The NCUA Information Security Examination Program: What to Expect
The NCUA's Information Security Examination program has been applied nationally for several years, and the framework carried forward into 2026 without substantial change. For credit unions, that stability is useful. It means the examination approach is knowable in advance, and there is no excuse for being surprised by it.
What continues to surprise credit unions is not the framework itself but which version of it applies to them, and what depth of evidence examiners expect at that level.
How the Program Is Structured
The ISE program applies a scaled approach, with a streamlined examination framework for smaller credit unions and progressively more detailed frameworks for larger and more complex institutions. The scope, number of review areas, and depth of evidence expected differ meaningfully between them.
Confirm which framework applies to your credit union directly with your examiner or through current NCUA materials rather than relying on general descriptions or on what applied in a prior cycle. Asset thresholds and program details are subject to change, and a credit union that has grown across a threshold since its last examination may be evaluated against a framework it has not prepared for.
The single most avoidable examination problem is preparing against the wrong framework. A credit union that has grown since its last cycle, or that has become more operationally complex, may face a broader review than it experienced previously.
The ACET and Self-Assessment
The NCUA maintains the Automated Cybersecurity Evaluation Toolbox as a voluntary tool credit unions may use to assess the maturity of their information security programs. It maps declarative statements to elements of the FFIEC IT Examination Handbook, relevant regulations, and industry standards including the NIST Cybersecurity Framework.
Running an internal assessment before your examination is the highest-value preparation available, for a straightforward reason. It surfaces gaps while you still have time to address them, and it produces documented evidence that your credit union assesses its own posture rather than waiting to be told.
What Examiners Consistently Find
Policies That Do Not Match Operations
One of the more common findings across examination types is a gap between documented policy and actual practice. Examiners test this by requesting evidence that a control operated, not by reading the policy that describes it. A policy referencing systems no longer in use, or omitting cloud environments and remote access, tends to signal that it has not been meaningfully reviewed.
Multi-Factor Authentication Gaps on Administrative Accounts
Incomplete MFA coverage on administrative accounts is a recurring gap. It tends to appear not on the primary systems most institutions check first, but on vendor-managed accounts, service accounts, and legacy systems that were never brought into the standard. Vendors with privileged access who are not subject to the same authentication requirements as internal staff are a common exposure, and one that is straightforward to verify before an examiner does.
Third-Party Vendor Management
Vendor relationships remain a focus area, and for structural reasons: the NCUA does not have examination authority over most credit union service organizations and core processors, so the agency examines whether the credit union has assessed those vendors adequately. Expect requests for vendor inventories with risk classifications, evidence of annual vendor risk assessments for critical vendors, and contractual security provisions.
Incident Response Plans That Have Not Been Tested
A written plan satisfies documentation. A tested plan demonstrates readiness. Tabletop exercises, with documented participation and outcomes, are what distinguish the two in an examiner's view. The plan should also specify how the 72-hour NCUA notification obligation is triggered and fulfilled, including when the trigger is a notification received from a third party.
Board Oversight
Examiners look at board meeting minutes for evidence that cybersecurity was discussed substantively, that board members asked questions, and that discussion produced decisions or direction. Minutes recording only that an update was presented are generally read as information rather than oversight.
Preparing on a Realistic Timeline
If an examination is expected within twelve months, work backward from it. Review and update information security policies so they reflect current operations. Complete an internal assessment against the applicable framework. Verify MFA coverage across all administrative access, including vendor and service accounts. Conduct and document a tabletop exercise. Confirm that annual vendor risk assessments for critical vendors are current. Prepare board reporting that demonstrates engagement rather than notification.
Credit unions that struggle in examinations are rarely those that discovered an unexpected requirement. They are usually those that knew about a gap and did not prioritize closing it. Examiners are experienced at telling the difference between an institution that treats security as a program and one that treats it as a filing.
Sources: NCUA Information Security Examination program materials and the agency's stated supervisory priorities. Confirm the examination framework applicable to your credit union with your examiner or through current NCUA publications.
This article is provided for general information and does not constitute legal advice. Regulatory requirements, compliance dates, examiner priorities, and enforcement posture change frequently. Verify current requirements against primary agency sources and your legal counsel before acting on anything described here.

