The FFIEC CAT sunset happened last August, and for most institutions the response followed a familiar rhythm: pick a path, map the old work, get back to running the bank. If that’s you, there’s a date worth noticing. If your last Cybersecurity Assessment Tool refresh was August 2025, your first assessment without it is due right about now.
We hear about that moment from community banks again and again. The question is no longer “which framework should we choose?” It’s “we chose one, and now the assessment (and the exam behind it) is here. Will what we built hold up?”
Where institutions actually landed
The regulators pointed to four recognized paths when the CAT sunset: NIST CSF 2.0, the Cyber Risk Institute (CRI) Profile, the CIS Controls, and banking-specific profiles built on those foundations. A year in, community banks have succeeded with each of them. If you’ve already chosen, don’t second-guess the framework. Make sure it can answer the questions coming at it.
And if you’re still deciding, you’re not behind in the way you might fear. In our recent webinars on choosing a CAT replacement, a majority of attendees weren’t part of their institution’s original CAT rollout. This is genuinely new work for a lot of people. The institutions handling it well aren’t the ones who moved first; they’re the ones who can explain what they did and why.
What examiners are asking for now
No agency has mandated a specific CAT replacement. But a year of exams and conversations with banks and regulators (our team has had senior-level conversations with FDIC, OCC, and Federal Reserve staff, and trained 86 state regulators) has made the expectations visible. Here’s the pattern.
- The inherent risk profile didn’t sunset. Banks tell us their examiners still want an institution inherent risk profile: the least-to-most picture of how risky your institution is, based on your delivery channels, technology, and footprint. Several replacement frameworks don’t include one. If yours doesn’t, you still need a way to produce that story, because the question hasn’t gone away.
- Controls scaled to your institution. A generic control set applied at its lowest tier can leave you exposed, because the control count never flexed to match your risk. A $2 billion institution and a $200 million institution shouldn’t hand in the same checklist, and that mismatch is easy to spot in an exam. Be ready to show how your risk profile determined the depth of your controls.
- Reporting your board actually understands. For a decade, boards learned to read the FFIEC CAT’s maturity-versus-risk picture, and that expectation survived the tool. Examiners are asking how leadership stays informed; a spreadsheet export doesn’t answer it. Your assessment needs to produce something a board member who has never worked in IT can follow.
- Continuity with your old CAT work. Your CAT history is evidence of a functioning program. Show the through-line: here’s what we assessed under the CAT, here’s how it maps to what we do now. Starting from a blank page reads like starting over, and it throws away work you already did.
The gap we see most often: the assessment isn’t the communication
The pattern that separates a clean exam from a stressful one usually isn’t the framework choice. It’s that the assessment produces data while the exam (and the boardroom) demands a story. Solid controls can still be hard to explain in terms leadership and examiners recognize. That gap is why executive reporting matters more after the CAT, not less.
Three things to do before your next exam
Refresh your inherent risk profile against today’s reality. If your risk questions predate AI tools, instant payments, and API connections into your core, your profile is describing a bank that no longer exists. Update it first; it drives everything else.
Document the crosswalk. Map your old CAT work to your current framework and write the mapping down. The goal is one page you could hand an examiner that says: nothing was lost, here’s where each piece went.
Pressure-test the reporting. Hand your current assessment output to someone on your board or executive team. If they can’t tell you where the institution stands in two minutes, that’s the gap to close before the exam, not during it.
If you’re weighing your options
We built the Finosec Cybersecurity Assessment Tool with the ICBA for exactly this moment: it keeps the institution inherent risk profile, scales controls to your risk, and produces board-ready reporting. Institutions that import their FFIEC CAT history typically see about half of their prior work carry over automatically.
Not sure which path fits your institution? Download the CAT replacement comparison chart and see the four options side by side.
Frequently asked questions
Do examiners require a specific replacement for the FFIEC CAT?
No. The agencies pointed to recognized frameworks (NIST CSF 2.0, the CRI Profile, CIS Controls) without mandating one. What they expect is a defensible choice, fitted to your institution’s size and risk, with reporting that shows leadership oversight.
Does our old CAT work carry over?
Much of it can. In the Finosec CAT, 27 of the inherent risk questions are unchanged from the FFIEC CAT, 12 were updated, and 13 are new, covering risks like ransomware recovery that didn’t exist in the 2017 version.
Our last exam went fine. Can this wait?
A good last exam bought you time; it didn’t answer the question. If your last CAT refresh was August 2025, your annual assessment is due now, and your next exam will be the first where “we’re still transitioning” is a year old. Institutions that treat this quarter as the deadline (not the exam date) walk in calm.




