A Bill Would Let NCUA Examine Your Vendors. The Text Is Broader Than the Coverage Says.
Resources/Blog

A Bill Would Let NCUA Examine Your Vendors. The Text Is Broader Than the Coverage Says.

A Bill Would Let NCUA Examine Your Vendors. The Text Is Broader Than the Coverage Says.
Compliance CISO
October 05 2026
8 min read

A Bill Would Let NCUA Examine Your Vendors. The Text Is Broader Than the Coverage Says.

A Bill Would Let NCUA Examine Your Vendors. The Text Is Broader Than the Coverage Says.

On September 2, 2026, Rep. Bill Foster introduced H.R. 10230, the Strengthening Oversight for the Financial Sector Act of 2026. It went to the House Committee on Financial Services the same day, and the status record shows no action since.

Coverage has described it as a cybersecurity bill giving NCUA authority over technology providers. FedScoop and SC Media both framed it that way. The operative text never uses the word cybersecurity, and nothing in it is limited to technology.

That gap changes which vendors would be in scope.

What the bill actually changes

Section 2 makes three edits to Section 206A of the Federal Credit Union Act, 12 U.S.C. 1786a.

It strikes "that" and inserts "an" in subsection (a)(1). It inserts a phrase into subsection (c)(2) requiring notice in a manner and method prescribed by the Board. And it strikes subsection (f).

Subsection (f) is the whole story. It says the section and all Board powers under it cease to be effective as of December 31, 2001. That happened. Section 1786a has been omitted from the U.S. Code ever since.

So the bill is not writing new authority. It removes an expiration date from a 1998 statute and switches that statute back on as written.

The first edit is a drafting fix. The 1998 text reads "to the same extent as that insured credit union," which has no antecedent. Changing "that" to "an" makes the sentence work.

That is the entire credit union portion of the bill.

Section 3 is separate. It adds a new section to the Federal Housing Enterprises Financial Safety and Soundness Act covering FHFA regulated entities and the Office of Finance: Fannie Mae, Freddie Mac, and the Federal Home Loan Banks. It does not touch credit unions.

That distinction matters for one widely repeated claim. Coverage reported the bill would require regulated entities to report new service relationships within 30 days. Section 3 creates that requirement, for FHFA entities. For credit unions, a 30-day notice obligation has sat in 1786a(c)(2) since 1998. The bill only changes how the Board wants it delivered.

Two doors, and most coverage found only one

The dormant statute reaches vendors through two provisions with different scope.

Subsection (a) grants examination and regulation authority over a "credit union organization." Subsection (e)(1) defines that term as an entity that is not a credit union, is one in which an insured credit union may lawfully hold an ownership interest, and is owned in whole or in part by an insured credit union. That is a CUSO. Ownership is the test.

Subsection (c) is the broad one. Where an insured credit union or credit union organization causes any service to be performed for it, by contract or otherwise, that performance becomes subject to Board regulation and examination as if it happened in-house. It covers any service authorized under the Federal Credit Union Act, or for a state charter, any applicable state law.

No ownership requirement. No technology limiter. No asset threshold.

Your core processor. Your digital banking provider. Your loan origination platform. Your collections agency. If the service is authorized, subsection (c) reaches it.

The bill's operative text never says cybersecurity or technology. Even the GAO recommendation the sponsor's office points to is narrower. GAO-15-509 asked Congress to consider authority over technology service providers, and GAO restated that in GAO-25-107197 in May 2025. This bill would reach any authorized service. If you are assessing scope, read subsection (c), not the press release.

What changed since the last version

The three amendments in Section 2 have been carried forward without change since at least a May 2021 House Financial Services discussion draft, through H.R. 7022 in the 117th Congress and H.R. 7036 in the 118th. Three things around them did change.

The title dropped the word the coverage kept

The 2022 and 2024 bills were titled the Strengthening Cybersecurity for the Financial Sector Act. This one is the Strengthening Oversight for the Financial Sector Act of 2026. The sponsor took cybersecurity out of the name. Much of the coverage put it back.

A safeguard came out and nothing replaced it

In mid-2022, Foster offered this same text as an amendment to Rules Committee Print 117-54, the House defense authorization vehicle. That version struck subsection (f) and replaced it. The replacement would have required the Board, to minimize duplicative efforts, to first seek the information from federal agencies supervising the credit union organization's activities and from any federal banking agency supervising an owner of it.

H.R. 10230 strikes subsection (f) and inserts nothing.

The public record does not explain the change. That is a specific, checkable thing to raise with your trade association or your representative.

NCUA has gone quiet on the ask

NCUA requested this authority repeatedly under prior leadership. Its June 2024 Cybersecurity and Credit Union System Resilience Report to Congress reported 892 cyber incidents between September 2023 and May 2024, roughly 73 percent involving a third party, and paired that with a direct request to close what it called a regulatory blind spot.

The two reports since read differently. NCUA's 2025 report, published April 2026, covers 539 incidents from May 2024 through April 2025. Its 2026 report, published June 2026, covers 588 incidents from May 2025 through April 2026. Neither contains a request for third-party vendor authority. GAO's May 2025 report notes that the NCUA Chairman acknowledged GAO's recommendation while raising risks in granting it, including a possible reduction in the quality and quantity of services available to credit unions.

GAO still recommends the authority. Across its last two reports to Congress, the agency that would receive it has not asked for it.

One correction to a common framing. NCUA is not blind to CUSOs today. Under 12 CFR 712.3(d), a credit union investing in or lending to a CUSO must first get the CUSO's written agreement to give NCUA complete access to its books and records, allow review of its internal controls, and report annually to NCUA. What NCUA lacks is the ability to compel a fix.

What to do now

Nothing here is in effect and may never be. Similar text cleared House Financial Services in 2022 and never reached a floor vote. Treat the following as work that pays off either way, and check the bill's status before acting, since committee action could change the picture quickly.

Build the inventory against the statutory test, not your risk tiers. Subsection (c) turns on whether a service is authorized under the Act or state law, not on how you rated the vendor. Pull your full contract list and tag two things per vendor: does an insured credit union own part of it, and what service is it performing. The first answers subsection (a). The second answers subsection (c). Your Low Risk Vendors classification does not map to either.

Capture your contract dates now. The 30-day notice in 1786a(c)(2) runs from the earlier of contract execution or service initiation. If this revives, you may be reconstructing dates for relationships signed years ago. Do it while the people who negotiated them are still there.

Ask your core and largest third parties what they would do. Some vendor agreements already contain regulatory examination language, some do not. That conversation goes better before a bill moves than during a markup.

If you are a CUSO or a vendor, your exposure runs the other way. Subsection (a) would make you examinable if a credit union owns any part of you, and subsection (b) applies section 1786, the enforcement provision, to you as if you were an insured credit union. In many cases that is a larger change than for your clients.

Source note

This article is based on the text of H.R. 10230 as introduced (BILLS-119hr10230ih, govinfo) and its bill status record; the text of 12 U.S.C. 1786a as it stood before its December 31, 2001 sunset (Office of the Law Revision Counsel, 1999 edition) and the OLRC note recording its omission from the Code; Foster's 2022 amendment to Rules Committee Print 117-54; a May 2021 House Financial Services discussion draft carrying the same three amendments; NCUA's Cybersecurity and Credit Union System Resilience Reports to Congress of June 2024, April 2026, and June 2026; 12 CFR 712.3; GAO-15-509 and GAO-25-107197; and contemporaneous reporting from FedScoop, SC Media, and credit union trade press.

Disclaimer

This article is provided for general information and does not constitute legal advice. Regulatory requirements, compliance dates, examiner priorities, and enforcement posture change frequently. Verify current requirements against primary agency sources and your legal counsel before acting on anything described here.

Tags:

NCUA Vendor AuthorityH.R. 10230CUSO OversightCredit UnionThird-Party Risk

Prepare Your Vendor Inventory for Potential NCUA Authority

Compliance CISO brings Fortune 500 security expertise, including programs at Equifax, Capital One, and Visa, to fintech companies and credit unions building security and compliance programs. Schedule a free consultation at complianceciso.com/contact.

Recent Posts