An official website of the United States government
OCC Bulletin 2026-48 | September 21, 2026
Share This Page:
Chief Executive Officers of All National Banks, Federal Savings Associations, and Federal Branches and Agencies; Department and Division Heads; All Examining Personnel; and Other Interested Parties
The Office of the Comptroller of the Currency (OCC) recently updated the structure and references of the OCC Cybersecurity Supervision Work Program (CSW) used by examiners. As cyberattacks evolve and as banks1 adopt various standardized tools and frameworks to assess cybersecurity preparedness, the OCC continues to update its approach to assessing cybersecurity risk as part of risk-based supervision. The CSW provides high-level examination objectives and procedures that are aligned with existing supervisory guidance and the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF). The OCC did not add any new procedures in the update to CSW, nor did it change any of the procedures. This update maintains alignment between the CSW structure and the evolving NIST CSF.
The CSW does not establish new regulatory expectations, and banks are not expected to use this work program to assess cybersecurity preparedness. The OCC continues to encourage, but does not require, the use of a standardized approach to assess and improve cybersecurity preparedness, and banks may choose from a variety of tools and frameworks available. 2
This bulletin rescinds OCC Bulletin 2023-22, “Cybersecurity: Cybersecurity Supervision Work Program,” issued on June 26, 2023.
The CSW continues to enable risk-based examination scoping and is scalable for banks of different sizes and complexity. Examiners may use the CSW’s examination procedures during examinations of a community bank’s cybersecurity preparedness.
The CSW
The CSW Overview page on www.occ.gov links to the CSW References page, which provides cross-references that map the CSW procedures to existing supervisory guidance, examiner guidance, and industry cybersecurity frameworks. For example, cross-references include the OCC Comptroller’s Handbooks, FFIEC IT Examination Handbook, the Center for Internet Security Critical Security Controls, and the Cyber Risk Institute Profile. Future changes to the CSW References page will be made available through www.occ.gov.
Please contact Debra Brown, Acting Director of Bank Information Technology Policy, at (202) 649-6550.
James M. Gallagher Senior Deputy Comptroller and Chief National Bank Examiner
1 “Banks” refers collectively to national banks, federal savings associations, and federal branches and agencies of foreign banking organizations.
2 Refer to the Federal Financial Institutions Examination Council press release titled “FFIEC Encourages Standardized Approach to Assessing Cybersecurity Preparedness,” August 28, 2019.