Changeflow GovPing Banking & Finance Maine BFI Bulletin 80: FFIEC Cybersecurity Tool...
Routine Notice Amended Final

Maine BFI Bulletin 80: FFIEC Cybersecurity Tool Sunset

Favicon for www.maine.gov ME BFI Bulletins
Published June 30th, 2025
Detected March 18th, 2026
Email

Summary

The Maine Bureau of Financial Institutions issued Bulletin #80, updated June 30, 2025, to notify financial institutions that the FFIEC Cybersecurity Assessment Tool (CAT) will sunset on August 31, 2025. The Bureau continues to expect institutions to assess cybersecurity preparedness using alternative methods and resources.

What changed

Maine's Bureau of Financial Institutions (BFI) has updated Bulletin #80 to inform financial institutions that the FFIEC Cybersecurity Assessment Tool (CAT) will be sunset on August 31, 2025. While the CAT was a voluntary tool previously encouraged by the Bureau, its discontinuation does not alter the BFI's expectation that institutions must continue to adopt methods for assessing their cybersecurity preparedness and integrate these measures into their information security programs. The Bureau recommends utilizing current resources from the FFIEC, CISA, and NIST.

Financial institutions operating in Maine should review their current cybersecurity assessment methodologies and ensure they have alternative, robust processes in place to measure cybersecurity risks and maturity by the August 31, 2025, sunset date. Bureau examination staff will continue to review these measures as part of the overall information security program. While no specific penalties are outlined for failing to adopt alternative measures, maintaining adequate cybersecurity preparedness is an ongoing expectation for regulated entities.

What to do next

  1. Review current cybersecurity assessment methodologies.
  2. Implement alternative methods for assessing cybersecurity preparedness by August 31, 2025.
  3. Incorporate updated cybersecurity measures into the institution's information security program.

Source document (simplified)

BUREAU OF FINANCIAL INSTITUTIONS Department of Professional and Financial Regulation State of Maine June 30, 2025 Bulletin #80 Cybersecurity Assessments- Notice of the Sunset of the FFIEC Cybersecurity Assessment Tool on August 31, 2025. To the Chief Executive Officer Addressed: This Bulletin has been updated to reflect the upcoming sunset of the FFIEC’s Cybersecurity Assessment Tool (CAT) and outline the Bureau’s continuing expectations regarding cybersecurity assessments. The FFIEC previously developed and published the CAT as a voluntary method to assist financial institutions in measuring their inherent risks to cyber threats and measuring their cybersecurity maturity (preparedness). The Bureau encouraged use of the FFIEC CAT when it issued Bulletin 80 on October 16, 2015. Despite the sunset of the CAT, the Bureau still expects that financial institutions adopt methods for assessing their cybersecurity preparedness and incorporate appropriate cybersecurity measures into their information security program. The FFIEC continues to provide resources to help financial institutions manage cybersecurity risks. As financial institutions develop and revise their cybersecurity programs, the Bureau encourages the use of the latest recommended resources from the FFIEC, which include guidance and recommendations from the Cybersecurity & Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST). More information from FFIEC can be found at: https://www.ffiec.gov/resources/cybersecurity-awareness. Bureau examination staff will continue to review an institution’s cybersecurity measures as a part of its information security program and understands that the measures adopted by an institution may change over time as cyber threats and the associated industry guidance continue to evolve.

/s/ Lloyd P. LaFountain III Superintendent Note: This bulletin is intended solely for informational purposes. It is not intended to set forth legal rights, duties or privileges nor is it intended to provide legal advice. Readers are encouraged to consult applicable statutes and regulations and to contact the Bureau of Financial Institutions if additional information is needed.

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
State Banking
Published
June 30th, 2025
Compliance deadline
August 31st, 2025 (199 days ago)
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Minor

Who this affects

Applies to
Banks Financial advisers Insurers
Geographic scope
State (Maine)

Taxonomy

Primary area
Financial Services
Operational domain
Compliance
Topics
Cybersecurity Information Security

Get Banking & Finance alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when ME BFI Bulletins publishes new changes.

Free. Unsubscribe anytime.