Connected Payments (Previously IPSI) Planned Release - Production

Scheduled Maintenance Report for IPSI Services

Completed

The scheduled maintenance has been completed.
Posted Jul 31, 2026 - 00:00 AEST

In progress

Scheduled maintenance is currently in progress. We will provide updates as necessary.
Posted Jul 30, 2026 - 20:00 AEST

Scheduled

What's happening

Please be advised of the upcoming planned release to the IPSI/Connected Payments platform, we will be performing security and vulnerability fixes across the platform.

Date and Time of Release:

•  Production deployment: Thursday, 30 July 2026
•  Start Time: 20:00 30/07/26 AEDT
•  End Time: 00:00 31/07/26 AEDT

Change Notes:

This release focuses on strengthening security posture, modernising underlying technology, upgrading dependencies, hardening infrastructure workflows, and improving build and test reliability.

The release is not intended to introduce new customer workflows or change existing payment behaviour. Customers can continue using CBA Connected Payments as usual unless they are contacted separately by CBA.


What customers need to know

1.  Stronger platform foundation: Security remediation, dependency upgrades, restricted infrastructure access, and modern cryptography help reduce platform risk.

2.  No intended workflow change: Payment processing, customer-facing journeys, and operational usage are expected to remain consistent with the current experience.

3.  Improved maintainability: Backend, frontend, Lambda, testing, and deployment tooling have been modernised to support ongoing reliability and safer change delivery.

4.  No customer action required: Customers do not need to update configurations, retrain users, or change integrations for this release unless separately notified.

Customer impact

Security posture

• What changed: Security vulnerabilities were remediated and cryptography was modernised.
• Customer impact: The platform has a stronger security foundation for payment experiences and supporting services.
• Action required: None

Backend services

• What changed: Core backend tooling and libraries were upgraded across services.
• Customer impact: Services are easier to maintain and test while preserving existing behaviour wherever possible.
• Action required: None

Infrastructure
• What changed: Network egress and deployment workflows were hardened.
• Customer impact: Reduced exposure from backend infrastructure while required AWS service connectivity is maintained.
• Action required: None

Frontend applications

• What changed: Frontend frameworks, dependencies, accessibility support, and local development support were updated.
• Customer impact: Customer-facing and embedded experiences benefit from refreshed platform components and targeted accessibility improvements.
• Action required: None

Deprecations

• What changed: Legacy and vulnerable dependencies and internal build tooling were removed or replaced.
• Customer impact: Reduced dependency risk with no expected change to customer-facing functionality.
• Action required: None

Reach out to your usual CBA support channel via connectedpayments@cba.com.au or refer to status page for real-time updates during the deployment windows.
Posted Jul 24, 2026 - 11:11 AEST
This scheduled maintenance affected: Gateway Services - EnterpriseSecure (API services - Production, Batch Services - Production, Dashboard Services - Production, Reporting Services - Production, Tokenisation Services - Production, Payment Page 2.0 Services - Production, Alias Service- Production).