APRA CPS 234 for MSPs: assurance your regulated clients can use
If a client is regulated by APRA, their obligations under CPS 234 extend to the service providers that look after their information assets, and that includes you.
Why CPS 234 reaches the MSP
Prudential Standard CPS 234 Information Security sets information security requirements for APRA-regulated entities. Among them, an entity must assess the information security capability of third parties that manage its information assets and be satisfied that controls are maintained commensurate with the risk. In practice, regulated clients ask their IT provider for evidence.
What Graften provides
- CPS 234 is one of the frameworks the Compliance module maps client findings to, alongside Essential Eight, ISO 27001, NIST CSF and SOC 2.
- A gap analysis per client showing which control areas are covered by measured evidence and which are not.
- Evidence packages for CPS 234 that can be shared with a client's risk team or auditor through a 30-day time-limited link.
- A risk register and regulatory alerts, so regulatory changes relevant to the client are surfaced and tracked.
Evidence, not a certificate. CPS 234 is not something a tool grants. Graften helps you collect, organise and present the evidence a regulated client needs, and shows plainly where evidence is missing.
Frequently asked questions
Is Graften data stored in Australia?
Yes. Data is stored in AWS ap-southeast-2 (Sydney).
Does mapping to CPS 234 mean a client is compliant?
No. Compliance is the regulated entity's responsibility. The mapping shows what evidence exists against each area so the entity can assess its third parties.