CeFPro Connect

News
OCC Revamps Cyber Oversight as Bank Threats Evolve
The OCC has updated the framework used by examiners to assess banks’ cybersecurity preparedness, aligning it with the evolving NIST Cybersecurity Framework while emphasizing that the changes introduce no new procedures or regulatory expectations.
Sep 29, 2026
Tags: Industry News Cyber
OCC Revamps Cyber Oversight as Bank Threats Evolve
The views and opinions expressed in this content are those of the thought leader as an individual and are not attributed to CeFPro or any other organization
  • OCC updates its Cybersecurity Supervision Work Program as cyber threats and industry frameworks evolve  
  • No new examination procedures or regulatory expectations have been introduced
  • The revised structure aligns with updated NIST Cybersecurity Framework categories
  • Banks remain free to choose which standardized cybersecurity assessment frameworks they use
  • The program remains scalable for community banks and larger institutions 

The Office of the Comptroller of the Currency has updated the framework its examiners use to assess banks’ cybersecurity preparedness, reflecting changes to widely used industry standards as cyber threats continue to evolve.

The regulator has revised the structure and references of its Cybersecurity Supervision Work Program, or CSW, which supports risk-based supervision of cybersecurity at national banks, federal savings associations and federal branches and agencies of foreign banks.

However, the OCC stressed that the update does not introduce new examination procedures or change existing ones.

Instead, the revised structure is designed to maintain alignment with the evolving National Institute of Standards and Technology Cybersecurity Framework.

The move reflects the growing use by banks of standardized tools and frameworks to assess their cyber defenses.

The CSW provides OCC examiners with high-level objectives and procedures for evaluating cybersecurity preparedness while connecting those assessments with existing supervisory guidance.

Importantly for banks, the OCC said the updated program does not establish new regulatory expectations. Institutions are also not expected to use the CSW itself to assess their own cybersecurity preparedness.

The regulator continues to encourage banks to adopt standardized approaches to evaluating and improving cyber resilience, but does not mandate a particular framework or tool.

The program is also intended to remain scalable across institutions of different sizes and levels of complexity. OCC examiners can therefore use its procedures when assessing cybersecurity preparedness at community banks as well as larger institutions.

The latest version reorganizes the CSW to correspond with updated NIST framework categories and subcategories while retaining the underlying examination procedures. It also maps those procedures against other established supervisory and industry resources.

These include the Federal Financial Institutions Examination Council’s Information Technology Examination Handbook, the Center for Internet Security Critical Security Controls and the Cyber Risk Institute Profile.

The CSW also supplements existing OCC information technology examination procedures contained within its supervisory handbooks for community banks, large banks and federal branches and agencies.

The OCC said its references will allow examiners and institutions to see how individual CSW procedures correspond with existing supervisory guidance and widely recognized cybersecurity frameworks.

Future revisions to those references will be published by the regulator as the external frameworks continue to develop.

Although the changes are primarily structural, they come as banks face an increasingly complex cybersecurity environment and regulators continue adapting supervisory approaches to changing threats and technology.

By keeping its examination framework aligned with NIST and other established standards, the OCC is seeking to maintain consistency between regulatory supervision and the cybersecurity methodologies institutions are increasingly using themselves.

The update replaces the previous version of the program issued in June 2023, with the OCC formally rescinding its earlier cybersecurity supervision bulletin.

Sign in to view comments
You may also like...
ad
Related insights —