Framework · Last verified

CRI Profile

CRI Profile is named in FFIEC's own sunset statement as one industry resource institutions may consider — not a designated successor to the CAT. CRI's own description of the Profile could not be verified to a verbatim standard from its own site in this round, so only FFIEC's characterization is recorded here.

Class
Framework
Owner
Cyber Risk Institute (CRI)
Last verified

What it is

The FFIEC's own CAT Sunset Statement: "Supervised financial institutions may also consider use of industry developed resources, such as the Cyber Risk Institute's (CRI) Cyber Profile, and the Center for Internet Security Critical Security Controls. These tools can be used in conjunction with other resources (e.g., frameworks, standards, guidelines, leading practices) to better address and inform management of continuously evolving cyber security risk."

The FFIEC's own statement does not call the CRI Profile a successor to the CAT; it lists the Profile as one of four resources institutions may consider, alongside NIST CSF 2.0, CISA's Cybersecurity Performance Goals and the CIS Critical Security Controls.

"While the FFIEC does not endorse any particular tool, these standardized tools can assist financial institutions in their self-assessment activities. The tools are not examination programs and the FFIEC members take a risk-focused approach to examinations."

The CRI Profile's own site (cyberriskinstitute.org) was reachable (HTTP 200), but repeated extraction attempts returned content that could not be confirmed as the page's actual verbatim text — including one quoted fragment that reproduced identically across independent requests in a bracketed form that does not match how a source page would present its own text. No fact from CRI's own site is recorded here as a result; see open questions.

Who owns it

The Cyber Risk Institute (CRI) is the named developer of the Profile, per the FFIEC's own reference to it. CRI's own description of its structure and governance was not independently verified to a verbatim standard for this record.

Who asks for it

Voluntary. Based on the FFIEC's own framing that supervised financial institutions "may also consider" the CRI Profile alongside other industry-developed resources — not a demand-driver statement from CRI's own site, which could not be verified to a verbatim standard this round (see open questions).

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"CRI Profile." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/cri-profile

All frameworks & audits →