Stay FFIEC examination-ready
What is the FFIEC?
The Federal Financial Institutions Examination Council (FFIEC) is the US interagency body that prescribes uniform principles, standards, and report forms for the federal examination of financial institutions. Its IT Examination Handbook is the reference examiners use to evaluate an institution's information security, business continuity, and IT risk management.
The CAT sunset
From 2015, many institutions used the FFIEC Cybersecurity Assessment Tool (CAT) to self-assess their cyber maturity. The FFIEC retired the CAT on August 31, 2025, having decided not to update it to reflect newer government resources. Institutions are expected to transition to standardized, actively maintained frameworks instead:
- NIST CSF 2.0 — by far the most common replacement.
- CRI Profile — the Cyber Risk Institute's financial-sector tailoring of NIST CSF, which maps to FFIEC handbooks, NY DFS Part 500, and other supervisory regimes.
- CIS Controls and the CISA Cybersecurity Performance Goals — additional options.
Importantly, the IT Examination Handbook and the examination program itself remain in force — only the voluntary CAT tool went away.
How episki helps
episki carries FFIEC expectations as evaluated controls rather than a maturity questionnaire: access, change, resilience, and vendor management checks that write explicit verdicts, with findings routed to owners and crosswalks to NIST CSF and ISO 27001 derived through the SCF hub. Start a free trial or book a demo.
FFIEC outcomes with episki
Why teams choose episki for FFIEC
- NIST CSF 2.0 mapping out of the box
- CRI Profile for financial-sector depth
- CIS Controls and CISA CPGs as options
- Control-to-handbook mapping
- Examiner-ready evidence library
- Risk assessment and board reporting
- Crosswalk to GLBA Safeguards
- Crosswalk to NY DFS Part 500
- Reuse SOC 2 and ISO 27001 evidence
FFIEC readiness inside episki
Plug episki into your stack and work directly from this checklist during the free trial.
- ✓ Successor framework selected (NIST CSF 2.0 or CRI Profile)
- ✓ Control library mapped to the FFIEC IT Examination Handbook
- ✓ Cybersecurity risk assessment kept current
- ✓ Board and management reporting
- ✓ Third-party / vendor risk management
- ✓ Examiner-ready evidence library