CiberLATAMbywhalemate

OCC keeps 36-hour incident reporting rule

The OCC keeps a 36-hour reporting rule for banks and foreign branches in the U.S., as CIRCIA and NYDFS add pressure.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

The federal Office of the Comptroller of the Currency requires national banks, federal branches and agencies of foreign banks in the U.S. to report incidents within 36 hours. The rule now intersects with CIRCIA, which is moving toward a 72-hour reporting framework for critical sectors, including financial services.

Update September 14, 2026: The note adds CIRCIA’s progress, the federal CISA framework that is moving toward a 72-hour reporting requirement for critical sectors, including financial services. It also adds new details on NYDFS Part 500, with annual privilege reviews, rapid termination of access after employee departures, and electronic reports to the superintendent within 72 hours.

The federal Office of the Comptroller of the Currency’s cyber incident notification rule explicitly covers branches and federal agencies of foreign banks, including financial firms from Argentina and Mexico operating in the United States, as well as their banking service providers. The rule requires notice to the appropriate supervisor as soon as possible and no later than 36 hours after determining that a reportable incident occurred.

Who does the OCC rule cover?

The requirement applies to national banks, federal savings associations, and the branches and federal agencies of foreign banks supervised by the OCC. It also covers banking service providers that work with organizations supervised by the agency in the United States.

That means technology and data-processing vendors used by U.S. subsidiaries or branches of banks from Argentina and Mexico also fall within the regulatory perimeter. According to the text compiled by GovRegs from 12 CFR Part 53, notice goes both to the supervised entity and to the relevant supervisor, depending on the structure involved.

What deadline does it set for incident reporting?

The OCC requires notice as soon as possible and no later than 36 hours after determining that a "notification incident" occurred and could have a material adverse effect on the institution. The threshold is designed to speed supervisory response to events with potentially significant impact.

For banking service providers, the rule is more specific. They must notify at least one designated contact point at each affected banking customer as soon as possible when they determine they suffered a cyber incident that materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, covered services for four or more hours.

What changes with CIRCIA?

CIRCIA, the federal cyber incident reporting framework run by CISA, is moving toward its final rule and adds a 72-hour reporting obligation for covered entities in critical infrastructure sectors, including financial services, as long as they exceed the Small Business Administration size standards.

According to RiskTemplates’ analysis, that creates a new reporting clock in practice for financial firms operating in the United States. BryceStreet adds that the regime will be dual, with any "substantial cyber incident" reported within 72 hours of the entity reasonably believing it occurred, and any ransomware payment reported within 24 hours, even if the underlying incident does not by itself meet that threshold.

The same analysis cites SBA-derived size benchmarks as practical reference points, with approximate ranges of 100 to 1,500 employees or $2.25 million to $47 million in annual revenue, depending on the NAICS code, to determine coverage in sectors such as financial services. RiskTemplates describes the framework as a "fifth clock" of notification layered on top of existing deadlines for banks and issuers.

What other regulatory signals did the U.S. leave for the financial sector?

On September 8, 2026, the OCC, together with FinCEN, the Federal Reserve Board, the FDIC and the NCUA, issued frequently asked questions on the use of mobile driver’s licenses and other government-issued verifiable digital credentials under Bank Secrecy Act compliance and anti-money laundering obligations.

The FAQ clarifies that institutions may use mobile licenses and other verifiable digital credentials in customer identification and verification processes, as long as they meet conditions on credential reliability and related technology controls. For financial groups with cross-border operations, the message comes alongside a broader push for greater privacy, digital identity and operational cybersecurity requirements.

How does this intersect with the SEC’s Regulation S-P?

The SEC’s updated Regulation S-P strengthens information security and governance obligations for broker-dealers, advisers and other regulated participants in the United States. According to Adil Karam’s analysis, larger entities had to comply fully by December 3, 2025, and smaller entities by June 3, 2026.

The same source says the amendments are now fully in force and include a written incident response program, a 30-day customer notification requirement after a breach, and a formal third-party service provider oversight program. It also says the 30-day clock begins when the firm becomes aware of unauthorized access to or use of customer information.

Karam also says service providers must notify the covered institution within 72 hours if they detect a confirmed or suspected breach involving customer data. For groups with operations in the United States, that adds pressure on contracts, third-party monitoring and internal escalation flows.

What changed in NYDFS Part 500?

A technical and regulatory checklist focused on NYDFS Part 500 says New York’s framework requires annual reviews of user access privileges, rapid termination of access after employees leave, electronic notice to the superintendent within 72 hours once a cyber incident is determined, and a mandatory annual report due by April 15.

That annual filing must cover the status of the cybersecurity program. The same source places the notification duty not only on the regulated entity, but also where the incident affects an affiliate or a third-party service provider.

What does NYDFS add, and how firm is it?

A technical analysis by DeepInspect says the second amendment to the NYDFS rule requires electronic notice to the superintendent no later than 72 hours after an incident is determined, and an annual certification due April 15 on material compliance or noncompliance. The source attributes that point to an unconfirmed official reading, so it should be treated cautiously until primary verification is available.

Sources

View all