Credit unions

Credit union cybersecurity compliance that goes beyond NCUA

We help credit unions meet NCUA and GLBA expectations, answer examiner questions with evidence and protect member data every day. You get independent testing, security leadership and 24/7 monitoring from one team.

  • Programs built on NCUA Part 748 and GLBA safeguards
  • Internal, external and social engineering testing
  • vCISO reporting your board can act on
Advisor meeting with a client at a table
Two colleagues reviewing financial reports

The challenge

What NCUA expects from your security program

Every federally insured credit union must maintain a written information security program under NCUA’s Part 748 and its Appendix A guidelines, which implement the GLBA safeguards for member information. The program has to be risk-based, approved by your board and reported on to the board at least annually. Since September 2023, a reportable cyber incident must also be reported to NCUA within 72 hours of forming a reasonable belief that it happened.

Examiners want to see that the program works in practice. That means documented risk assessments, independent testing, vendor oversight, a tested incident response plan and board-level engagement. Most credit unions run lean IT teams, and the work lands on a few people who are already busy.

  • Member data spread across core, online banking and vendors
  • Heavy reliance on third-party processors and fintechs
  • Phishing and account takeover aimed at staff and members
  • Board oversight that needs clear, regular reporting
  • Exam findings that need tracked, documented remediation

Going beyond NCUA requirements

Cybersecurity for credit unions: the requirements and the best practices

NCUA’s rules set the foundation. A strong program adds the practices below, which examiners increasingly expect and which stop the attacks credit unions actually face.

Independent testing

Internal penetration testing shows what someone with network access could reach. External testing checks internet-facing systems such as online banking, VPNs and email. Social engineering tests measure how staff handle phishing and phone pretexts. Regular IT audits confirm your controls match your policies.

GLBA safeguards and state privacy laws

Your written information security program should cover risk assessment, access controls, encryption, monitoring, training, vendor oversight and incident response. State laws can add obligations; in California, for example, the CCPA can apply to some member data.

ACET and maturity assessments

The FFIEC retired its Cybersecurity Assessment Tool in August 2025. NCUA kept its Automated Cybersecurity Evaluation Toolbox (ACET) available, now framed as the ACET Maturity Assessment with statements mapped to NIST CSF 2.0. It remains voluntary. Many credit unions use it alongside a NIST CSF assessment to benchmark maturity and plan improvements.

Third-party and vendor risk

Your board remains responsible for activities you outsource. NCUA’s guidance on evaluating third-party relationships calls for risk assessment and planning, due diligence before you sign, and ongoing monitoring. Keep an inventory of vendors, rank them by risk and review the critical ones on a schedule.

Incident response, continuity and recovery

Keep a written incident response plan that includes the 72-hour NCUA notification and member communication, and test it with tabletop exercises. Pair it with business continuity and disaster recovery plans that are tested and updated.

Access, encryption and monitoring

  • Least privilege and multi-factor authentication for staff and administrators
  • Encryption of member data at rest and in transit
  • Centralized logging and real-time monitoring of network activity
  • PCI DSS controls where you process card transactions
  • Regular review of policies for access, acceptable use, incident response and data retention

Board and management oversight

Give the board regular, plain-language reporting on risk, testing results, incidents and remediation progress. A framework such as NIST CSF or ISO 27001 gives that reporting a consistent structure.

Regulations and frameworks

Credit union requirements we help you meet

  • NCUA Part 748 information security program
  • GLBA safeguards for member information (Appendix A)
  • NCUA 72-hour cyber incident notification readiness
  • ACET Maturity Assessment support
  • NCUA third-party relationship guidance
  • NIST Cybersecurity Framework maturity assessment
  • PCI DSS for card programs
  • Credit union information security policy development

FAQ

Credit union cybersecurity questions

NCUA’s Part 748 requires a written, board-approved information security program that protects member information, based on the GLBA guidelines in Appendix A. Credit unions must also report reportable cyber incidents to NCUA within 72 hours. Examiners review risk assessments, testing, vendor oversight and incident response to see that the program works.

Yes. The FFIEC sunset its Cybersecurity Assessment Tool in August 2025, but NCUA kept the ACET available and updated it as the ACET Maturity Assessment, mapped to NIST CSF 2.0. Using it remains voluntary.

At least annually for internal and external testing, and after major changes such as a new core, online banking platform or network redesign. Many credit unions move to a recurring program so testing keeps pace with change.

Yes. Our vCISO team writes and updates policies for access, acceptable use, incident response, vendor management and data retention, and aligns them to your risk assessment and board reporting.

The number of branches, users and systems in scope, the types of testing you need and whether you add ongoing monitoring or vCISO support. We scope the work after a short call and quote a fixed price.

No. Your core and other vendors remain responsible for their own controls. We help you review those vendors, secure your own network and endpoints and monitor the connections between them.

Talk to an expert

Strengthen your program before the next exam

Tell us about your credit union and your last exam, and an advisor will reply by email to set up a conversation.

  • A starting point based on NCUA expectations
  • Testing and reporting your board can act on

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message