xmodoxmodo

Frameworks · Global standards

CRI Profile v2.1

The Cyber Risk Institute Profile is the financial sector's cybersecurity assessment framework. It is built on the NIST Cybersecurity Framework and mapped to financial regulators' expectations. Version 2.1, issued on 15 April 2025, keeps the structure and diagnostic statements of version 2.0. It adds mappings including DORA, alongside a maturity model.

Who it applies to

It applies to banks, insurers, asset managers and market infrastructures that use the Profile to assess once and report to several regulators. It also applies to the technology providers those institutions assess.

Main requirements

Impact tiering

The institution's tier reflects its systemic impact and determines which diagnostic statements apply.

Functions

Govern, Identify, Protect, Detect, Respond, Recover and the Profile's extension functions are expressed as diagnostic statements.

Regulatory mapping

Each diagnostic statement maps to the regulations it provides evidence for, including DORA in version 2.1.

Maturity

Maturity is assessed against the Profile's maturity model.

How xmodo supports it

  • 1

    Diagnostic statements are set up as controls scoped by tier, with evidence and a calculated compliance status.

  • 2

    The regulatory mappings become mappings between frameworks, so one Profile assessment provides evidence for DORA, 23 NYCRR 500 and other mapped regulations on the same record.

Related frameworks

CRI Profile v2.1 shares requirements with the frameworks below. Controls you already run for any of them count towards CRI Profile v2.1 as well.

Frequently asked questions

What changed in version 2.1?

The core structure and diagnostic statements did not change. Version 2.1 added regulatory mappings including DORA, and a maturity model. xmodo records the edition as a field and migrated 2.0 assessments without rework.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo