Fannie Mae Information Security and Business Resiliency Supplement
We encourage you to adopt the following requirements now, but your organization must complete full implementation no later than the effective dates outlined below.
- Single-Family seller and servicers and Multifamily lenders: August 12, 2025
- Technology service providers: December 31, 2025
- Document custodians: April 1, 2026
Fannie Mae recognizes that cyber risk is a business risk and protecting data is a shared responsibility.
Due to an evolving landscape, Fannie Mae has introduced new and updated cybersecurity requirements that our business partners must follow to ensure the safety and soundness of the enterprise. The new Fannie Mae Information Security and Business Resiliency Supplement (also referred to as the "Supplement") includes updates to:
- information security controls;
- cybersecurity incident notification requirements, including a requirement that business partners subject to the Supplement’s requirements are required to report cybersecurity incidents to Fannie Mae within 36 hours of identification; and
- business continuity and resiliency requirements.
The Supplement has been updated to make additional parties with whom Fannie Mae does business subject to its requirements. Effective on the dates outlined above, Single-Family sellers and servicers, Multifamily lenders, technology service providers, and document custodians (each defined as a "Company" in the "Supplement") are/or will be subject to and must comply with the terms of the Supplement.
Supplement
View the SupplementSupplement Bulletin 25-01
Read the Supplement Bulletin 25-01Need a refresher on some of the current requirements?
- The Consolidated Technology Guide is the single point of reference for Fannie Mae’s technology licensing contract, the Software Subscription Agreement, which governs external party access and use of Fannie Mae’s applications and related application programming interfaces.
- Single-Family sellers and servicers are bound by the provisions of the Fannie Mae Single-Family Selling and Servicing Guides.
- Multifamily lenders are bound by the provisions of the Multifamily Selling and Servicing Guide and Multifamily Lender Program Rules (login required).
- Technology service providers are bound by the Integration Agreement they enter into with Fannie Mae.
- Document custodians are bound by the provisions in the Fannie Mae Requirements for Document Custodians and Master Custodial Agreement (Form 2017).
Supplement and Related Bulletins Archive
This section contains copies of all previously issued Information Security and Business Resiliency Supplement Bulletins, as well as all prior versions of the Supplement published to date. Each edition of the Supplement supersedes and replaces the prior version in its entirety, as of the effective date(s) provided in the corresponding Bulletin.
Supplement
Information Security and Business Resiliency Supplement (effective August 12, 2025 for Single-Family sellers and servicers and Multifamily lenders)
Bulletin
Intentionally Left Blank
