Maine BFI Bulletin 80: FFIEC Cybersecurity Tool Sunset
Summary
The Maine Bureau of Financial Institutions issued Bulletin #80, updated June 30, 2025, to notify financial institutions that the FFIEC Cybersecurity Assessment Tool (CAT) will sunset on August 31, 2025. The Bureau continues to expect institutions to assess cybersecurity preparedness using alternative methods and resources.
What changed
Maine's Bureau of Financial Institutions (BFI) has updated Bulletin #80 to inform financial institutions that the FFIEC Cybersecurity Assessment Tool (CAT) will be sunset on August 31, 2025. While the CAT was a voluntary tool previously encouraged by the Bureau, its discontinuation does not alter the BFI's expectation that institutions must continue to adopt methods for assessing their cybersecurity preparedness and integrate these measures into their information security programs. The Bureau recommends utilizing current resources from the FFIEC, CISA, and NIST.
Financial institutions operating in Maine should review their current cybersecurity assessment methodologies and ensure they have alternative, robust processes in place to measure cybersecurity risks and maturity by the August 31, 2025, sunset date. Bureau examination staff will continue to review these measures as part of the overall information security program. While no specific penalties are outlined for failing to adopt alternative measures, maintaining adequate cybersecurity preparedness is an ongoing expectation for regulated entities.
What to do next
- Review current cybersecurity assessment methodologies.
- Implement alternative methods for assessing cybersecurity preparedness by August 31, 2025.
- Incorporate updated cybersecurity measures into the institution's information security program.
Source document (simplified)
BUREAU OF FINANCIAL INSTITUTIONS Department of Professional and Financial Regulation State of Maine June 30, 2025 Bulletin #80 Cybersecurity Assessments- Notice of the Sunset of the FFIEC Cybersecurity Assessment Tool on August 31, 2025. To the Chief Executive Officer Addressed: This Bulletin has been updated to reflect the upcoming sunset of the FFIEC’s Cybersecurity Assessment Tool (CAT) and outline the Bureau’s continuing expectations regarding cybersecurity assessments. The FFIEC previously developed and published the CAT as a voluntary method to assist financial institutions in measuring their inherent risks to cyber threats and measuring their cybersecurity maturity (preparedness). The Bureau encouraged use of the FFIEC CAT when it issued Bulletin 80 on October 16, 2015. Despite the sunset of the CAT, the Bureau still expects that financial institutions adopt methods for assessing their cybersecurity preparedness and incorporate appropriate cybersecurity measures into their information security program. The FFIEC continues to provide resources to help financial institutions manage cybersecurity risks. As financial institutions develop and revise their cybersecurity programs, the Bureau encourages the use of the latest recommended resources from the FFIEC, which include guidance and recommendations from the Cybersecurity & Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST). More information from FFIEC can be found at: https://www.ffiec.gov/resources/cybersecurity-awareness. Bureau examination staff will continue to review an institution’s cybersecurity measures as a part of its information security program and understands that the measures adopted by an institution may change over time as cyber threats and the associated industry guidance continue to evolve.
/s/ Lloyd P. LaFountain III Superintendent Note: This bulletin is intended solely for informational purposes. It is not intended to set forth legal rights, duties or privileges nor is it intended to provide legal advice. Readers are encouraged to consult applicable statutes and regulations and to contact the Bureau of Financial Institutions if additional information is needed.
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Banking & Finance alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when ME BFI Bulletins publishes new changes.