Skip to content
RiskTemplates · The Daily Brief Sunday, October 4, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Feature Business Continuity

The FFIEC CAT Is Retired. The OCC Just Updated Its Exam Checklist to NIST CSF 2.0. Here's the Govern Function Gap Most Financial Institutions Are Missing.

OCC Bulletin 2026-48 aligned the OCC's Cybersecurity Supervision Work Program to NIST CSF 2.0 — including the new Govern function that didn't exist when most financial institutions built their cybersecurity programs. Here's what examiners are now checking and where programs are falling short.

By Rebecca Leung · October 3, 2026 ·
Table of Contents

TL;DR

  • The FFIEC CAT was retired in 2024 and OCC Bulletin 2026-48 (September 22, 2026) officially aligned OCC cybersecurity examination procedures to NIST CSF 2.0, including the new Govern function
  • The Govern function — completely absent from CSF 1.1 — requires documented board oversight, a cybersecurity risk appetite statement, and treatment of supply chain risk at the governance layer
  • Most financial institutions built their programs to the FFIEC CAT or CSF 1.1 structure, which means the Govern function is a gap most have never explicitly addressed
  • Examiners now organize their reviews against six CSF 2.0 functions; institutions that can’t show Govern-function artifacts — risk appetite, board oversight evidence, GV.SC documentation — will surface gaps at their next exam

The Tool That Defined a Decade Is Gone

Walk into any compliance team at a community bank between 2016 and 2024 and you’d find the same artifact: an Excel spreadsheet populated against the FFIEC Cybersecurity Assessment Tool. Five domains, two maturity levels, 494 declarative statements. Love it or hate it, the CAT gave institutions something cybersecurity compliance had rarely had: a predictable, examiner-tested checklist.

The FFIEC retired the CAT in 2024. The agencies recommended institutions transition to NIST CSF 2.0 — but “recommended” didn’t mean “required,” and most institutions responded the way institutions typically respond to voluntary guidance: they kept doing what they were doing.

Then came OCC Bulletin 2026-48, issued September 22, 2026. The bulletin rescinds the previous version of the OCC Cybersecurity Supervision Work Program and explicitly restructures it around the six NIST CSF 2.0 functions. The bulletin says it doesn’t add new requirements — and that’s technically accurate. But it does mean OCC examiners now organize cybersecurity reviews against the CSF 2.0 architecture, including the function that didn’t exist when most financial institutions designed their programs.

That function is Govern.

What NIST CSF 2.0 Actually Changed

NIST published CSF 2.0 in February 2024. The four-page executive summary makes it sound incremental. It isn’t.

The original CSF 1.0 and 1.1 had five functions: Identify, Protect, Detect, Respond, Recover. These mapped cleanly to the FFIEC CAT domains. Institutions that maintained good FFIEC CAT scores had reasonable confidence they were covering the framework.

CSF 2.0 added a sixth function, Govern, placed at the front of the framework — listed first, before Identify. This placement is intentional. NIST’s rationale is that cybersecurity decisions are organizational decisions: they require leadership accountability, documented risk tolerance, and governance structures that sit above the technical controls the other five functions address.

The Govern function has six categories:

  • GV.OC — Organizational Context: The mission, legal and regulatory requirements, business dependencies, and stakeholder expectations that shape how the organization manages cybersecurity risk
  • GV.RM — Risk Management Strategy: Established risk appetite and tolerance statements, priorities, and processes for making cybersecurity risk decisions
  • GV.RR — Roles, Responsibilities, and Authorities: Documented ownership, accountability for cybersecurity outcomes, and authority to accept, escalate, or remediate risk
  • GV.PO — Policy: Policies that define how cybersecurity decisions are made, what is and isn’t permitted, and how compliance is verified
  • GV.OV — Oversight: How leadership validates that the cybersecurity risk management program is working as designed — board and committee oversight, independent testing results review, escalation triggers
  • GV.SC — Cybersecurity Supply Chain Risk Management: Governance-layer treatment of third-party and supply chain cybersecurity risk, including risk appetite for vendor relationships, criteria for acceptable vendor security, and board-level accountability

That last one — GV.SC — is particularly important for financial institutions, and it’s where the architectural shift from CSF 1.1 is most pronounced.

The Supply Chain Risk Migration

Under CSF 1.1, cybersecurity supply chain risk appeared in the Identify function (asset inventories that included vendor relationships) and the Protect function (access controls, due diligence procedures, contractual security requirements). In other words, it was a technical-layer activity: document your vendors, assess their security posture, require appropriate controls.

CSF 2.0 moved supply chain risk to Govern. That’s not a reclassification — it’s an architectural redesign. The message is that vendor cyber risk is not just a TPRM program deliverable to be managed by the third-party risk team. It is a governance-layer obligation requiring board-level strategy, documented risk tolerance for vendor relationships, and explicit accountability at the leadership level.

This connects directly to where OCC examiners have been applying pressure. The June 2026 OCC cybersecurity resilience report identified “management of critical dependencies” as one of five examination expectations — and specifically noted that the relevant question is no longer whether you have vendor due diligence procedures, but whether leadership has established and tested the organization’s ability to withstand a critical vendor failure. GV.SC formalizes exactly that expectation in the examination framework.

What the Govern Function Gap Looks Like in Practice

If you’re wondering whether your institution has a Govern function gap, here’s a quick diagnostic:

GV.RM gap signs:

  • Your board cybersecurity update includes metrics like number of phishing tests conducted and patch percentage, but no statement of what’s considered an acceptable vs. unacceptable level of risk
  • You have a cybersecurity policy but no documented cybersecurity risk appetite
  • Risk acceptance decisions are made at the CISO or IT level without a documented threshold for escalation to senior management or the board

GV.RR gap signs:

  • You have a RACI for cybersecurity tasks but no documented authority matrix — who can approve a high-risk vendor relationship, who can accept an open vulnerability, who is accountable if a critical system is down for 72 hours
  • The board understands it “oversees” cybersecurity but cannot identify what specific responsibilities that means

GV.SC gap signs:

  • Vendor cybersecurity risk is assessed and tracked in your TPRM program but never aggregated or reported to the board as a portfolio
  • You have vendor security questionnaires and SOC 2 review processes but no documented organizational risk appetite for vendor cyber risk
  • The TPRM team handles vendor cyber risk entirely; the board receives annual TPRM updates but has no documented cybersecurity-specific standard for vendor relationships

GV.OV gap signs:

  • The board receives quarterly cybersecurity reports but the reports describe activities, not outcomes — no metrics tied to whether the cybersecurity program is achieving its stated objectives
  • Independent testing results (penetration tests, tabletop exercises, audit findings) are summarized but not used to feed a formal management review of program adequacy

The NYDFS Part 500 guidance issued September 2026 provides a parallel view: NYDFS examiners have been asking covered entities to demonstrate board-level oversight of cybersecurity risk specifically — not just report cybersecurity activities to the board, but show that the board has received, reviewed, and acted on cybersecurity risk information. That maps precisely to GV.OV.

What This Means for Your Next Exam

OCC Bulletin 2026-48 restructured the Cybersecurity Supervision Work Program around CSF 2.0’s six functions. Examiners will work through the structure in that order. When they reach Govern, they will look for:

  1. Risk appetite documentation: A board-approved statement that defines the organization’s acceptable level of cybersecurity risk — not generic language about “maintaining a strong cybersecurity posture,” but specific thresholds: acceptable downtime, data exposure limits, minimum vendor security tiers, escalation triggers
  2. Role documentation: Clarity on who owns cybersecurity risk at each level of the organization and what authority each role carries
  3. Supply chain governance: Evidence that vendor cybersecurity risk is managed at the governance layer, not just the operational layer — board-level visibility into concentration risks, critical dependency mapping, and vendor cyber risk appetite
  4. Oversight evidence: Documentation that leadership is validating the program, not just receiving reports — independent testing results reviewed by management, explicit linkage between test results and program adjustments

This is different from the FFIEC CAT environment, where meeting a maturity tier required demonstrating specific practices. The CSF 2.0 environment — like the post-CAT OCC examination approach — is principles-based. Examiners aren’t checking boxes; they’re asking whether governance structures actually work.

The Cloud Concentration Intersection

Cloud provider concentration risk is a live governance issue that sits squarely in GV.SC. If your institution’s primary core system, fraud detection platform, and customer-facing digital banking all run on the same cloud provider, that concentration is a governance-layer question: has leadership explicitly acknowledged the concentration, assessed the tolerable downtime, and documented contingency plans? A TPRM due diligence questionnaire on each vendor separately does not address the concentration risk that emerges when they share infrastructure.

Examiners working through GV.SC will ask whether the organization has visibility into infrastructure-level concentration across its vendor portfolio — not just whether each vendor has adequate security controls.

What to Do Now

If your cybersecurity program was designed around the FFIEC CAT, you have a structural gap: the Govern function doesn’t exist in your program because it didn’t exist in the tool you were building to.

A practical remediation sequence:

Step 1 — Document your cybersecurity risk appetite. This doesn’t require a 50-page policy. It requires a concise statement approved by the board that defines the organization’s tolerance for cybersecurity risk — what’s acceptable, what triggers escalation, and what would require an immediate board discussion. One to two pages, board-reviewed, dated.

Step 2 — Map authority. Who can accept cybersecurity risk at each tier? Document it explicitly. If no one knows whether the CISO can approve a critical vendor with open findings or whether that requires the CEO, that’s the gap.

Step 3 — Elevate supply chain. Take your TPRM program’s critical vendor analysis and present it to your board in terms of cybersecurity risk appetite: these are the vendors whose failure would cause material harm; this is our concentration; this is our documented tolerance. Make it a governance artifact, not just an operational deliverable.

Step 4 — Create oversight linkage. Connect your testing results (pen tests, tabletop exercises, red team findings) to a management-level review of whether the program is working. Show that leadership looked at results and made decisions — not just received a report.

An institution that can produce these four artifacts will be well-positioned for an OCC exam organized around CSF 2.0 functions. An institution that has strong controls in Identify, Protect, Detect, Respond, and Recover but nothing in Govern will have a clearly visible gap — because Govern is now the first thing in the examination work program.


The OCC Bulletin 2026-48 is framed as a structural update with no new requirements. In the narrow regulatory sense, that’s accurate. In the practical examination sense, what it says is: the framework your examiners are working from now has a function your program was never designed to address. That function is specifically where board oversight, risk appetite, and supply chain governance live.

The FFIEC CAT didn’t test those things. NIST CSF 2.0 does.


Sources: OCC Bulletin 2026-48 | NIST Cybersecurity Framework 2.0 | FFIEC CAT transition analysis — myabt.com | NIST CSF 2.0 Govern function — Rivial Security | NIST CSF 2.0 Govern implementation — PlayCISO

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is OCC Bulletin 2026-48 and why does it matter?
OCC Bulletin 2026-48, issued September 22, 2026, rescinds OCC Bulletin 2023-22 and updates the OCC's Cybersecurity Supervision Work Program (CSW) to align its structure with NIST Cybersecurity Framework 2.0 — which added a sixth core function (Govern) that was not present in CSF 1.0 or 1.1. Importantly, the bulletin states that no new regulatory requirements were added; however, it means that examiners now organize their cybersecurity reviews against the six CSF 2.0 functions, including Govern, which most financial institutions have not explicitly built into their programs.
What happened to the FFIEC Cybersecurity Assessment Tool (CAT)?
The FFIEC retired the CAT in 2024. For several years it had served as the de facto examination benchmark for community and mid-size financial institutions, with its 494 declarative statements across five maturity tiers giving compliance teams a predictable checklist. Its retirement left many institutions without a clear mapping between their existing controls and what examiners would test against. NIST CSF 2.0 is now the practical replacement, and OCC Bulletin 2026-48 makes that official for OCC-supervised institutions.
What is the NIST CSF 2.0 Govern function and what does it require?
The Govern function is the most significant addition to CSF 2.0 — it is literally the first function in the updated framework (GV) and contains six categories: Organizational Context, Risk Management Strategy, Roles and Responsibilities, Policy, Oversight, and Cybersecurity Supply Chain Risk Management. In practice, Govern requires that cybersecurity be framed as an enterprise risk with documented board-level oversight, a written risk appetite for cybersecurity, clearly documented roles (including who can authorize risk acceptance), and explicit treatment of third-party and supply chain cyber risk as a governance-layer obligation — not just a technical control.
What is the most common Govern function gap at financial institutions today?
The most common gap is that financial institutions have never explicitly documented a cybersecurity risk appetite. They have policies. They have control frameworks. They have FFIEC CAT maturity scores. What most do not have is a board-approved statement that defines acceptable vs. unacceptable levels of cybersecurity risk — how much downtime is tolerable, what data exposure threshold triggers escalation, and how the institution will respond if a vendor exceeds its inherent risk tier. The second most common gap is treating cybersecurity supply chain risk as a technical-layer issue (TPRM due diligence questionnaires, SOC 2 reviews) rather than a governance-layer obligation requiring board visibility.
Does OCC Bulletin 2026-48 create new requirements for banks?
The bulletin explicitly states it does not add new procedures or change existing ones. But 'no new requirements' and 'no new examiner expectations' are not the same thing. When examiners use a work program restructured around six CSF 2.0 functions — including Govern — they will ask questions that presuppose Govern-function artifacts exist: a documented risk appetite, board-level oversight evidence, and a supply chain cyber risk management process at the governance layer. Institutions that cannot produce those artifacts will surface as gaps in the examination, regardless of whether they're technically 'required.'
How does NIST CSF 2.0 change the treatment of third-party cybersecurity risk?
Under CSF 1.1, third-party risk appeared primarily in the Identify and Protect functions — vendor inventories, access controls, and due diligence procedures. CSF 2.0 moved supply chain risk management to the Govern function, under GV.SC (Cybersecurity Supply Chain Risk Management). This is architecturally significant: it means cybersecurity supply chain risk is now a governance-layer obligation, not just a technical-layer activity. Boards and senior leadership are expected to set strategy, risk tolerance, and accountability for supply chain cyber risk — not just receive a quarterly TPRM report.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Business Continuity & Disaster Recovery (BCP/DR) Kit

BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.