OCC updates bank cybersecurity guide
The OCC reorganized its cyber supervision program for national banks and federal savings associations without adding new requirements.
The Office of the Comptroller of the Currency updated the structure and references in its Cybersecurity Supervision Work Program, the guide examiners use to assess the cybersecurity of national banks and federal savings associations. The agency said the change does not add new regulatory expectations or require banks to use it to measure their own readiness.
The Office of the Comptroller of the Currency, or OCC, has updated the structure and references in its Cybersecurity Supervision Work Program, the guide its examiners use to assess the cybersecurity of national banks and federal savings associations. The regulator said the change does not create new regulatory expectations and that institutions are not required to use it to review their own readiness.
What changed in the program?
The update reorganizes the material to keep it aligned with the updated categories and subcategories in the NIST Cybersecurity Framework. According to the OCC, the goal was to adjust the structure and references used by examiners, not to add new exam procedures or change the scope of supervision.
CU Daily also reported that this version replaces OCC Bulletin 2023-22. VitalLaw said the alignment is with NIST CSF 2.0 and that the 2023 bulletin was rescinded. Paul Hastings described the program as a high-level examination tool that remains aligned with NIST, but does not turn that framework into a mandatory assessment for banks.
What does this mean for supervised banks?
The OCC made clear that the program remains an internal guide for examining national banks and federal savings associations. That means the update brings supervision references and categories into order, but it does not impose a new compliance requirement or a deadline for institutions to adapt.
Independent coverage agreed that no exam procedures were added or changed. The update is meant to reflect the updated NIST framework within supervision, while each bank's decision to use that framework to assess its own cybersecurity maturity remains optional.
Sources
- Cybersecurity: Cybersecurity Supervision Work Programocc.gov· Office of the Comptroller of the Currency (OCC)
- Regulador dos EUA revê guia cyber de bancos sem exigir maisletsmoney.com.br· Let's Money
- OCC Updates Structure, References in Cybersecurity Program Examiners Use to Evaluate Banksthecudaily.com· The CU Daily
- PRUDENTIAL REGULATION—OCC updates cybersecurity supervision work program structure and referencesvitallaw.com· VitalLaw
- Daily Financial Regulation Update — Tuesday, September 22, 2026paulhastings.com· Paul Hastings



