FFIEC CAT Sunset: What Replaces the CAT
The FFIEC retired the Cybersecurity Assessment Tool on August 31, 2025 and named no successor, stating that it does not endorse any particular tool. Here is what the sunset statement actually said, how the four named alternatives compare for a financial institution, and why the self-assessment expectation survived the tool.
By the Scrutineer team
August 2026 · 10 min read
Try it while you read
No account, nothing to install.
Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.
›
Illustrative sample · not an audit attestation
Last updated August 2026. The FFIEC retired the Cybersecurity Assessment Tool on August 31, 2025, having announced the sunset on August 29, 2024. There is no official replacement. The FFIEC pointed institutions toward NIST CSF 2.0, the Cyber Risk Institute Profile, CISA's Cybersecurity Performance Goals and the CIS Controls, but stated plainly that it does not endorse any particular tool. It also said expectations for cybersecurity self-assessments have not changed. The tool went away; the obligation did not.
That combination is what makes this awkward. Your examiner still expects to see a cybersecurity self-assessment, and the one artifact everybody used for a decade no longer exists. This guide covers what the sunset statement actually said, how the four named alternatives really compare for a bank or credit union, what to do with the CAT work you already have, and how to answer the question an examiner will eventually ask.
When did the FFIEC CAT sunset?
August 31, 2025. The Federal Financial Institutions Examination Council published its sunset statement on August 29, 2024, giving institutions two years of notice, and removed the CAT from the FFIEC website on the sunset date. The OCC circulated it as Bulletin 2024-25, and state regulators including the Texas Department of Banking and the Louisiana Office of Financial Institutions republished it to their supervised institutions.
The CAT itself dated from June 2015. It was always voluntary: a self-assessment tool, not a rule. That distinction matters more now than it did then, because it explains why nothing had to be issued in its place.
Why did the FFIEC retire the CAT?
The sunset statement is unusually candid. The FFIEC said the fundamental security controls addressed throughout the maturity levels of the CAT are sound, then said it had determined not to update the CAT to reflect newer government resources, naming NIST Cybersecurity Framework 2.0 and CISA's Cybersecurity Performance Goals. The Texas Department of Banking's summary put the reasoning more bluntly, describing the tool as inadequate given new technologies and advances in hacking techniques in the nine years since it was introduced.
Read those together and the picture is a maintenance decision rather than a policy reversal. The CAT was built against the 2014 version of the NIST framework. NIST CSF 2.0 arrived in February 2024 and added a sixth function, Govern, which the CAT's structure had no place for. Rather than rebuild a tool that duplicated frameworks other bodies were already maintaining, the FFIEC stepped back and let institutions choose.
What is replacing the FFIEC CAT?
Nothing, in the official sense, and this is the single most misreported part of the story. Plenty of published guidance names one framework as "the CAT replacement." The FFIEC did not. The sunset statement lists alternative resources and then explicitly declines to endorse any of them, saying that while the FFIEC does not endorse any particular tool, these standardized tools can assist financial institutions in their self-assessment activities.
So the choice is genuinely yours, and it should be made on fit rather than on which vendor's blog you read first. Here is how the four named alternatives actually differ for a supervised institution.
| Alternative | Who maintains it | Built for financial institutions? | Scales by institution size? | Best fit |
|---|---|---|---|---|
| CRI Profile | Cyber Risk Institute, an industry non-profit | Yes. Designed for the financial sector specifically. | Yes. Scope is set by an impact tier, so a community bank is not assessed like a global systemically important one. | The closest thing to a like-for-like CAT successor. Harmonizes a large body of regulatory requirements into roughly 300 control objectives and maps to NIST CSF 2.0. |
| NIST CSF 2.0 | NIST, a US federal agency | No. Cross-sector by design. | Partly. Tiers and Profiles let you scope it, but you do the scoping work yourself. | Institutions that already run CSF elsewhere in the group, or that want the most widely recognized framework for talking to customers and insurers as well as examiners. |
| CISA Cybersecurity Performance Goals | CISA, a US federal agency | No. Aimed at critical infrastructure broadly, with small and medium organizations in mind. | Not really. It is a deliberately short baseline rather than a tiered model. | A floor, not a program. Useful as a fast gap check or for a very small institution starting from nothing. Thin as a standalone examination artifact. |
| CIS Critical Security Controls | Center for Internet Security, a non-profit | No. Cross-sector and technically oriented. | Yes, through Implementation Groups IG1 to IG3. | Strong on concrete technical safeguards and weaker on governance. Works well underneath CSF or the CRI Profile rather than instead of them. |
In practice most banks and credit unions have gone to the CRI Profile or NIST CSF 2.0, and a fair number run the CRI Profile precisely because it is CSF-aligned underneath, which means picking it does not close off the other. The CRI Profile reached version 2.2 on April 30, 2026, adding 13 new mappings and three updated ones for a total of 40 mappings to regulatory sources and industry standards, along with AI risk resources. The core diagnostic statements were left unchanged in both 2.1 and 2.2, so an institution that adopted the Profile in 2025 has not been forced to reassess.
Is the FFIEC CAT still valid, and do we still need a self-assessment?
The CAT is no longer maintained or published, so using it now means working from an archived copy of a document its authors have declared out of date. Some institutions did exactly that through 2025 while they chose a successor, which was defensible as a transition step and is much harder to defend as a standing position two years on.
The self-assessment expectation, though, is untouched. The FFIEC's own language is that expectations for cybersecurity self-assessments have not changed and that the only change is the retirement of the CAT from the portfolio of available self-assessment tools. That is the sentence to keep, because it answers the question institutions actually have.
The underlying legal authority never ran through the CAT anyway. It runs through section 501(b) of the Gramm-Leach-Bliley Act and the Interagency Guidelines Establishing Information Security Standards, codified at 12 CFR Part 30 Appendix B for the OCC, Part 208 Appendix D-2 for the Federal Reserve, Part 364 Appendix B for the FDIC and Part 748 Appendix A for the NCUA. Those require a written information security program built on a risk assessment. Which of those four parts binds you follows your charter, and a holding company with a non-bank lending or servicing affiliate can find that affiliate sitting under the far more prescriptive FTC Safeguards Rule instead, with named MFA and penetration testing duties the banking guidelines never impose. Our reference table of GLBA compliance software requirements sets the regulators side by side. Examiners work from the FFIEC IT Examination Handbook series on top of them. None of that changed on August 31, 2025.
What do we do with the CAT work we already have?
Do not throw it away. The CAT produced two things worth keeping: an Inherent Risk Profile and a maturity rating across five domains, both supported by evidence you gathered. The framing is retired; the underlying assessment is not. Mapping it forward is faster than starting clean, and it gives you a defensible story about continuity when an examiner asks how you handled the transition.
| What the CAT gave you | What it was | Where it lands now |
|---|---|---|
| Inherent Risk Profile | Five categories rated across five levels: least, minimal, moderate, significant and most. | Becomes the scoping input. It sets your CRI Profile impact tier, or your CSF Target Profile and Tier selection. This is the part that transfers most cleanly. |
| Domain 1: Cyber Risk Management and Oversight | Governance, strategy, policies, risk management, audit, training and culture. | Largely the new NIST CSF 2.0 Govern function, which did not exist as a function in the version the CAT was built against. Expect gaps here, because this is where CSF 2.0 raised the bar. |
| Domain 2: Threat Intelligence and Collaboration | Threat intelligence gathering, monitoring and information sharing. | Splits across Identify and Detect. Information-sharing expectations, including FS-ISAC participation, are treated more explicitly in the sector frameworks. |
| Domain 3: Cybersecurity Controls | Preventative, detective and corrective controls. | Protect and Detect. Maps almost one-for-one onto the CIS Controls if you want technical depth underneath. |
| Domain 4: External Dependency Management | Connections to third parties and relationship management. | Govern and Identify, under supply chain risk management. This expanded materially in CSF 2.0 and is a common gap after transition. |
| Domain 5: Cyber Incident Management and Resilience | Incident planning, detection, response, mitigation, escalation, reporting and resilience. | Respond and Recover. Now sits alongside harder notification clocks, including Regulation S-P's 30-day customer notification for advisers and broker-dealers. |
| Maturity ratings | Baseline, evolving, intermediate, advanced or innovative, per domain. | No direct equivalent. The CRI Profile has its own maturity model, released alongside version 2.1. CSF 2.0 uses Tiers, which describe rigor of governance rather than control depth, so do not treat them as a rename of the CAT levels. |
The practical warning from institutions that have done this: the gaps cluster in Domains 1 and 4. Governance and third-party management are exactly where CSF 2.0 and the CRI Profile ask for more than the CAT did, so a bank that rated itself intermediate across the board in 2024 should not assume the new assessment lands in the same place.
How do we choose between NIST CSF 2.0 and the CRI Profile?
Pick the CRI Profile if your assessment exists mainly to satisfy examiners and you want the regulatory mapping done for you. It was built by the sector for the sector, it scales by impact tier, and its whole value proposition is collapsing overlapping regulatory requirements into one set of control objectives so you answer each question once.
Pick NIST CSF 2.0 if your institution is part of a wider group already standardized on CSF, if you need one framework that also speaks to enterprise customers, cyber insurers and counterparties, or if you want the largest available pool of tooling and trained staff. You will do more scoping work yourself, and you will need to be ready to explain to an examiner how a cross-sector framework covers your sector-specific obligations.
What does not work is choosing neither and hoping the question does not come up. The gap between the sunset and your next examination is finite, and "we used to do the CAT" is not an answer. Whichever framework you land on, the examinable artifact is the same as it always was: a dated assessment, the evidence behind each rated control, and a record of what you decided to fix and when. Getting that evidence out of your cloud, identity and ticketing systems on a schedule is the part that actually takes time, which is why financial services compliance software earns its place here rather than another spreadsheet.
What will an examiner ask about the transition?
Expect three questions, and prepare the answers now rather than in the exam room.
- Which framework did you adopt, and why that one? A short written rationale, approved at the right level, is worth more than a long one. Tie it to your inherent risk and your regulatory footprint.
- When did you complete your first assessment under it, and who reviewed it? A dated assessment with named reviewers and a board or committee minute receiving it. An undated assessment invites the assumption that it was produced for the exam.
- What did the assessment find, and what happened next? This is the one that separates a mature program from a paper one. Findings with owners, target dates and evidence of closure. Findings with no remediation record read worse than having fewer findings.
The third question is where the reporting effort usually lands, because the assessment output and the version a director will actually read are different documents. Boards want the risk picture, the movement since last time and the decisions being asked of them, not a control-by-control export, so it is worth having a way to turn a long technical assessment into a short board-ready deck without rewriting it by hand each quarter.
Does this change anything for non-bank financial institutions?
Directly, no. The CAT was an FFIEC product for institutions examined by FFIEC member agencies. If you are supervised by the FTC rather than a prudential regulator, your obligations sit in the FTC Safeguards Rule at 16 CFR Part 314, which has its own nine required elements and its own written risk assessment duty. Advisers and broker-dealers answer to the SEC under the amended Regulation S-P instead, whose compliance dates passed in December 2025 and June 2026.
Indirectly it matters, because the frameworks the FFIEC named are the same ones the rest of the sector is converging on. A New York licensee running 23 NYCRR Part 500 alongside the Interagency Guidelines will find that one assessment, mapped properly, feeds both. The controls are largely shared. What differs is who asks, on what clock, and with what penalty behind the question, which is the argument for mapping once and pointing several regimes at the same evidence rather than running parallel programs.
The short version
The CAT is gone as of August 31, 2025 and nothing official replaced it, because the FFIEC deliberately chose not to endorse a successor. The self-assessment expectation is unchanged and still rests on GLBA 501(b), the Interagency Guidelines and the FFIEC IT handbooks. Most institutions have moved to the CRI Profile or NIST CSF 2.0, with the CRI Profile the closer fit for a sector-specific examination story. Your old CAT work maps forward usefully, especially the Inherent Risk Profile, but expect new gaps in governance and third-party management. And the artifact that matters has not changed at all: a dated assessment, real evidence behind each control, and a remediation record that shows someone acted on what it found. If you want the mechanics of producing that assessment, our guide on how to conduct a cybersecurity risk assessment walks through it step by step.
Sources: the FFIEC CAT Sunset Statement of August 29, 2024, as circulated by OCC Bulletin 2024-25 and republished by state banking regulators including the Texas Department of Banking; NIST Cybersecurity Framework 2.0; Cyber Risk Institute release notes for CRI Profile v2.1 and v2.2. Framework fit descriptions are our reading and are offered as decision support, not legal advice. Scrutineer prepares and maintains control evidence; examinations are conducted by your regulator.
See Scrutineer scrutinize your posture
Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.