By David Chernitzky, CEO, Armour Cybersecurity · Serving Toronto and organizations across North America · Last updated August 25, 2026
Quick Answer
Banks, credit unions, wealth managers, and fintechs in the US and Canada face overlapping bank cybersecurity regulations that have grown significantly more prescriptive in recent years. OSFI B-13 in Canada, FFIEC supervision and NYDFS Part 500 in the US, and shared standards like PCI DSS and SOC 2 create a complex compliance environment. A programme built around the common control core of these frameworks satisfies the majority of requirements without maintaining separate compliance silos for each regulator.
Key Takeaways
- Canadian federally regulated financial institutions must align to OSFI Guideline B-13 across its three domains: governance and risk management, technology operations and resilience, and cyber security. Third-party risk sits in the companion Guideline B-10.
- US banks and credit unions operate under FFIEC supervision by the OCC, FDIC, Federal Reserve, and NCUA, with NYDFS Part 500 adding mandatory requirements for New York-licensed entities.
- NYDFS Part 500 is among the most prescriptive state-level cybersecurity regulations in the US and applies to any entity with a New York banking or financial services licence.
- Both jurisdictions have moved toward mandatory board-level accountability, incident notification timelines, and independent security testing.
- A single documented cybersecurity programme built around common controls satisfies the majority of requirements across OSFI, FFIEC, NYDFS, PCI DSS, and SOC 2 simultaneously.
The Canadian Framework: OSFI Guideline B-13
The Office of the Superintendent of Financial Institutions issued Guideline B-13 as the primary technology and cyber risk management standard for federally regulated financial institutions in Canada, including banks, foreign bank branches, trust and loan companies, insurers, and the small number of federal credit unions. B-13 is not advisory. OSFI uses it as the framework for supervisory reviews, and institutions that cannot demonstrate alignment face findings with defined remediation timelines.
B-13 organizes expectations across three domains. Governance and risk management requires board-level accountability for technology risk, defined risk appetite, and integration of cyber risk into strategic decision-making. Technology operations and resilience covers asset inventory, system lifecycle management, and tested business continuity and recovery capabilities. Cyber security addresses the controls framework, vulnerability management, security testing, and incident detection. Third-party technology risk was removed from B-13 during consultation and is addressed in the companion Guideline B-10, Third-Party Risk Management, effective May 1, 2024, which requires documented oversight of technology service providers and fintech partners across the full vendor lifecycle.
OSFI assesses maturity, not just policy existence. A written incident response plan that has never been tested, a vendor risk programme that covers only a subset of third parties, or a penetration test conducted years ago will generate supervisory findings regardless of how well the policy documents are written. Evidence of operating controls is what OSFI examiners look for.
The US Federal Framework: FFIEC and Interagency Guidance
In the United States, banking cybersecurity regulation is primarily delivered through the Federal Financial Institutions Examination Council, whose member agencies include the OCC, FDIC, Federal Reserve, NCUA, and CFPB. FFIEC guidance is not a single regulation but a body of guidance documents and examination procedures that define what examiners from each agency assess during safety and soundness reviews.
The FFIEC Cybersecurity Assessment Tool, introduced in 2015, historically gave institutions a structured way to assess cybersecurity preparedness across five domains: cyber risk management and oversight, threat intelligence and collaboration, cybersecurity controls, external dependency management, and cyber incident management and resilience. The FFIEC retired the CAT on August 31, 2025, and now points institutions to established frameworks, primarily the NIST Cybersecurity Framework 2.0 and the Cyber Risk Institute (CRI) Profile, with CISA’s Cybersecurity Performance Goals and the CIS Controls as further options. The five domains the CAT covered still describe what examiners assess in practice and map closely to the NIST CSF, which has become the common reference point.
The 2023 Interagency Guidance on Third-Party Relationships, issued jointly by the OCC, FDIC, and Federal Reserve, significantly strengthened US expectations around vendor risk management. The guidance requires a documented risk-based approach to managing third-party relationships across the full lifecycle: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. Community banks and smaller institutions received supplemental guidance acknowledging proportionality, but the expectation of a structured programme applies broadly.
NCUA separately regulates federal credit unions and federally insured state-chartered credit unions. NCUA examination procedures include cybersecurity assessment and align with FFIEC standards, with specific provisions around credit union-scale programmes that account for the cooperative structure and often smaller IT footprint of credit union members.
NYDFS Part 500: The US State Standard That Raised the Bar
New York State’s Department of Financial Services Cybersecurity Regulation, known as Part 500, applies to any entity holding a licence, registration, charter, or authorization under New York banking or financial services law. For financial institutions with a New York presence, Part 500 is effectively mandatory and is among the most prescriptive cybersecurity regulations in the United States.
Part 500 requires covered entities to maintain a written cybersecurity programme assessed annually, conduct a cybersecurity risk assessment, implement specific technical controls including multi-factor authentication and encryption, appoint a Chief Information Security Officer responsible for overseeing the programme, train personnel in cybersecurity awareness, and conduct annual penetration testing and vulnerability assessments.
The 2023 amendments to Part 500 introduced additional requirements that significantly increased the burden for larger covered entities. These include annual independent audits of the cybersecurity programme for large entities, board-level cybersecurity expertise or an independent committee with responsibility for cybersecurity oversight, 72-hour notification to NYDFS of material cybersecurity events, and 24-hour notification of ransomware payments. The amendments also imposed specific requirements around privileged access management and application security.
For banks and financial services firms operating in both Canada and New York, Part 500 and OSFI B-13 together create a demanding compliance environment. The good news is that the control overlap is substantial. An institution that meets Part 500 requirements for MFA, penetration testing, incident response, and third-party oversight covers the majority of the same ground that B-13 and B-10 require.
Where the Frameworks Converge
Despite different regulatory structures, US and Canadian financial institution cybersecurity frameworks have converged on several common expectations. Board-level accountability for cyber risk is now explicit in OSFI B-13 and NYDFS Part 500, and expected by FFIEC examiners. Annual independent penetration testing is required by Part 500, expected under FFIEC supervision, and strongly implied by B-13’s security testing expectations. Documented incident response with defined notification timelines is mandatory under Part 500, required by B-13, and assessed in FFIEC examinations.
Multi-factor authentication on all systems containing sensitive financial data is required by Part 500, treated as baseline by OSFI, and expected under FFIEC guidance. Third-party risk management with documented due diligence and ongoing monitoring is addressed explicitly by OSFI’s Guideline B-10, the 2023 Interagency Guidance, and the Part 500 amendments. A programme built around these common controls satisfies the shared requirements of both jurisdictions without duplicating effort.
What Does a Cross-Jurisdictional Programme Look Like in Practice?
Armour Cybersecurity delivers banking cybersecurity services to financial institutions that hold licences and serve clients in both Canada and the United States. The starting point is a regulatory mapping exercise that identifies every applicable framework based on charter type, licence jurisdiction, and business activities. From that map, a common control baseline is built that satisfies the intersection of requirements, with jurisdiction-specific additions layered on top.
The vCISO service provides the governance leadership that both OSFI and NYDFS require: a designated senior cybersecurity professional who oversees the programme, prepares board reporting, manages regulatory examination support, and maintains awareness of regulatory developments in both jurisdictions. The compliance audit service produces the documented evidence that examiners assess and the attestations that counterparties and insurers request.
Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the institutions that operate across borders without drowning in regulators are the ones that stopped maintaining a separate programme per jurisdiction. They built one control set, mapped it to OSFI, FFIEC, NYDFS, PCI DSS, and SOC 2 at once, and let the jurisdiction-specific extras, a 24-hour ransomware notice here, a B-10 vendor file there, sit as thin layers on a common core rather than five programmes competing for the same team’s attention.
Frequently Asked Questions
Does NYDFS Part 500 apply to Canadian banks with New York operations?
Yes. Part 500 applies to any entity holding a New York banking licence or operating as a foreign banking organization in New York. A Canadian bank with a New York branch or agency is subject to Part 500 requirements for its New York-regulated operations. The requirements apply to the covered entity’s New York cybersecurity programme, which in practice means most of the bank’s programme given integrated technology environments.
How does FFIEC examination differ from OSFI supervisory review?
FFIEC examination is conducted by the institution’s primary federal regulator, which varies by charter type: the OCC for national banks, the FDIC for state non-member banks, the Federal Reserve for state member banks, and the NCUA for federal credit unions. Each examiner follows FFIEC guidance but applies it through their agency’s examination procedures. OSFI conducts its own supervisory reviews directly. Both processes assess evidence of operating controls, not just policy documentation, and both can result in findings that require formal remediation.
What is the timeline for Part 500 incident notification?
Covered entities must notify NYDFS within 72 hours of determining that a cybersecurity event has occurred that meets the materiality threshold: unauthorized access to nonpublic information, disruption of business operations, or impact on the institution’s ability to conduct normal business. Ransomware payments must be reported within 24 hours of payment. These timelines require an incident response programme that can make materiality determinations quickly, which means having the plan, the team, and the decision authority defined before an incident occurs.
Can a smaller community bank or credit union realistically meet these requirements?
Yes, with proportionate implementation. FFIEC guidance and OSFI B-13 both acknowledge that programme scope and sophistication should reflect the institution’s size, complexity, and risk profile. A community bank or small credit union is not expected to maintain the same programme as a large Schedule I bank. What is expected is a documented programme appropriate to the institution’s actual risk, with evidence that it is operating. Armour’s fractional vCISO and managed cybersecurity services are structured specifically to make that achievable at community institution scale.
The Bottom Line
A financial institution operating across the US and Canada is not choosing which cybersecurity regulator to answer to; it answers to all of them, OSFI under B-13 and B-10, the FFIEC agencies through their examinations, and NYDFS under Part 500, alongside PCI DSS and SOC 2. The costly mistake is running a separate compliance programme for each. These frameworks have converged on the same core: board accountability, MFA, encryption, tested incident response, independent security testing, and documented third-party oversight. Build that core once, document it well, and map it to each regulator, and the jurisdiction-specific requirements become manageable additions rather than parallel programmes. Armour Cybersecurity helps banks, credit unions, and financial institutions build banking cybersecurity programmes that satisfy OSFI B-13, FFIEC supervision, NYDFS Part 500, and related requirements across Canada and the United States, so a cross-border footprint becomes a competitive strength rather than a compliance burden that grows with every new jurisdiction.
About the author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate. Learn more about Armour Cybersecurity.



