Fannie Mae Information Security and Business Resiliency Supplement

Fannie Mae recognizes that cyber risk is a business risk and protecting data is a shared responsibility.
Due to an evolving landscape, Fannie Mae has introduced new and updated cybersecurity requirements that our business partners must follow to ensure the safety and soundness of the enterprise. The new Fannie Mae Information Security and Business Resiliency Supplement (the "Supplement") includes updates to:
- information security controls;
- cybersecurity incident notification requirements; and
- business continuity and resiliency requirements.
Need a refresher on current requirements?
The Consolidated Technology Guide is the single point of reference for Fannie Mae’s technology licensing contract, the Software Subscription Agreement, which governs external party access and use of Fannie Mae’s applications and related application programming interfaces. In addition:
- Single-Family sellers and servicers are bound by the provisions of the Selling Guide A3-2-01, Compliance With Laws.
- Multifamily lenders are bound by the provisions of the Multifamily Lender Program Rules (login required).