Late last year, the FFIEC dropped a major announcement: the Cybersecurity Assessment Tool (CAT) will be officially retired by August 31, 2025.
With this significant change on the horizon, now is the time to future-proof your cybersecurity strategy. To help you stay ahead, we’re breaking down a few alternative frameworks that not only keep your program aligned with regulatory best practices but also drive continuous improvement in your cybersecurity posture.
At Rivial, we stay on top of examiner insights as we help clients through their exams. Lately, we’ve seen credit union examiners advising against the new ISE tool, reminding them that ACET (CAT) is optional, and recommending they adopt an internal security framework instead. Banks are getting similar advice—CAT isn’t required while having a solid internal framework is key. From our experience, a few that we would recommend are CIS, NIST, and ISO27001 as they are well aligned with examiner expectations and regulatory standards.
The National Institute of Standards and Technology (NIST) Cybersecurity Framework is one of the most widely adopted security frameworks out there. It’s flexible, scalable, and especially useful for financial services organizations looking to build a strong cybersecurity foundation.
🔹 Why NIST?
The Center for Internet Security (CIS) Critical Security Controls is all about practicality. It provides a prioritized list of security measures to protect against the most common cyber threats—perfect for organizations looking for an actionable approach to cybersecurity.
🔹 Why CIS Controls?
ISO/IEC 27001 is an internationally recognized standard for Information Security Management Systems (ISMS). If your organization needs a structured, risk-based approach to managing sensitive data, this framework has you covered.
🔹 Why ISO 27001?
At Rivial, we’ve streamlined framework transitions by pre-mapping essential control frameworks—such as FFIEC CAT, NIST CSF 2.0, CIS Top 18, PCI, ACET, NCUA ISE, CRI Profile, and more—directly to the necessary evidence within our platform.
With everything already aligned, switching frameworks is as simple as selecting the one you need, significantly reducing the time and effort required—by up to 80%.
Want to see it in action? Schedule a demo below to experience a seamless transition firsthand.