Determine your CRI impact tier

The Cyber Risk Institute (CRI) Profile is quickly becoming the new cybersecurity baseline for the financial sector. It replaces the FFIEC Cybersecurity Assessment Tool (CAT), which was retired in August 2025.

The CRI Profile offers a clear, regulator-backed way to understand and demonstrate your security posture. It recognizes that not all institutions carry the same level of systemic risk—so you only need to show controls that match your risk level, based on your designated impact tier (1–4).

Download this assessment to:

  • Learn how CRI defines each impact tier
  • Identify your institution’s impact tier

Determine your CRI impact tier

The Cyber Risk Institute (CRI) Profile is quickly becoming the new cybersecurity baseline for the financial sector. It replaces the FFIEC Cybersecurity Assessment Tool (CAT), which was retired in August 2025.

The CRI Profile offers a clear, regulator-backed way to understand and demonstrate your security posture. It recognizes that not all institutions carry the same level of systemic risk—so you only need to show controls that match your risk level, based on your designated impact tier (1–4).

Download this assessment to:

  • Learn how CRI defines each impact tier
  • Identify your institution’s impact tier

Download

Determine your CRI impact tier

The Cyber Risk Institute (CRI) Profile is quickly becoming the new cybersecurity baseline for the financial sector. It replaces the FFIEC Cybersecurity Assessment Tool (CAT), which was retired in August 2025.

The CRI Profile offers a clear, regulator-backed way to understand and demonstrate your security posture. It recognizes that not all institutions carry the same level of systemic risk—so you only need to show controls that match your risk level, based on your designated impact tier (1–4).

Download this assessment to:

  • Learn how CRI defines each impact tier
  • Identify your institution’s impact tier

The Agentic Trust Platform powering security for over [customer_count] customers

Atlassian logo
Ramp logo
Modern Health logo
IcelandAir logo
Intercom
Cursor logo

The Vanta Agent: your 24/7
GRC engineering team

The Vanta agent is everywhere you need it to be—drafting policies, completing your questionnaires, calling out issues, and generally making you wonder what you did before it existed.

Chat interface greeting Cathy with options to prepare a compliance audit, evaluate risk posture, or measure sales impact and a prompt to ask anything.

Built for you

Whether you're managing a complex program or just getting started.

leaf icon

Startups

Are you a startup founder in need of a SOC 2 yesterday, but lacking time and resources? We'll automate the process and get you big-deal-ready.

chart icon

Mid-market

Security leaders, keep scaling fast—no need for more headcount. Vanta automates and continuously monitors your program, so you can do more with the team you have.

globe icon

Enterprise

Vanta combines compliance, risk, and proof, right where CISOs and security leaders need them—clearly visible and all on one platform.

Vanta in ActionVanta Delivers logoAlmost AMA Logo

Interested in learning more about Vanta?