← All sectors
Resilience Rulebook · By sector

Credit Unions

The operational-resilience, BCDR, and crisis-handling obligations that most likely apply to credit unions — by regulator, domain, and compliance status. Filter and search the full set below.

A WSquare Advisory analysis In partnership with Resilis
Profile credit_union · 68 likely-applicable · 0 excluded by asset size
Disclaimer. Applicability is determined entity by entity, based on each firm's specific facts and circumstances — charter, registrations, activities, asset/AUM size, and more. These profiles are an automated first-pass filter to help triage what likely applies; they are NOT a legal determination and NOT legal advice. Confirm applicability for your specific entity with qualified counsel or compliance.
WITHIN THE RESILIENCE CORPUS — 68 obligations · Credit union pure continuity / DR / crisis (neither): 43 Cybersecurity 19 total · 15 only Third-party 10 total · 6 only 4 both
Within this corpus, cybersecurity (19) and third-party (10) overlap (4) and each keeps its own space (15 cyber-only, 6 third-party-only); 43 are pure continuity / DR / crisis. This is a thematic split of the resilience body — not the entirety of either theme.
The wider picture — cyber & third-party are far larger than resilience
US financial-sector final rules, Federal Register, since 2015 · as of 2026-06-24 (federal proxy; excludes state/EU/UK/Canada)
Cybersecurity19 of 62 rules touch resilience (31%) · 43 outside scope
Third-party33 of 416 rules touch resilience (8%) · 383 outside scope
Most cyber and (especially) third-party rulemaking does not touch resilience and is intentionally out of this corpus. The Venn above is a thematic split within the resilience body, not the whole of either theme.
Applicable rules by regulator
NCUA: 68 (100%)NCUA68

Resilience sub-themes in scope

How this persona’s 68 applicable obligations distribute across cross-cutting themes. For the full lens (what each requires), run python3 -m regwatch.theme <theme> --persona credit_union.

ThemeObligationsof which proposed
Third-Party / Vendor Risk Management10
Cybersecurity × Resilience19
Incident Reporting & Notification19
Resilience Testing & Exercises5

Likely applicable (68)


Country:
Domain:
Regulator:
IDCountryRegulatorDomainSize triggerObligation (with source quote)CitationStatusSuggested evidence to comply
OBL-01076United StatesNCUAbusiness continuityEstablish a written vital records preservation program within six months of insurance certificate issuance to identify, store, and reconstruct vital records in the event such records are destroyed.
“The board of directors of a credit union is responsible for establishing a vital records preservation program within six months of its insurance certificate being issued. The program must be in writing and contain procedures for maintaining duplicate vital records at a vital records center.”
12 CFR 749.2(a)finalBoard-approved written vital records preservation program; date-stamped adoption records showing compliance with six-month deadline.
OBL-01077United StatesNCUAbusiness continuityInclude in the written program designated staff responsible for vital records preservation.
“The procedures must include: (1) Designated staff responsible for vital records preservation”
12 CFR 749.2(a)(1)finalWritten program identifying named roles or positions responsible for vital records preservation; current assignment documentation.
OBL-01078United StatesNCUAbusiness continuityInclude in the written program a schedule for the storage and destruction of vital records.
“The procedures must include: (2) A schedule for the storage and destruction of vital records”
12 CFR 749.2(a)(2)finalWritten schedule within the program specifying frequency of storage updates and criteria/timeline for destruction of superseded vital records.
OBL-01079United StatesNCUAbusiness continuityMaintain a records preservation log that will aid in locating and easily accessing vital records, in electronic or any other format as determined by the credit union.
“A records preservation log as determined by the credit union that will aid in locating and easily accessing the vital records. The log may be in electronic or any other format as determined by the credit union.”
12 CFR 749.2(a)(3)finalMaintained records preservation log (electronic or otherwise) demonstrating location and access information for all stored vital records.
OBL-01080United StatesNCUAbusiness continuityStore duplicate vital records at a vital records center located far enough from the credit union's offices to avoid simultaneous loss of both sets of records in a catastrophic event.
“contain procedures for maintaining duplicate vital records at a vital records center... a storage facility...at any location far enough from the credit union's offices to avoid the simultaneous loss of both sets of records in the event of a catastrophic act.”
12 CFR 749.2(a); 12 CFR 749.1 (definition of 'Vital records center')finalDocumentation of offsite vital records center location; geographic separation analysis; copies of storage or hosting agreements.
OBL-01081United StatesNCUAbusiness continuityEnsure the vital records preservation program covers the six specified categories of vital records, including member account balances, financial reports, bank reconcilements, account/investment lists, and emergency contact information.
“Vital records are the most recent and current versions of the records a credit union needs to restore vital member services. These records are: (1) A list of share, deposit, and loan balances... (2) A financial report... (3) Bank reconcilements... (4) A list of the credit union's accounts... (5) Eme”
12 CFR 749.1 (definition of 'Vital records', subsections (1)-(5))finalInventory of vital records preserved; confirmation each required category is current; storage logs showing most-recent business day or month-end versions.
OBL-01082United StatesNCUAbusiness continuityWhere vital records are maintained by an off-site data processor, ensure the service agreement specifies that the data processor safeguards against simultaneous destruction of production and back-up information.
“A credit union that has some or all of its vital records maintained by an off-site data processor is considered to be in compliance for the storage of those records if the service agreement specifies the data processor safeguards against the simultaneous destruction of production and back-up informa”
12 CFR 749.2(b)finalExecuted service agreement with off-site data processor containing explicit contractual provision against simultaneous destruction of production and backup data.
OBL-01083United StatesNCUAbusiness continuityMaintain, or contract with a third-party service provider to maintain, any equipment or software necessary for the vital records center so the credit union can access its records.
“A credit union must maintain, or contract with a third-party service provider to maintain, any equipment or software for its vital records center necessary for the credit union to access its records.”
12 CFR 749.3finalInventory of equipment/software at vital records center; contracts with third-party providers; tested access procedures demonstrating records are retrievable.
OBL-01084United StatesNCUAbusiness continuityMaintain effective oversight of any third-party service provider contracted to maintain vital records to ensure the records meet the requirements of 12 CFR 749.3.
“If a credit union contracts with a third-party service provider to maintain its records, the credit union must maintain effective oversight of the third-party service provider to ensure the records meet the requirements of this section.”
12 CFR 749.3finalThird-party oversight program documentation; periodic audits or assessments of service provider; written oversight reports; corrective action records.
OBL-01085United StatesNCUAbusiness continuityPreserve vital records in a format that accurately reflects the information, remains accessible to all entitled persons, and is capable of reproduction by transmission, printing, or otherwise.
“Preserved vital records may be in any format that can be used to reconstruct the credit union's vital records. The format used must accurately reflect the information in the record, remain accessible to all persons entitled to access by statute, regulation, or rule of law, and be capable of reproduc”
12 CFR 749.4finalDocumentation of format(s) used; periodic access and reproduction tests; evidence of successful reconstruction of records in chosen format.
OBL-01312United StatesNCUAcybersecurityReport a reportable cyber incident to the NCUA-designated point of contact as soon as possible and no later than 72 hours after the FICU reasonably believes a reportable cyber incident has occurred.
“The NCUA must receive this notification as soon as possible but no later than 72 hours after a federally insured credit union reasonably believes that it has experienced a reportable cyber incident”
12 CFR 748.1(c)finalIncident log showing date/time FICU formed reasonable belief; notification record (email/phone/portal) to NCUA within 72h; incident tracking policy.
OBL-01313United StatesNCUAcybersecurityReport via email, telephone, or other NCUA-prescribed method to the NCUA-designated point of contact upon occurrence of a reportable cyber incident.
“Each federally insured credit union must notify the appropriate NCUA-designated point of contact of the occurrence of a reportable cyber incident via email, telephone, or other similar methods that the NCUA may prescribe.”
12 CFR 748.1(c)finalWritten notification procedures identifying approved channels; records of each notification transmitted to NCUA.
OBL-01314United StatesNCUAcybersecurityReport a cyber incident causing a substantial loss of confidentiality, integrity, or availability of a network or member information system resulting from unauthorized access to sensitive data, disruption of vital member services, or serious impact on safety and resiliency of operational systems.
“A substantial loss of confidentiality, integrity, or availability of a network or member information system...that results from the unauthorized access to or exposure of sensitive data, disrupts vital member services...or has a serious impact on the safety and resiliency of operational systems and p”
12 CFR 748.1(c)(1)(i)(A)finalIncident classification criteria in IR policy; incident reports filed with NCUA; documentation of impact assessment at time of notification.
OBL-01315United StatesNCUAcybersecurityReport a cyber incident where a cyberattack or exploitation of vulnerabilities causes disruption of business operations, vital member services, or a member information system.
“A disruption of business operations, vital member services, or a member information system resulting from a cyberattack or exploitation of vulnerabilities.”
12 CFR 748.1(c)(1)(i)(B)finalIncident log entries; NCUA notification records; evidence of cyberattack/vulnerability exploitation (e.g., SIEM alerts, forensic summary).
OBL-01316United StatesNCUAcybersecurityReport within 72 hours a cyber incident where a compromise of a credit union service organization, cloud service provider, third-party data hosting provider, or supply chain causes disruption of business operations or unauthorized access to sensitive data.
“A disruption of business operations or unauthorized access to sensitive data facilitated through, or caused by, a compromise of a credit union service organization, cloud service provider, or other third-party data hosting provider or by a supply chain compromise.”
12 CFR 748.1(c)(1)(i)(C)finalThird-party incident notifications received; NCUA notification filed within 72h of receipt or reasonable belief; vendor management records.
OBL-01317United StatesNCUAcybersecurityWhen notified by a third-party of a compromise affecting the FICU, report to NCUA within 72 hours of that third-party notification, whichever is sooner than the FICU's own reasonable belief.
“within 72 hours of being notified by a third-party, whichever is sooner.”
12 CFR 748.1(c)finalTimestamped third-party notification records; NCUA notification log showing submission within 72h of third-party notice.
OBL-01489United StatesNCUAbusiness continuityEstablish and maintain a written vital records preservation program to identify, store, and reconstruct vital records in the event records are destroyed.
“All credit unions must have a written program that includes plans for safeguarding records and reconstructing vital records.”
12 CFR 749.0(a); 12 CFR 749.2finalBoard-approved written vital records preservation program; program inception date within 6 months of insurance certificate issuance.
OBL-01490United StatesNCUAbusiness continuityBoard of directors must establish the vital records preservation program within 6 months after the credit union's insurance certificate is issued.
“The board of directors of a credit union is responsible for establishing a vital records preservation program within 6 months after its insurance certificate is issued.”
12 CFR 749.2finalBoard meeting minutes authorizing/approving the program; dated program document showing compliance with 6-month requirement.
OBL-01491United StatesNCUAbusiness continuityWritten vital records preservation program must contain procedures for maintaining duplicate vital records at a vital records center.
“The program must be in writing and contain procedures for maintaining duplicate vital records at a vital records center.”
12 CFR 749.2finalWritten program document specifying duplicate vital records procedures; records center agreement or designation documentation.
OBL-01492United StatesNCUAbusiness continuityWritten vital records preservation program must designate staff responsible for vital records preservation.
“The procedures must include: designated staff responsible for vital records preservation, a schedule for the storage and destruction of records, and a records preservation log...”
12 CFR 749.2finalProgram document naming designated staff roles; job descriptions or assignment documentation for records preservation responsibilities.
OBL-01493United StatesNCUAbusiness continuityWritten vital records preservation program must include a schedule for the storage and destruction of records.
“The procedures must include: designated staff responsible for vital records preservation, a schedule for the storage and destruction of records, and a records preservation log...”
12 CFR 749.2finalDocumented records storage and destruction schedule within the written program; retention schedule approved by the board.
OBL-01494United StatesNCUAbusiness continuityWritten vital records preservation program must include a records preservation log detailing each record stored, its name, storage location, storage date, and name of the person sending the record.
“a records preservation log detailing for each record stored, its name, storage location, storage date, and name of the person sending the record for storage.”
12 CFR 749.2finalActive records preservation log with required fields (name, storage location, storage date, sender name) maintained and updated.
OBL-01495United StatesNCUAbusiness continuityCredit unions using an off-site data processor must ensure the service agreement specifies the data processor safeguards against simultaneous destruction of production and back-up information.
“Credit unions which have some or all of their records maintained by an off-site data processor are considered to be in compliance...if the service agreement specifies the data processor safeguards against the simultaneous destruction of production and back-up information.”
12 CFR 749.2finalExecuted service agreement with off-site data processor containing explicit safeguard language against simultaneous production and backup destruction.
OBL-01496United StatesNCUAbusiness continuityMaintain or contract with a third party to maintain equipment or software at the vital records center necessary to access vital records.
“A credit union must maintain or contract with a third party to maintain any equipment or software for its vital records center necessary to access records.”
12 CFR 749.3finalDocumentation of owned or contracted equipment/software at vital records center; third-party contract if applicable; periodic access testing records.
OBL-01497United StatesNCUAbusiness continuityThe vital records center must be located far enough from the credit union's offices to avoid simultaneous loss of both sets of records in the event of a catastrophic act.
“A vital records center is defined as a storage facility...at any location far enough from the credit union's offices to avoid the simultaneous loss of both sets of records in the event of a catastrophic act.”
12 CFR 749.3finalDocumented geographic separation analysis or policy justifying vital records center location; site address relative to primary office.
OBL-01498United StatesNCUAbusiness continuityPreserved vital records must be maintained in a format that accurately reflects information in the record, remains accessible to entitled persons, and is capable of reproduction.
“The format used must accurately reflect the information in the record, remain accessible to all persons entitled to access by statute, regulation or rule of law, and be capable of reproduction by transmission, printing, or otherwise.”
12 CFR 749.4finalFormat specification documentation; sample reproduction test results; NCUA examiner access confirmation procedures.
OBL-01499United StatesNCUAbusiness continuityNOT YET IN FORCE (effective 2026-07-16): Develop a catastrophic act preparedness program that includes a business impact analysis to evaluate potential threats.
“(1) A business impact analysis to evaluate potential threats;”
12 CFR Part 749 Appendix B, Element (1)finalWritten business impact analysis document identifying and evaluating potential threats to credit union operations; board oversight records.
OBL-01500United StatesNCUAbusiness continuityNOT YET IN FORCE (effective 2026-07-16): Develop a catastrophic act preparedness program that includes a risk assessment to determine critical systems and necessary resources.
“(2) A risk assessment to determine critical systems and necessary resources;”
12 CFR Part 749 Appendix B, Element (2)finalWritten risk assessment identifying critical systems and required resources; documentation of methodology and board oversight.
OBL-01501United StatesNCUAbusiness continuityNOT YET IN FORCE (effective 2026-07-16): Develop a written catastrophic act preparedness plan identifying persons with authority to enact the plan.
“A written plan addressing: i. Persons with authority to enact the plan;”
12 CFR Part 749 Appendix B, Element (3)(i)finalWritten plan document with named/titled individuals authorized to activate the plan; delegation of authority documentation.
OBL-01502United StatesNCUAbusiness continuityNOT YET IN FORCE (effective 2026-07-16): Written catastrophic act preparedness plan must address preservation and ability to restore vital records.
“A written plan addressing:...ii. Preservation and ability to restore vital records;”
12 CFR Part 749 Appendix B, Element (3)(ii)finalWritten plan section detailing vital records preservation procedures and recovery/restoration steps; test results demonstrating restoration capability.
OBL-01503United StatesNCUAbusiness continuityNOT YET IN FORCE (effective 2026-07-16): Written catastrophic act preparedness plan must include a method for restoring vital member services through alternate operating locations or service mediums.
“iii. A method for restoring vital member services through identification of alternate operating location(s) or mediums to provide services, such as telephone centers, shared service centers, agreements with other credit unions, or other appropriate methods;”
12 CFR Part 749 Appendix B, Element (3)(iii)finalWritten plan with identified alternate operating locations or service mediums; executed agreements with service providers or other credit unions.
OBL-01504United StatesNCUAbusiness continuityNOT YET IN FORCE (effective 2026-07-16): Written catastrophic act preparedness plan must include communication methods for employees and members during a catastrophic act.
“iv. Communication methods for employees and members;”
12 CFR Part 749 Appendix B, Element (3)(iv)finalWritten plan section detailing employee and member communication protocols; contact trees; communication channel documentation.
OBL-01505United StatesNCUAbusiness continuityNOT YET IN FORCE (effective 2026-07-16): Written catastrophic act preparedness plan must address notification of regulators as required under 12 CFR 748.1(b).
“v. Notification of regulators as addressed in 12 CFR 748.1(b);”
12 CFR Part 749 Appendix B, Element (3)(v)finalWritten plan section referencing and detailing regulatory notification procedures; contact information for regional director; prior notification records.
OBL-01506United StatesNCUAbusiness continuityNOT YET IN FORCE (effective 2026-07-16): Written catastrophic act preparedness plan must include training and documentation of training for all employees and volunteer officials on catastrophic act procedures.
“vi. Training and documentation of training to ensure all employees and volunteer officials are aware of procedures to follow in the event of destruction of vital records or loss of vital member services;”
12 CFR Part 749 Appendix B, Element (3)(vi)finalTraining program documentation; training completion records for all employees and volunteer officials; training content covering catastrophic act procedures.
OBL-01507United StatesNCUAbusiness continuityNOT YET IN FORCE (effective 2026-07-16): Written catastrophic act preparedness plan must include testing procedures with a means for documenting testing results.
“vii. Testing procedures, including a means for documenting the testing results.”
12 CFR Part 749 Appendix B, Element (3)(vii)finalWritten testing procedures within the plan; documented test results from each exercise; remediation actions recorded.
OBL-01508United StatesNCUAbusiness continuityNOT YET IN FORCE (effective 2026-07-16): Establish internal controls for reviewing the catastrophic act preparedness plan at least annually and revising it as circumstances warrant.
“(4) Internal controls for reviewing the plan at least annually and for revising the plan as circumstances warrant, for example, to address changes in the credit union's operations;”
12 CFR Part 749 Appendix B, Element (4)finalAnnual plan review schedule; documented review records with dates and any revisions made; change log tracking updates to the plan.
OBL-01509United StatesNCUAbusiness continuityNOT YET IN FORCE (effective 2026-07-16): Conduct annual testing of the catastrophic act preparedness program.
“(5) Annual testing.”
12 CFR Part 749 Appendix B, Element (5)finalAnnual test completion records; test scenario documentation; after-action reports; evidence of board or management review of test outcomes.
OBL-01510United StatesNCUAbusiness continuityNOT YET IN FORCE (effective 2026-07-16): Catastrophic act preparedness program must be developed with oversight and approval of the board of directors.
“The program should be developed with oversight and approval of the board of directors.”
12 CFR Part 749 Appendix B (introductory paragraph)finalBoard meeting minutes reflecting approval of the catastrophic act preparedness program; evidence of ongoing board oversight.
OBL-01511United StatesNCUAbusiness continuityA FICU board of directors must establish a written succession plan that addresses specified positions and contains required information to ensure continuity of critical leadership. [adjacent]
“a FICU board of directors establish a written succession plan that addresses specified positions and contains certain information”
12 CFR 701.4(e)finalBoard-approved written succession plan covering required positions; documentation of plan contents meeting regulatory elements; examiner-reviewable plan on file.
OBL-01512United StatesNCUAbusiness continuityThe FICU board of directors must review the succession plan no less than every 24 months to ensure it remains current and adequate. [adjacent]
“a credit union board must review its succession plan no less than every 24 months, as opposed to the annual review that would have been required under the proposed rule”
12 CFR 701.4(e)finalBoard meeting minutes documenting succession plan review at least every 24 months; updated plan reflecting review outcomes.
OBL-01513United StatesNCUAbusiness continuityNewly appointed FICU board members must obtain working familiarity with the succession plan no later than six months after appointment. [adjacent]
“newly appointed members of the board of directors have a working familiarity with the succession plan no later than six months after appointment”
12 CFR 701.4(e)finalOnboarding records showing date of appointment and date of succession plan familiarization; attestation or training log for each new board member.
OBL-01515United StatesNCUAbusiness continuityThe succession plan must identify the anticipated vacancy date for each covered position, such as the incumbent's retirement eligibility date or announced departure date. [adjacent]
“The final rule does not require the FICU use a specific date, but suggests some possible proxies, including the individual's anticipated retirement date or announced departure date. A credit union can also note that a retirement or departure date is unknown.”
12 CFR 701.4(e)finalSuccession plan listing anticipated vacancy dates or proxies for each covered position; updated dates reflecting changes in incumbents' circumstances.
OBL-01516United StatesNCUAbusiness continuityThe succession plan must cover specified senior leadership positions responsible for oversight or day-to-day management of the FICU, including management officials and senior executive officers per 12 CFR 701.14(b)(2). [adjacent]
“succession plans are intended to cover senior leadership positions responsible for the oversight of the FICU or its day-to-day management”
12 CFR 701.4(e)(2)finalSuccession plan listing all required covered positions; mapping of plan positions to regulatory definitions in 12 CFR 701.14(b)(2) and model FCU bylaws.
OBL-01517United StatesNCUAbusiness continuityThe succession plan may include other personnel the board deems critical given the FICU's size, complexity, or risk of operations, including positions required due to planned operational changes. [adjacent]
“other personnel the board of directors deems critical given the [FICU's] size, complexity, or risk of operations. This includes new positions that may be required due to planned changes in operations, supervisory landscape, or corporate structure.”
12 CFR 701.4(e)(2)(iii)finalBoard resolution or plan documentation identifying additional critical positions and rationale; succession plan sections addressing those positions.
OBL-01518United StatesNCUAbusiness continuityFISCUs must adhere to the NCUA succession planning requirements to the extent they do not conflict with an applicable state requirement; NCUA defers to enforceable state requirements where no conflict exists. [adjacent]
“a FISCU must adhere to the succession planning requirements 'to the extent these regulatory provisions do not conflict with an applicable state requirement.'”
12 CFR 741.228finalAnalysis of applicable state statutory or regulatory succession planning requirements; documented compliance mapping showing areas of deference or NCUA rule application.
OBL-01833United StatesNCUAbusiness continuityDevelop and maintain a written security program within 90 days of insurance effective date that prevents destruction of vital records and responds to unauthorized access incidents.
“Each federally insured credit union will develop a written security program within 90 days of the effective date of insurance.”
12 CFR 748.0(a), 748.0(b)(3), 748.0(b)(5)finalWritten security program document; board approval records; procedures for incident response and vital records protection.
OBL-01834United StatesNCUAbusiness continuityNotify the NCUA regional director within 5 business days of any catastrophic act causing physical destruction or interruption of vital member services projected to last more than two consecutive business days.
“Each federally insured credit union will notify the regional director within 5 business days of any catastrophic act that occurs at its office(s).”
12 CFR 748.1(b)finalIncident notification log; dated communications to regional director; post-incident records filed at main office.
OBL-01835United StatesNCUAbusiness continuityPrepare and file a record of each catastrophic act at the credit union's main office, documenting location, timing, losses, operational deficiencies, and corrective actions.
“Within a reasonable time after a catastrophic act occurs, the credit union shall ensure that a record of the incident is prepared and filed at its main office.”
12 CFR 748.1(b)finalPost-incident written record filed at main office covering: office affected, date, loss amount, deficiencies identified, corrective actions taken or planned.
OBL-01836United StatesNCUAbusiness continuityNotify NCUA's designated point of contact of a reportable cyber incident as soon as possible but no later than 72 hours after the credit union reasonably believes it has experienced such an incident.
“The NCUA must receive this notification as soon as possible but no later than 72 hours after a federally insured credit union reasonably believes that it has experienced a reportable cyber incident.”
12 CFR 748.1(c)finalCyber incident log with timestamps; 72-hour notification records to NCUA; escalation procedures documented in incident response plan.
OBL-01837United StatesNCUAbusiness continuityReport a cyber incident within 72 hours when a disruption of business operations or vital member services results from a cyberattack or exploitation of vulnerabilities.
“A disruption of business operations, vital member services, or a member information system resulting from a cyberattack or exploitation of vulnerabilities.”
12 CFR 748.1(c)(1)(i)(B)finalIncident classification records showing determination of reportability; 72-hour notification to NCUA; incident response documentation.
OBL-01838United StatesNCUAbusiness continuityReport within 72 hours when a third-party (CUSO, cloud provider, or other data hosting provider) compromise causes a disruption of business operations or unauthorized access to sensitive data.
“A disruption of business operations or unauthorized access to sensitive data facilitated through, or caused by, a compromise of a credit union service organization, cloud service provider, or other third-party data hosting provider or by a supply chain compromise.”
12 CFR 748.1(c)(1)(i)(C)finalThird-party incident notifications received; 72-hour NCUA notifications; third-party monitoring logs; supply chain incident records.
OBL-01839United StatesNCUAbusiness continuityDevelop and implement a comprehensive written information security program with administrative, technical, and physical safeguards appropriate to the credit union's size and complexity. [adjacent]
“A comprehensive written information security program includes administrative, technical, and physical safeguards appropriate to the size and complexity of the credit union and the nature and scope of its activities.”
12 CFR Part 748, Appendix A, Section II.AfinalWritten information security program document; board approval; evidence of coordination across all credit union elements.
OBL-01840United StatesNCUAbusiness continuityHave the board of directors approve the written information security policy and program, and oversee its development, implementation, and maintenance including reviewing management reports. [adjacent]
“Approve the credit union's written information security policy and program; and oversee the development, implementation, and maintenance of the credit union's information security program.”
12 CFR Part 748, Appendix A, Section III.AfinalBoard meeting minutes reflecting program approval; board committee oversight records; management reports submitted to board.
OBL-01841United StatesNCUAbusiness continuityAssess reasonably foreseeable internal and external threats to member information systems, evaluate likelihood and potential damage of threats, and assess sufficiency of existing controls.
“Identify reasonably foreseeable internal and external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of member information or member information systems.”
12 CFR Part 748, Appendix A, Section III.BfinalDocumented risk assessment; threat inventory; likelihood and impact ratings; gap analysis of current controls.
OBL-01842United StatesNCUAbusiness continuityImplement response programs specifying actions when unauthorized access to member information systems is suspected or detected, including reports to regulatory and law enforcement agencies.
“Response programs that specify actions to be taken when the credit union suspects or detects that unauthorized individuals have gained access to member information systems, including appropriate reports to regulatory and law enforcement agencies.”
12 CFR Part 748, Appendix A, Section III.C.1.gfinalWritten incident response plan; escalation procedures; evidence of regulatory/law enforcement notification workflows.
OBL-01843United StatesNCUAbusiness continuityImplement measures to protect member information against destruction, loss, or damage due to environmental hazards such as fire, water damage, or technical failures.
“Measures to protect against destruction, loss, or damage of member information due to potential environmental hazards, such as fire and water damage or technical failures.”
12 CFR Part 748, Appendix A, Section III.C.1.hfinalEnvironmental hazard controls documentation; backup and recovery procedures; physical security and disaster recovery controls.
OBL-01844United StatesNCUAbusiness continuityImplement monitoring systems and procedures to detect actual and attempted attacks on or intrusions into member information systems. [adjacent]
“Monitoring systems and procedures to detect actual and attempted attacks on or intrusions into member information systems.”
12 CFR Part 748, Appendix A, Section III.C.1.ffinalIntrusion detection/prevention system records; security monitoring logs; alert and escalation procedures documentation.
OBL-01845United StatesNCUAbusiness continuityRegularly test key controls, systems, and procedures of the information security program, with tests conducted or reviewed by independent parties, at a frequency determined by risk assessment. [adjacent]
“Regularly test the key controls, systems and procedures of the information security program. The frequency and nature of such tests should be determined by the credit union's risk assessment.”
12 CFR Part 748, Appendix A, Section III.C.3finalTest schedules; test results reports; documentation of independent reviewer or third-party involvement; risk-based frequency rationale.
OBL-01846United StatesNCUAbusiness continuityExercise due diligence in selecting service providers, require them by contract to implement appropriate information security measures, and monitor their compliance where indicated by risk assessment. ⚠ audit
“Exercise appropriate due diligence in selecting its service providers; Require its service providers by contract to implement appropriate measures designed to meet the objectives of these guidelines.”
12 CFR Part 748, Appendix A, Section III.DfinalVendor due diligence records; service provider contracts with security requirements; audit reviews or monitoring reports for key service providers.
OBL-01847United StatesNCUAbusiness continuityMonitor, evaluate, and adjust the information security program in response to relevant changes in technology, threat environment, member information sensitivity, and business arrangements including outsourcing. [adjacent]
“Monitor, evaluate, and adjust, as appropriate, the information security program in light of any relevant changes in technology, the sensitivity of its member information, internal or external threats to information, and the credit union's own changing business arrangements.”
12 CFR Part 748, Appendix A, Section III.EfinalProgram review records tied to trigger events (technology changes, new outsourcing arrangements, threat landscape changes); documented program update history.
OBL-01848United StatesNCUAbusiness continuityReport to the board or board committee at least annually on the overall status of the information security program, including risk assessment, risk management decisions, service provider arrangements, test results, and security breaches. [adjacent]
“Each credit union should report to its board or an appropriate committee of the board at least annually. This report should describe the overall status of the information security program and the credit union's compliance with these guidelines.”
12 CFR Part 748, Appendix A, Section III.FfinalAnnual board/committee report; board minutes recording receipt of report; report covering risk assessment, control decisions, testing, breaches, and service provider status.
OBL-01849United StatesNCUAbusiness continuityDevelop and implement a risk-based response program to address incidents of unauthorized access to member information, as a key component of the information security program. [adjacent]
“Every credit union should also develop and implement a risk-based response program to address incidents of unauthorized access to member information in member information systems that occur nonetheless.”
12 CFR Part 748, Appendix B, Section IIfinalWritten incident response program document; evidence of integration into information security program; program scaled to credit union size and complexity.
OBL-01850United StatesNCUAbusiness continuityInclude in the response program procedures to assess the nature and scope of an incident and identify which member information systems and information types were accessed or misused.
“Assessing the nature and scope of an incident, and identifying what member information systems and types of member information have been accessed or misused.”
12 CFR Part 748, Appendix B, Section II.A.1.afinalIncident response procedures with scope-assessment steps; incident records documenting system and data type identification during incidents.
OBL-01851United StatesNCUAbusiness continuityNotify the appropriate NCUA Regional Director (and state supervisory authority for state-chartered CUs) as soon as possible upon discovering an incident involving unauthorized access to sensitive member information. [adjacent] ⚠ audit
“Notifying the appropriate NCUA Regional Director, and, in the case of state-chartered credit unions, its applicable state supervisory authority, as soon as possible when the credit union becomes aware of an incident involving unauthorized access to or use of sensitive member information.”
12 CFR Part 748, Appendix B, Section II.A.1.bfinalNotification log with timestamps; contact list for NCUA Regional Director; evidence of state authority notification for state-chartered CUs.
OBL-01852United StatesNCUAbusiness continuityTake appropriate steps to contain and control incidents of unauthorized access to prevent further unauthorized access, including monitoring, freezing, or closing affected accounts while preserving records and evidence.
“Taking appropriate steps to contain and control the incident to prevent further unauthorized access to or use of member information, for example, by monitoring, freezing, or closing affected accounts, while preserving records and other evidence.”
12 CFR Part 748, Appendix B, Section II.A.1.dfinalIncident response playbooks with containment steps; evidence preservation procedures; post-incident containment action records.
OBL-01853United StatesNCUAbusiness continuityRequire service providers by contract to promptly notify the credit union of unauthorized access incidents to member information to enable timely implementation of the credit union's response program. [adjacent]
“A credit union's contract with its service provider should require the service provider to take appropriate actions to address incidents of unauthorized access to or use of the credit union's member information, including notification of the credit union as soon as possible of any such incident.”
12 CFR Part 748, Appendix B, Section II.iifinalService provider contracts containing incident notification clauses; records of notifications received from service providers.
OBL-01856United StatesNCUAbusiness continuityAnnually certify compliance with all requirements of 12 CFR Part 748 via the Credit Union Profile through NCUA's online information management system. [adjacent]
“The president or managing official of each federally insured credit union must certify compliance with the requirements of this part in its Credit Union Profile annually through NCUA's online information management system.”
12 CFR 748.1(a)finalAnnual compliance certification submitted via NCUA online system; records of certification filings by year.
OBL-01857United StatesNCUAbusiness continuityDesign the information security program to control risks commensurate with information sensitivity and business complexity, considering and adopting appropriate controls including encryption, access controls, and modification procedures. [adjacent]
“Design its information security program to control the identified risks, commensurate with the sensitivity of the information as well as the complexity and scope of the credit union's activities.”
12 CFR Part 748, Appendix A, Section III.C.1finalRisk-based security program with documented rationale for controls selected; encryption policy; access control documentation; system modification procedures.

Turning this into an operating plan?

Knowing which rules bind you is step one. WSquare Advisory builds the operating capability behind compliance — the continuity, third-party, and recovery disciplines these regimes expect. If that's your challenge, let's talk.

Start with an Operating Survey · $5,000 →