The Federal Reserve, Federal Deposit Insurance Corporation (FDIC) and Office of the Comptroller of the Currency (OCC) issued a joint statement on July 16, 2026 committing to notify banks of a compromise of confidential supervisory information within 72 hours — exactly twice the 36-hour clock those same agencies enforce against banks under a binding 2021 rule, and with no enforcement mechanism attached.
The joint statement directs examiners to leave banks’ most sensitive material — technology diagrams and schematics, detailed cyber-vulnerability test results, succession planning data — inside the supervised institution’s own systems wherever possible, using on-site review, direct digital review from bank systems, or redacted and summarised documents instead of transferring the data onto agency networks. It is the first written concession by US federal banking regulators that they are themselves a material attack surface. It is also supervisory guidance rather than a rule: effective immediately, with no comment period, no rulemaking, and no private right of action. This analysis sets out what the statement requires, how the 36-hour and 72-hour obligations diverge, how the EU and UK treat the same problem, and what supervised firms need in place before their next examination.
Key Facts:
• Joint statement issued: July 16, 2026, by the Federal Reserve, FDIC and OCC — effective immediately, no transition period
• Regulator notification commitment: “as soon as practicable and within no more than 72 hours” once an agency has a reasonable basis to believe a compromise occurred and has determined which banks are affected
• Bank notification obligation: 36 hours from determination of a notification incident — 12 CFR Part 53 (OCC), Part 225 (Federal Reserve), Part 304 Subpart C (FDIC)
• Bank rule in force since: April 1, 2022, with compliance required from May 1, 2022 — unchanged by the July 2026 statement
• Precipitating incident: OCC email compromise affecting at least 103 email accounts, with unauthorised access persisting from approximately mid-2023 until February 2025
• Classified a “major incident” under the Federal Information Security Modernization Act (FISMA) on April 7, 2025; Congress notified April 8, 2025
• Industry ask: four recommendations submitted to Treasury on June 9, 2025 by the Bank Policy Institute (BPI), American Bankers Association (ABA), Managed Funds Association and SIFMA
Methodology and sources
This analysis draws on the Federal Reserve press release and joint interagency statement of July 16, 2026; the Computer-Security Incident Notification final rule as codified at 12 CFR Part 53 and implemented via OCC Bulletin 2021-55; OCC news releases on the 2025 email compromise; the June 9, 2025 joint trade-association letter to the Treasury Secretary; and the European Banking Authority’s technical standards under the Digital Operational Resilience Act (DORA) alongside the Prudential Regulation Authority’s Policy Statement PS7/26. Jurisdictional scope is the United States, European Union and United Kingdom. Time window: November 2021 to July 20, 2026. Caveat: the joint statement was published as a supervisory document without an attributed principal’s comment from any of the three agencies, and companion agency letters carry their own reference numbers that firms should verify directly against the FDIC and OCC issuance pages before citing internally.
What the statement actually says
The operative mechanism is delegation. The agencies will rely on bank management to identify which requested data and documents warrant treatment as highly sensitive, rather than applying a regulator-defined taxonomy. Once flagged, examiners are directed toward alternatives to data transfer: reviewing material on-site, accessing it digitally but directly from the bank’s own systems, or accepting redacted or summarised versions. The statement names three categories warranting particular caution — technology diagrams and schematics, detailed cyber-vulnerability testing results, and succession planning information. The agencies also committed to providing examiners with written guidance and training on handling sensitive information, and told institutions with concerns to raise them with their examiners or primary agency contact.
Two features limit its force. First, it is guidance, not a rule, so it creates no enforceable obligation and no remedy for a bank whose data is mishandled. Second, the notification commitment is heavily conditioned. The 72-hour clock starts not at detection but once the affected agency “has a reasonable basis to believe a compromise has occurred and determines the banks affected,” and the commitment is further qualified as “subject to applicable legal considerations.” Each of those conditions is a judgement the agency makes about itself.
The banks’ own obligation is drafted very differently. Under the 2021 rule, a banking organisation must notify its primary federal regulator as soon as possible and no later than 36 hours after determining that a notification incident has occurred — meaning an incident that has materially disrupted or is reasonably likely to materially disrupt operations, the ability to deliver products and services to a material portion of the customer base, or a line of business that would result in material loss. Bank service providers face a parallel duty to notify at least one designated contact at each affected bank when covered services are materially disrupted or degraded for four or more hours. These are rules with examination consequences, not commitments.
How three regimes compare
| Regime | Who reports to whom | Deadline | Legal status | Effective date |
|---|---|---|---|---|
| US — 12 CFR 53 / 225 / 304 Subpart C | Bank to federal regulator | 36 hours from determination | Binding rule; examination and enforcement consequences | April 1, 2022; compliance May 1, 2022 |
| US — interagency joint statement | Regulator to bank | 72 hours, conditioned on “reasonable basis to believe” and identification of affected banks | Supervisory guidance; no private right of action | July 16, 2026, immediate |
| EU — DORA | Financial entity to competent authority | 4 hours from classification as major; no later than 24 hours from detection; 72-hour intermediate; final report within one month | Binding regulation and technical standards | In force |
| UK — PRA PS7/26 | Firm to PRA, FCA and Bank of England | Single report in three phases via FCA Connect | Binding rules | March 18, 2027 |
Sources: eCFR Title 12; Federal Reserve joint statement, July 16, 2026; EBA joint technical standards on major incident reporting; PRA PS7/26. Last updated: July 20, 2026.
The comparison cuts both ways, and the honest reading requires holding both halves. On timing, the US regulator commitment is the weakest instrument in the table: 72 hours against DORA’s 24-hour outer limit from detection, and guidance against binding regulation. On principle, it is the strongest. Neither DORA nor PS7/26 imposes any reciprocal incident-disclosure duty running from the European Supervisory Authorities, national competent authorities, the PRA or the FCA back to supervised firms. Europe has not conceded that the supervisor owes the supervised anything at all when the supervisor is breached. The US has now put such a commitment in writing for the first time in a major jurisdiction. The criticism worth making is not that 72 hours is slow in the abstract, but that it is slow relative to the 36 hours the same agencies enforce.
The asymmetry is not merely one of duration. Three drafting choices compound it. The bank’s clock starts on determination that an incident occurred; the agency’s starts once it has a reasonable basis to believe a compromise occurred and has additionally determined which banks are affected — a second condition with no outer time limit of its own. The bank’s obligation is enforceable through the examination process; the agency’s is guidance. And the agency’s commitment carries a “subject to applicable legal considerations” carve-out with no analogue in Part 53. Applied to the OCC’s own 2025 incident, where access persisted from roughly mid-2023 until February 2025, the difference is stark: a supervised institution with a comparable detection gap would face an enforcement action, not a press release.
“Talk is cheap, especially when there is no enforcement mechanism.”
— Julie Andersen Hill, Dean and Excellence Chair, University of Wyoming College of Law (American Banker)
Hill has also noted that banks “will not be able to sue to enforce the document” — the guidance creates no cause of action. Her second concern is subtler and more operationally relevant: because the statement delegates the sensitivity designation to bank management without defining the category, the equilibrium is unstable. Institutions that over-designate will find examiners treating the label as noise and pushing back on it; institutions that under-designate forfeit the protection entirely. There is no defined appeal route beyond discussing concerns with the examiner.
Industry bodies read the statement more favourably, and their reasoning is substantive rather than merely diplomatic.
“By making clear that banks can maintain control of highly sensitive data within their own secure systems—and by directing examiners to use alternative methods such as on-site review and appropriately redacted materials—the agencies have reduced avoidable risk exposure without compromising supervisory effectiveness.”
— Heather Hogsett, Executive Vice President and Head of BITS, Bank Policy Institute (BPI)
Paul Benda, executive vice president for risk, fraud and cybersecurity at the American Bankers Association, framed the shared exposure directly, saying that “banks and regulators share a common responsibility to protect sensitive data from nation-state actors and other well-resourced cyber adversaries,” and that the ABA was “encouraged by the agencies’ commitment to strengthen their cybersecurity practices, provide greater flexibility for the review of highly sensitive information, and explore approaches that allow such information to remain within banks’ own systems whenever possible.” Notably, no named official from the Federal Reserve, FDIC or OCC is quoted anywhere in the issuance — the statement went out without an attributed principal, which is itself a signal about how the agencies wish the document to be read.
Enforcement context: the candour standard applied to banks
The contrast with how regulators treat disclosure failures by supervised firms is sharp and recent. On July 16, 2026 — the same day as the joint statement — the New York State Department of Financial Services announced a $50 million penalty against Swedbank under a consent order resolving a probe opened in 2019 into anti-money-laundering controls and disclosures covering 2007 to 2019. The department found that the bank had created a false impression it would review its Baltic subsidiaries, intentionally excluded its Latvian, Lithuanian and Estonian units from its production, and failed to disclose adverse findings by European regulators. The penalty was not for the underlying laundering conduct but for the failure of candour toward the supervisor.
That is the precedent worth sitting with. US supervisors maintain, and enforce with nine-figure consequences, a duty of candour running from the regulated to the regulator — covering not just breaches but the completeness of what is disclosed and the timeliness of adverse findings. The July 16 statement establishes the reciprocal duty as an aspiration with a 72-hour target and an explicit legal carve-out. A bank that took 18 months to detect unauthorised access to 103 mailboxes containing confidential supervisory information, then disclosed it through a press release, would not be availing itself of guidance. It would be responding to a consent order.
What this means for supervised firms
The operational burden created by this statement falls almost entirely on the banks it is designed to protect, because the agencies have declined to define the protected category. Firms need four things in place before their next examination cycle.
Compliance and legal teams need a written internal taxonomy defining what the institution treats as highly sensitive, mapped to the three categories the statement names and approved at a level senior enough to defend under examiner challenge. Without it, designation decisions will be made ad hoc by whoever receives the document request, which is precisely the failure mode Hill identifies. That taxonomy needs designation governance attached: who decides, who reviews, and how a disputed designation is escalated given that no formal appeal channel exists.
Chief information security officers and exam-management functions need the technical capability to support direct digital review from the bank’s own systems — read-only examiner access, session logging, and the ability to produce redacted or summarised versions of technical documentation at examination speed. A firm that can only satisfy a document request by transferring files has no practical access to the alternatives the statement contemplates.
Broker-dealers, fund managers and non-bank financial institutions should note the scope limit. This statement addresses bank examinations conducted by the three federal banking agencies. The Managed Funds Association co-signed the June 2025 letter but the resulting fix does not extend to buy-side supervision, and no equivalent commitment exists from the SEC or CFTC. Firms outside the banking perimeter that submit sensitive material to their own supervisors have received nothing.
All supervised institutions should treat the 36-hour rule as entirely unchanged. Nothing in the July 16 statement alters Part 53, Part 225 or Part 304 Subpart C, the notification-incident trigger, or the four-hour service-provider threshold. Reading the statement as a general relaxation of incident-reporting expectations would be a serious misreading.
The forward view
Three threads are worth tracking. First, whether the agencies convert the 72-hour pledge into a rule. As guidance it can be withdrawn or narrowed without process, and its “subject to applicable legal considerations” qualifier is broad enough to swallow the commitment in precisely the circumstances — a national-security-linked intrusion — where notification would matter most. A notice-and-comment rulemaking would settle both problems.
Second, the structural asks that were refused. According to American Banker’s analysis, regulators answered roughly half of the four requests the trade bodies submitted in June 2025: data can now stay on bank systems, and there is a notification commitment. Declined were the request to hold agencies to the same or substantively similar security standards as the institutions they examine, and the request to consolidate overlapping examinations and reduce the aggregate volume of data flowing to regulators. Those refusals are the more consequential half, because the total quantity of confidential supervisory information sitting on federal networks does not shrink, and the agencies remain exempt from the standards they examine against.
Third, the international trajectory runs the other way. UK firms face a hard implementation date of March 18, 2027 for PS7/26, and DORA’s four-hour classification clock is already live for EU entities. Both regimes keep tightening the firm-to-regulator direction while conceding nothing in reverse. Whether US agencies harden their own commitment, or Congress takes up the refused asks, remains open — no legislative vehicle has been identified.
TL;DR
On July 16, 2026 the Federal Reserve, FDIC and OCC issued supervisory guidance directing examiners to leave banks’ most sensitive data — network schematics, penetration-test results, succession plans — inside bank systems rather than moving it onto agency networks, and committing to notify affected banks of a compromise within 72 hours. The commitment is guidance, not a rule, and carries no enforcement mechanism. Banks remain bound by a legally enforceable 36-hour notification rule in force since May 1, 2022 under 12 CFR Parts 53, 225 and 304 Subpart C. The statement follows an OCC email compromise affecting at least 103 accounts with access persisting roughly 18 months undetected. Firms need a written sensitivity taxonomy before their next examination.
FAQ
Does the July 16 statement change banks’ 36-hour notification obligation?
No. The Computer-Security Incident Notification Rule at 12 CFR Part 53 (OCC), Part 225 (Federal Reserve) and Part 304 Subpart C (FDIC) is unchanged. Banks must still notify their primary federal regulator as soon as possible and no later than 36 hours after determining a notification incident has occurred. The July 2026 statement addresses only how examiners handle sensitive bank data and what the agencies commit to do if their own systems are compromised.
Is the 72-hour regulator commitment legally enforceable?
No. It was issued as supervisory guidance rather than through notice-and-comment rulemaking, and creates no private right of action. Julie Andersen Hill, dean of the University of Wyoming College of Law, has noted that banks will not be able to sue to enforce the document. The commitment is also conditioned on the agency having a reasonable basis to believe a compromise occurred, having determined which banks are affected, and on applicable legal considerations.
Which data categories does the statement identify as highly sensitive?
The statement specifically names technology diagrams and schematics, detailed cyber-vulnerability testing results, and succession planning data as warranting particular caution. It does not provide an exhaustive definition. Identification of highly sensitive material is delegated to bank management, which means institutions need their own written taxonomy to apply the protection consistently across examinations.
What alternatives to data transfer are examiners directed to use?
Three are named: review conducted on-site at the institution, direct digital review from the systems of the supervised bank, and redacted or summarised versions of documents. The agencies also referenced additional protective measures and committed to giving examiners written guidance and training. Institutions need read-only examiner access and redaction capability to make these alternatives workable in practice.
How does this compare with EU and UK requirements?
DORA requires financial entities to notify competent authorities within four hours of classifying an incident as major and no later than 24 hours from detection, with a 72-hour intermediate report and a final report within one month. The UK’s PS7/26 takes effect March 18, 2027. Neither regime imposes any reciprocal notification duty on supervisors toward supervised firms, making the US commitment a first of its kind despite its weaker timeline.
Does the statement apply to non-bank financial institutions?
No. It addresses examinations conducted by the Federal Reserve, FDIC and OCC of supervised banking organisations. Asset managers, broker-dealers and other non-bank firms are outside its scope, and no equivalent commitment has been issued by the SEC or CFTC. The Managed Funds Association co-signed the June 2025 industry letter but the resulting guidance does not cover buy-side supervision.
What should firms do before their next examination?
Establish a written internal taxonomy defining highly sensitive information, with designation governance identifying who decides and how disputes escalate. Build technical capability for on-site and read-only digital examiner review, plus redaction at examination speed. Brief exam-management staff that designation now happens at the point of the document request, and confirm that existing 36-hour incident-reporting procedures remain unchanged.
Related coverage: DORA’s third-party oversight split across EU, UK and US resilience rules, Hong Kong’s OTP ban and operational security, the CFTC’s no-deny settlement reversal, and ASIC’s $300m CFD penalty.
This article is informational analysis only and does not constitute legal, regulatory, tax, or investment advice. Regulatory frameworks change frequently and interpretation depends on facts and circumstances; primary documents and official regulator guidance always supersede summaries. Firms should consult qualified legal counsel and their relevant supervisory authority before taking any action based on the analysis above.