Frameworks · Global standards
CRI Profile v2.1
The Cyber Risk Institute Profile is the financial sector's cybersecurity assessment framework. It is built on the NIST Cybersecurity Framework and mapped to financial regulators' expectations. Version 2.1, issued on 15 April 2025, keeps the structure and diagnostic statements of version 2.0. It adds mappings including DORA, alongside a maturity model.
Who it applies to
It applies to banks, insurers, asset managers and market infrastructures that use the Profile to assess once and report to several regulators. It also applies to the technology providers those institutions assess.
Main requirements
Impact tiering
The institution's tier reflects its systemic impact and determines which diagnostic statements apply.
Functions
Govern, Identify, Protect, Detect, Respond, Recover and the Profile's extension functions are expressed as diagnostic statements.
Regulatory mapping
Each diagnostic statement maps to the regulations it provides evidence for, including DORA in version 2.1.
Maturity
Maturity is assessed against the Profile's maturity model.
How xmodo supports it
- 1
Diagnostic statements are set up as controls scoped by tier, with evidence and a calculated compliance status.
- 2
The regulatory mappings become mappings between frameworks, so one Profile assessment provides evidence for DORA, 23 NYCRR 500 and other mapped regulations on the same record.
Related frameworks
CRI Profile v2.1 shares requirements with the frameworks below. Controls you already run for any of them count towards CRI Profile v2.1 as well.
Frequently asked questions
What changed in version 2.1?
The core structure and diagnostic statements did not change. Version 2.1 added regulatory mappings including DORA, and a maturity model. xmodo records the edition as a field and migrated 2.0 assessments without rework.