FFIEC Cybersecurity Assessment Tool (CAT)
Evidence request list. 49 controls, 49 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Cybersecurity Maturity - Cyber Incident Management and Resilience
FFIEC announced CAT will sunset on 31 August 2025 with institutions transitioning to the CRI Profile v2.1 mapped to NIST CSF 2.0.
- CAT to CRI Profile mapping workbook
- Sunset transition project plan
- Gap analysis against CRI diagnostic statements
- Board update on transition
- No board awareness of CAT sunset
- Mapping treats CRI as identical scoring
Incident response plan, playbooks, and resilience strategy aligned to scenarios.
- IR plan latest revision
- Scenario playbooks ransomware, DDoS, wire fraud
- BIA outputs
- Crisis communications plan
- Plan not socialised to business
- Wire fraud playbook missing
Detection, triage, containment, and eradication procedures with defined RTOs and RPOs.
- IR ticketing export sample
- MTTD and MTTR metrics
- Containment evidence per incident class
- Post-incident review template
- MTTD measured only for SIEM-detected
- Containment improvisation not captured
Internal and external escalation including 36 hour computer security incident notification rule and customer notification.
- 36 hour notification SOP
- Primary federal regulator contact card
- Sample notification template
- Customer notification template
- 36 hour rule not tested in tabletop
- Sub-servicer breach trigger unclear
Cybersecurity Maturity - Cyber Risk Management and Oversight
Board and senior management oversight of cybersecurity strategy, with documented roles, accountability, and reporting cadence.
- Cyber governance charter
- Board meeting minutes referencing cyber
- CISO reporting line org chart
- Cyber strategy approved document
- Board cyber expertise undocumented
- Strategy not refreshed against threat changes
Integrated cyber risk management program with risk appetite, risk assessments, and exception handling tied to ERM.
- Cyber risk register with treatment plans
- Risk appetite document
- Risk acceptance log
- Annual cyber risk assessment
- Risk appetite not quantitative
- Risk register not linked to controls
Budget, staffing, and training to sustain cyber capabilities including role-based training for privileged users.
- Cyber budget allocation by program
- Role-based training matrix
- Completion rates report
- Phishing simulation results
- Privileged role training conflated with general awareness
- Vendor staff excluded from awareness metrics
Embed cyber accountability across business lines with incentives, disciplinary measures, and culture surveys.
- Cyber accountability policy
- Performance review templates referencing cyber
- Culture survey results
- Disciplinary action log redacted
- Business line ownership of risks unclear
- Survey only IT staff
Cybersecurity Maturity - Cybersecurity Controls
Network segmentation, secure configuration baselines, and change management to prevent compromise.
- Hardening standards by platform
- Configuration drift report
- Segmentation review
- Change management metrics
- Cloud baselines absent
- OT and IT segmentation not enforced
Least privilege, MFA, identity governance, and data loss prevention across critical systems.
- MFA enrollment report
- Privileged access review
- DLP policy and incident log
- Joiner mover leaver evidence
- MFA gaps on legacy apps
- DLP egress monitoring rules stale
Logging, monitoring, anomaly detection, and EDR with documented coverage and tuning.
- Log source inventory
- Detection coverage matrix
- EDR deployment report
- Tuning change log
- Servers and containers underlogged
- EDR exclusions undocumented
Timely vulnerability remediation, patch management, and end-of-life replacement.
- Vulnerability scan reports
- Patch compliance dashboard
- EOL inventory and replacement plan
- Exception register
- KEV catalogue not prioritised
- EOL systems carry-forward without compensating controls
Cybersecurity Maturity - External Dependency Management
Inventory and risk-rate all external connections including third party access and APIs.
- External connection diagram
- API register with auth model
- Connection risk ratings
- Decommission log
- API to fintech partners undocumented
- VPN tunnels orphaned
Due diligence, contracts, and ongoing monitoring of third parties with cyber requirements.
- TPRM policy and tiering
- Sample due diligence package
- SOC 2 review log
- Contract clauses for cyber, breach notification, audit
- Fourth parties not assessed
- Breach notice SLAs missing in legacy contracts
Cybersecurity Maturity - Threat Intelligence
Subscribe to and act on cyber threat intelligence from FS-ISAC, CISA, vendors, and peers with documented triage.
- FS-ISAC membership confirmation
- Threat intel platform export
- Triage SOP
- Indicator pushdown to SIEM evidence
- Intel consumed but not actioned
- No measurement of mean time to deploy IOCs
Continuous monitoring, correlation, and analysis of threat data against institutional context.
- SIEM use case catalogue
- Threat hunting reports
- Detection coverage map
- Analyst playbooks
- Coverage gaps against ATT&CK not measured
- Hunt program ad hoc
Share threat indicators and incident learnings with sector partners and law enforcement.
- Information sharing agreements
- TLP marking policy
- Submitted IOC log
- FBI and Secret Service contact register
- TLP mishandled on outbound
- No metrics on contributions
Domain 1: Cyber Risk Management and Oversight
Board and senior management oversight of institution-wide cybersecurity strategy and direction
- board charter
- board cyber briefing pack
- cyber risk committee minutes
- governance policy
- board cyber expertise gap
- infrequent reporting
- no defined cadence
- tone from top weak
Robustness of the cybersecurity risk management program and integration with enterprise risk management
- risk management framework
- risk register
- risk appetite statement
- treatment plans
- risk appetite undefined
- register stale
- treatment plans absent
- no risk acceptance documentation
Staffing, budgeting, and allocation of resources for information security and cybersecurity
- security budget
- headcount plan
- tooling inventory
- skills assessment
- chronic under investment
- skills gaps
- no capacity plan
- tool sprawl
Annual information security training, cybersecurity awareness programs, and security culture development
- training plan
- completion records
- culture survey results
- phishing test data
- below 100 percent completion
- no role based content
- culture metric absent
- phishing remediation slow
Domain 2: Threat Intelligence and Collaboration
Processes for uncovering, acquiring, and analyzing cybersecurity threat information
- threat intel programme charter
- feed inventory
- intel briefs
- FS-ISAC membership
- no formal programme
- free feeds only
- no actioning of intel
- low FS-ISAC engagement
Monitoring threat intelligence sources and analyzing threat data for relevance to the institution
- SIEM use cases
- monitoring SOP
- incident metrics
- analyst playbooks
- use case coverage low
- alert tuning weak
- no 24x7 monitoring
- playbooks outdated
Sharing cybersecurity threat findings with stakeholders, peers, and information sharing organizations
- FS-ISAC membership
- intel sharing log
- MOUs
- industry forum participation
- one way consumption only
- no anonymised sharing
- MOUs absent
- engagement low
Domain 3: Cybersecurity Controls
Maturity of preventative controls including access management, device security, and network security
- firewall rules baseline
- EDR deployment report
- patching SLAs
- secure config baselines
- patching SLA breaches
- EDR coverage gaps
- firewall rule sprawl
- no baseline drift detection
Maturity of detective controls including logging, monitoring, and anomaly detection capabilities
- detection use cases
- anomaly detection config
- SOC dashboards
- detection coverage map
- detection coverage gaps
- weak anomaly tuning
- no MITRE ATTACK mapping
- logs siloed
Maturity of corrective controls including patch management, vulnerability remediation, and configuration management
- containment playbooks
- patch remediation tracker
- IR runbooks
- lessons learned reports
- remediation backlog
- no automated containment
- weak post incident review
- lessons not implemented
Domain 4: External Dependency Management
Managing and securing external connections that have access to enterprise information and technology assets
- connection inventory
- DMZ architecture
- B2B gateway config
- review of external connections
- connection inventory stale
- unsanctioned connections
- weak segmentation
- no annual review
Programs overseeing and managing third-party relationships including due diligence and ongoing monitoring
- vendor inventory
- lifecycle SOP
- performance reviews
- exit plans
- weak ongoing monitoring
- no exit plans
- concentration risk unmanaged
- no performance reviews
Controls governing third-party access to institutional systems and data
- third party access policy
- access requests log
- JIT access tooling
- session recording
- standing third party access
- no session recording
- no privilege separation
- weak deprovisioning
Domain 5: Cyber Incident Management and Resilience
Incident response planning including roles, responsibilities, communication plans, and escalation procedures
- incident response plan
- communications plan
- stakeholder matrix
- regulator contact list
- IR plan stale
- no executive crisis plan
- communications plan absent
- tabletops infrequent
Capabilities for detecting, responding to, and mitigating cyber incidents in a timely manner
- detection coverage map
- response runbooks
- mitigation playbooks
- tooling inventory
- MTTD high
- MTTR high
- playbooks untested
- no automated response
Procedures for escalating cyber incidents to management and reporting to regulators and stakeholders
- escalation matrix
- regulator reporting SOP
- executive briefing template
- customer notification template
- unclear escalation thresholds
- regulator reporting SLAs missed
- no executive briefings
- communications inconsistent
Planning and testing to recover normal operations after a cybersecurity event including BCP and DR testing
- BCP plan
- DR test reports
- resilience metrics
- exercise scenarios
- BCP not tested
- DR test scenarios narrow
- resilience metrics absent
- no scenario based exercises
Inherent Risk Profile
Catalogue technologies, connection types, and external service providers that drive inherent cyber risk to determine the institution's risk level (Least to Most).
- IRP scoring workbook with technology counts
- Network diagram showing external connections
- Inventory of cloud services and SaaS
- ISP and MPLS circuit list
- Wireless access point register
- Shadow IT not captured
- ISP redundancy unscored
- Cloud connections undercounted
Score inherent risk arising from online and mobile delivery channels including ATM operations and number of customers served.
- Online banking user counts
- Mobile banking enrollment report
- ATM fleet inventory
- Channel risk scoring sheet
- Mobile counts stale
- ATM third-party operators excluded
Identify products and services offered through digital channels including wire transfers, P2P, merchant services, and trust services.
- Product and service register
- Wire transfer volume report
- P2P transaction logs
- Merchant card processing summary
- High-risk product overlap with risk appetite undocumented
- Volumes not refreshed quarterly
Score risk from mergers, locations, employee counts, IT staff changes, and direct employee internet access.
- Headcount trend
- M&A timeline last 12 months
- IT staff turnover report
- Privileged user counts
- Contractor counts excluded
- Post-merger integration risk unrated
Quantify attempted attacks against the institution including phishing, DDoS, and reconnaissance traffic.
- Phishing attempts blocked report
- DDoS mitigation summary
- Threat intel digest
- Attempted intrusion log
- Phishing metrics aggregated only annually
- Attempted versus successful conflated
Inherent Risk Profile: Risk Categories
Evaluates risk from third-party connections, unsecured external links, wireless networks, and hosting arrangements
- technology inventory
- connection types register
- risk profile worksheet
- annual reassessment
- inventory stale
- shadow IT
- risk profile not reassessed
- scoring inconsistent
Assesses risk from websites, mobile applications, ATMs, and other customer-facing channels
- channel inventory
- transaction volume metrics
- channel risk assessment
- fraud metrics
- new channels not assessed
- fraud metrics weak
- channel inventory outdated
- no concentration analysis
Reviews payment and transaction service security challenges from online and mobile offerings
- product inventory
- mobile app security testing
- online service risk assessments
- feature rollout review
- mobile app testing infrequent
- new features unassessed
- API security gaps
- third party SDKs unreviewed
Examines staffing, access privileges, data center locations, employee count, and organizational structure
- org profile worksheet
- M&A integration plans
- geographic footprint analysis
- headcount trends
- M&A risk not integrated
- geo expansion unassessed
- merger inheritance untracked
- outsourcing concentration
Analyzes attack frequency, types of threats, and the threat landscape facing the institution
- threat landscape briefings
- attack surface assessments
- intel reports
- annual threat review
- threat landscape stale
- attack surface unmapped
- no sector specific intel
- no annual review
Maturity Levels
Minimum set of cybersecurity practices expected for all institutions regardless of size or risk profile
- baseline declaration
- control assessment
- gap analysis
- remediation plan
- below baseline declared
- gap analysis missing
- no remediation plan
- baseline definition weak
Maturing cybersecurity practices beyond baseline with additional controls and risk management capabilities
- maturity assessment
- evolving control evidence
- improvement plan
- executive approval
- overstated maturity
- no evidence of evolving controls
- improvement plan absent
- no peer benchmarking
Detailed and formally documented cybersecurity processes validated on a regular basis
- maturity assessment
- intermediate control evidence
- metrics dashboard
- executive review
- control depth lacking
- metrics absent
- no executive review
- self attestation unreliable
Integrated cybersecurity practices, real-time monitoring, and advanced threat detection capabilities
- automation evidence
- advanced control runbooks
- KPI dashboards
- external assessment
- automation absent
- advanced controls unverified
- metrics not trended
- no external assurance
Cutting-edge cybersecurity practices, active contribution to industry knowledge, and continuous innovation
- innovation roadmap
- leading practice attestations
- industry collaboration
- research outputs
- self assessed as innovative without evidence
- no industry contribution
- no R and D
- claims unsubstantiated
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FFIEC Cybersecurity Assessment Tool (CAT) framework page.