Perspective · Regulatory readiness

Life after the FFIEC CAT

On August 31, 2025, the FFIEC removed the Cybersecurity Assessment Tool from its website, retiring a fixture of bank and credit-union security programs since 2015. The tool is gone. The expectation it stood in for is not, and that gap is where the real exposure now sits.

What changed, and what didn't

The FFIEC's decision was narrower than it first appears. It chose not to keep updating the CAT to match newer standards, and pointed institutions toward a set of modern alternatives instead. What it did not do was lower the bar. Supervisors still expect a structured, risk-based cybersecurity self-assessment that is current, documented, and commensurate with the institution's size and complexity. Examinations remain risk-focused, and examiners may probe areas that no single tool fully covers.

In other words, the questionnaire retired; the obligation to know and evidence your cyber posture did not. The institutions most exposed today are the ones that quietly stopped assessing when the CAT went away and have not yet adopted a replacement, leaving a conspicuous gap in the record between their last CAT and whatever comes next.

The successors and how they differ

The FFIEC named several resources but deliberately endorsed none, leaving the choice to each institution. Four come up most often:

  • NIST CSF 2.0: the common foundation, and the most widely adopted alternative. Its functions (Govern, Identify, Protect, Detect, Respond, and Recover) give a flexible, outcome-based structure that maps cleanly to nearly everything else. For most institutions, this is the anchor.
  • CRI Profile (Cyber Risk Institute): the one widely used option built specifically for financial services. It extends the NIST CSF, maps directly back to the CAT (which makes the transition far easier), and scales its scope to your institution's impact tier.
  • CISA Cybersecurity Performance Goals: a prioritized, high-impact baseline of practices. Useful as a check on the essentials, and for smaller institutions that want a defensible starting set rather than a full maturity model.
  • CIS Controls: a concrete, technical control set. Strongest as an implementation companion to a CSF or CRI Profile assessment rather than a board-level maturity view on its own.

A common and defensible pattern: anchor on a NIST CSF 2.0 maturity assessment, then layer the CRI Profile where a financial-sector lens and continuity with the CAT matter most.

The CAT retired. The expectation to know (and prove) your cyber posture did not.

A transition, not a tool swap

The mistake is treating this as swapping one questionnaire for another. What supervisors and boards actually want is a defensible process. Four things make it defensible:

  • Map your last CAT results into the new framework, so nothing is lost and the through-line is clear.
  • Set a target maturity that is explicitly tied to your risk, not a reflexive aspiration to “all fives.”
  • Document the gaps and the plan to close them, with named owners and dates.
  • Keep it board-visible and repeatable, so each cycle shows measurable movement rather than a one-time exercise.

The CRI Profile's direct mapping back to the CAT makes that first step materially easier for institutions coming straight off the tool.

What examiners will actually look for

Not which framework you chose: the FFIEC is explicit that it endorses none. What draws attention is whether your self-assessment is current, commensurate with your risk, documented, and acted upon. A clean transition tells a simple story: here is where we stood under the CAT, here is the framework we moved to and why, here is our current versus target maturity, and here is what we are doing about the gaps.

A lapse (a year with no assessment at all) tells a different and far less comfortable story. The work now is to make sure yours reads like the first one.

Choosing the right framework, mapping cleanly off the CAT, and turning it into a board-ready view of readiness is exactly the regulatory-readiness work NorthBridge does for regulated institutions. If your program is between frameworks, let's close the gap before an examiner does.

Start a conversation

Related: What boards should ask the CISO, and our illustrative board cyber dashboard.