The FFIEC Cybersecurity Assessment Tool (CAT) is retired. But the need to prove your security controls isn't. The FFIEC CAT tool was sunset on August 31, 2025, and financial institutions are transitioning from maturity-based self-assessment to more flexible, risk-based cybersecurity programs. While FFIEC has withdrawn its support for the tool, the need for effective cybersecurity risk management and control testing remains. As banks face more complex cyber threats, penetration testing is crucial for demonstrating that security systems can withstand real-world attacks, rather than just meeting compliance requirements.
Learn about the CAT retirement's implications for banks, the FFIEC guidance that will be relevant in 2026, and the important areas that financial institutions should focus when developing a risk-oriented penetration testing program.
What the CAT Retirement Means for Penetration Testing
The retirement of the FFIEC Cybersecurity Assessment Tool (CAT) does not eliminate the need for financial institutions to regularly evaluate the effectiveness of their cybersecurity controls. The CAT provided a formal, voluntary framework for assessing cybersecurity maturity, but it was never intended to replace traditional security practices, independent assessments, or ongoing control testing. Instead of relying on a single maturity-based assessment tool, financial institutions can use current resources identified by FFIEC, including the NIST Cybersecurity Framework 2.0, CISA Cybersecurity Performance Goals, CISA Cybersecurity Performance Goals: Sector-Specific Goals, Cyber Risk Institute Cyber Profile, and Center for Internet Security Controls. FFIEC does not endorse any particular tool. Separately, institutions should continue to reference the FFIEC IT Examination Handbook, Information Security booklet, which provides examination guidance for information security.
This shift places greater emphasis on flexible, risk-based cybersecurity validation. The CISA Cross-Sector Cybersecurity Performance Goals (CPGs) provide a voluntary baseline of high-impact practices, while NIST Cybersecurity Framework 2.0, released on February 26, 2024, adds Govern alongside Identify, Protect, Detect, Respond, and Recover to strengthen cybersecurity governance and risk management. Within this approach, penetration testing helps financial institutions validate whether security controls can withstand real-world attack scenarios, identify exploitable vulnerabilities across critical systems and applications, and provide evidence that supports cybersecurity risk management and examination readiness. The goal is not to replace CAT with another single assessment tool, but to continuously identify risk, test critical controls, and improve the institution's overall security posture.
FFIEC Cybersecurity Guidance Banks Should Follow in 2026
With the retirement of the FFIEC Cybersecurity Assessment Tool (CAT), financial institutions should be aware that the FFIEC has not reduced its expectations for effective cybersecurity risk management. Instead, banks are encouraged to take a flexible, risk-based approach that uses current cybersecurity frameworks and demonstrates the effectiveness of security measures through testing, governance, and fact-based reporting.
This involves moving away from checklist-driven evaluations and focusing on assessing the systems, apps, and business procedures that pose the most risk to the institution. Rather than using a static questionnaire to assess cybersecurity maturity, FFIEC examiners require banks to produce objective proof that their security policies can resist real-world attack scenarios.
The following is guidance for banks regarding FFIEC cybersecurity in 2026:
What Banks Must Test in 2026
Financial institutions should focus penetration testing on the systems, applications, infrastructure, and security controls that present the greatest risk to the institution. Testing should reflect the organization's current technology environment and risk profile rather than follow a one-size-fits-all checklist. Key areas include external and internal networks, customer-facing applications, APIs, cloud environments, identity and access controls, authentication mechanisms, remote access services, critical business applications, and third-party connections. Testing should also evaluate whether vulnerabilities can be chained together to gain unauthorized access, escalate privileges, move laterally, or reach sensitive systems and data.
Penetration testing should be performed or reviewed by qualified personnel who are organizationally independent of those responsible for developing or maintaining the security programs being tested. Testing should use recognized methodologies appropriate to the engagement, such as NIST SP 800-115, OWASP Testing Guide, OSSTMM, PTES (Penetration Testing Execution Standard), and the Penetration Testing Framework. The scope and frequency of testing should be driven by the institution's risk assessment and applicable regulatory requirements, with findings documented, prioritized, remediated, and retested to verify that identified weaknesses have been effectively addressed.
Common Gaps That Weaken Banking Penetration Test
Below are some of the most common gaps that reduce the effectiveness of banking penetration testing programs in 2026.
1. A Limited Testing Scope
Many financial organizations continue to prioritize traditional network infrastructure above modern attack surfaces. When establishing the scope of a penetration test, it is important to consider internet-based applications, cloud-based workloads, APIs, phone banking platforms, remote access tools, and identity services. An incomplete range leaves vital assets unexplored, increasing the possibility of exploitable security flaws.
2. Treating Penetration Testing as a Compliance Exercise
Penetration testing shouldn't be considered as an annual checkbox exercise carried out only to meet regulatory requirements. Banks that merely test to satisfy compliance deadlines may fail to discover emerging risks or ensure that their security policies remain effective. For OCC-supervised institutions, the frequency and nature of security testing should be determined by the institution's risk assessment, and testing should be conducted or reviewed by independent third parties or staff independent of those who develop or maintain the security programs. Similar guidelines apply to Federal Reserve-supervised banks under 12 CFR Part 208 Appendix D-2 and FDIC-supervised banks under 12 CFR Part 364 Appendix B. A mature strategy aligns assessment with the institution's changing risk profile and substantial technological advancements.
3. Insufficient Testing of Identity and Access Controls
Identity has grown into one of the most common attack vectors in the banking sector. Weak authentication procedures, excessive user privileges, poorly maintained service accounts, and insufficient multi-factor authentication (MFA) testing can all compromise important banking systems. Identity systems, special privileges, and authorization restrictions should all be assessed during penetration testing to discover potential for unauthorized access or privilege escalation.
4. Overlooking APIs and Digital Banking Services
APIs are now crucial for linking mobile apps, payment methods, fintech partners, and customer-facing platforms as financial institutions continue to develop their digital banking capabilities. Vulnerabilities including faulty authentication, improper authorization, and inappropriate data exposure could go unnoticed if APIs are left out of penetration testing. In addition to standard web application testing, comprehensive evaluations should incorporate API security.
5. Ignoring Cloud Security Risks
The banking attack surface has increased due to the growing use of cloud platforms. Significant risks can be introduced by poorly segmented networks, overly permissive identity and access management (IAM) policies, misconfigured storage services, and accessible administrative interfaces. For a comprehensive picture of the institution's security posture, cloud environment penetration testing should be assessable in addition to on-premises technology.
6. Failing to Validate Remediation
Finding vulnerabilities is just the beginning. Organizations cannot show that identified risks have been successfully mitigated without confirming that remedial operations have been successfully executed. Retesting important results increases trust in the organization's cybersecurity program and shows that remedial measures are effective.
7. Weak Executive Reporting and Documentation
Technical results by themselves are rarely adequate for regulatory or management reviews. Reports from penetration tests should document remediation efforts, prioritize risks, clearly explain business effect, and offer practical recommendations. During FFIEC examinations, executive leadership may demonstrate strong cybersecurity governance and make well-informed decisions thanks to well-structured reporting.
Common Gaps and Recommended Actions
| Common Gap | Potential Impact | Recommended Action |
|---|---|---|
| Limited testing scope | Critical systems remain untested | Expand testing to include cloud, APIs, identity infrastructure, and customer-facing applications. |
| Compliance-focused assessments | Emerging threats may go undetected | Adopt a continuous, risk-based penetration testing strategy. |
| Weak identity testing | Increased risk of unauthorized access and privilege escalation | Evaluate IAM, MFA, privileged accounts, and authentication controls. |
| Inadequate cloud security testing | Misconfigurations and exposed services remain undetected | Include cloud workloads, IAM policies, and network segmentation in testing. |
| No remediation validation | Security gaps may persist after fixes | Perform retesting to verify remediation effectiveness. |
| Poor reporting and documentation | Reduced visibility for executives and examiners | Deliver risk-based reports with remediation tracking and executive summaries. |
Moving Ahead
The FFIEC CAT's departure marks a move away from recurring evaluations and toward ongoing, risk-based cybersecurity validation. Effective penetration testing should improve examination readiness, bolster cyber resilience, and confirm crucial security procedures for financial institutions in 2026. As you improve your cybersecurity approach, you can find gaps before they become security or regulatory issues by routinely comparing your penetration testing program to industry standards.