Credit union security
The FFIEC CAT is gone. Your examiner still wants a maturity story.
On August 31, 2025 the Cybersecurity Assessment Tool was retired. The NCUA's ACET now maps to NIST CSF 2.0 — and boards and examiners expect you to show your program in that language. This guide gives you the transition, without redoing years of work.
What's inside
Built for the transition, not the theory
What actually changed
A side-by-side of the retired CAT versus the ACET Maturity Assessment, including how ACET statements now map to NIST CSF 2.0 functions and categories.
What the examiner expects
The documentation and maturity evidence NCUA examiners look for during the transition window, and the gaps that most often draw findings.
A 90-day plan
A board-ready sequence for moving your program onto CSF 2.0 without re-doing years of work — plus a one-page summary for your supervisory committee.
Why Principle Security
Real-world experience, not a sales deck
We work with community credit unions on FFIEC and NCUA alignment, vendor oversight, and board reporting — as fractional security leadership, not checkbox consultants.
Explore