FRAMEWORKS & CERTIFICATIONS
What Is CRI Profile?
DEFINITION
The CRI Profile is the Cyber Risk Institute's cybersecurity assessment framework for the financial sector, built by harmonizing the NIST Cybersecurity Framework with financial regulations and supervisory expectations. After the FFIEC retired its Cybersecurity Assessment Tool on August 31, 2025, the Profile became the de facto sector standard. Version 2.1, released in April 2025, adds a maturity model to the diagnostic statements.
The CRI Profile condenses hundreds of regulatory and supervisory requirements applicable to financial institutions into a single set of diagnostic statements organized around the NIST Cybersecurity Framework structure, with financial-sector extensions for governance and third-party dependencies. Its tiering approach scales the number of applicable diagnostic statements to an institution's size and systemic importance, so a community-scale firm answers a much smaller set than a global bank. Version 2.1 introduced a maturity model, giving institutions a way to express not just whether a practice exists but how well it operates.
Banks, credit unions, insurers, and their examiners are the primary audience. With the FFIEC Cybersecurity Assessment Tool retired as of August 31, 2025, U.S. regulators have pointed institutions toward standardized alternatives, and the CRI Profile is the one most of the industry has coalesced around. Financial institutions also increasingly use it to assess their own vendors.
For a mid-market financial firm that built its self-assessment on the CAT, the practical task is remapping to the Profile. Because the Profile is anchored to the NIST CSF, an existing CSF-aligned program carries over largely intact. Z Cyber's NIST CSF services cover that alignment work.
Running a program that has to satisfy this?
A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.
Meet Your Security Team →