OMB control number

Computer Security Incident Notification Requirements

OMB 3064-0214 · FDIC.

OMB 3064-0214

The Office of the Comptroller of the Currency (OCC), Board of Governors of the Federal Reserve System (Board), and the Federal Deposit Insurance Corporation (FDIC) (collectively, the agencies) are issuing a notice of proposed rulemaking (the proposal or proposed rule) that would require a banking organization to notify its primary federal regulator upon the occurrence of a significant computer security incident. This notification requirement is intended to serve as an early alert to a banking organization’s primary federal regulator and is not intended to include an assessment of the incident. The proposed rule would allow a banking organization to authorize or contract with a bank service provider to allow the bank service provider to make the relevant notifications to the banking organization’s primary federal regulator on the banking organization’s behalf. Moreover, a bank service provider as defined herein and in accordance with the Bank Service Company Act (BSCA) would be required to notify affected banking organization customers within four hours of when it experiences a computer-security incident that it reasonably believes could disrupt, degrade, or impair services provided subject to the BSCA for four or more hours. “Bank service providers” would include both bank service companies and third-party service providers, under the BSCA.

The latest form for Computer Security Incident Notification Requirements expires 2028-02-29 and is listed under ICR 202408-3064-006.

All Historical Document Collections

Historical document collections
ReferenceFilingReceivedConcludedAction
202408-3064-006 Extension without change of a currently approved collection 2025-01-22
202111-3064-008 New collection (Request for a new OMB Control Number) 2021-12-09 Approved without change
202101-3064-001 New collection (Request for a new OMB Control Number) 2021-01-13 Comment filed on proposed rule

OMB Details

Notification Incident Reporting

Federal Enterprise Architecture: Economic Development - Financial Sector Oversight