WATCHUR6 // FFIEC // AUDIT READINESS

The exam didn't go away.
The tool you used for it did.

The FFIEC retired the Cybersecurity Assessment Tool on August 31, 2025 — but examiners still expect an annual cybersecurity self-assessment. The obligation survived; the tool didn't. We migrate you to a current framework and get you ready for the IT examination that never stopped.

Book an FFIEC Readiness Call
FFIEC IT EXAM HANDBOOK CAT RETIRED AUG 2025 CRI PROFILE / NIST CSF VETERAN-LED

// WHY FFIEC, WHY NOW

The tool retired. The expectation didn't budge.

CAT GONE

Retired August 31, 2025

The FFIEC sunset its Cybersecurity Assessment Tool and removed it from the website — and chose not to update it. The framework most institutions used is no longer available.

SAME EXAM

Examiners still expect it

The FFIEC was explicit: expectations for an annual cybersecurity self-assessment have not changed. Only the tool retired — not the obligation behind it.

5 AGENCIES

One handbook they examine to

The Fed, FDIC, OCC, NCUA, and CFPB examine against the FFIEC IT Handbook. There's no "FFIEC certificate" — there's an exam, and the evidence behind it.

// THERE IS NO "FFIEC CERTIFICATE"

We just need to get FFIEC certified.
FFIEC is an examination, not a certification — and the CAT that anchored it is gone.

There's no FFIEC certificate to earn. The FFIEC sets uniform standards and its member agencies examine you against the IT Handbook. For a decade, institutions leaned on the CAT to run the annual self-assessment examiners expect — but it retired August 31, 2025. The expectation didn't. So the real task isn't a certificate; it's choosing a current framework, mapping your old CAT history into it, and walking into the exam with a credible, documented self-assessment. That migration is exactly where institutions stall.

// THE OBLIGATION, AND HOW YOU MEET IT NOW

The CAT is gone. The self-assessment it powered is not.

What examiners actually want is a credible, repeatable annual cybersecurity self-assessment. With the CAT retired, you run it against a successor framework — and map your old results in so you don't lose your history.

The Annual Self-Assessment The obligation that outlived the CAT

What didn't change when the tool retired: examiners still expect a documented, repeatable assessment of your inherent risk and cybersecurity maturity, refreshed annually and reportable to your board. The CAT was just one way to produce it. The three frameworks below are how institutions run that same assessment now — pick the one that fits your size and risk, and map your prior CAT results into it.

// SECTOR-SPECIFIC

CRI Profile

Built for financial institutions, maps directly to the retired CAT, and scales by impact tier. The common successor.

// THE CONVERGENCE STANDARD

NIST CSF 2.0

The framework the FFIEC pointed to, and the one its IT Handbook increasingly references. Pairs with CISA's CPGs.

// WHAT EXAMINERS USE

FFIEC IT Handbook

The booklet series examiners measure against — information security, business continuity, operations, and more.

Credit unions also have the NCUA ACET, derived from the CAT and still supported.

FFIEC · FED · FDIC · OCC · NCUA · CFPB CAT · RETIRED AUG 31, 2025 Annual Self-Assessment · STILL EXPECTED

// THE PATH

From migration to a clean exam.

How institutions move off the CAT and into a repeatable cycle. The amber stages are the examiner-facing moments — the board reporting and the IT examination itself.

Select

Successor Framework

WK 1–3

Migrate

Map CAT History

WK 3–6

Assess

Run Self-Assessment

MO 1–3

Remediate

Close Handbook Gaps

MO 3–6

Report

Board & Examiner

ANNUAL

Exam

IT Examination

ON CYCLE

Amber stages are the examiner-facing moments — the board and regulator reporting that documents your self-assessment, and the IT examination your agency conducts on its cycle. Everything before them is the migration and assessment work that makes the exam routine.

// IS THIS YOU?

Three signs this is on your plate.

// 01 // STILL ON CAT

Your last assessment was the CAT

You ran the CAT for years and haven't yet chosen a successor. Your next exam will expect a current framework — and a reason you picked it.

// 02 // EXAMINED FI

You're a bank or credit union

You're examined by an FFIEC member agency, or you're a technology service provider to one. The IT Handbook expectations apply to you directly.

// 03 // EXAM ON THE CALENDAR

An IT exam is coming

You have an examination on the horizon and no documented, repeatable self-assessment to put in front of examiners. That gap shows up fast.

// WHAT WE DO

The migration, the assessment, and the exam.

// Phase 01 · Migrate

Framework Selection & Mapping

We help you choose a successor framework fit to your size and risk — usually the CRI Profile or NIST CSF 2.0 — and map your prior CAT results into it so you keep your history and your maturity baseline.

  • Successor framework selection and rationale
  • CAT-to-CRI Profile / NIST CSF mapping
  • Inherent risk profiling and scoping

// Phase 02 · Assess

Self-Assessment & Remediation

We run the annual cybersecurity self-assessment against your chosen framework, then close the gaps the FFIEC IT Handbook booklets examine — information security, continuity, operations, and vendor management.

  • Annual cybersecurity self-assessment
  • FFIEC IT Handbook gap analysis
  • Third-party / service-provider oversight

// Phase 03 · Examine

Reporting & Exam Readiness

We package the assessment into board and examiner reporting, and prepare your team and evidence so the IT examination is a confirmation of work already done — not a scramble.

  • Board and examiner reporting package
  • Examination evidence and document requests
  • Ongoing annual self-assessment cadence

// THE CAT WON'T BE ON THE TABLE NEXT EXAM

"We used to run the CAT" isn't an answer an examiner accepts anymore.

Book an FFIEC Readiness Call

// FREQUENTLY ASKED

The FFIEC questions institutions keep asking.

Is FFIEC a certification we can get?

No — this is the most common misunderstanding. The FFIEC (Federal Financial Institutions Examination Council) is not a certification body and there's no FFIEC certificate to earn. It's an interagency council — the Federal Reserve, FDIC, OCC, NCUA, and CFPB — that issues uniform standards and examination procedures. Its member agencies then examine banks, credit unions, and their technology service providers against those standards.

What you actually prepare for is an IT examination, and what examiners use is the FFIEC IT Examination Handbook — booklets covering information security, business continuity, architecture and operations, development and acquisition, audit, management, and outsourcing. "FFIEC readiness" means being ready to demonstrate, with evidence, that your security and technology risk management meet those expectations. We prepare you for the exam, not a certificate that doesn't exist.

The FFIEC retired the CAT. What are we supposed to use now?

The FFIEC Cybersecurity Assessment Tool was sunset and removed from the FFIEC website on August 31, 2025, and the FFIEC decided not to update it. The critical point is what did not change: examiners still expect an annual cybersecurity self-assessment. Only the tool retired, not the obligation.

The FFIEC didn't endorse a single replacement, but pointed to newer resources including the NIST CSF 2.0 and CISA's Cybersecurity Performance Goals. The most widely adopted successor among financial institutions is the Cyber Risk Institute (CRI) Profile, because it's built for the financial sector, maps directly to the retired CAT, and scales to your size and risk. Credit unions also have the NCUA's ACET, derived from the CAT and still supported. The right move: choose a fitting framework, map your prior CAT results into it so you keep your history, and run your next self-assessment against it before your exam.

Does the CAT sunset mean we can stop self-assessing?

No — and treating it that way is the trap. The FFIEC was explicit that expectations for cybersecurity self-assessments have not changed; the only change is the CAT's retirement from the available tools. Many institutions are also subject to state requirements — several state banking departments require state-chartered institutions to assess cybersecurity maturity annually — so the obligation often exists at both the federal-exam and state levels.

If anything, the sunset raises the bar: you can no longer point to a familiar, examiner-recognized tool, and instead must select an appropriate framework, justify the choice, and demonstrate a credible, repeatable process. An institution that quietly stopped self-assessing when the CAT retired would be in a worse position at its next exam, not a better one. We help you make and document the framework selection, run the assessment, and produce results examiners and your board will accept.

How does FFIEC relate to NIST, and do we need both?

They operate at different layers and increasingly point the same direction. NIST publishes the underlying frameworks and control catalogs — the CSF 2.0 and SP 800-53 — that define good practice. The FFIEC sets examination expectations for financial institutions and has steadily aligned its IT Handbook booklets with NIST references rather than maintaining a separate parallel system; retiring the CAT in favor of pointing to the NIST CSF 2.0 is part of that same convergence.

So you're not really choosing between FFIEC and NIST: you use a NIST-aligned framework, or the financial-sector CRI Profile that extends the NIST CSF, to run your assessment, and you map it to the FFIEC IT Handbook expectations examiners apply. For an institution that already has a NIST CSF program, much of the substance carries over — the work is organizing it into a financial-institution self-assessment with the evidence an examiner expects. We handle that mapping so one program satisfies both the framework and the exam.

// THE NEXT MOVE

Replace the retired tool before your examiner asks what you used.

Book a 30-minute FFIEC readiness call with a WatchUr6 advisor. Bring whether you still rely on the CAT, what framework you're considering, and when your next IT exam is. You'll walk away with a successor-framework recommendation, a migration plan that preserves your history, and a clear path to a clean exam — whether you hire us or not.

Book an FFIEC Readiness Call

SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED