IT Security Blog | Rivial Security

NIST CSF vs CIS vs CRI Profile: Which Framework Should Your Credit Union Choose?

Written by Randy Lindberg | 07 Oct 2026

Every credit union security leader eventually asks the same question, usually right before an exam or right after a merger: which framework does the NCUA actually want us on? Two credit unions of the same size sit on different frameworks and both pass their exams, which makes the choice feel arbitrary. Meanwhile, a migration wave is underway: teams are moving off the NCUA's ACET workbook and onto the CRI Profile, and others are weighing NIST CSF against CIS Controls.


This post gives you the honest comparison and a decision rule, so the choice takes an afternoon instead of a quarter.


Quick answer:
The NCUA does not prescribe a framework; it expects you to choose one and run your program against it. NIST CSF 2.0 is the broad default and the safest general choice. CIS Controls suit teams that want a technical, prioritized checklist. The CRI Profile is NIST tailored to financial institutions and is where much of the industry is heading. Do not use the NCUA's own ISE controls as your framework, because that is the tool examiners use to test you. Avoid NIST 800-53 unless you are a very large institution.


An Examiner Approved Cyber Risk Model

Check out the Cyber Risk Management Model that examiners reference below

 

 


What the NCUA actually expects


Start with the part that surprises people. Examiners do not hand out a preferred framework. What we hear from the NCUA, consistently, is two things. First, choose a recognized framework and be able to show your program mapped to it. Their current guidance says it plainly: align to a framework internally, and it can be any framework you pick. Second, do not adopt the NCUA's ISE control set as your framework, because ISE is the examiners' own testing tool. Building your program on the exam answer key impresses no one and leaves you without an independent standard.


The pressure is not only federal. State regulators are starting to set deadlines: at least one state is requiring institutions to be demonstrably aligned to a framework by 2028. "We have not picked one yet" is becoming an answer with an expiration date.


So the question is not "which one passes the exam." All three pass the exam when the program behind them is real. The question is which one fits how your team works.


NIST CSF 2.0: the broad default


The NIST Cybersecurity Framework is the most widely adopted option and the safest choice when nothing pulls you elsewhere. Version 2.0 organizes a program into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. The new Govern function matters for credit unions because it puts board oversight, risk management strategy, and supply chain expectations on equal footing with the technical work, which matches where exams have been heading.

 

CSF's strength is breadth and recognition. Every auditor, examiner, and vendor speaks it. Its weakness is that it is deliberately generic: it tells you what outcomes to achieve, not how a financial institution specifically should achieve them.

 

Choose CSF if you want the most portable, most recognized structure and you are comfortable translating general outcomes into credit union specifics yourself.


CIS Controls: the technical checklist


The CIS Critical Security Controls are a prioritized list of specific technical safeguards: inventory your assets, control admin privileges, manage vulnerabilities, and so on, organized into implementation groups by organization size. Teams that live close to the infrastructure often prefer CIS because every control is concrete and testable. There is little interpretation required.


The trade-off is coverage. CIS is strongest on technical hygiene and lighter on governance, third-party risk, and program management, which are exactly the areas examiners probe hardest at financial institutions. Many teams that choose CIS end up bolting governance elements back on.


Choose CIS if your team is technical, you want a prioritized to-do list rather than a management framework, and you are willing to supplement the governance side.


The CRI Profile: NIST, tailored for financial institutions


The Cyber Risk Institute's Profile takes NIST CSF and makes it financial institution specific. It keeps the NIST structure, adds the regulatory expectations financial institutions actually face, and scales the assessment by institution tier, so a $300 million credit union is not held to the same depth as a global bank.


This is why the migration wave is real. In the last few months we have watched multiple credit unions move from the NCUA's ACET workbook to the CRI Profile, and others ask for one control set mapped across NCUA ACET, FFIEC, and ISE at once. The Profile answers the translation problem that CSF leaves open: it already speaks regulator.


Choose the CRI Profile if you want NIST's structure with financial institution language built in, and especially if you are leaving ACET and want a durable home.


A note on NIST 800-53


It comes up, so here is the short version: 800-53 is the deep federal control catalog, over a thousand controls at full depth. Unless you are a very large institution with a dedicated GRC team, it is more framework than you need, and the maintenance burden will crowd out actual security work. Almost every credit union is better served by CSF or the CRI Profile.


The part no framework answers: what is the risk worth?


Here is the thing every comparison article skips. A framework tells you which controls to have. It does not tell you which risks cost the most, which gaps to fund first, or how to explain any of it to a board. Two credit unions can score identically against the CRI Profile and carry wildly different real exposure, because the framework measures presence of controls, not dollars of risk.


That is why the framework choice matters less than most teams fear, and the risk quantification behind it matters more. Do not take our word for it: on our annual panel with NCUA Regional Information Systems Officers, one RISO made the point himself, noting that the agency's own risk assessment appendix is built on NIST 800-30, which is qualitative or semi-quantitative, and that when you talk about risk, you really want to put a dollar cost on it so you can calculate the return on investing in a particular solution. Whichever framework you pick, the next step is putting a dollar figure on the risk each control category actually mitigates, so budget decisions rest on exposure instead of checklist coverage.

 

This is also where switching frameworks stops being scary. In Rivial Software, frameworks come pre-mapped, and because roughly 60 to 70 percent of controls overlap across them, one piece of evidence validates every framework that requires it. Clients moving from ASET to the CRI Profile carry their evidence and their quantified risk assessment with them, and the risk still reports to the board in dollars no matter which framework sits underneath. The migration becomes a mapping exercise, not a rebuild.


How to decide this week


Three questions settle it for most teams:

  1. Are you leaving ACET or consolidating multiple regulatory checklists? Go to the CRI Profile.

  2. Is your team primarily technical and hungry for a concrete checklist? CIS, with a plan to cover governance.

  3. Neither? NIST CSF 2.0 is the durable default.


Whatever you choose, write down why. "We selected the CRI Profile because it maps NIST to financial institution regulatory expectations at our tier" is one sentence, and it is the sentence your examiner wants to see.

 

 

An Examiner Approved Cyber Risk Model

Check out the Cyber Risk Management Model that examiners reference below