Computer-Security Incident Notification Requirements for Banking Organizations and Their Bank Service Providers
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 May 2022.
A vulnerability and incident reporting rule binding private bodies.
As of 20 September 2026.
What it requires
- This instrument reaches your organization only if it is a banking organization under this rule, meaning a national bank, Federal savings association, or Federal branch or agency of a foreign bank; a bank holding company, savings and loan holding company, state member bank, the United States operations of a foreign banking organization, or an Edge or agreement corporation; or an insured state nonmember bank, insured state licensed branch of a foreign bank, or insured State savings association, or if it is a bank service provider that performs services for one of them under the Bank Service Company Act. Declare provides_financial_services where either role holds; no activity stands in for either role, and a designated financial market utility is excluded from both.
- If your organization is a banking organization, notify your primary federal banking regulator, the OCC, the Federal Reserve Board, or the FDIC, whichever supervises it, about a notification incident, as soon as possible and no later than 36 hours after your organization determines that a notification incident has occurred. A notification incident is the subset of computer-security incidents that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, your ability to serve customers, a business line, or an operation whose failure would threaten the financial stability of the United States, so a computer-security incident that falls short of that threshold does not by itself start this clock.
- If your organization is a bank service provider, notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible after your organization determines that it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, covered services provided to that banking organization for a period of four hours or more. This duty carries a standard, as soon as possible, rather than a fixed number of hours to notify by, and that disruption threshold is what engages the duty rather than a period to notify within.
- This bank service provider duty does not apply to scheduled maintenance, testing, or a software update you already communicated to the banking organization customer.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Comptroller of the Currency, the Federal Reserve Board, and the Federal Deposit Insurance Corporation issued this Computer-Security Incident Notification rule as one joint final rule, codified in parallel at 12 CFR Part 53 for the Comptroller, 12 CFR Part 225, Subpart N for the Board, and 12 CFR Part 304, Subpart C for the Corporation. For the Comptroller, a banking organization is a national bank, Federal savings association, or Federal branch or agency of a foreign bank.
For the Board, a banking organization is a bank holding company, savings and loan holding company, state member bank, the United States operations of a foreign banking organization, or an Edge or agreement corporation. For the Corporation, a banking organization is an insured state nonmember bank, insured state licensed branch of a foreign bank, or insured State savings association.
None of the three agencies treats a designated financial market utility as a banking organization or as a bank service provider. A bank service provider is a bank service company or other person that performs covered services under the Bank Service Company Act. A computer-security incident is any occurrence that results in actual harm to the confidentiality, integrity, or availability of an information system or the information the system processes, stores, or transmits.
A notification incident is a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, a banking organization's ability to carry out banking operations, activities, or processes, or to deliver banking products and services to a material portion of its customer base, a business line whose failure would result in a material loss of revenue, profit, or franchise value, or operations whose failure or discontinuance would threaten the financial stability of the United States.
A banking organization must notify its primary federal regulator about a notification incident as soon as possible and no later than 36 hours after the banking organization determines that a notification incident has occurred.
A bank service provider must separately notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible when the bank service provider determines that it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, covered services provided to that banking organization for four or more hours.
This bank service provider notification duty does not apply to scheduled maintenance, testing, or a software update previously communicated to the banking organization customer. The rule's own regulatory text became effective on April 1, 2022. Both notification duties began binding their subjects on the May 1, 2022 compliance date.
When LexLint raises it
provides_financial_services
Read the law
Electronic Code of Federal Regulations
12 CFR Part 53, with parallel definitions and duties at 12 CFR Part 225, Subpart N and 12 CFR Part 304, Subpart C, and the effective and compliance dates from the agencies' 2021 joint final rule, 86 FR 66424
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.