GRADUM
    FeaturesMaturity ModelsFor CreatorsPricingBlogCompareSupport
    DashboardSign Up Free
    Blog/Compare/EN 1090 vs APRA CPS 234
    Standards Comparison

    EN 1090 vs APRA CPS 234

    EN 1090

    Mandatory
    2009

    European standards for execution of steel and aluminium structures

    VS

    APRA CPS 234

    Mandatory
    2019

    Australian prudential standard for information security capability

    Quick Verdict

    EN 1090 ensures CE-marked structural steel/aluminium compliance for EU construction, while APRA CPS 234 mandates information security resilience for Australian financial entities. Fabricators adopt EN 1090 for market access; banks/insurers use CPS 234 to meet regulatory oversight and avoid penalties.

    Structural Metalwork

    EN 1090

    EN 1090: Execution of steel and aluminium structures

    Cost
    €€€€
    Complexity
    High
    Implementation Time
    6-12 months

    Key Features

    • Risk-based Execution Classes (EXC1-EXC4) scaling requirements
    • Certified Factory Production Control (FPC) system mandatory
    • Enables CE marking under EU Construction Products Regulation
    • Integrates ISO 3834 for welding quality management
    • Ensures full material and process traceability
    Information Security

    APRA CPS 234

    APRA Prudential Standard CPS 234 Information Security

    Cost
    €€€€
    Complexity
    High
    Implementation Time
    12-18 months

    Key Features

    • Board ultimately responsible for information security
    • Third-party managed assets fully in scope
    • Systematic independent testing of controls required
    • 72-hour notification for material incidents
    • Risk-based asset classification by criticality

    Detailed Analysis

    A comprehensive look at the specific requirements, scope, and impact of each standard.

    EN 1090 Details

    What It Is

    EN 1090 is a harmonized European standard series (EN 1090-1, -2, -3) for the execution and conformity assessment of structural steel and aluminium components. It serves as the primary framework under the EU Construction Products Regulation (CPR), enabling CE marking for load-bearing components in construction works. Its risk-based approach uses Execution Classes (EXC1-EXC4) to scale requirements based on failure consequences, service conditions, and production complexity.

    Key Components

    • **EN 1090-1Conformity assessment via Factory Production Control (FPC) certification by Notified Bodies.
    • **EN 1090-2/-3Technical rules for steel/aluminium execution, covering materials, welding (ISO 3834 integration), tolerances, inspection, and corrosion protection.
    • Core principles: traceability, qualified personnel, NDT inspection, and ongoing surveillance.
    • Certification model: AVCP systems with initial audits and continuous monitoring.

    Why Organizations Use It

    Provides mandatory market access in EEA, reduces liability via proven processes, ensures weld quality consistency, and builds stakeholder trust. Strategic benefits include risk mitigation, rework reduction, and competitiveness in high-stakes projects like bridges and stadia.

    Implementation Overview

    Phased approach: gap analysis, FPC development, welding qualification, NB certification (3-12 months typical). Applies to fabricators of structural components; requires personnel training, digital traceability, and surveillance for steel/aluminium producers in Europe.

    APRA CPS 234 Details

    What It Is

    APRA Prudential Standard CPS 234 (Information Security) is a binding prudential regulation from the Australian Prudential Regulation Authority, effective 1 July 2019. It mandates APRA-regulated entities—banks, insurers, super funds—to maintain an information security capability commensurate with threats, protecting confidentiality, integrity, and availability of information assets, including those managed by third parties. It employs a risk-based, proportionate approach focused on governance, controls, and assurance.

    Key Components

    • **Governance and rolesBoard ultimate accountability, defined responsibilities.
    • **Core areasPolicy framework, asset classification by criticality/sensitivity, commensurate controls, incident response, systematic testing, third-party assessments.
    • No fixed controls; built on CIA triad principles.
    • Compliance via self-management, independent assurance, APRA notifications—no formal certification.

    Why Organizations Use It

    • Mandatory for regulated entities to avoid enforcement, penalties.
    • Mitigates cyber risks, ensures operational resilience.
    • Builds customer trust, enables partnerships, reduces costs.
    • Provides competitive edge in security posture.

    Implementation Overview

    • Phased: gap analysis, governance setup, asset register, controls, testing, monitoring.
    • Suits all sizes in APRA sectors (Australia).
    • Involves internal audit, annual testing; 72-hour incident reporting to APRA. (178 words)

    Key Differences

    AspectEN 1090APRA CPS 234
    ScopeExecution and conformity of steel/aluminium structuresInformation security capability for financial entities
    IndustryConstruction, fabrication; EU/EEA marketAustralian financial services (banks, insurers)
    NatureHarmonized technical standard; CE marking mandatoryBinding prudential regulation; APRA enforcement
    TestingFPC certification, surveillance audits by Notified BodiesSystematic control testing, internal audit assurance
    PenaltiesMarket exclusion, no CE marking, legal liabilityFines, supervisory actions, license restrictions

    Scope

    EN 1090
    Execution and conformity of steel/aluminium structures
    APRA CPS 234
    Information security capability for financial entities

    Industry

    EN 1090
    Construction, fabrication; EU/EEA market
    APRA CPS 234
    Australian financial services (banks, insurers)

    Nature

    EN 1090
    Harmonized technical standard; CE marking mandatory
    APRA CPS 234
    Binding prudential regulation; APRA enforcement

    Testing

    EN 1090
    FPC certification, surveillance audits by Notified Bodies
    APRA CPS 234
    Systematic control testing, internal audit assurance

    Penalties

    EN 1090
    Market exclusion, no CE marking, legal liability
    APRA CPS 234
    Fines, supervisory actions, license restrictions

    Frequently Asked Questions

    Common questions about EN 1090 and APRA CPS 234

    EN 1090 FAQ

    APRA CPS 234 FAQ

    You Might also be Interested in These Articles...

    Thailand PDPA Enforcement Trends 2025: Analyzing 1,048 Complaints, Breach Volumes, and Hidden Lessons for Proactive Compliance

    Thailand PDPA Enforcement Trends 2025: Analyzing 1,048 Complaints, Breach Volumes, and Hidden Lessons for Proactive Compliance

    Decode PDPC Thailand's 1,048 complaints & 610 breaches. Uncover consent/security violations, project 2025 enforcement. Risk heatmap, self-assessment & playbook

    PDPA Cross-Border Transfer Rules Decoded: Singapore, Thailand, and Taiwan Mechanisms Compared with Practical Implementation Templates

    PDPA Cross-Border Transfer Rules Decoded: Singapore, Thailand, and Taiwan Mechanisms Compared with Practical Implementation Templates

    Decode PDPA cross-border transfers for Singapore, Thailand, Taiwan. Statutory excerpts, approved mechanisms, SCC templates. Harmonize with GDPR, navigate exempt

    Image this: What if GDPR would have NOT been implemented by the EU

    Image this: What if GDPR would have NOT been implemented by the EU

    What if the EU never implemented GDPR? Explore this hypothetical: consumer data protection in Dec 2025, key differences, pros/cons for users & companies. Read t

    Run Maturity Assessments with GRADUM

    Transform your compliance journey with our AI-powered assessment platform

    Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.

    100+ Standards & Regulations
    AI-Powered Insights
    Collaborative Assessments
    Actionable Recommendations

    Explore More Comparisons

    See how EN 1090 and APRA CPS 234 compare against other standards

    Other EN 1090 Comparisons

    • TOGAF vs EN 1090
    • COBIT vs EN 1090
    • ISO 20000 vs EN 1090
    • SAFe vs EN 1090
    • ITIL vs EN 1090

    Other APRA CPS 234 Comparisons

    • APRA CPS 234 vs 23 NYCRR 500
    • APRA CPS 234 vs ISO 27018
    • APRA CPS 234 vs CIS Controls
    • APRA CPS 234 vs U.S. SEC Cybersecurity Rules
    • APRA CPS 234 vs ISO 27701
    GRADUM

    Transform your assessment process with collaborative, AI-powered maturity evaluations that deliver actionable insights.

    Navigation

    FeaturesMaturity ModelsFor CreatorsPricing

    Legal

    Terms and ConditionsPrivacy PolicyImprintCopyright PolicyCookie Policy

    © 2026 Gradum. All Rights Reserved