Principle Security Principle Security.

Compliance

Could you meet the 72-hour reporting rule?

Since September 2023, NCUA requires credit unions to report a reportable cyber incident within 72 hours — and FFIEC-regulated institutions face parallel expectations. Six questions on whether you could actually meet that clock.

6 questions ~2 minutes No signup Runs in your browser

The 72-hour clock starts whether or not you're ready. This checks the decisions and evidence habits that let you meet it without improvising.

1
Have you defined, in writing, what counts as a reportable incident for your institution?
2
Is it clear who decides to report, and who files, at any hour?
3
Do you have an escalation path from 'something's wrong' to a reporting decision?
4
Would you find out in time if the incident happened at a vendor (core, digital banking, MSP)?
5
Have you tabletop-tested the reporting decision specifically?
6
Could you produce the evidence an examiner expects afterward (timeline, decision log, notice)?

Why this matters

The clock starts before you understand the incident

Seventy-two hours sounds generous until you're in it: the hardest part isn't filing, it's deciding whether the event even qualifies, at 2 a.m., with partial information, when the incident may have started at a vendor you don't monitor. Institutions that meet the deadline do it because the reportability criteria, the decision-maker, and the escalation path were all set in advance — and because they documented the decision as they went.

72 hrs
to report a reportable cyber incident to NCUA
12 CFR Part 748.1(c), in force since Sept 1, 2023.

How this is scored

Six weighted questions on the specific capabilities the rule demands: written reportability criteria, a named decision-maker, a tested escalation path, timely vendor notice, a reporting-focused tabletop, and a real-time decision log. Each scores 0–3; the total maps to a readiness band with prioritized gaps.

Questions

What counts as a reportable incident?

Broadly, a substantial cyber incident that disrupts operations or member services, or that involves unauthorized access to sensitive data — including at a vendor. The critical move is to write your own criteria in advance so the call isn't made cold.

Does the rule apply to incidents at our vendors?

Yes. If a reportable incident occurs at a third party that affects the credit union, the clock still applies — which is why timely contractual notice from core, digital-banking and MSP vendors matters.

What do examiners look for afterward?

A tested plan, evidence it was tested, and a decision log showing how and when you determined reportability and filed. Reconstructed-after-the-fact evidence is weak; log it in real time.

Make the 72-hour clock a non-event

We set your reportability criteria, escalation path and evidence habits in advance, so the decision is made with a recommendation in hand.