On September 16, 2025, the National Credit Union Administration (NCUA) announced an update to their Automated Cybersecurity Examination Toolbox (ACET). Here's an overview of what's new.
ACET Maturity Assessment
The ACET webpage previously referred to the application as a way to complete assessments based on the FFIEC Cybersecurity Assessment Tool (CAT). Following the FFIEC CAT sunset in August 2025, the ACET application now refers to its assessment as the "ACET Maturity Assessment."
Continued Support of CAT Content
Even with the name change, the ACET Maturity Assessment still includes all FFIEC CAT content. It also provides a mapping of ACET statements to CAT components, making it easier to bridge past and current assessments.
NIST CSF 2.0 Mapping
ACET statements are now mapped to the NIST Cybersecurity Framework (CSF) 2.0. Previously, the ACET was mapped to NIST CSF 1.1 through the FFIEC CAT mapping.
Application Security Updates
The ACET application was upgraded to run on .NET 8 and SQL Server 2022 LocalDB, replacing older versions. These updates keep the ACET on fully supported platforms, delivering stronger security, better performance, and the ability to implement future improvements.
Additional Supported Frameworks
Beyond the ACET Maturity Assessment, the ACET application supports a range of frameworks, including:
- NIST CSF 2.0
- CIS Controls v8
- PCI-DSS
- CISA Ransomware Readiness Assessment (RRA)
- And others
Looking Ahead
In an email announcing the update, the NCUA's Office of Examination and Insurance shared:
"The NCUA will continue to support ACET development and will align future content with evolving standards and frameworks, such as the Cybersecurity and Infrastructure Security Agency's Cross Sector Cybersecurity Performance Goals."
Complete the ACET in Tandem
The NCUA encourages credit unions to use the ACET to assess cybersecurity preparedness levels. Tandem Cybersecurity Assessment is a software that allows you to complete the ACET Maturity Assessment alongside many other frameworks. Our web application offers enhanced features, such as peer analysis, multi-user access, custom reporting, and reminder notifications. Learn more and sign up for free at Tandem.App/Cybersecurity.