HomeBlogsAPRA CPS 234 Penetration Testing: What Evidence Does APRA Actually Require, and What Happens When It Is Missing?

APRA CPS 234 Penetration Testing: What Evidence Does APRA Actually Require, and What Happens When It Is Missing?

Updated: October 01, 2026|4.2 min read
APRA CPS 234 Penetration Testing: What Evidence Does APRA Actually Require, and What Happens When It Is Missing?
APRA CPS 234 Penetration Testing Requirements

The testing requirements in CPS 234 are not prescriptive about methodology. The standard does not use the words "penetration test." What it requires is that entities test the effectiveness of their information security controls, with the nature and frequency of testing commensurate with the criticality of the assets being protected and the rate of change in the threat environment.

Penetration testing is the standard mechanism regulated entities use to meet that requirement. It is not the only mechanism, but it is the one APRA auditors and supervisors accept as evidence of systematic control testing under the standard. Understanding what the paragraphs actually say, and what the paragraph 36A consequence is for unresolved findings, is more useful to a compliance team than any summary of what APRA "recommends."

What Paragraphs 27 and 28 Actually Require

What Paragraphs 27 and 28 Actually Require

Paragraphs 27 and 28 of CPS 234 require APRA-regulated entities to test the effectiveness of their information security controls through a systematic testing programme.

The nature and frequency of the systematic testing must be commensurate with the rate at which vulnerabilities and threats change, the criticality and sensitivity of the information asset, the consequences of an information security incident, the risks associated with exposure to environments where the entity is unable to enforce its information security policies, and the materiality and frequency of change to information assets. Testing must occur when there are material changes to information assets and at least annually. This is the clause most auditors reference when they ask how recently the last penetration test ran.

The practical implication is that "annually" is a floor, not a ceiling. An APRA-regulated entity that launches a new digital banking product, migrates workloads to a cloud environment, or undergoes a material system change has a testing obligation triggered by that change, independent of the annual cycle. For APRA-regulated entities managing third-party cloud infrastructure, if data is managed by third parties, they must also comply with CPS 234, including undergoing penetration testing.

What Paragraph 28A Requires from the Testing Provider

Beyond the frequency requirement, CPS 234 addresses who can conduct the testing. The standard requires testing to be performed by appropriately skilled and functionally independent specialists. This has two implications for regulated entities selecting a penetration testing provider.

Functional independence means the testing cannot be performed by the team responsible for building or operating the systems being tested. Internal security teams can support scoping and coordination. They cannot conduct the testing that produces APRA compliance evidence without compromising the independence requirement. CREST-certified penetration testing from an external provider satisfies functional independence, provides independently validated tester competency evidence, and produces a report that references recognised methodology standards.

For third-party and cloud environments, the independence requirement applies to those environments as well. An APRA-regulated entity cannot rely on a vendor's self-assessment as a substitute for independent testing of the controls that protect the regulated entity's information assets.

The guide to how CREST penetration testing works in Australia covers how to verify CREST accreditation and why firm-level and individual-level certification both matter for APRA evidence purposes.

What am I risking by not acting?

Your Last Pentest Is Already Out of Date

Every week you ship without continuous testing is a week a vulnerability goes unseen. See what Capture The Bug finds in your first engagement.

What Paragraph 36A Means for Unresolved Findings

Paragraph 36A Notifiable Matter for Unresolved Findings

This is the APRA CPS 234 consequence that most compliance teams underestimate.

When APRA identifies a deficiency in a regulated entity's testing programme through a supervisory review or attestation process, the entity is required to remediate the deficiency within agreed timeframes and to notify APRA if a material information security control weakness is identified that has not been remediated within a defined period. A material weakness identified through testing that remains open and unremediated is a notifiable matter under paragraph 36A of the standard.

Conducting a thorough penetration test and receiving a significant finding creates an obligation. Receiving the finding is not the risk. Failing to remediate or escalate it in accordance with the standard is. Organisations that conduct penetration testing primarily to produce a document for auditors, without a genuine remediation process attached, are creating a compliance liability rather than reducing one.

This reframes the penetration test from a compliance exercise into a risk management obligation. The test is not complete when the report is delivered. It is complete when material findings are remediated, retested, and the remediation evidence is archived against the timeline paragraph 36A creates.

For how the remediation and re-testing cycle produces the specific evidence that satisfies paragraph 36A requirements, the guide to what happens after a penetration test covers the confirmation steps that convert a finding list into confirmed compliance evidence that APRA supervisors accept.

What APRA's Thematic Review Found

APRA Thematic Review Penetration Testing Findings

APRA's supervisory observations have identified recurring gaps in how regulated entities approach their testing programmes. Auditors are looking for proof: security monitoring logs, penetration testing results, vulnerability management programmes, and board-level oversight. Auditors trace controls end-to-end, from policy through to evidence, often requesting artefacts such as SIEM logs, incident tickets, and control testing outputs.

The most common gap is not that testing did not occur. It is that testing occurred and remediation did not follow. An entity that can produce a penetration test report but cannot produce the retest evidence confirming material findings were closed has satisfied paragraph 27 and failed paragraph 36A simultaneously. That combination is the outcome APRA's thematic review found to be the most prevalent compliance deficiency across the entities reviewed.

For APRA-regulated entities approaching their next attestation cycle, the penetration testing programme should produce three distinct artefacts: the initial engagement report, the remediation evidence for each material finding, and the retest report confirming closure. Each is a separate document with a separate archival requirement. The penetration test report alone is necessary but not sufficient.

APRA CPS 234 Scoping Consultation

Book a scoping consultation with Capture The Bug to structure an APRA CPS 234-aligned penetration testing programme that produces all three required artefacts with CREST-certified evidence.

Plan Security Better

Plan Your Annual Pentesting Strategy the Right Way

Learn how modern SaaS companies structure pentesting across the year to reduce risk, stay compliant, and avoid last-minute panic before audits.

Frequently Asked Questions

Does APRA CPS 234 require penetration testing for Australian financial institutions?

CPS 234 does not use the words "penetration test" in the standard text. Paragraphs 27 and 28 require APRA-regulated entities to conduct systematic testing of information security controls, with testing frequency commensurate with asset criticality, threat environment change rate, and materiality of system changes. Penetration testing is the standard mechanism regulated entities use to satisfy this requirement. Testing must occur at least annually and whenever a material change to information assets occurs. APRA auditors reference the most recent penetration test as the primary evidence of systematic control testing.

How often must APRA-regulated entities conduct penetration testing?

At least annually as a baseline, with additional testing required following any material change to information assets. Material changes that trigger a testing obligation include new product launches, significant system changes, cloud migrations, and material changes to third-party service providers handling regulated entity information assets. Paragraph 28 is principles-based: the frequency must reflect the rate at which vulnerabilities and threats change, the criticality of the assets, and the consequences of a security incident. For high-criticality assets with frequent change, annually is insufficient.

What is the paragraph 36A notifiable matter requirement under CPS 234?

Paragraph 36A requires APRA-regulated entities to notify APRA if a material information security control weakness is identified that has not been remediated within a defined period. A material weakness identified through penetration testing that remains open and unremediated is a notifiable matter under this paragraph. This means conducting a thorough penetration test and receiving a material finding creates a remediation obligation, not just a recommendation. Failing to remediate or escalate a material finding in accordance with the standard creates a compliance liability. The penetration test report alone does not satisfy the obligation; remediation evidence and retest confirmation are also required.

Does CPS 234 require independent penetration testing from an external provider?

Paragraph 28A of CPS 234 requires testing to be performed by appropriately skilled and functionally independent specialists. Functional independence means the testing cannot be conducted by the team responsible for building or operating the systems under test. Internal security teams cannot produce APRA compliance evidence without compromising this independence requirement. CREST-certified external penetration testing satisfies functional independence, provides independently validated tester competency, and produces reports that reference recognised methodology standards accepted by APRA supervisors.

Does CPS 234 penetration testing requirement apply to material service providers and third parties?

Yes. CPS 234 extends to material service providers and third-party vendors that manage APRA-regulated entity information assets. Where data is managed by a third party, including cloud providers, that third party must also comply with CPS 234 requirements, including undergoing penetration testing. An APRA-regulated entity cannot rely on a vendor's self-assessment as a substitute for independent testing of the controls protecting the regulated entity's information assets.

Jitendra Kumar Singh

Jitendra Kumar Singh

Associate Director & Pentester • eWPTX

Cybersecurity professional & pentester | Associate Director @ CaptureTheBug | Securing web, APIs & networks one vulnerability at a time.

- 07 / RESOURCES

Read Industry Insights

Security that works like you do.

Flexible, scalable PTaaS for modern product teams.