OCC Updated Cybersecurity Supervision Work Program
The Office of the Comptroller of the Currency aligned its guidance with the NIST framework to bolster banking IT exams.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Should federal regulators require banks to adopt standardized cybersecurity frameworks?
The Office of the Comptroller of the Currency (OCC) released an updated Cybersecurity Supervision Work (CSW) program on September 21, 2026. The update, which rescinds the previous OCC Bulletin 2023-22, aligns the agency's internal guidance with the NIST Cybersecurity Framework.
Why it matters
The revision updates bank information technology examination procedures to address evolving threats in the financial sector, following the agency's identification of AI-driven cybersecurity risks in May 2026. It serves to refine the OCC's risk-based oversight rather than establishing new regulatory requirements.
The new CSW structure maps directly to the FFIEC IT Examination Handbook categories to support risk-based bank IT examinations. While the guidance is updated, the OCC explicitly stated the CSW does not impose new regulatory expectations or mandate a specific assessment methodology for banks.
The players
Office of the Comptroller of the Currency
A bureau within the U.S. Department of the Treasury that charters, regulates, and supervises all national banks and federal savings associations.
The details
The updated program integrates the NIST Cybersecurity Framework — a set of voluntary standards for reducing cyber risk — into the OCC's bank examination procedures. By restructuring the CSW to align with these categories, the OCC aims to streamline how examiners evaluate institutional resilience. The bulletin also reinforces the agency's existing focus on material financial risks, a priority highlighted in October 2025.
Timeline
June 26, 2023: OCC Bulletin 2023-22 was issued.
October 2025: OCC oversight began focusing on material financial risks.
May 2026: The OCC identified AI as a cyber threat to the landscape.
September 21, 2026: The updated CSW bulletin was released.
The Tech Race
This update follows a broad industry shift toward adopting the NIST Cybersecurity Framework as the benchmark for institutional digital defense. It marks a departure from older, siloed regulatory bulletins by standardizing terminology across federal IT examination procedures.
Banks are not required to adopt the CSW for their own internal cybersecurity assessments, meaning there is no immediate change in compliance costs for institutions. However, internal IT teams should prepare for updated documentation requirements during upcoming examinations.
The takeaway
The agency is signaling that its examination process will now more closely track the NIST standard to better address AI-linked vulnerabilities. Institutional stakeholders should monitor future exam feedback to see how the mapping affects the depth of technical reviews.
Further reading
For broader context on how federal agencies are navigating digital threats, explore the latest trends in Cybersecurity.
Source note: This article includes information reported by PYMNTS.
Live Poll
Should federal regulators require banks to adopt standardized cybersecurity frameworks?









