---
kind: "section"
citation: "12 C.F.R. § 304.21"
title: "12"
number: "304.21"
heading: "Authority, purpose, and scope."
url: "https://uscodex.org/cfr/12/304.21"
---

# §304.21. Authority, purpose, and scope.

- (a) **Authority.** This subpart is issued under the authority of 12 U.S.C. [1463](/usc/12/1463.md), [1811](/usc/12/1811.md), [1813](/usc/12/1813.md), [1817](/usc/12/1817.md), [1819](/usc/12/1819.md), and [1861-1867](/usc/12/1861-1867.md).
- (b) **Purpose.** This subpart promotes the timely notification of computer-security incidents that may materially and adversely affect FDIC-supervised institutions.
- (c) **Scope.** This subpart applies to all insured state nonmember banks, insured state licensed branches of foreign banks, and insured State savings associations. This subpart also applies to bank service providers, as defined in [§ 304.22(b)(2)](/cfr/12/304.22.md?p=b-2).

## Notes

### Source

Source: 86 FR 66443, Nov. 23, 2021, unless otherwise noted.

### Authority

Authority: 5 U.S.C. 552; 12 U.S.C. 1463, 1464, 1811, 1813, 1817, 1819, 1831, and 1861-1867. Link to an amendment published at 91 FR 38268, June 25, 2026.

### Source

Source: 84 FR 29052, June 21, 2019, unless otherwise noted.
