yourstate.us
12 CFR 225.303

§ 225.303 Bank service provider notification.

United States · 12 CFR — Banks and Banking · Status: effective

Get this as JSONEmbed this
Cite this
Citation
12 CFR 225.303, § 225.303 Bank service provider notification, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/44772
Permanent ID
ys:prov:44772@1
SHA-256
7dcf6b8983e4099ffa823595cd87f7aa7015dbfcbb35100427bf01cb4fce779b

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

(a) A bank service provider is required to notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible when the bank service provider determines that it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, covered services provided to such banking organization for four or more hours. (1) A bank-designated point of contact is an email address, phone number, or any other contact(s), previously provided to the bank service provider by the banking organization customer. (2) If the banking organization customer has not previously provided a bank-designated point of contact, such notification shall be made to the Chief Executive Officer and Chief Information Officer of the banking organization customer, or two individuals of comparable responsibilities, through any reasonable means. (b) The notification requirement in paragraph (a) of this section does not apply to any scheduled maintenance, testing, or software update previously communicated to a banking organization customer.

Legislative history

This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.