What's happened?

We've updated our CommBiz Automated Secure File Transfer service to improve connectivity and resiliency for our customers.

A CommBiz Automated service is still accessible via our two connectivity options:

  • DNS: securetransfer.commbank.com.au
  • Directly through provided IP address

What you need to confirm

We're asking customers to confirm the following by 27 February 2026:

  1. The software or tool you use to connect to the CommBiz Automated service is compatible with our upgraded environment.

    Note if you are still connecting to CommBiz Automated, no action required.
  2. The cipher suites used for encryption and authentication are among the supported options listed below. If your setup already uses the below ciphers, no action required. 
  3. If you require assistance, contact our team at [email protected] if you need help validating or testing your setup

Supported Ciphers

For ongoing security and resilience of the CommBiz Automated service, we’re phasing out older cipher support from 27 February 2026.

Please ensure your system supports one or more of the following ciphers in each category:

Encryption Ciphers
  • aes128-gcm
  • aes256-gcm
  • aes192-ctr
  • aes256-ctr
Key Exchange & Algorithms
  • diffie-hellman-group-exchange-sha256
  • [email protected]
  • ecdh-sha2-nistp256
  • ecdh-sha2-nistp384
  • ecdh-sha2-nistp521
Integrity / Authentication (MACs)
  • hmac-sha2-256-etm
  • hmac-sha2-512-etm
  • hmac-sha2-256
  • hmac-sha2-512
 

Connectivity testing

Testing your connectivity using the supported ciphers is optional but recommended.

Pilot and production testing environments are available to help confirm that your configuration works as expected before the cut-over date.

Pilot mode

You can choose for CommBank to move the CommBiz Automated Service back into Pilot Mode for a short period of time.  A CommBank Project Manager will assist you with testing in Pilot Mode.

Any files uploaded into the CommBiz/outbox during this phase of testing will be automatically re-routed to the CommBiz/inbox for collection.

Pilot Mode testing is to ensure that the SFTP client can connect, upload and download files appropriately. CommBiz Automated will not attempt to validate any files while on Pilot Mode.

Pilot Mode testing could take place at a quieter time of day when no payments are planned.

End-to-end testing in production mode

If your IT Team feel comfortable to do so, they can test in Production Mode once you have made the scripting changes. 

In Production Mode all files uploaded into the CommBiz/outbox will be collected, validated and processed (if validation is successful) by CommBiz. Any files that do not pass validation will be unable to be imported for processing.

Note: You do not need to advise CommBank of testing in Production Mode.

FAQs

We don’t have visibility of customer system configurations. Confirming cipher compatibility ensures that your connectivity to the upgraded environment remains secure and uninterrupted.

If your current setup already uses one or more of the supported cipher suites listed above, no further action is required.

If your system uses unsupported ciphers, please update your software or configuration to align with the supported cipher list before 27 February 2026. This will ensure your service continues without disruption

No. This upgrade does not involve any changes to file formats, encryption keys, login credentials, or reporting outputs.

No, you will still have the same Logon ID and other existing CommBiz service details.

No, current key pairings are still valid

No. There are no changes to files specifications, status reporting or reporting formats.

If you use CommBiz Automated to send payment files, our recommendation is to test a low-value-live payment (ABA) file (e.g. $0.01) to your own account or a trusted beneficiary. 

If testing payment file processing, we recommend you work with your IT Team (for full straight through processing) and your CommBiz Authorisers (for manual authorisation of payments) so they are aware of the testing and do not accidentally generate files or authorise transactions that your IT team did not want processed.

If you use CommBiz Automated for reporting purposes only, please test by confirming successful collection of report files.

If you have any questions not answered on this page, or seeking help for this upgrade, email us at [email protected].

Important information

  • This guide is published solely for information purposes. As this guide has been prepared without considering your objectives, financial situation or needs, you should consider its appropriateness to your circumstances and if necessary seek the appropriate financial advice before acting on information in this guide. Call 13 1998 or view the CommBiz Terms and Conditions.