Life After the CAT: How Community Banks Handle FFIEC Expectations
The Cybersecurity Assessment Tool is retired, but examiners aren't. Transitioning community banks to NIST CSF 2.0 and the CRI Profile with evidence that satisfies an exam. A community bank in the Hudson Valley — about $900M in assets, one information security officer who also runs BSA — called us the month the FFIEC announced the Cybersecurity Assessment Tool would sunset. The question was blunt: "We've been filling out the CAT since 2016. Now what?" It's the question I've heard from a dozen banks since, and the honest first answer is that nothing about examiner expectations actually changed. The tool went away. The expectation that you assess your cybersecurity maturity in a structured, repeatable way did not. The CAT was always a bridge. It gave institutions a common vocabulary for inherent risk and maturity, and examiners got used to seeing it. But it was frozen in 2015 era thinking, it never kept pace with cloud and third party dependency, and the FFIEC was clear that the underlying guidance, the IT Handbook, the Architecture, Infrastructure and Operations booklet, the ransomware self assessment, is what matters. The CAT retiring is a good thing dressed up as a scary one. What examiners still want to see In our engagements, the examiner conversation comes down to a few durable things. They want to see that the board understands the bank's cyber r