Banking and Finance Law Daily Wrap Up, PRUDENTIAL REGULATION—OCC updates cybersecurity supervision work program structure and references, (Sep 22, 2026)
Organizations Mentioned:Office of the Comptroller of the Currency

By Shashi Kant, BALLB, LLM
The OCC said it added or changed no procedures, and banks are not expected to use the program.
The Office of the Comptroller of the Currency (OCC) has updated the structure and references of the Cybersecurity Supervision Work Program (CSW) used by its examiners, according to OCC Bulletin 2026-48, issued Sept. 21, 2026. The bulletin states that the update maintains alignment between the CSW structure and the evolving National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF). The OCC said it did not add any new procedures to the CSW and did not change any existing procedures. The bulletin rescinds OCC Bulletin 2023-22, issued June 26, 2023, which introduced the CSW (see Banking and Finance Law Daily, Jun. 27, 2023).
Reason for the update. The OCC said that, as cyberattacks evolve and as banks adopt various standardized tools and frameworks to assess cybersecurity preparedness, it continues to update its approach to assessing cybersecurity risk as part of risk-based supervision. According to the bulletin, the CSW provides high-level examination objectives and procedures that are aligned with existing supervisory guidance and the NIST CSF. The bulletin states that the CSW addresses evolving risks and supports risk-based bank information technology (IT) examinations.
Alignment with CSF 2.0. The bulletin states that the CSW structure was updated to align with the updated NIST CSF categories and subcategories. The OCC’s CSW Overview page states that the CSW is structured to align with the six NIST CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, and Recover) and their related categories and subcategories. According to the OCC, this alignment provides examiners with a common framework and terminology for discussions with bank management.
The OCC’s CSW References page explains that each procedure’s unique ID follows the hierarchy of NIST CSF functions, categories, and subcategories. The OCC added two characters at the end of each unique ID to designate the specific procedure, according to the agency. The CSW does not include NIST CSF categories or subcategories that are addressed in other examination programs or that do not apply to the OCC’s bank IT supervision process. The OCC notes that the CSW uses the term “IT Asset Management,” rather than the CSF term “Asset Management,” to distinguish it from financial asset management.
No new expectations. The bulletin states that the CSW does not establish new regulatory expectations and that banks are not expected to use the work program to assess cybersecurity preparedness. The OCC said it continues to encourage, but does not require, the use of a standardized approach to assess and improve cybersecurity preparedness. Banks may choose from a variety of available tools and frameworks, according to the bulletin. “Banks” are defined as national banks, federal savings associations, and federal branches and agencies of foreign banking organizations.
Community banks. According to the bulletin, the CSW continues to enable risk-based examination scoping and is scalable for banks of different sizes and complexity. The OCC said examiners may use the CSW’s examination procedures during examinations of a community bank’s cybersecurity preparedness.
Cross-references. The bulletin states that the CSW focuses on cybersecurity preparedness and supplements the OCC’s bank IT examination procedures in the “Community Bank Supervision,” “Large Bank Supervision,” and “Federal Branches and Agencies Supervision” booklets of the Comptroller’s Handbook. It also supplements the Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook booklets, according to the bulletin.
MainStory: TopStory BankingOperations CyberPrivacyFeed DataPrivacy DataSecurity FinancialStability FinTech GCNNews IdentityTheft Privacy PrudentialRegulation