CiberLATAMbywhalemate

OCC updates bank cybersecurity guide

The OCC reorganized its cyber supervision program for national banks and federal savings associations without adding new requirements.

Whalemate Labs · AI-assisted researchPublished:2 min read

The Office of the Comptroller of the Currency updated the structure and references in its Cybersecurity Supervision Work Program, the guide examiners use to assess the cybersecurity of national banks and federal savings associations. The agency said the change does not add new regulatory expectations or require banks to use it to measure their own readiness.

The Office of the Comptroller of the Currency, or OCC, has updated the structure and references in its Cybersecurity Supervision Work Program, the guide its examiners use to assess the cybersecurity of national banks and federal savings associations. The regulator said the change does not create new regulatory expectations and that institutions are not required to use it to review their own readiness.

What changed in the program?

The update reorganizes the material to keep it aligned with the updated categories and subcategories in the NIST Cybersecurity Framework. According to the OCC, the goal was to adjust the structure and references used by examiners, not to add new exam procedures or change the scope of supervision.

CU Daily also reported that this version replaces OCC Bulletin 2023-22. VitalLaw said the alignment is with NIST CSF 2.0 and that the 2023 bulletin was rescinded. Paul Hastings described the program as a high-level examination tool that remains aligned with NIST, but does not turn that framework into a mandatory assessment for banks.

What does this mean for supervised banks?

The OCC made clear that the program remains an internal guide for examining national banks and federal savings associations. That means the update brings supervision references and categories into order, but it does not impose a new compliance requirement or a deadline for institutions to adapt.

Independent coverage agreed that no exam procedures were added or changed. The update is meant to reflect the updated NIST framework within supervision, while each bank's decision to use that framework to assess its own cybersecurity maturity remains optional.

Sources

View all