Verification note: the FFIEC CAT retirement date below was checked directly against FDIC and OCC guidance. The NCUA/ACET section was corrected after research turned up a distinction our prior coverage had blurred; see the rewritten section below.
First Call has worked alongside Montana banks and credit unions on cybersecurity and compliance for more than 25 years, and this year’s biggest change has less to do with new attack techniques and more to do with what examiners now expect to see. The FFIEC retired its Cybersecurity Assessment Tool this past year, and institutions are increasingly asked to produce evidence that their controls actually work, not just describe them on paper.
The CAT Is Gone. Here’s What’s Filling the Gap
The Cybersecurity Assessment Tool, built in 2015, gave institutions a structured way to self-assess maturity levels using standardized controls. Since then, NIST released CSF 2.0 and CISA published updated frameworks that better reflect the current environment, so the FFIEC retired the CAT on August 31, 2025, rather than update it piece by piece.
Credit unions have their own version of this shift, and it happened earlier than most institutions realize. NCUA’s Automated Cybersecurity Evaluation Toolbox (ACET) stopped being the actual examination framework back in 2020, replaced by the Information Security Examination (ISE), which has been the real exam standard since 2023. The ACET Toolbox itself still exists as a free, voluntary self-assessment application that NCUA continues to update and align with NIST CSF 2.0, but it is a self-assessment tool, not what your examiner is actually using to evaluate you. If your credit union has been treating ACET as exam prep, you have likely been preparing against the wrong framework since 2023. Our NCUA IT Requirements guide breaks down the ISE tiers (SCUEP, ISE Core, and ISE Core+) and what each one expects.
The Shift Examiners Actually Care About: Evidence Over Description
Most Montana banks and credit unions we talk with already have real controls in place. Producing the evidence on short notice is usually the harder part: a current MFA enforcement report, a documented access review, a backup restore that has actually been tested, and an incident response plan someone has walked through recently. Having a control on paper and being able to prove it works today are two different conversations with an examiner, and the exam only credits the second one.
NCUA’s 2026 supervisory priorities, published January 14, 2026, make this explicit for credit unions: board-level cybersecurity training and vendor and payment-processor risk assessments are both named as active examination focus areas this year, not background expectations.
Where Montana Institutions Are Commonly Behind
- Vendor risk assessments that exist but have not been updated since the vendor relationship changed
- Backup and restore testing that happens more often in theory than in practice
- Access reviews that catch stale logins only when someone happens to notice, rather than on a set schedule
- Incident response plans that were written once and never rehearsed with the team
These same four gaps show up across the two areas we have covered this month. Our piece on vendor cyber incidents walks through building a vendor risk file examiners can actually review, and our piece on business email compromise covers the verification habits that turn a documented control into a tested one.
What This Means for Your Board
Boards are increasingly asked to demonstrate oversight of cybersecurity, not just delegate it to IT. That does not mean board members need to understand every technical control, but it does mean they need a regular, plain-language summary of where the institution stands: which functions have current evidence, which are due for review, and what the plan is for closing any open gaps. A short quarterly briefing built around the same six functions you use for exam prep does double duty, since the material you prepare for your board is largely the same material an examiner will want to see.
Building a Program Instead of Chasing an Exam Date
Treating compliance as a once-a-year scramble before an exam tends to leave gaps everywhere else on the calendar. A steadier approach maps your current controls to a framework like NIST CSF 2.0, assigns a named owner to each function, and reviews progress on a regular cadence instead of an annual one.
Our Advanced Cybersecurity and Compliance program is built around this evidence-first approach, so the documentation you need for an exam is already sitting in your file when the date arrives, instead of being assembled the week before.
Getting Ahead of the 2026 Exam Cycle
- Map your current controls against NIST CSF 2.0’s six functions and note where the documentation is thin.
- Prioritize evidence, not just controls: reports, logs, and dated reviews an examiner can actually look at.
- Sequence the work against your actual audit calendar so nothing turns into a last-minute scramble.
- Revisit the plan on a regular cadence with a named owner for each function, rather than a once-a-year exercise.
Frequently Asked Questions
Is the FFIEC Cybersecurity Assessment Tool still required?
No. The FFIEC retired the CAT on August 31, 2025, and institutions are being directed toward more current frameworks such as NIST CSF 2.0.
Is NCUA’s ACET still used to examine credit unions?
Not as an examination framework. NCUA replaced ACET with the Information Security Examination (ISE) as its actual exam program back in 2020, and ISE has been the standard since 2023. The ACET Toolbox still exists as a free, voluntary self-assessment application, but it is not what your examiner uses to evaluate you.
What framework should replace the CAT?
NIST CSF 2.0 is the framework most commonly cited as a replacement path, organized around six core functions. The right fit still depends on your institution’s size, complexity, and existing program, so a gap assessment against your actual environment is a better starting point than adopting a framework wholesale.
What do examiners mean by evidence of a control?
Evidence means something an examiner can review directly and see is dated: an MFA enforcement report, a completed access review log, a documented and tested backup restore, or a walked-through incident response exercise, not a policy statement saying the control exists.
Do smaller community banks need to follow the same framework as larger banks?
The core expectations around evidence, documented reviews, and tested plans apply regardless of size, but the scope and complexity of implementation should match your institution’s size and risk profile. A gap assessment against your actual environment is a better starting point than adopting a large framework wholesale.
Take the Next Step
Not sure how your current controls map to what examiners expect in 2026? The SecurityStack Challenge gives you a clear picture in about 20 minutes, no sales pitch, or visit our Advanced Cybersecurity and Compliance page to talk through building an evidence-first program.


