Skip to main content
Rule2021-25510

Computer-Security Incident Notification Requirements for Banking Organizations and Their Bank Service Providers

Primary source

Metadata and text below are from the Federal Register, a public-domain U.S. government work. Always verify the official published version before relying on it for any legal matter.

Published
November 23, 2021
Effective
April 1, 2022

Issuing agencies

Treasury DepartmentComptroller of the CurrencyFederal Reserve SystemFederal Deposit Insurance Corporation

Abstract

The OCC, Board, and FDIC are issuing a final rule that requires a banking organization to notify its primary Federal regulator of any ``computer-security incident'' that rises to the level of a ``notification incident,'' as soon as possible and no later than 36 hours after the banking organization determines that a notification incident has occurred. The final rule also requires a bank service provider to notify each affected banking organization customer as soon as possible when the bank service provider determines that it has experienced a computer-security incident that has caused, or is reasonably likely to cause, a material service disruption or degradation for four or more hours.

Indexed from Federal Register on November 23, 2021.

This is legal information, not legal advice. Laws vary by jurisdiction and change frequently. Always verify current law with official sources and consult a licensed attorney in your jurisdiction for advice on your specific situation.