Free assessment for credit unions
Know before your examination
Twenty-two questions against 12 CFR Part 748 and NCUA's Information Security Examination expectations. Ten minutes, an instant score across six domains, and your top gaps mapped to the citations an examiner would cite.
No login, no email gate to see your score. Answers never leave your browser.
Why this exists
Since September 2023, a significant cyber incident means an NCUA Board notification within 36 hours of confirming it — and a filing with NCUA within 72 hours of that notice. Most credit unions discover whether they can meet that clock during an actual incident. This self-score tells you now.
How the 36-hour rule works →The self-score
Answer honestly — nobody sees this but you
Rate each statement as it is today, not as your policy manual claims. "Unsure" is a real answer, and it's the one that most often matches what an examiner finds.
Your results
Where you stand
Answer the questions above and hit See my score.
Straight answers
Part 748, ISE, ACET — what's what
What is Part 748?
The NCUA rule that requires federally insured credit unions to maintain a written, board-approved information security program (Appendix A) and incident-response and business-continuity programs (Appendix B) — plus the requirement to notify the NCUA Board within 36 hours of confirming a significant cyber incident and file with the NCUA within 72 hours of that notice (§748.1(c)).
What is the ISE?
NCUA's Information Security Examination — the on-site (or remote) examination where examiners work through published procedures, scaled to your asset size and risk profile. It's the exam; Part 748 is the syllabus.
Where does ACET fit?
The NCUA Assessment of Cybersecurity for Examined Institutions (ACET) is the voluntary self-assessment, built on the FFIEC Cybersecurity Assessment Tool lineage (the CAT retired in 2025; ACET carries its structure). It measures inherent risk and control maturity — the same language examiners were trained on. An ACET nobody acts on is worse than none: it's documented awareness of unclosed gaps.
Is this self-score an audit?
No — it's an indicative readiness view, re-derived from public regulatory text and published examination-procedure themes. It's the conversation-starter, not the attestation. The validated version — answers checked against deployed reality, evidence organized examiner-style — is the readiness engagement.
Turn the score into a plan.
A self-score is a mirror. We bring the roadmap: gaps owned, scheduled, evidenced — and a pre-exam rehearsal so exam week holds no surprises.
Explore
Also from Principle Security
ISE & ACET Readiness
We run your program against NCUA's examination procedures before the examiners do.
ServiceThe 36-Hour Rule
Board notification within 36 hours, NCUA filing within 72 — most credit unions can't meet either today.
Free toolDomain Security Check
Grade your public security posture in seconds — DNS, mail, TLS and headers.