Back to Blog

Almost a Year After the FFIEC CAT Sunset: What Examiners Expect Now

By Zach Duke

July 31, 2026

Get notified on new insights from Finosec now!

Be the first to know about new Finosec blogs to grow your knowledge of the cybersecurity governance industry today!

The FFIEC CAT sunset happened last August, and for most institutions the response followed a familiar rhythm: pick a path, map the old work, get back to running the bank. If that’s you, there’s a date worth noticing. If your last Cybersecurity Assessment Tool refresh was August 2025, your first assessment without it is due right about now.

We hear about that moment from community banks again and again. The question is no longer “which framework should we choose?” It’s “we chose one, and now the assessment (and the exam behind it) is here. Will what we built hold up?”

Where institutions actually landed

The regulators pointed to four recognized paths when the CAT sunset: NIST CSF 2.0, the Cyber Risk Institute (CRI) Profile, the CIS Controls, and banking-specific profiles built on those foundations. A year in, community banks have succeeded with each of them. If you’ve already chosen, don’t second-guess the framework. Make sure it can answer the questions coming at it.

And if you’re still deciding, you’re not behind in the way you might fear. In our recent webinars on choosing a CAT replacement, a majority of attendees weren’t part of their institution’s original CAT rollout. This is genuinely new work for a lot of people. The institutions handling it well aren’t the ones who moved first; they’re the ones who can explain what they did and why.

What examiners are asking for now

No agency has mandated a specific CAT replacement. But a year of exams and conversations with banks and regulators (our team has had senior-level conversations with FDIC, OCC, and Federal Reserve staff, and trained 86 state regulators) has made the expectations visible. Here’s the pattern.

  1. The inherent risk profile didn’t sunset. Banks tell us their examiners still want an institution inherent risk profile: the least-to-most picture of how risky your institution is, based on your delivery channels, technology, and footprint. Several replacement frameworks don’t include one. If yours doesn’t, you still need a way to produce that story, because the question hasn’t gone away.
  2. Controls scaled to your institution. A generic control set applied at its lowest tier can leave you exposed, because the control count never flexed to match your risk. A $2 billion institution and a $200 million institution shouldn’t hand in the same checklist, and that mismatch is easy to spot in an exam. Be ready to show how your risk profile determined the depth of your controls.
  3. Reporting your board actually understands. For a decade, boards learned to read the FFIEC CAT’s maturity-versus-risk picture, and that expectation survived the tool. Examiners are asking how leadership stays informed; a spreadsheet export doesn’t answer it. Your assessment needs to produce something a board member who has never worked in IT can follow.
  4. Continuity with your old CAT work. Your CAT history is evidence of a functioning program. Show the through-line: here’s what we assessed under the CAT, here’s how it maps to what we do now. Starting from a blank page reads like starting over, and it throws away work you already did.

The gap we see most often: the assessment isn’t the communication

The pattern that separates a clean exam from a stressful one usually isn’t the framework choice. It’s that the assessment produces data while the exam (and the boardroom) demands a story. Solid controls can still be hard to explain in terms leadership and examiners recognize. That gap is why executive reporting matters more after the CAT, not less.

Three things to do before your next exam

Refresh your inherent risk profile against today’s reality. If your risk questions predate AI tools, instant payments, and API connections into your core, your profile is describing a bank that no longer exists. Update it first; it drives everything else.

Document the crosswalk. Map your old CAT work to your current framework and write the mapping down. The goal is one page you could hand an examiner that says: nothing was lost, here’s where each piece went.

Pressure-test the reporting. Hand your current assessment output to someone on your board or executive team. If they can’t tell you where the institution stands in two minutes, that’s the gap to close before the exam, not during it.

If you’re weighing your options

We built the Finosec Cybersecurity Assessment Tool with the ICBA for exactly this moment: it keeps the institution inherent risk profile, scales controls to your risk, and produces board-ready reporting. Institutions that import their FFIEC CAT history typically see about half of their prior work carry over automatically.

Not sure which path fits your institution? Download the CAT replacement comparison chart and see the four options side by side.

Frequently asked questions

Do examiners require a specific replacement for the FFIEC CAT?

No. The agencies pointed to recognized frameworks (NIST CSF 2.0, the CRI Profile, CIS Controls) without mandating one. What they expect is a defensible choice, fitted to your institution’s size and risk, with reporting that shows leadership oversight.

Does our old CAT work carry over?

Much of it can. In the Finosec CAT, 27 of the inherent risk questions are unchanged from the FFIEC CAT, 12 were updated, and 13 are new, covering risks like ransomware recovery that didn’t exist in the 2017 version.

Our last exam went fine. Can this wait?

A good last exam bought you time; it didn’t answer the question. If your last CAT refresh was August 2025, your annual assessment is due now, and your next exam will be the first where “we’re still transitioning” is a year old. Institutions that treat this quarter as the deadline (not the exam date) walk in calm.

More from Finosec

Type Once. Use Everywhere.

Type Once. Use Everywhere.

How Finosec Keeps Your Data Working Harder So You Don’t Have To At Finosec, we believe cybersecurity governance should be simple, and that starts with not asking you to enter the same information more than once. Whether you're reviewing access, managing vendors, or...

What Banks Need For a Cybersecurity Assessment 

What Banks Need For a Cybersecurity Assessment 

Cybersecurity is no longer just an IT concern. For community banks, it is a core part of risk management, regulatory compliance, and board level governance. Yet many institutions still struggle to answer two basic questions: Are we doing enough? Can we prove it? These...

Talk To An Expert Now
Talk To An Expert Now 770.268.2765