NCUA Cybersecurity Compliance: How Picus Supports Credit Unions

Umut Bayram | 11 MIN READ

| August 19, 2026

What Is the National Credit Union Administration (NCUA)?

The National Credit Union Administration (NCUA) is the independent federal agency that regulates and supervises federal credit unions and insures deposits at federally insured credit unions through the National Credit Union Share Insurance Fund.

Cybersecurity falls within the NCUA’s supervisory responsibilities because cyber incidents can affect member information, financial services, operational resilience, and the safety and soundness of credit unions. Federally insured credit unions are therefore subject to NCUA information security requirements, examinations, and cyber incident notification rules, including requirements established under NCUA Part 748.

What Is NCUA Cybersecurity Compliance?

NCUA cybersecurity compliance refers to the cybersecurity and information security obligations that federally insured credit unions must address under NCUA regulations and examination procedures.

Key expectations include maintaining an information security program, assessing cybersecurity risk, testing key controls and systems, overseeing third-party service providers, reporting relevant security matters to the board, and notifying the NCUA of reportable cyber incidents within 72 hours.

Compliance is not only about having documented policies or deployed tools. Credit unions also need evidence that their safeguards are appropriate for their risks and operate effectively.

What Is NCUA Part 748?

NCUA Part 748 is a section of NCUA regulations covering security programs, reportable cyber incidents, and other security-related obligations for federally insured credit unions.

Appendix A establishes guidelines for safeguarding member information, including risk assessment, security controls, testing, service-provider oversight, program adjustment, and board reporting.

Part 748 also contains the NCUA cyber incident notification requirement, under which federally insured credit unions must notify the NCUA as soon as possible and no later than 72 hours after reasonably believing a reportable cyber incident has occurred.

How Does the NCUA Evaluate Cybersecurity During Credit Union Examinations?

The NCUA evaluates cybersecurity through its Information Security Examination (ISE) program, which uses a risk-focused and scalable approach. Examiners assess management’s ability to identify, assess, monitor, and manage technology risk; whether the credit union has sufficient expertise; whether internal controls adequately safeguard member information; and whether the board provides appropriate governance over information systems and security.

Examination depth can vary according to the institution’s size, complexity, systems, and risk profile. This means credit unions should be prepared to demonstrate not only that cybersecurity policies and controls exist, but that their security program is appropriate and effectively managed.

What Are the NCUA Third-Party Risk Management Requirements?

NCUA third-party risk management expectations require credit unions to evaluate and manage risks created by service providers such as core processors, CUSOs, cloud providers, payment providers, and other technology vendors.

Part 748 calls for appropriate due diligence when selecting service providers and monitoring their safeguards where warranted by risk. Third-party incidents are also important under the NCUA cyber incident notification rule because certain compromises or disruptions at a provider can trigger a credit union’s own 72-hour notification obligation.

Credit unions therefore need effective vendor due diligence, contractual notification provisions, ongoing oversight, and current information about critical provider security and resilience.

What Other Cybersecurity Regulations Apply to Credit Unions Besides NCUA Part 748?

NCUA Part 748 is the primary cybersecurity regulation for federally insured credit unions, but additional frameworks and regulations may apply depending on the institution’s activities, data handling, and service-provider relationships.

GLBA (Gramm-Leach-Bliley Act) requirements are effectively incorporated into NCUA’s information security guidelines, which means credit unions must still implement safeguards to protect member information in line with GLBA principles.

Credit unions that process or store payment card data may also need to comply with PCI DSS requirements imposed by card networks.

In some cases, DORA (Digital Operational Resilience Act) may become relevant indirectly for credit unions that rely on EU-based ICT service providers or operate within global financial service ecosystems.

Additionally, NIST CSF 2.0 is widely used as a voluntary cybersecurity framework to support regulatory alignment and maturity benchmarking rather than as a binding regulation.

You can learn more in Picus’s GLBA compliance guide, PCI DSS compliance guide, DORA compliance resource, and NIST CSF compliance guide.

How Does Picus Support NCUA Cybersecurity Requirements?

NCUA cybersecurity compliance involves several interconnected responsibilities for protecting member information and maintaining resilient operations. The Picus Platform supports these responsibilities by continuously validating exposures, attack paths, and security controls, and by providing evidence that helps credit unions assess risk, verify control effectiveness, prioritize remediation, and demonstrate security outcomes.

The sections below map Picus capabilities to practical cybersecurity expectations reflected across NCUA Part 748, Appendix A (Guidelines for Safeguarding Member Information), Appendix B (Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice) [1], and the NCUA Information Security Examination (ISE) program [2].

The sections covered are:

  • Part 748 Appendix A Section III.C.3: Testing Key Controls, Systems, and Procedures
  • 12 CFR § 748.0(a)-(b)(2) & Part 748 Appendix A Sections II and III.B: Information Security Program and Risk Assessment
  • Part 748 Appendix A Section III.E: Adjusting the Information Security Program
  • 12 CFR § 748.1(c) & Part 748 Appendix B: Cyber Incident Response and the 72-Hour Notification Requirement
  • Part 748 Appendix A Sections III.A and III.F & NCUA ISE: Board Oversight and Information Security Reporting

Part 748 Appendix A Section III.C.3: Testing Key Controls, Systems, and Procedures

Appendix A's security guidance addresses regular testing of key controls, systems, and procedures, with the scope and frequency of testing informed by the institution's risk assessment. NCUA's IT Security Compliance Guide further explains that testing should account for the rapid evolution of computer-security threats and should be performed or reviewed with appropriate independence.

How Picus Supports This Requirement

Picus Breach and Attack Simulation (BAS) continuously tests deployed prevention and detection controls using real-world attack scenarios mapped to MITRE ATT&CK and organized within the Picus Threat Library, which serves as the catalog of adversary behaviors, techniques, and attack chains, regularly updated by Picus Labs. It measures whether technologies including EDR, SIEM, firewalls, IPS, proxies, and WAFs actually prevent or detect the attacker techniques they are intended to address.

Figure 1. Picus Threat Library, MITRE ATT&CK-mapped threats

Figure 1. Picus Threat Library, MITRE ATT&CK-mapped threats

When a test identifies a gap, Picus provides mitigation guidance through the Picus Mitigation Library, which maps detected weaknesses to both vendor-specific and vendor-neutral signatures and rules. These mitigations can be applied with a one-click fix, enabling teams to quickly implement recommended changes without manual configuration effort.

Figure 2. Picus Mitigation Library provides vendor-specific and vendor-neutral mitigation.

Figure 2. Picus Mitigation Library provides vendor-specific and vendor-neutral mitigation.

Because Picus BAS runs continuously, it helps turn security-control testing from a point-in-time exercise into a repeatable evidence-generating process.

12 CFR § 748.0(a)-(b)(2) & Part 748 Appendix A Sections II and III.B: Information Security Program and Risk Assessment

Federally insured credit unions must maintain a written information security program addressing safeguards for member information. NCUA's Appendix A guidance describes a risk-based approach in which institutions identify reasonably foreseeable internal and external threats, evaluate their likelihood and potential impact, assess whether existing safeguards sufficiently control those risks, and adapt the program to the institution's size and complexity.

How Picus Supports This Requirement

Picus helps credit unions make risk assessments more evidence-based by determining which identified exposures can actually be exploited in their environment.

Picus Autonomous Penetration Testing executes real exploit chains where testing is safe, showing which vulnerabilities, identities, and misconfigurations can be chained to reach critical assets.

Figure 3. Picus Autonomous Penetration Testing finds attack paths to critical assets.

Figure 3. Picus Autonomous Penetration Testing finds attack paths to critical assets.

Picus Exposure Validation complements this by using TTP-chain validation when live exploitation is unsafe, restricted, or unavailable.

Figure 4. TTP-chain Validation in action

Figure 4. TTP-chain Validation in action

Together, these capabilities help organizations prioritize risk according to validated exploitability, reachability, asset criticality, and security control effectiveness, rather than relying only on theoretical severity scores.

Part 748 Appendix A Section III.E: Adjusting the Information Security Program

Appendix A's guidance calls for an information security program to be adjusted as risks and operating conditions change. NCUA guidance specifically identifies changes in technology, threats, member information, information systems, and business arrangements such as mergers, acquisitions, outsourcing arrangements, and joint ventures as factors that may require program changes.

The practical implication is that security assurance cannot depend exclusively on the results of an assessment performed months earlier.

How Picus Supports This Requirement

The Picus Platform operates around a continuous Validate → Decide → Fix → Re-validate workflow.

Picus BAS can repeatedly test security controls as configurations, security products, and attacker techniques change. Exposure Validation can reassess exploitability as vulnerabilities, assets, threat intelligence, and compensating controls change.

Picus also has a workforce of specialist AI agents, Picus Swarm, for discovery, exploitation, validation, mobilization, and reporting, orchestrated by Numi AI. Numi AI continuously monitors relevant environmental signals, such as emerging threat intelligence indicating a new ransomware variant targeting VPN appliances, determines when a validation workflow should be triggered, and coordinates the appropriate agents from start to finish. Organizations can run these workflows in Manual, Supervised, or Autonomous modes, with agent actions retained in an auditable record.

Figure 5. Picus Swarm specialist AI agents orchestrated by Numi AI

Figure 5. Picus Swarm specialist AI agents orchestrated by Numi AI

This helps credit unions maintain current evidence of security effectiveness instead of assuming that controls validated during an earlier assessment continue to work after the environment changes.

12 CFR § 748.1(c) & Part 748 Appendix B: Cyber Incident Response and the 72-Hour Notification Requirement

12 CFR § 748.1(c) requires federally insured credit unions to notify the NCUA as soon as possible and no later than 72 hours after reasonably believing that a reportable cyber incident has occurred. NCUA states that reportable incidents can include substantial losses of confidentiality, integrity, or availability, disruption from cyberattacks, and qualifying incidents involving third-party service providers.

Appendix B and associated NCUA guidance address the broader response process for unauthorized access to member information, including assessing incidents, containment, regulatory notification, and member notification where appropriate.

How Picus Supports This Requirement

Picus does not determine whether an incident legally qualifies as reportable and does not replace the credit union's incident-notification process. Its role is to help validate the technical prevention and detection capabilities that support incident readiness.

Picus BAS can simulate relevant attacker techniques and establish whether preventive controls stop the activity and whether the activity produces security telemetry.

For example, validation may uncover a scenario where malicious activity executes successfully but generates no useful alert, or where an endpoint product records the activity but the corresponding SIEM rule does not fire.

Finding these weaknesses before an actual incident helps strengthen the detection capabilities on which rapid investigation and escalation depend, supporting an organization's readiness to evaluate potentially reportable incidents within the NCUA's notification timeframe.

Part 748 Appendix A Sections III.A and III.F & NCUA ISE: Board Oversight and Information Security Reporting

NCUA guidance places the board in an oversight role for the information security program and describes reporting to the board or an appropriate committee on the overall status of the program and material matters. NCUA guidance identifies areas such as risk-management decisions, service-provider arrangements, testing results, and security incidents as relevant to this reporting.

This is reinforced through the Information Security Examination (ISE) program, whose objectives include evaluating the adequacy of information security controls and determining whether the board provides appropriate governance over information systems and security.

How Picus Supports This Requirement

Picus turns security-validation activity into measurable evidence that can support management, board, audit, and examination reporting.

Rather than relying primarily on vulnerability counts or lists of deployed products, credit unions can report outcomes such as:

  • prevention and detection effectiveness;
  • validated attack paths to critical assets;
  • exploitable exposures remaining open;
  • remediation and re-validation status;
  • changes in control effectiveness over time; and
  • exposures dispositioned as Patch, Mitigate, Monitor, or Accept with Evidence.

The Picus Swarm Reporting Agent is designed to provide different levels of evidence for security practitioners, boards, and audit use cases while preserving the context and audit trail behind the validation results.

This helps organizations use operational security evidence for governance and examination readiness rather than assembling a separate body of evidence only when an examination approaches.

Building Continuous Evidence for NCUA Compliance

NCUA cybersecurity requirements extend well beyond a checklist. Part 748 addresses risk management, testing, third-party oversight, program adjustment, board reporting, and incident notification. The ISE program then evaluates whether governance and controls are adequate for the risks facing the institution.

Picus helps credit unions operationalize the evidence side of those expectations.

Picus Breach and Attack Simulation validates whether prevention and detection controls work. Picus Autonomous Penetration Testing proves exploitable attack paths with real exploits where doing so is safe. Picus Exposure Validation determines exploitability through TTP-chain validation where live exploitation is unavailable or inappropriate. Picus Swarm can orchestrate the validation, remediation, re-validation, and reporting workflow at the level of autonomy the security team chooses.

Together, these capabilities allow credit unions to move from periodic assertions about security to a continuously refreshed body of evidence.

See how Picus can help your credit union turn NCUA cybersecurity requirements into continuous, defensible security evidence. Book a demo to see the Picus Platform in action.

References

[1] “12 CFR Part 748 -- Security Program, Suspicious Transactions, Catastrophic Acts, Cyber Incidents, and Bank Secrecy Act Compliance.” Accessed: Aug. 19, 2026. [Online]. Available: https://www.ecfr.gov/current/title-12/chapter-VII/subchapter-A/part-748

[2] “2025 Cybersecurity and Credit Union System Resilience Report,” NCUA. Accessed: Aug. 19, 2026. [Online]. Available: https://ncua.gov/news/publication-search/cybersecurity/2025-cybersecurity-and-credit-union-system-resilience-report

Table of Contents

Ready to start? Request a demo