FFIEC IT Examination Handbook Assessments – Examiner-Ready Cybersecurity for Financial Institutions. Call +1 (888) 896-7580 today!

Lazarus Alliance delivers independent FFIEC-aligned IT and cybersecurity assessments for banks, credit unions, bank holding companies, and technology service providers (TSPs). We map your control environment to the current FFIEC Information Technology Examination Handbook, close gaps before your next safety-and-soundness or IT examination, and replace retired Cybersecurity Assessment Tool (CAT) scoring with examiner-credible frameworks such as NIST CSF 2.0, the Cyber Risk Institute (CRI) Profile, and CISA Cybersecurity Performance Goals.

The Federal Financial Institutions Examination Council does not regulate institutions itself. Member agencies—the OCC, FDIC, Federal Reserve, NCUA, CFPB, and state supervisors through the State Liaison Committee—use the Handbook, URSIT ratings, and related interagency guidance when they examine you. Lazarus Alliance prepares that package: evidence, board reporting, third-party risk files, and a defensible information security program your examiner can follow.

Call +1 (888) 896-7580 or schedule your free consultation today.

Who This Service Is For

  • Community, regional, and large banks preparing for an OCC, FDIC, or Federal Reserve IT examination
  • Credit unions preparing for NCUA information security and technology reviews
  • Technology service providers (core processors, cloud hosts, fintech platforms) subject to FFIEC Supervision of Technology Service Providers guidance
  • Institutions still carrying CAT maturity language in board packs after the August 31, 2025 sunset
  • Organizations that must also satisfy GLBA / FTC Safeguards, NYDFS 23 NYCRR 500, PCI DSS, SOC 2, or SOX 404 ITGC expectations from the same control set

What FFIEC Expects After the CAT Sunset

The FFIEC released the Cybersecurity Assessment Tool in 2015 as a voluntary way to measure inherent risk and cybersecurity maturity. On August 31, 2025, the Council retired the CAT and removed it from the FFIEC website. Member agencies told supervised institutions to use current government and industry resources instead of a replacement form.

Examiners still expect a cybersecurity program commensurate with inherent risk. They still use the IT Examination Handbook work programs and the Uniform Rating System for Information Technology (URSIT). What changed is the self-assessment instrument—not the duty to govern, identify, protect, detect, respond, and recover.

Resource Role after August 31, 2025
FFIEC Cybersecurity Assessment Tool (CAT) Retired. Do not present CAT maturity levels as current examiner evidence.
FFIEC IT Examination Handbook Current. Provides examination guidance and procedures used by FFIEC member agencies when evaluating financial institutions' IT risks and controls.
URSIT Current. Rating system examiners use to score IT risk and risk management quality.
NIST Cybersecurity Framework 2.0 One current framework financial institutions may consider for cybersecurity self-assessment after the CAT sunset.
CISA Cybersecurity Performance Goals (CPGs) Recommended baseline practices; financial-sector CPGs used where published.
CRI Profile Industry profile built for financial institutions, mapped to NIST CSF and supervisory expectations.
CIS Critical Security Controls Optional, prioritized technical control set many community institutions use alongside CSF 2.0.

FFIEC IT Examination Handbook Coverage

Lazarus Alliance assesses against the current Handbook booklets examiners actually open:

  • Management — board and senior management oversight, IT strategy, IT risk management, and accountability
  • Information Security — information security program, risk measurement, security operations, and assurance
  • Architecture, Infrastructure, and Operations — enterprise architecture, infrastructure design, and service delivery
  • Development, Acquisition, and Maintenance — secure development, acquisition, change control, and system maintenance
  • Business Continuity Management — resilience, recovery, testing, and disruption preparedness
  • Audit — independence, coverage, IT audit methodology, and reporting to the audit committee
  • Outsourcing Technology Services — vendor due diligence, contracts, ongoing monitoring, and concentration risk
  • Supervision of Technology Service Providers — TSP control expectations when you are the service provider or rely on one
  • Retail Payment Systems and Wholesale Payment Systems — payment integrity, authentication, and operational resilience where in scope

FFIEC Examination Areas

Examination Area What Lazarus Alliance Evaluates
Management Governance, board oversight, IT strategy and risk management
Information Security Security program, risk assessment, access controls and security operations
Architecture, Infrastructure & Operations Architecture, infrastructure, configurations and operational resilience
Development, Acquisition & Maintenance SDLC, acquisition, change management and system maintenance
Business Continuity Management BIA, resilience, disaster recovery and testing
Audit Independence, scope, methodology, findings and audit-committee reporting
Third-Party Risk Due diligence, contracts, monitoring and concentration risk
Technology Service Providers TSP controls and supervisory expectations
Payment Systems Payment security, authentication, availability and operational controls

Lazarus Alliance FFIEC Services

1. FFIEC Readiness Assessment and Gap Analysis
We score your current program against the Handbook booklets in scope, NIST CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover), and—when requested—the CRI Profile. Findings are risk-rated and mapped to the evidence an examiner will request, not to a retired CAT worksheet.

2. CAT-to-CSF 2.0 / CRI Profile Transition
If board reports still cite CAT inherent-risk and maturity levels, we convert that work into a current self-assessment, preserve historical trend where it is still useful, and produce examiner-ready language that no longer depends on a sunset tool.

3. URSIT Pre-Exam Package
We organize evidence, policies, risk assessments, vendor files, incident metrics, and audit results into a package aligned with URSIT components: Audit, Management, Development and Acquisition, Support and Delivery, and Information Security quality. This is readiness support—not an official regulatory rating.

4. Information Security Program and Board Reporting
We strengthen the written information security program, risk assessment cadence, Qualified Individual / CISO reporting line, and the board and audit-committee packages examiners review first.

5. Third-Party and TSP Risk
Core processors, cloud providers, fintech partners, and managed security vendors are now a primary examination focus. We assess due diligence files, contract clauses, SOC reports, concentration risk, and ongoing monitoring against the Outsourcing and TSP booklets.

6. Technical Testing Aligned to Handbook Expectations
Vulnerability assessment, penetration testing, authentication reviews, and configuration testing that support Information Security and Architecture, Infrastructure, and Operations procedures—executed to NIST 800-115 methods and documented for both IT exam and PCI / SOC reuse.

7. Multi-Framework Mapping on Continuum GRC
One evidence set in the Continuum GRC IT Audit Machine® (ITAM) with AITAMBot AI assistance, mapped simultaneously to FFIEC Handbook procedures, NIST CSF 2.0, GLBA / FTC Safeguards, NYDFS 500, PCI DSS, SOC 2, ISO 27001, and NIST 800-53 where those programs overlap. Clients typically reduce duplicate collection by 40 percent or more.

8. Cybervisor® Advisory and Continuous Monitoring
Ongoing vCISO / Cybervisor® support, annual program updates, tabletop exercises, vendor monitoring, and ConMon dashboards so the next exam is a confirmation exercise—not a reconstruction project.

FFIEC Readiness Assessment vs. Regulatory Examination

  Lazarus Alliance FFIEC Assessment Regulatory Examination
Performed by Independent assessor OCC, FDIC, Federal Reserve, NCUA or applicable supervisor
Purpose Identify gaps and prepare for examination Supervisory evaluation
Official regulatory examination No Yes
Official URSIT rating No Where applicable
Remediation preparation Yes Findings may require corrective action
Evidence preparation Yes Evidence is examined
Board-ready reporting Yes Supervisory results communicated as applicable

Why Financial Institutions Choose Lazarus Alliance

  • 26+ years of Proactive Cybersecurity® assessments across regulated industries
  • Veteran-Owned Small Business (VOSB) and Delaware-licensed CPA firm
  • Authorized CMMC C3PAO (CPN 10251) and A2LA-accredited FedRAMP 3PAO
  • PCI DSS Qualified Security Assessor (QSA) for cardholder-data environments that sit inside the same institution
  • SOC 1 / SOC 2 examination capability for TSPs that must give banks an attestation, not only a self-assessment
  • Continuum GRC IT Audit Machine® + AITAMBot for faster evidence collection, live dashboards, and reusable crosswalks
  • Concierge-level Cybervisor® teams—collaborative, not adversarial. It’s an audit, not an expedition.
Phase Activities Typical Duration Key Deliverables
1. Pre-Engagement & Scoping NDA/SOW, charter type and primary regulator, inherent-risk profile, booklet selection, portal setup 3–5 business days Approved SOW, rules of engagement, scoped booklet list
2. Gap Analysis Handbook mapping, CAT artifact conversion (if any), CSF 2.0 / CRI baseline, vendor inventory review 1–2 weeks Gap report, prioritized remediation roadmap, inherent-risk narrative
3. Evidence Collection Policies, risk assessments, board minutes, vendor files, BCM tests, audit reports, technical configs in ITAM 1–2 weeks Traceable evidence package with control-to-booklet crosswalk
4. Assessment Execution Interviews, control testing, sampling, authentication and access reviews, optional pentest 2–4 weeks Preliminary findings log, weekly dashboards
5. Remediation & Validation POA&M support, re-test of closed items, board-pack language 1–2 weeks Risk-rated POA&M, validation memo
6. Final Reporting Examiner-oriented report, CSF 2.0 profile, optional continuous monitoring setup 1 week Final assessment report, executive summary, 24/7 ITAM access

Total typical duration: 6–12 weeks from kickoff to final report. Community institutions with a current risk assessment and complete vendor files often finish in 6–8 weeks. Multi-charter holding companies, complex cloud estates, and TSPs typically run 10–12 weeks.

Pro Tip: Start with a free Cybervisor® consultation and upload existing CAT workpapers, the last IT exam letter, and current vendor SOC reports first. Call +1 (888) 896-7580.

Independence Statement

Lazarus Alliance, Inc., Lazarus Alliance Compliance, LLC, Continuum GRC, Inc., and the Horse Project / Lazarus Alliance Foundation are separate legal entities under common ownership. Assessment and certification activities are segregated from software licensing and from non-profit education. This structure supports impartiality requirements under ISO/IEC 17020, Cyber AB, FedRAMP, PCI SSC, and AICPA independence rules.

An FFIEC-aligned assessment from Lazarus Alliance is an independent readiness and control evaluation. It is not a substitute for an examination by the OCC, FDIC, Federal Reserve, NCUA, CFPB, or a state banking or credit-union supervisor, and it does not assign an official URSIT or CAMELS rating.

Frequently Asked Questions

Yes. The FFIEC sunset the CAT on August 31, 2025, and removed it from the FFIEC website. Member agencies directed institutions to current resources such as NIST CSF 2.0, CISA Cybersecurity Performance Goals, the CRI Profile, and CIS Controls. Keep using a structured self-assessment. Stop presenting CAT maturity levels as current evidence.

There is no single official replacement form. Most institutions now use NIST CSF 2.0 as the primary self-assessment structure, often with the CRI Profile for financial-sector specificity and CISA CPGs as a baseline. Lazarus Alliance builds that successor assessment, maps it to Handbook procedures, and retires CAT language from board reports.

No. URSIT ratings are assigned by supervisory agencies. We prepare the evidence, narratives, and control testing that support a stronger examination outcome and show management quality before the examiner scores the components.

Insured depository institutions meet GLBA information-security expectations primarily through their prudential regulator and the Handbook. Non-bank financial institutions are often under the FTC Safeguards Rule. Many holding-company structures touch both. We map one control set across Handbook procedures, GLBA, and Safeguards Rule requirements so you do not run two disconnected programs.

Yes. Core processors, cloud platforms, and fintech TSPs are examined under the Supervision of Technology Service Providers booklet and related interagency guidance. Banks that rely on those TSPs are examined under Outsourcing Technology Services. We assess either side—and can add a SOC 2 examination when your bank clients need an attestation.

Most initial engagements finish in 6–12 weeks. Continuum GRC ITAM and early evidence upload typically cut elapsed time by 40–50 percent versus spreadsheet-driven reviews.

A risk-rated assessment report, Handbook and CSF 2.0 crosswalk, prioritized POA&M, board-ready executive summary, and a populated Continuum GRC workspace you can reuse for the next exam cycle, GLBA reviews, PCI, and SOC 2.

Yes. Lazarus Alliance is an authorized CMMC C3PAO (CPN 10251), A2LA-accredited FedRAMP 3PAO, PCI DSS QSA, and a Delaware-licensed CPA firm offering SOC examinations—useful when a financial institution or its TSP also serves defense, federal, or card-brand customers.

Credentials You Can Count On

  • Veteran-Owned Small Business (VOSB) | UEI: CQD9NFDH7AH4 | CAGE: 4PHZ4
  • Authorized CMMC C3PAO (CPN 10251) | A2LA ISO/IEC 17020
  • A2LA-accredited FedRAMP 3PAO
  • PCI DSS Qualified Security Assessor (QSA)
  • Delaware-licensed CPA firm — SOC 1, SOC 2, SOC 3
  • GSA MAS 47QRAA22D009A

Talk with one of our experts

Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.

We're here to answer any questions you may have.

Download our company brochure.

We want to be your partner and FFIEC-aligned cybersecurity assessor of choice! For additional information, please call +1 (888) 896-7580.