Fannie Mae Information Security and Business Resiliency Supplement

fnma-infosec-resiliency-supplement

Fannie Mae Information Security and Business Resiliency Supplement (published Sept 2, 2025) — the cybersecurity, incident-management, and business-resiliency requirements LL-2026-04 requires sellers/servicers to comply with.

Update kit for this regulation → Get this register: .xlsx .csv More bundles →
Update kit

Need to act on this regulation? FNMA AI Lender Letter (LL-2026-04) — Survivors Compliance Guide →

Verbatim regulatory text (5)

Verbatim provisions from Fannie Mae Information Security and Business Resiliency Supplement — each quote is a verified substring of the regulator-published source snapshot, not retyped. Quoted for reference; this is not legal advice. The operational layer (P&P updates, prompts) lives in the regulation update kits.

3. Information Security Program

align its Information Security Program with, or exceed, a current industry standard such as the National Institute of Standards in Technology (NIST) Framework or the International Organization for Standardization (ISO) 27001 Standard; • designate and keep a senior executive responsible for the development, implementation, and maintenance of its Information Security Program;

Source: Fannie Mae Information Security and Business Resiliency Supplement · source URL · snapshot fnma-isbrs-2026-06-16-pdf

Incident Management and Reporting

Without undue delay and no later than 36 hours after identification of the Cybersecurity Incident, or the reasonable conclusion a Cybersecurity Incident may have occurred, and promptly thereafter as requested, provide Fannie Mae via e-mail at [email protected] (or by such other means as Fannie Mae may otherwise request) all known details of the Cybersecurity Incident, including:

Source: Fannie Mae Information Security and Business Resiliency Supplement · source URL · snapshot fnma-isbrs-2026-06-16-pdf

Business Continuity

Business Continuity Plan must: • address Business Continuity Procedures and Disaster Recovery Procedures and provide a level of preparation, coordination, facilitation, resiliency, and testing that addresses disruptions that could impact normal operations and processing and • ensure the Company’s ability to recover critical business operations if: (A) there is a disruption or disaster, including to back-up systems, and (B) in the event of the expiration or termination of any contract that is material for the Company's sale or servicing of Fannie Mae loans or ability to comply with the Lender Contract or other agreements the Company has or relates to business conducted with Fannie Mae.

Source: Fannie Mae Information Security and Business Resiliency Supplement · source URL · snapshot fnma-isbrs-2026-06-16-pdf

Supply Chain Risk Management

The Company must develop, document, and implement a formal vendor risk management program to ensure the controls of new and existing vendors align with and are at least as protective as the Company’s Information Security Program and those required in this Supplement.

Source: Fannie Mae Information Security and Business Resiliency Supplement · source URL · snapshot fnma-isbrs-2026-06-16-pdf

Supply Chain Risk Management

Perform related business continuity due diligence on its third parties to ensure they meet contracted service requirements and maintain a business continuity program that aligns with industry best practices; Establish business continuity planning strategies that includes loss scenarios for people, technology, data, facilities, and third parties; Exercise its business and technology continuity planning documentation annually through tabletop or other similar exercises; and Document lessons learned and after actions when plans are tested or activated.

Source: Fannie Mae Information Security and Business Resiliency Supplement · source URL · snapshot fnma-isbrs-2026-06-16-pdf

Operationalizing Fannie Mae Information Security and Business Resiliency Supplement

This is verbatim, source-snapshotted regulator text from the Claude for Compliance open corpus. To turn a rule like this into compliance work product: gap-analyze your policies and procedures (P&Ps) against these requirements to surface stale, conflicting, or missing provisions; operationalize any change with a ready-to-run update kit; and produce audit-ready evidence — every step grounded only in the regulator’s own words, never invented.

To work from the whole rulebook rather than this one page: download the corpus — every register on this site, verbatim, each with its source snapshot and effective date — then follow the methodology. It asks your assistant to answer only from the downloaded text, cite the register id and effective date it used, and tell you when the corpus does not cover something instead of filling the gap from memory. Running it locally also means no one sees which regulations you are looking at.

Source of record: https://claudeforcompliance.com/regs/fnma-infosec-resiliency-supplement/ · register fnma-infosec-resiliency-supplement · Claude for Compliance. Free to read and download; see regulatory updates and methodology.