Credit unions rarely fail an NCUA information security exam for lacking security. They fail for lacking provable security. The control exists, but the policy is undated, the test is undocumented, or last cycle's finding is still open. This guide walks through what NCUA examines, what the regulation requires, and the artifacts to have ready before the examiner asks.
The regulatory frame in one page
Four things govern a federally insured credit union's cybersecurity obligations.
| Requirement | Where it lives | What it demands |
|---|---|---|
| Information security program | 12 CFR Part 748, Appendix A | A written program to safeguard member information, approved and overseen by the board, with a risk assessment, controls, vendor oversight, testing, training and annual adjustment |
| Response program | Part 748, Appendix B | A program to respond to unauthorized access to member information, including member notice when warranted |
| Cyber incident reporting | 12 CFR 748.1(c) | Report a reportable cyber incident to NCUA as soon as possible and no later than 72 hours after the credit union reasonably believes one occurred. In force since September 1, 2023 |
| Examination | NCUA Information Security Examination (ISE) procedures, ACET self-assessment | Examiners test whether the program is documented, operating, tested and overseen. ACET is the maturity self-assessment; ISE is what the examiner runs |
FFIEC guidance sits underneath all of it. The FFIEC Cybersecurity Assessment Tool was retired on August 31, 2025, and NCUA's ACET, which was built on it, is being aligned to NIST CSF 2.0. Examiners now expect the maturity narrative in CSF language.
What the examiner is looking for
The ISE procedures test four things, in this order of weight.
- Governance. Has the board approved the program, received an annual report, and been told about material risk? Minutes are the evidence.
- Risk assessment. Does the assessment describe the credit union's actual environment: the core, digital banking, remote access, cloud services, vendors? Is it dated within the year?
- Control operation. Not whether a policy exists, but whether the control runs. Patch reports, access review sign-offs, backup restore logs, MFA coverage, email authentication records.
- Third-party oversight. A tiered vendor inventory, due diligence for tier one, contracts with security clauses, and evidence of ongoing monitoring.
Everything else, from training records to the incident response test, hangs off those four.
The Part 748 readiness checklist
This is the list we build before an exam. Each line is an artifact, not a task. If you cannot put your hands on it in five minutes, treat it as missing.
Governance
- Written information security program, board-approved, with the approval date in the minutes
- Annual report to the board on the program's status, dated within twelve months
- Named program owner with authority and a documented reporting line
- Policy set with owners, review dates and version history
Risk assessment
- Enterprise information security risk assessment dated within twelve months
- Asset inventory covering systems that store or process member information
- Data flow or system inventory that shows where member information lives, including vendors
- Risk register with owners, ratings and treatment decisions
Controls that operate
- Multifactor authentication coverage report for remote access, email and privileged accounts
- Patch and vulnerability management reports for the last two quarters
- Privileged and user access reviews, signed and dated
- Backup schedule, offline or immutable copy, and the last restore test result
- Logging and monitoring evidence: what is collected, who reviews it, sample alerts and dispositions
- Email authentication: SPF, DKIM and DMARC at enforcement, with the records on file
- Endpoint protection deployment coverage
- Network segmentation diagram for member-facing systems and the core
Third-party risk
- Vendor inventory tiered by member data access and operational dependence
- Due diligence files for tier-one vendors: SOC reports reviewed with exceptions noted, financials, insurance, incident history
- Contracts with information security, breach notification and audit clauses
- Ongoing monitoring evidence: annual reviews, SOC bridge letters, incident notifications received
- Registrar and DNS provider treated as vendors. A domain hijack is a vendor incident
Incident response and the 72-hour rule
- Incident response plan with roles, escalation tree and contact lists
- Reportability criteria written against 748.1(c) so the decision is made before the incident
- Pre-drafted notification for the realistic scenarios: ransomware, vendor breach, business email compromise, domain or DNS compromise
- Tabletop exercise within the last twelve months, with attendance, scenario and findings documented
- Member notice procedure under Appendix B
Training and awareness
- Annual security training completion records for staff and board
- Phishing simulation results and follow-up
- Role-specific training for wire, ACH and administrative staff
Testing
- Vulnerability scan results, internal and external, with remediation tracking
- Penetration test within the cycle examiners expect for your size and complexity
- Findings from the prior exam, each mapped to an owner, a date and closure evidence
The 72-hour rule in practice
The reporting clock starts when the credit union reasonably believes a reportable incident has occurred, not when it is confirmed. That makes the definition the control. Credit unions that handle the rule well have decided in advance what counts as reportable, who makes the call, and what the first notification says. Those that struggle are debating definitions at hour forty.
A workable decision path:
- Detection or vendor notice reaches a named person within one hour.
- That person applies the written reportability criteria and escalates within four hours.
- The program owner and the CEO decide, with counsel available, by hour twenty-four.
- The notification goes to NCUA by hour forty-eight, leaving margin.
- The decision, the timeline and the evidence are documented whether or not the incident is reported.
Vendor incidents follow the same path. In the rule's first year, 69 percent of the 1,072 incidents credit unions reported traced back to a third party.
Why credit unions fail exams
From the exam cycles we have sat through on the credit union's side of the table, the same five findings recur.
- Stale governance. The program was approved three years ago and never revisited. The board has not seen a security report since.
- A risk assessment that describes a different credit union. Cloud services, remote work and new vendors arrived; the assessment did not.
- Controls without evidence. MFA is "everywhere" but nobody can produce the coverage report. Backups run but were never restored.
- Vendor files that stop at the contract. SOC reports collected, never read, exceptions never tracked.
- Open findings. The prior cycle's items are half done with no closure evidence.
None of these are technology problems. They are ownership and calendar problems, which is why a program owner matters more than another tool.
How we run exam readiness
Our NCUA readiness work is delivered as a fixed-scope engagement or continuously through a vCISO.
- Baseline, weeks one and two. Inherent risk profile and control maturity assessment validated against the deployed environment: interviews, configuration review, documentation sweep.
- Gap-to-roadmap, weeks three and four. Every gap gets an owner, a priority and a date. Quick wins execute immediately. Structural work is scheduled and budgeted.
- Evidence build, ongoing. Artifacts organized the way examiners request them, so responses take minutes.
- Pre-exam rehearsal. A dry run against the ISE procedures with leadership briefed on posture, open items and the narrative.
- Exam and after. Support during the exam, and findings remediated to closure with evidence.
Frequently asked questions
What is the difference between ACET and ISE? ACET is the self-assessment credit unions complete to measure inherent risk and control maturity. ISE is the examination procedure NCUA examiners use. ACET results inform the exam, but the exam tests evidence, not self-reported maturity.
How often does NCUA examine cybersecurity? Information security is part of the regular examination cycle, with depth scaled to the credit union's size and risk profile. Larger and higher-risk institutions see a fuller ISE; smaller ones see a core set of procedures. Every credit union should expect governance, risk assessment, controls and vendor oversight to be tested.
Does Part 748 apply to state-chartered credit unions? Part 748 applies to federally insured credit unions, which includes federally insured state charters. State regulators may add requirements, and the 72-hour rule applies to all federally insured credit unions.
What counts as a reportable cyber incident? An incident that leads to substantial loss of confidentiality, integrity or availability of a network or member information system, that disrupts business operations or member services, or that involves unauthorized access to sensitive data. Vendor incidents that affect the credit union count. Write the criteria down before you need them.
Is a penetration test required? NCUA expects testing proportionate to size and complexity. For most credit unions that means annual external testing and regular vulnerability scanning, with results tracked to remediation. The examiner asks for the results and the follow-up, not the report cover.
We have an MSSP. Does that cover the program? An MSSP operates monitoring and response tools. It does not own the written program, the risk assessment, the board reporting or vendor oversight. Those still need an owner inside or on behalf of the credit union.