Skip to main content
GuidesBy Jason LeeAugust 28, 20269 min read

The FFIEC CAT Is Gone: What Banks and Credit Unions Use Now

The FFIEC CAT Is Gone: What Banks and Credit Unions Use Now

The direct answer: there is no mandated replacement for the FFIEC Cybersecurity Assessment Tool. The FFIEC retired the CAT on August 31, 2025, removed it from its website, and pointed institutions to recognized frameworks instead: NIST CSF 2.0, the Cyber Risk Institute (CRI) Profile, CISA's Cybersecurity Performance Goals, and the CIS Controls. One year on, the CRI Profile has become the de facto successor for banks, and the NCUA's Information Security Examination remains the exam framework for credit unions. What examiners expect now is not a particular tool. It is a documented mapping to a recognized framework, chosen deliberately, backed by evidence, and defensible in the exam room.

Status verified August 27, 2026. This page is updated when the regulatory status changes.

One year after the sunset

This week marks one year since the CAT went away. The FFIEC's sunset statement gave institutions a long runway, and the tool came down on August 31, 2025. The agencies were explicit that they would not mandate or endorse a single successor. That decision created a vacuum that community banks and credit unions have spent the past year filling on their own, with uneven results.

The institutions that handled it well treated the sunset as a translation project: pick a recognized framework, map the old CAT baseline into it, and keep the annual self-assessment rhythm going without a gap year. The institutions that handled it badly did one of two things. Some kept running the retired CAT because the spreadsheet still opens, which leaves the board consuming maturity reports against a framework no regulator maintains. Others simply stopped self-assessing and planned to sort it out before the next exam, which is how a one-year gap in the program's evidence trail gets created. We covered how to rebuild the maturity roadmap itself in our guide to a post-CAT cybersecurity maturity roadmap. This post is about the framework decision underneath it.

The four frameworks regulators point to

Regulatory direction since the sunset has consistently named four options, a list summarized well in CIS's own sunset explainer. NIST CSF 2.0 is the general-purpose governance framework, sector-neutral and widely understood; if your team is starting there, our NIST CSF 2.0 compliance checklist walks the six functions in practical order. The CRI Profile is the financial-sector extension of CSF 2.0, built by and for financial institutions. CISA's Cybersecurity Performance Goals are a shorter baseline of high-impact practices, useful for institutions with lean security teams that need a floor before they need a framework. The CIS Controls are a technical control catalog, strongest as the implementation layer underneath one of the governance frameworks rather than as a standalone answer.

None of these is required. All of them are recognized. The exam question is no longer "what is your CAT maturity level" but "which framework did you choose, why was it right for your size and complexity, and where is the evidence."

Why the CRI Profile became the de facto successor

The CRI Profile won the banking segment for a practical reason: it is the only option that was purpose-built to absorb CAT refugees. Version 2.0, released in 2024, extended NIST CSF 2.0 into financial-sector language. Version 2.1, released April 15, 2025, added the two things former CAT users missed most: a Maturity Model, which restores the maturity narrative boards were accustomed to, and mappings to the FFIEC examination handbooks, CIS Controls v8.1, NIST 800-53 r5, and DORA. The FFIEC handbook mapping matters because it lets an institution show an examiner exactly how each Profile diagnostic statement connects to the guidance the examiner is working from. The DORA mapping matters for any institution with EU financial-sector exposure.

CRI has since announced a version 2.2 with AI implementation resources. We have not been able to verify its release date, so treat the specifics as unconfirmed until you check the CRI site directly. The direction is clear enough: the Profile is being actively maintained and extended, which is exactly what the CAT was not.

Heading into an exam without a successor framework?

A Z Cyber advisor can review your last CAT baseline, recommend the right successor framework for your size, and guide the mapping so your team walks into the exam with a defensible answer.

Talk to an Advisor →

A decision guide by institution size

The right successor depends less on preference and more on what your institution can actually operate. A framework you cannot staff is worse than a simpler one you run every quarter.

Your situation Practical starting point Why
Community bank that ran the CAT annuallyCRI Profile v2.1Financial-sector language, FFIEC handbook mappings, and a Maturity Model that keeps the board's reporting continuous with the CAT era
Credit union of any sizeNCUA ISE, with CRI Profile or NIST CSF 2.0 underneathThe ISE is still the exam; the framework underneath organizes your evidence against it and against the 2026 priorities
Small institution with a lean or part-time security functionCISA CPGs or NIST CSF 2.0, then grow into the CRI ProfileA baseline you complete beats a framework you abandon; the CPGs establish a floor without a full diagnostic exercise
Larger or more complex institution, or one with EU exposureCRI Profile v2.1The 800-53 r5 and DORA mappings let one assessment serve multiple regulatory audiences instead of running parallel exercises
Institution whose real gap is technical controls, not governanceCIS Controls under whichever governance framework you pickCIS gives the implementation layer; v8.1 maps into the CRI Profile, so the two stack rather than compete

Whatever the choice, make it a governed decision. A framework selection memo approved by the board or its designated committee, with the reasoning recorded, is itself an exam artifact.

Credit unions: the ISE never left, and 2026 raised the bar

Credit unions sometimes read the CAT sunset as a holiday. It was not, because the NCUA's Information Security Examination remains the exam framework, and the NCUA's 2026 supervisory priorities added specific expectations on top of it: annual board cybersecurity training, vulnerability management with measurable targets, scenario-specific incident response playbooks, third-party risk management, payment fraud controls, and AI governance.

Two of those deserve emphasis. The board training expectation is new as an annual, explicit item, and it is easy to satisfy and easy to fail: either the training happened and is minuted, or it is not. And "vulnerability management with measurable targets" means a scanner report is no longer evidence of a program. Examiners will look for defined remediation targets and whether you hit them. The third-party expectation is a program of its own; we broke down what that looks like for financial institutions in our guide to third-party risk management for banks, and the same structure serves a credit union preparing for an ISE exam.

What examiners expect to see in the file

Across charters, the post-CAT expectation converges on the same short list. A named framework, chosen through governance. A completed current-cycle self-assessment against it, with dated evidence behind the statements rather than bare yes answers. A mapping or crosswalk from the old CAT baseline, so year-over-year progress is still legible. And a remediation queue derived from the assessment, with owners and dates. An institution that shows up with a retired CAT workbook and nothing else is telling the examiner that its assessment discipline was the tool, not the program.

This is also where outside help fits, and it is worth being precise about the division of labor. A structured risk assessment run by an advisor can apply the successor framework, test the evidence, and present the findings and prioritized recommendations to management and the board. The institution decides which recommendations to accept, approves the framework choice, and owns the risk. Exam prep support means your team walks in prepared and fluent in its own program, not that someone else answers for it.

What to watch next

Three things between now and your next exam cycle. First, CRI Profile v2.2: confirm its release status and whether its AI implementation resources are relevant to your program, since AI governance is already an NCUA 2026 priority and examiner interest in AI is not going away. Second, the NCUA's 2027 supervisory priorities, which will show whether the 2026 additions harden into standing expectations. Third, your own calendar: if your last completed self-assessment is the CAT you ran before August 31, 2025, you are past the one-year mark on a retired framework, and the next exam is the wrong place to discover what that gap looks like. If you want a second set of eyes on the migration before then, talk to a Z Cyber advisor.

Frequently Asked Questions

What replaced the FFIEC Cybersecurity Assessment Tool?

Nothing was mandated. The FFIEC retired the CAT on August 31, 2025 and removed it from its website without endorsing a single successor. Regulators instead direct institutions to recognized frameworks: NIST CSF 2.0, the Cyber Risk Institute (CRI) Profile, CISA's Cybersecurity Performance Goals, and the CIS Controls. In practice the CRI Profile has become the de facto successor for banks because it extends NIST CSF 2.0 with financial-sector language, FFIEC handbook mappings, and a maturity model.

Is the CRI Profile mandatory for banks after the CAT sunset?

No. No regulator has mandated the CRI Profile or any other specific framework. The expectation examiners carry into the room is different: a documented, deliberate mapping of your program to a recognized framework, with evidence behind each assessment statement. The CRI Profile is the most common choice for banks because version 2.1 maps to the FFIEC handbooks, CIS Controls v8.1, NIST 800-53 r5, and DORA, and its maturity model fills the role the CAT's maturity levels used to play.

What should a credit union use for its next NCUA exam instead of the CAT?

The NCUA's Information Security Examination (ISE) remains the exam framework for credit unions, so nothing changed there. What changed is the 2026 supervisory priorities layered on top: annual board cybersecurity training, vulnerability management with measurable targets, scenario-specific incident response playbooks, third-party risk management, payment fraud controls, and AI governance. A credit union should run its program against a recognized framework underneath the ISE and be ready to show evidence for each 2026 priority.

How do we migrate our old CAT results to the CRI Profile?

Treat your last completed CAT as the baseline, not as waste. Map each CAT declarative statement to the corresponding CRI Profile diagnostic statement, carry over the evidence that still holds, and flag statements with no current evidence as open items. The CRI Profile's maturity model, added in version 2.1, gives the board a maturity narrative comparable to the CAT levels it was used to seeing. The migration is a translation exercise, not a restart, and one framework cycle is usually enough to complete it.

Do examiners require a specific cybersecurity framework in 2026?

No specific framework is required, but arriving without one is the wrong answer. Examiners expect a documented mapping to a recognized successor framework: NIST CSF 2.0, the CRI Profile, CISA CPGs, or CIS Controls. The choice should fit the institution's size and complexity, be approved through governance, and be backed by dated evidence. An institution that still hands over a stale CAT workbook, or nothing at all, is signaling that its self-assessment discipline ended when the tool did.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.