12 C.F.R. § 225.300

Authority, purpose, and scope.

Last amended: 2022Year: 2026Length: 87 wordsSubsections: 3Official source

Cite as 12 C.F.R. § 225.300 (2026)

(a) Authority. This subpart is issued under the authority of 12 U.S.C. 1, 321-338a, 1467a(g), 1818(b), 1844(b), 1861-1867, and 3101 et seq. (b) Purpose. This subpart promotes the timely notification of computer-security incidents that may materially and adversely affect Board-supervised entities. (c) Scope. This subpart applies to all U.S. bank holding companies and savings and loan holding companies; state member banks; the U.S. operations of foreign banking organizations; and Edge and agreement corporations. This subpart also applies to their bank service providers, as defined in § 225.301(b)(2).
Cross-references to the US Code
12:1
Cross-references to the CFR
225.301
12 C.F.R. § 225.300: Authority, purpose, and scope. | Justis AI