What Replaced the FFIEC Cybersecurity Assessment Tool (CAT)

What Replaced the FFIEC Cybersecurity Assessment Tool (CAT) in 2026?

Nothing replaced the CAT as a single official form. That is the point most institutions still miss.

The Federal Financial Institutions Examination Council retired the Cybersecurity Assessment Tool on August 31, 2025, and removed it from the FFIEC website. Member agencies did not issue a successor worksheet. They told supervised institutions to use current government and industry resources that better reflect today’s threat landscape, then keep a cybersecurity program commensurate with inherent risk.

In 2026, examiners still use the FFIEC IT Examination Handbook and, where applicable, the Uniform Rating System for Information Technology (URSIT). What disappeared is the CAT maturity score as credible board and exam evidence. What replaced it is a short list of living frameworks—most often NIST Cybersecurity Framework 2.0, supported by the Cyber Risk Institute (CRI) Profile, CISA Cybersecurity Performance Goals, and, for some community institutions, the CIS Critical Security Controls.

Call +1-888-896-7580 if your board pack still cites CAT inherent-risk or maturity levels.

Why the CAT Was Retired

The CAT was released in June 2015 as a voluntary tool to help institutions measure inherent cybersecurity risk and maturity. It was useful. It was also static.

By 2024–2025, the Council concluded that the control ideas inside the CAT remained sound, but the tool itself would not be updated to reflect newer government resources—especially NIST CSF 2.0 and CISA’s Cybersecurity Performance Goals. Updating the CAT would have locked institutions to another form. Pointing them at current frameworks lets the assessment evolve with the threat.

OCC Bulletin 2024-25 and parallel FFIEC member-agency statements made the same point: use an industry-standard cybersecurity framework appropriate to the institution’s risk profile. Do not treat a retired self-assessment as the program.

What Did Not Change

Retirement of the CAT did not retire supervisory expectations.

  • The FFIEC IT Examination Handbook remains the primary source of examination procedures.
  • URSIT remains the rating system examiners use to score IT risk and the quality of IT risk management.
  • Boards and senior management are still expected to understand inherent risk, oversee the information security program, and receive reporting they can act on.
  • Third-party and technology-service-provider risk, authentication, business continuity, and audit coverage remain high-visibility topics.

If CAT language is gone and nothing current is in its place, the institution has a documentation gap—not a lighter exam.

What Institutions Are Using Instead in 2026

There is no mandated one-for-one replacement. The FFIEC pointed institutions to several current resources. In practice, most programs now rest on one primary self-assessment framework and one or two supporting baselines.

Resource Role in 2026 Best use
FFIEC CAT Retired August 31, 2025 Historical reference only. Do not present CAT maturity levels as current evidence.
NIST CSF 2.0 Primary successor self-assessment for most institutions Structure the program around Govern, Identify, Protect, Detect, Respond, and Recover.
CRI Profile Financial-sector profile of NIST CSF Translate CSF outcomes into banking and credit-union control language, including core processing, online/mobile banking, and third-party risk. Version 2.2 added updated regulatory mappings and AI-related resources.
CISA Cybersecurity Performance Goals Prioritized baseline practices Set a minimum control floor. Cross-Sector CPG 2.0 now includes a Govern category and aligns to CSF 2.0. Financial-sector goals are used where published.
CIS Critical Security Controls Optional technical control set Give community institutions a prioritized implementation list alongside CSF 2.0.
FFIEC IT Examination Handbook Current examination procedures Map self-assessment results to the booklets examiners actually open.
URSIT Current supervisory rating system Organize evidence for Audit, Management, Development and Acquisition, Support and Delivery, and Information Security quality.

NIST CSF 2.0 is the most common backbone because it is current, widely understood, and now includes a Govern function. That function covers the board, strategy, policy, oversight, and risk-management questions examiners ask first—questions the original CAT handled only indirectly.

The CRI Profile is the most useful sector overlay. It was built for financial institutions and maps threats to mitigating controls and related regulatory expectations. Institutions that stopped at a generic CSF spreadsheet often still struggle to explain core processing, payments, and vendor concentration in examiner language. The Profile closes that gap.

CISA’s CPGs are not a full program. They are a prioritized subset of practices intended to reduce the most common, high-impact risk. They work as a baseline and a board-level “are the basics in place?” check. They do not replace Handbook procedures or a complete CSF or CRI assessment.

CIS Controls remain a practical option for smaller institutions that need a sequenced technical punch list. They should still be mapped back to CSF 2.0 functions and Handbook expectations so the board report and the exam file tell the same story.

How Examiners Look at the Transition

Examiners are not looking for a CAT score with a new logo. They are looking for four things:

  1. A current self-assessment method that matches the institution’s size, complexity, and inherent risk.
  2. Evidence that the assessment drives decisions—budget, control changes, vendor action, and board reporting.
  3. Alignment between the self-assessment and the FFIEC IT Examination Handbook booklets in scope.
  4. No stale CAT maturity claims in policies, audit reports, or board minutes.

A 2025–2026 industry pattern is consistent: most institutions selected NIST CSF as the CAT replacement, but many did not finish the conversion. The leftover gap is documentation. The program may have improved. The file still describes 2015 maturity tiers.

That is the finding to avoid.

A Practical Replacement Model

A defensible 2026 model looks like this:

  1. Keep the inherent-risk story. The CAT’s inherent-risk idea was useful. Recast it in current terms: products, delivery channels, technology complexity, third-party dependence, online/mobile banking, and threat exposure.
  2. Adopt NIST CSF 2.0 as the program structure. Score or describe current state and target state by function and category, with extra weight on Govern.
  3. Overlay the CRI Profile where the institution is a bank, credit union, or TSP serving them. Use it to connect CSF outcomes to financial-sector controls and regulatory mappings.
  4. Use CISA CPGs as the baseline floor. Confirm the high-priority practices exist before debating advanced maturity.
  5. Map everything to Handbook booklets. Management, Information Security, Architecture/Infrastructure/Operations, Development/Acquisition/Maintenance, Business Continuity Management, Audit, Outsourcing, TSP supervision, and payment-system booklets as applicable.
  6. Prepare a URSIT-oriented evidence package. Do not assign yourself an official rating. Do organize the file the way the examiner will score management quality.
  7. Retire CAT language from the board pack. Preserve historical trend in an appendix if needed. The current narrative should speak CSF 2.0 / CRI / Handbook, not 2015 maturity levels.

Community institutions can run a lighter version of the same model. Complex holding companies and technology service providers should expect a deeper third-party, architecture, and payments overlay.

What to Stop Doing

  • Do not present CAT maturity levels as the current cybersecurity score.
  • Do not assume “we retired the CAT” means “we no longer need a structured assessment.”
  • Do not run NIST CSF in IT and leave GLBA, FTC Safeguards, NYDFS 500, PCI DSS, or SOC 2 as disconnected exercises.
  • Do not confuse an independent readiness assessment with a regulatory examination. Only the OCC, FDIC, Federal Reserve, NCUA, or applicable state supervisor issues the official exam result and, where applicable, the URSIT rating.

How Lazarus Alliance Helps

Lazarus Alliance performs independent FFIEC-aligned readiness assessments. We convert remaining CAT workpapers into a current CSF 2.0 and, where appropriate, CRI Profile assessment; map results to the IT Examination Handbook; prepare board-ready reporting; and organize evidence for the next supervisory review.

The assessment is not a substitute for a regulatory examination and does not assign an official URSIT rating. It is the work that should be finished before the examiner arrives.

Continuum GRC IT Audit Machine® and Cybervisor® teams keep the same evidence set reusable across FFIEC Handbook procedures, NIST CSF 2.0, GLBA / FTC Safeguards, PCI DSS, and SOC 2—so the institution is not rebuilding the file for every audience.

Call +1-888-896-7580 or schedule a consultation to review whether your current self-assessment would survive an examiner’s first request list.