Quick answer
The CRI Profile, from the Cyber Risk Institute, is the financial sector's harmonized cybersecurity framework: it consolidates the overlapping expectations of dozens of financial regulators and standards (NIST CSF-based, mapped to 23 NYCRR 500, FFIEC guidance, DORA, and more) into one control set, scaled by four impact tiers so a community bank and a global systemically important institution each assess against proportionate depth. Financial companies use it to answer many regulators with one program.
The problem it solves
A financial institution faces a pile of overlapping cyber expectations: state regulators, federal examiners, international rules, and counterparty demands, each with its own vocabulary for substantially the same controls. Answering each separately multiplies the compliance program by the number of regulators. The Profile inverts that: implement and assess one harmonized control set, then present each regulator its own view through the maintained mappings, the cross-mapping strategy formalized at industry scale.
The four tiers
Tiering calibrates depth to systemic impact: institutions assess their tier through impact questions (size, interconnectedness, criticality of services), and the tier determines which diagnostic statements apply, from the reduced set for smaller firms to the full set for the most systemic. That proportionality is why the Profile works across the sector's size range, the same scale-to-fit logic as implementation groups elsewhere.
Who uses it
- Banks, insurers, and asset managers structuring their cyber program to face multiple examiners efficiently.
- Financial market utilities and fintechs whose counterparties assess them in Profile terms.
- Technology providers to the sector, who meet the Profile through customer due diligence: the third-party sections generate the questionnaires vendors receive, making a maintained, shareable posture the efficient response.
Relationship to your other frameworks
The Profile deliberately builds on the NIST CSF's functions, so a CSF-shaped program slots in naturally, and its mappings mean evidence gathered once serves the Profile, DORA, NYDFS, and the rest simultaneously.

Get a personalized walkthrough of automated compliance for your team. No commitment required.