CFOtech Australia - Technology news for CFOs & financial decision-makers
Australia
How CPS 230 will indirectly impact manufacturers through their customers and suppliers

How CPS 230 will indirectly impact manufacturers through their customers and suppliers

Wed, 26th Aug 2026 (Today)
Adam Bowles
ADAM BOWLES Regional Director, Australia & New Zealand OneAdvanced

For many Australian manufacturers, APRA's CPS 230 Operational Risk Management standard may seem like a financial services issue. It applies directly to APRA-regulated entities, including banks, insurers and superannuation funds, not to manufacturers in general. However, that does not mean manufacturers can ignore it.

CPS 230 is part of a broader regulatory shift that is changing how large organisations assess operational resilience across their supply chains. The practical effect for manufacturers will not always come through direct regulation. It will often come from customers, lenders, insurers, logistics partners, technology providers and procurement teams, who are asking tougher questions about continuity, cyber risk, supplier concentration, data, subcontractors and recovery planning.

APRA says CPS 230 requires regulated entities to maintain critical operations during disruptions and to manage risks arising from service providers. The standard took effect on 1 July 2025, with pre-existing service provider arrangements required to comply from the earlier of the next contract renewal or 1 July 2026.

Timing matters as APRA-regulated entities update contracts and supplier registers; manufacturers supplying financial services organisations, insurers, superannuation funds or their major service providers may start to see new operational resilience expectations reflected in commercial agreements.

This is not just about traditional procurement. CPS 230 requires APRA-regulated entities to identify and maintain a register of material service providers and to manage the risks associated with those providers. It also requires formal agreements covering service levels, data ownership and control, audit access, liability, indemnity, subcontracting notifications, force majeure and termination rights.

For manufacturers, resilience is becoming a valuable commercial credential. A customer may want evidence that a manufacturer can continue supplying critical components, meet agreed service levels during a disruption, manage cyber risk, maintain accurate operational data and explain how it monitors its own suppliers. In some cases, the manufacturer may not be a direct material service provider to an APRA-regulated entity, but it may sit within the fourth-party network that supports one.

The Australian Signals Directorate's supply chain guidance makes this point clear: cyber supply chain risk can originate with suppliers, manufacturers, distributors and retailers and organisations can transfer the cyber supply chain risk they hold to their customers. It recommends identifying the supply chain, understanding risk, setting security expectations, auditing compliance and continuously monitoring for improvement.

The Cyber Security Act 2024 also introduced mandatory reporting of ransomware and cyber extortion payments, with the rules commencing on 30 May 2025. This does not make every manufacturer a regulated financial institution, but it reinforces the direction of travel: operational disruption, cyber incidents and supply chain dependencies are now issues at the board, contract and reporting levels.

The Australian Industry Group has reported that 44 per cent of manufacturers intend to increase investment in supply chain resilience in 2026, with a focus on digital technologies and AI. After COVID, the Productivity Commission developed a framework to identify vulnerable supply chains and manage supply chain risk, highlighting the national importance of resilience in both imports and exports.

Top priorities for manufacturers

There are five areas manufacturers should prioritise now:

  1. Understand which customers operate in regulated or critical sectors - A manufacturer supplying packaging to a healthcare provider, components to a defence contractor, equipment to a logistics business or services to a bank's facilities network may be closer to regulated supply chains than it realises.
  2. Map critical suppliers and dependencies - This should include raw materials, logistics providers, technology systems, workforce availability, offshore dependencies, subcontractors and single points of failure. Many manufacturers still rely on strong operational knowledge in people's heads, with little visibility into it across different systems.
  3. Improve business continuity planning - Customers will increasingly expect evidence of recovery timeframes, alternative suppliers, inventory strategies, incident escalation and tested continuity plans. A business continuity plan that sits in a folder and is reviewed once a year will not be enough.
  4. Strengthen cyber and data governance - Manufacturing is now heavily digitised, from ERP and procurement systems to warehouse management, connected production equipment and supplier portals. If a cyber incident stops orders, invoicing, production scheduling or dispatch, it becomes an operational resilience issue, not just an IT issue.
  5. Digitise operational assurance - The ability to show accurate, timely information on suppliers, contracts, stock, workforce, procurement, financial controls and production status will matter more as customers look for evidence of resilience. Manual processes, fragmented spreadsheets and disconnected systems make it harder to answer customer questions quickly and confidently.

Looking forward

CPS 230 should be seen as a clear signal of where supply chain expectations are heading. For manufacturers, resilience questions are likely to appear more often in tenders, contract renewals and customer audits, particularly when serving regulated or critical sectors.

The opportunity is to move from reactive compliance to proactive resilience. Manufacturers that can identify their exposure, manage operational risk and demonstrate continuity will be better placed to retain customers, win new business and build trust. CPS 230 may not have been written for manufacturers, but its influence will flow through supply chains, procurement processes and customer expectations. Those who act early can turn resilience into a competitive advantage.