMandatory APRA notification (72 hours / 10 business days)IR family controls; no external regulator by default
Board accountabilityExplicit and centralAddressed via PM family, less prominent

The practical takeaway: CPS 234 decides whether you are compliant, and NIST 800-53 helps you build the evidence that you are. You cannot substitute one for the other, but you can let NIST do the heavy lifting on control design while CPS 234 defines the scope and the accountability structure.

Mapping the Control Domains

The most useful exercise is to line CPS 234's expectations up against the NIST families that operationalise them. Below is how I map them during readiness work. This is not a certified crosswalk; it is a practical starting point that gives auditors a clear line of sight from obligation to control.

Governance and Roles

CPS 234 puts Board accountability and clearly defined roles at the centre. NIST's Program Management (PM) family and Planning (PL) family carry this weight, covering the information security program plan, senior security officer roles, and organisation-wide risk management. Use PM controls to document who owns what, how the program is resourced, and how risk decisions reach the Board. This is also where you formalise the risk appetite that CPS 234 assumes exists.

Risk Management and Testing

CPS 234 requires systematic testing of control effectiveness. NIST's Risk Assessment (RA) family, including RA-3 for the risk assessment process and RA-5 for vulnerability monitoring and scanning, plus the Assessment, Authorization and Monitoring (CA) family with CA-2 (control assessments) and CA-7 (continuous monitoring), give you a defensible testing regime. Together they let you show the regulator a repeatable cycle rather than a one-off penetration test. A structured vulnerability assessment and periodic penetration testing map directly onto RA-5 and CA-8.

Access Control and Identity

CPS 234 expects controls that prevent unauthorised access proportionate to the sensitivity of the asset. NIST's Access Control (AC) family (AC-2 account management, AC-6 least privilege) and Identification and Authentication (IA) family (IA-2 for multi-factor authentication) turn that expectation into specific, testable requirements. If you operate on Microsoft or a similar identity platform, an Active Directory security assessment is one of the fastest ways to prove AC and IA controls are actually working rather than merely documented.

Logging and Assurance

APRA expects you to detect and respond to incidents, which is impossible without logging. NIST's Audit and Accountability (AU) family (AU-2 event logging, AU-6 audit review) specifies what to log, how to protect logs, and how to review them. This is the evidentiary backbone for the 72-hour notification clock.

Incident Response

CPS 234's notification obligations sit on top of an incident response capability. NIST's Incident Response (IR) family (IR-4 handling, IR-6 reporting, IR-8 incident response plan) gives you the structure. The one thing NIST does not include is the APRA notification workflow itself, so you must add the 72-hour and 10-business-day triggers into your IR plan explicitly.

Third-Party and Supply Chain

This is where Revision 5 shines. CPS 234 holds you responsible for information assets managed by third parties. NIST's Supply Chain Risk Management (SR) family and System and Services Acquisition (SA) family give you concrete controls for assessing and monitoring vendors, closing the gap the earlier NIST revision left open.

CPS 234 ExpectationPrimary NIST 800-53 FamiliesExample Controls
Board and role accountabilityPM, PLPM-1, PM-2, PL-1
Risk assessment and testingRA, CARA-3, RA-5, CA-2, CA-7, CA-8
Preventing unauthorised accessAC, IAAC-2, AC-6, IA-2
Logging and detectionAU, SIAU-2, AU-6, SI-4
Incident response and notificationIRIR-4, IR-6, IR-8
Third-party managementSR, SASR-3, SR-6, SA-9
Data protection in transitSCSC-7, SC-8, SC-13

A Practical Compliance Strategy

Here is the sequence I use when a regulated entity wants to meet CPS 234 and use NIST 800-53 as the control backbone. It keeps the regulator's outcomes in the driving seat and treats NIST as the implementation reference, not the goal.

  1. Inventory your information assets first. Everything in CPS 234 is scaled to the criticality and sensitivity of assets. If you do not have a current, classified inventory, nothing downstream is defensible. Build it before you touch a control catalogue.
  2. Anchor on CPS 234 outcomes. Write down each obligation as an outcome you must be able to evidence: defined roles, tested controls, third-party assurance, incident notification. These become your assessment criteria.
  3. Select a NIST baseline per system. Use the moderate baseline as a sensible default for systems holding customer or financial data, and step up to high for your most critical assets. Do not apply the full catalogue everywhere; that is how programs stall.
  4. Map controls to outcomes, not the reverse. For each CPS 234 outcome, pull the relevant NIST controls from the table above. This keeps the program lean and gives auditors a clean trace from obligation to implementation.
  5. Build the testing program. CPS 234 explicitly requires systematic testing. Combine continuous vulnerability scanning (RA-5), scheduled control assessments (CA-2), and independent penetration testing (CA-8) on a cadence tied to change and criticality.
  6. Wire in the APRA notification triggers. Put the 72-hour incident and 10-business-day control-weakness clocks directly into your incident response runbook, with named owners and a tested escalation path.
  7. Close the loop with the Board. Produce reporting that a non-technical Board can act on. CPS 234 makes them accountable, so they need visibility into risk decisions, testing results, and open weaknesses.

Most mid-sized regulated entities do not have the internal bandwidth to stand this up while also running day-to-day security. This is precisely the kind of program a virtual CISO or fintech virtual CISO engagement is built for: senior leadership to own the framework mapping, the testing program, and the Board reporting without the cost of a permanent executive hire. If you want an independent view of where you stand today, an IT security audit against the CPS 234 outcomes is the fastest way to find the gaps before an auditor does.

Common Mistakes I See

  • Treating NIST as the compliance target. Implementing 800-53 does not make you CPS 234 compliant. The regulator judges you against CPS 234 outcomes, not against a control count.
  • Applying every NIST control everywhere. Without baselines and asset classification, teams drown in controls that add no risk reduction and delay the whole program.
  • Skipping the testing evidence. CPS 234 is explicit that testing must be systematic. A single annual pen test is not a program and will not survive scrutiny.
  • Forgetting the notification clocks. The 72-hour and 10-business-day obligations are unique to CPS 234 and absent from NIST. If they are not in your runbook, you will miss them under pressure.
  • Ignoring third parties. You remain responsible for outsourced assets. Vendor risk is one of the most common gaps I find during assessments.

Frequently Asked Questions

Does implementing NIST 800-53 make my organisation CPS 234 compliant?
No. CPS 234 is an enforceable APRA standard judged on outcomes; NIST 800-53 is a voluntary control catalogue. NIST helps you build and evidence the controls that satisfy CPS 234, but compliance is assessed against CPS 234 itself.

Is CPS 234 mandatory, and who does it apply to?
Yes. It has applied since 1 July 2019 to APRA-regulated entities: authorised deposit-taking institutions, general and life insurers, private health insurers, and superannuation (RSE) licensees.

What are the CPS 234 incident notification timeframes?
You must notify APRA within 72 hours of becoming aware of a material information security incident, and within 10 business days of identifying a material control weakness you cannot remediate in a timely manner.

Which NIST baseline should a financial services firm use?
The moderate baseline is a sensible default for systems holding customer or financial data, stepping up to high for your most critical assets. Baselines come from SP 800-53B and are chosen per system based on impact.

What did Revision 5 of NIST 800-53 change that matters here?
It added a dedicated Supply Chain Risk Management (SR) family and a PII Processing and Transparency (PT) family, and integrated privacy controls throughout. The SR family is especially useful for CPS 234's third-party responsibilities.

Can a virtual CISO run a CPS 234 program?
Yes. A virtual CISO can own the framework mapping, the systematic testing program, third-party assurance, and Board-level reporting, which are exactly the areas CPS 234 emphasises, without the cost of a full-time executive.

If you are working toward CPS 234 and want the control depth of NIST 800-53 without the wasted effort, get in touch with Atlant Security for a readiness review tailored to your environment.

Alexander Sverdlov

Alexander Sverdlov

Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.

CPS 234 vs NIST 800-53: Key Differences | Atlant Security