SEC and FINRA: Which Framework Should I Use?
MSPs supporting financial services firms (registered investment advisers, broker-dealers and similar firms) often ask which ControlMap framework to use for SEC or FINRA compliance. The short answer: neither the SEC nor FINRA prescribes a specific cybersecurity framework. Both expect firms to adopt a recognized industry framework that fits their size and risk, and to back it with documented policies, risk assessments and oversight.
SEC
The SEC does not have a specific framework. Its guidance is to use an appropriate framework that includes risk management and written policies, such as CIS Controls, NIST CSF, the FTC Safeguards Rule or the CRI Profile as examples.
The SEC goes a step further by publishing annual Exam Priorities, which include a cybersecurity section. They’re worth reading each year: SEC Cybersecurity.
Firms should also be aware of the 2024 amendments to Regulation S-P. These require a written incident response program, oversight of service providers, and customer notification after unauthorized access to sensitive information. The SEC’s Small Entity Compliance Guide gives a plain-language overview. Any of the frameworks above will help support these requirements.
FINRA
Like the SEC, FINRA does not mandate a framework. It expects member firms to keep a cybersecurity program that fits their size and business model, and it points to recognized industry frameworks such as NIST CSF and CIS.
FINRA does publish a Small Firm Cybersecurity Checklist, which is included in ControlMap as a framework to work from. It’s built for smaller broker-dealers and is a practical starting point when a full framework such as CIS, NIST CSF, FTC Safeguards or CRI among others would be more than the firm needs.
Helpful FINRA resources:
- FINRA Cybersecurity key topic page
- Core Cybersecurity Threats and Effective Controls for Small Firms
- 2026 FINRA Annual Regulatory Oversight Report: Cybersecurity and Cyber-Enabled Fraud. FINRA publishes this report every year. Like the SEC Exam Priorities, it’s worth reviewing annually to see what examiners are focused on.
Which framework should I choose in ControlMap?
Since there’s no single required framework, choose based on the firm’s size, complexity and what its compliance team or auditors expect:
- FINRA Small Firm Cybersecurity Checklist: a good fit for smaller FINRA member firms that want a simple, regulator-published checklist.
- CIS Controls: a good fit for most small to mid-sized firms (SEC- or FINRA-regulated) that want a prescriptive, prioritized set of technical controls. Implementation Group 1 (IG1) is a common starting point.
- NIST CSF: a good fit for larger or more mature firms, or firms whose clients, auditors or parent organizations already use NIST.
Tip: Many firms start with the FINRA checklist or CIS IG1 and grow into a broader framework over time. Whatever you choose, document the choice and the reasoning in the firm’s written policies. Examiners want to see that the firm chose a framework deliberately and follows it.
This article is general guidance, not legal or regulatory advice. Firms should confirm their specific obligations with their compliance officer or legal counsel. Generated with AI and reviewed by a human.
Related to