# OCC Updates Cybersecurity Audit Rules

The Office of the Comptroller of the Currency (OCC) has updated its Cybersecurity Supervision Work Program (CSW) to better align with the latest categories of the National Institute of Standards and Technology (NIST) Cybersecurity Framework. This update enhances the risk-based IT examination process for banks by integrating current cybersecurity best practices without imposing new regulatory requirements or mandatory assessments. The revised CSW supports banks' cybersecurity preparedness while maintaining flexibility in their approach to managing cyber risks.

- **Why this matters:** Procurement professionals and contractors serving the banking sector should note that while no new compliance mandates are introduced, the alignment with NIST standards may influence future cybersecurity service requirements and risk assessments.
- The update reflects federal supervisory agencies' emphasis on modernized cybersecurity frameworks, potentially affecting contract scopes related to IT security audits and consulting.
- Organizations providing cybersecurity solutions to banks can leverage this update to tailor offerings that align with the OCC's enhanced supervisory expectations.
- This development signals ongoing federal efforts to harmonize cybersecurity oversight with recognized standards, which may inform procurement strategies and vendor qualifications in financial services IT security.

**Jurisdictions:** federal
**Industries:** Professional Services
**Topics:** Cybersecurity
**Published:** September 21, 2026

### Government Entities
- Office of the Comptroller of the Currency (OCC)
- National Institute of Standards and Technology (NIST)
- Federal Financial Institutions Examination Council (FFIEC)

### Sources
- [PYMNTS | OCC Updates Cyber Audit Rules for Banks](https://www.pymnts.com/legal/bank-regulation/2026/occ-updates-cyber-audit-rules-for-banks) - PYMNTS.com