12 CFR 304.21
§ 304.21 Authority, purpose, and scope.
United States · 12 CFR — Banks and Banking · Status: effective
Cite this
- Citation
- 12 CFR 304.21, § 304.21 Authority, purpose, and scope, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/46025
- Permanent ID
ys:prov:46025@1- SHA-256
d5aa974fe6f12afee17949639fdee106757394b73ac07115f59efa25394c0377
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
(a) Authority. This subpart is issued under the authority of 12 U.S.C. 1463, 1811, 1813, 1817, 1819, and 1861-1867.
(b) Purpose. This subpart promotes the timely notification of computer-security incidents that may materially and adversely affect FDIC-supervised institutions.
(c) Scope. This subpart applies to all insured state nonmember banks, insured state licensed branches of foreign banks, and insured State savings associations. This subpart also applies to bank service providers, as defined in § 304.22(b)(2).
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.