Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Banks Must Report Major Cyber Incidents Within 36 Hours Under U.S. Regulation

Covered U.S. banks must notify their primary federal regulator as soon as possible and within 36 hours after determining that a computer-security incident meets the rule’s material-impact threshold. Bank service providers have a separate four-hour service-disruption notice duty.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Under the U.S. interagency Computer-Security Incident Notification Rule, a covered bank must notify its primary federal regulator as soon as possible and no later than 36 hours after it determines that a qualifying “notification incident” has occurred. The clock does not automatically start when suspicious activity is first detected.

What the 36-hour bank cyber-incident rule requires

The Office of the Comptroller of the Currency (OCC), Federal Reserve Board and Federal Deposit Insurance Corporation (FDIC) finalized the rule in November 2021. It applies when a covered banking organization determines that a computer-security incident has caused, or is reasonably likely to cause, a material disruption or degradation of its operations, ability to provide banking products or services, or financial stability.

The required recipient is the bank’s primary federal regulator. Notice must be sent as soon as possible, with 36 hours as the outside deadline after the bank makes the qualifying determination.

When does the 36-hour clock start?

The clock starts when the banking organization determines that the event meets the rule’s “notification incident” threshold. It is not necessarily measured from initial detection, the first alert, or the moment an attack began.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

That distinction does not permit delay. Banks need an escalation process that can quickly evaluate operational impact, involve the appropriate decision-makers and make the regulatory determination in time to meet the outside deadline. The Federal Reserve’s SR 22-4 guidance states that the Board must receive notice as soon as possible and no later than 36 hours after that determination.

What counts as a notification incident?

The rule is based on material operational or financial impact, not on a particular type of criminal attack or a fixed dollar threshold. A covered incident is one that actually causes, or is reasonably likely to cause, a material disruption or degradation of:

  • the bank’s ability to carry out its operations;
  • the bank’s ability to deliver banking products or services; or
  • financial stability, where the rule’s qualifying impact standard is met.

Examples identified in official explanations include a major computer-system failure, a distributed-denial-of-service attack that prevents customers from accessing accounts, ransomware that disables operations and another significant operational interruption. A hardware or software failure can qualify; the event does not have to involve malicious hacking.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

The rule does not establish a universal technical severity score or a single dollar amount. When classification is uncertain, the bank should use its internal legal and incident-escalation procedures and consult its regulator’s guidance. The Federal Reserve specifically encourages an organization facing uncertainty to contact the Board.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which banking organizations are covered?

Coverage depends on which agency is the institution’s primary federal regulator. The rule does not treat every entity that describes itself as a bank identically.

Regulator Organizations included in the rule’s definitions
OCC National banks, federal savings associations, and federal branches and agencies of foreign banks
Federal Reserve Board U.S. bank holding companies and savings and loan holding companies, state member banks, U.S. operations of foreign banking organizations, and Edge and agreement corporations
FDIC Insured state nonmember banks, insured state-licensed branches of foreign banks, and insured state savings associations

Designated financial market utilities are excluded from these definitions. A bank should confirm its primary federal regulator and follow that agency’s current submission instructions before an incident occurs.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Do bank service providers have a separate reporting duty?

Yes. The provider obligation is separate from the bank’s 36-hour regulatory notice.

A bank service provider must notify at least one bank-designated contact at each affected banking-organization customer as soon as possible after determining that a computer-security incident has materially disrupted, or is reasonably likely to materially disrupt, covered services for four or more hours. If no designated contact was provided, the rule directs notice to the customer’s chief executive officer and chief information officer, or comparable officers.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Previously communicated scheduled maintenance, testing and software updates are excluded from this provider-notice requirement.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Bank regulator notice Service-provider customer notice
Responsible party Covered banking organization Bank service provider
Recipient Primary federal regulator Each affected bank customer
Threshold Notification incident involving material or likely material disruption, degradation or qualifying financial-stability impact Material or likely material disruption or degradation of covered services for four or more hours
Timing As soon as possible, no later than 36 hours after the bank determines a notification incident occurred As soon as possible after the provider makes its determination

A provider outage therefore does not automatically create a 36-hour notice for the bank. The bank must independently decide whether the event is a notification incident and then apply its own deadline.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Effective and compliance dates

  • The final rule was issued on November 18, 2021, and published on November 23, 2021.
  • It took effect on April 1, 2022.
  • Compliance was required beginning May 1, 2022.

How notification is delivered

Communication channels depend on the supervising agency. Federal Reserve guidance identifies email and telephone as notice channels and directs organizations to use the Board’s current contact details. OCC guidance identifies the appropriate supervisory office or OCC-designated point of contact. Contact information can change, so institutions should use the live instructions from their regulator rather than rely on an old address or telephone number.

Is this the same as the EU’s DORA reporting rule?

No. The 36-hour requirement is a U.S. banking rule. The European Union’s Digital Operational Resilience Act (DORA) uses different incident categories, templates and deadlines.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Under Commission Delegated Regulation (EU) 2025/301, an initial report for a major ICT incident is due as early as possible, within four hours after classification and no later than 24 hours after the entity becomes aware. Intermediate and final reports follow. Those European timelines do not amend or replace the U.S. interagency rule.

What customers should understand

The rule is a regulator-notification requirement, not a promise that every customer will be contacted within 36 hours or that every cyber event is publicly disclosed. Its trigger is a bank’s determination of material or likely material operational impact. Separate privacy, breach-notification and communications obligations may apply depending on what information was affected and which jurisdictions are involved.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.