Most credit unions under a billion in assets do not need a full-time chief information security officer. They need someone senior who owns the security program, answers to the board and the examiner, and does the work between exams. That is what a virtual CISO is for. This guide explains what the role covers at a credit union, how it fits NCUA's expectations, what it costs, and how to tell a real program owner from a part-time auditor.
What NCUA actually requires
NCUA does not require a credit union to employ a CISO. It requires a written information security program under 12 CFR Part 748, Appendix A, that the board approves and oversees, a risk assessment behind it, controls that operate, and an incident response program (Appendix B) that can meet the 72-hour cyber incident reporting rule in 748.1(c), in force since September 1, 2023.
What the regulation does require is accountability. Someone has to own the program, report to the board at least annually, and be able to answer an examiner's questions with evidence. At a 500 million dollar credit union that owner is usually the IT manager, who is also running the core conversion, the help desk and the phone system. Examiners notice.
A vCISO fills the ownership gap without the full-time salary. The credit union keeps its staff. The vCISO owns the program, the calendar, the evidence, and the conversations with the board and the examiner.
What a credit union vCISO owns
A real vCISO engagement covers six things. If a proposal covers fewer, it is advisory, not ownership.
| Area | What the vCISO owns | What the examiner asks for |
|---|---|---|
| Program and governance | The written Part 748 program, annual review, board reporting with minutes | Board-approved program, dated policies, annual report to the board |
| Risk assessment | A risk assessment that matches the real environment, refreshed yearly and after major change | Risk assessment tied to controls and to the vendor inventory |
| Control operation | Patching cadence, identity and MFA, backups and restore tests, logging, email authentication | Evidence that controls run, not policies that describe them |
| Vendor oversight | Tiered vendor inventory, due diligence on tier one, contract clauses, ongoing monitoring | Due diligence files for the core, digital banking, card processor, MSSP, registrar |
| Incident response | Reportability criteria, escalation tree, tabletop exercises, the 72-hour decision path | A tested plan and evidence of the test |
| Exam readiness | ISE and ACET preparation, findings tracking, remediation to closure | Last cycle's findings closed with evidence |
The last row is where most credit unions lose exams. The control exists, but the finding from the previous cycle is still open, or the evidence is in someone's inbox. A vCISO's first job is usually to make the evidence retrievable.
How it fits the exam cycle
NCUA's Information Security Examination procedures and the ACET self-assessment both test whether the program is demonstrable. A vCISO engagement is built around that cycle.
- Baseline, weeks one and two. Inherent risk profile, control maturity, documentation sweep, vendor inventory. This is where the program owner learns what the examiner will find before the examiner does.
- Gap-to-roadmap, weeks three and four. Every gap gets an owner, a priority and a date. Quick wins execute. Structural work is budgeted.
- Operate, ongoing. The calendar runs: patch reviews, access reviews, vendor reviews, backup tests, training, board reporting. Evidence accrues as a by-product of the work.
- Pre-exam rehearsal. A dry run against the ISE procedures with leadership briefed on posture, open items and the narrative.
- Exam support. The vCISO sits at the table, answers the technical questions, and drafts responses to findings.
What it costs
A full-time CISO with credit union experience costs 180,000 to 260,000 dollars in salary before benefits, and is hard to hire at all outside major metros. A vCISO engagement for a credit union between 200 million and 2 billion in assets typically runs 4,000 to 12,000 dollars a month depending on scope, exam timing and how much hands-on work is included. The cost scales with what the credit union needs owned, not with asset size alone.
Three things move the price:
- Hands-on scope. Whether the vCISO also does the engineering work (identity, email authentication, segmentation, backups) or only directs staff and vendors to do it.
- Exam proximity. A credit union six months from an ISE with open findings needs more hours in the first quarter.
- Vendor load. Third-party oversight is the largest recurring effort in most programs. Sixty-nine percent of the cyber incidents credit unions reported to NCUA in the rule's first year traced to a third party.
Our vCISO cost calculator gives a figure for your asset size in about a minute.
Fractional, full-time, or an MSSP
| Option | Owns the program | Does the technical work | Answers to the board and examiner | Typical annual cost |
|---|---|---|---|---|
| Full-time CISO | Yes | Sometimes | Yes | $220K–$320K loaded |
| vCISO with resident engineering | Yes | Yes | Yes | $50K–$150K |
| Advisory-only vCISO | Partly | No | Sometimes | $30K–$80K |
| MSSP or managed IT provider | No | Yes, within their scope | No | Varies; security is usually an add-on |
An MSSP runs tools. A managed IT provider runs the help desk and the servers. Neither owns the program or signs the board report. A vCISO can direct both. The mistake credit unions make is assuming the MSSP's "security package" is the program. It is one control family inside it.
How to judge a provider
Ask for these before signing:
- The names and backgrounds of the people who will actually work the account, not the firm's roster.
- Two references from credit unions that have been through an NCUA exam cycle with the provider.
- A sample board report and a sample risk assessment, redacted.
- How they handle the 72-hour rule: who decides reportability, and who has done it.
- Whether they will do the technical work or only direct it, in writing.
- How they separate security oversight from any managed IT or MSSP work they also sell. Whoever runs the servers should not be the only party checking them.
What the first ninety days look like
- Day one to thirty: baseline, vendor inventory, evidence sweep, the three fixes that reduce the most risk fastest (usually MFA coverage, email authentication, and backup restore testing).
- Day thirty to sixty: written program and risk assessment updated to match reality, board briefing scheduled, findings from the last exam mapped to owners.
- Day sixty to ninety: incident response criteria set, tabletop run, tier-one vendor due diligence current, reporting cadence in place.
By the end of the quarter the credit union has a program owner, a calendar, and evidence that retrieves in minutes. That is what examiners grade.
Frequently asked questions
Does NCUA require a credit union to have a CISO? No. Part 748 requires a board-approved information security program with an accountable owner, a risk assessment, operating controls, vendor oversight and an incident response program. A vCISO satisfies the ownership requirement without a full-time hire.
Can our managed IT provider be our vCISO? They can hold the title, but it weakens the program. The party that runs the systems should not be the only party assessing them. Keep program ownership and security oversight independent of the provider doing the operational work, or at least under separate accountability.
How much time does a vCISO spend with us? Typically 20 to 60 hours a month, front-loaded before an exam. The number matters less than what is owned. A provider that quotes hours without a scope of ownership is selling consulting, not a program.
What happens when the 72-hour clock starts? The vCISO applies the reportability criteria set in advance, convenes the escalation tree, drafts the notification, and documents the decision. The credit union's leadership makes the call with a recommendation in hand instead of a blank page.
We are between exams. Where should a vCISO start? Third-party risk and evidence retrieval. Vendor incidents drove most reported incidents in the rule's first year, and open findings from the last cycle are the most common exam failure.