The FFIEC Cybersecurity Assessment Tool Sunset: What Comes Next
The FFIEC retired the Cybersecurity Assessment Tool in 2025. What examiners expect banks to use instead, and how to make the transition without losing years of assessment history.
The business problem
Since 2015, many banks built years of board reporting and examiner conversation around the FFIEC's Cybersecurity Assessment Tool (CAT) — a maturity-based self-assessment that became the shared reference point for discussing cyber risk with examiners. In 2025, the FFIEC member agencies jointly announced the sunset of the CAT, directing institutions toward risk-based resources — commonly the NIST Cybersecurity Framework (CSF) 2.0 — rather than a single mandated tool. Institutions that never planned for CAT to disappear now need an actual transition plan, not a shrug.
Why it matters
Examiners no longer expect a specific tool by name, but they still expect a documented, risk-based process for assessing cyber risk. A bank that has nothing to show once CAT disappears from the conversation doesn't look more flexible — it looks less prepared, at exactly the moment its peers are adopting a clear replacement.
“Retiring a tool doesn't retire the expectation behind it. The FFIEC didn't lower the bar on cyber risk assessment — it removed the one tool everyone had agreed to use to measure it.”
Signs the organization should pay attention now
- The most recent board cybersecurity update still cites a CAT maturity level as the primary metric
- No one has mapped the institution's prior CAT assessment factors to NIST CSF 2.0 functions, or to whatever risk-based process is meant to replace it
- IT staff are unsure what to bring to the next exam now that CAT isn't the shared reference point it used to be
- Historical CAT self-assessments exist, but nobody has decided what documentation replaces them going forward
- The transition has been treated as an IT project rather than a board-reporting one
What good looks like
A well-handled transition picks a documented risk-based framework — commonly NIST CSF 2.0, though the FFIEC did not mandate a single specific replacement — maps the institution's prior CAT assessment history onto the new structure so years of trend data aren't simply discarded, and updates board reporting templates before the gap between the old and new approach becomes visible to the board itself.
See where your program stands under the FFIEC's current expectations.
Take the FFIEC Readiness AssessmentPractical guidance
Retire the CAT-branded board slide. Adopt NIST CSF 2.0, or another documented risk-based framework, explicitly and in writing — don't let the transition happen implicitly. And preserve the historical maturity trend line by cross-walking old CAT ratings to the new framework's categories, rather than starting the board conversation over from zero.
My CISO Partner's perspective
We treat a regulatory tool sunset like this one as a forcing function for a conversation that was overdue anyway — whether the underlying cyber risk assessment process was ever more than "the CAT said we're here."
Where to go from here
If the next board cybersecurity update is still built around a CAT maturity level, that slide needs to change before the tool it's based on is a memory nobody can point back to.
Questions, answered directly.
No. The FFIEC did not mandate a single replacement tool, pointing instead to risk-based resources including the NIST Cybersecurity Framework 2.0, which many institutions have adopted as the practical successor.
It's worth preserving as a baseline — cross-walking prior CAT ratings to whatever framework replaces it keeps the historical trend line intact for board reporting rather than starting over.
Examiner practice is shifting with the sunset, but institutions should still expect to be asked how they assess cyber risk today and be able to answer clearly, regardless of which specific tool is named.
NCUA's ACET is a separate, NCUA-administered tool modeled on the former FFIEC CAT. The FFIEC's sunset applies to FFIEC member-agency-regulated banks; credit unions should confirm directly with NCUA whether or how ACET itself is affected.
Talk to a CISO about your CAT transition.
30 minutes. No obligation. No sales pitch.