Skip to main content

What CUs Need to Know About the New Cyber Incident Reporting Requirements

The NCUA’s final rule goes into effect on Sept. 1.

reported data breach Image: Shutterstock

The NCUA has approved new cyber incident reporting requirements for credit unions. Under the final rule, federally insured credit unions will be required to notify the NCUA of a “reportable cyber incident” within 72 hours of such an event. The NCUA’s final rule follows the 36-hour notification requirement implemented for banking organizations last year. While the final rule doubles the reporting time for credit unions, it also could require credit unions to notify the NCUA of a significantly broader set of incidents than required for banking organizations. The final rule continues the trend of regulators increasing their focus on the cybersecurity safeguards among financial institutions and, in particular, of requiring faster notifications when incidents occur.

The final rule will go into effect on Sept. 1, 2023. Here, we’ll provide a primer about the rule and proactive steps credit unions should be taking in anticipation of these new reporting requirements.

What Is a Reportable Cyber Incident?

The rule requires credit unions to notify the NCUA no later than 72 hours after it reasonably believes a reportable cyber incident has occurred. A reportable cyber incident is defined as any substantial cyber incident that leads to:

  • A substantial loss of confidentiality, integrity or availability of a network or member information system that results from the unauthorized access to or exposure of sensitive data, disrupts vital member services, or has a serious impact on the safety and resiliency of operational systems and processes;
  • A disruption of business operations, vital member services, or a member information system resulting from a cyberattack or exploitation of vulnerabilities; and/or
  • A disruption of business operations or unauthorized access to sensitive data facilitated through, or caused by, a compromise of a CUSO, cloud service provider, managed service provider, or other third-party data hosting provider or a supply chain compromise.

Examples of Reportable Incidents

The NCUA’s final rule contained some examples of what may constitute a reportable cyber incident, including, without limitation:

  • If a member information system has been unlawfully modified and/or sensitive data has been left exposed to an unauthorized person, process or device;
  • A failed system upgrade or change that results in unplanned widespread user outages for credit union members and employees; or
  • A distributed denial of service (DDoS) attack that disrupts member account access.

The rule does state that incidents such as unsuccessful malware attacks or failed attempts to gain access to systems do not have to be reported. In addition, third-party incidents that are unknown to a credit union and hold information about individuals who happen to be credit union members or employees do not impose a notification requirement.

How Should Incidents Be Reported?

According to the final rule, incidents may be reported to the NCUA “via email, telephone or other similar methods that the NCUA may prescribe.” The reporting methods are designed to give credit unions flexibility based upon the impact of a potential cyber incident. The NCUA has also stressed that an initial report does not have to include a full assessment of the incident.

Next Steps for Credit Unions

The NCUA will be providing additional guidance, including examples of reportable and non-reportable incidents, before the final rule becomes effective in September. In the meantime, credit unions should be reviewing and updating their incident response plans and vendor management programs to ensure that they are prepared to comply with these enhanced requirements.

Comments

Popular posts from this blog

IRS Rules Turn ‘Simple’ Auto Loan Tax Break Into Compliance Challenge

  PLANO, Texas— A new federal tax deduction allowing consumers to deduct interest on qualifying auto loans is being billed as a borrower benefit, but newly issued regulations from the U.S. Department of the Treasury and the Internal Revenue Service show the program will impose significant compliance and reporting obligations on credit unions and other auto lenders. That’s the assessment of Brian Turner, president and chief economist with Meridian Economics, who said the rules governing the so-called auto loan interest deduction are “far more technical” than initially described and will require system and process changes for many finance providers, including credit unions active in indirect and direct auto lending. Deduction Comes With Detailed Conditions Brian Turner Under the proposed regulations, interest is deductible only if the loan and vehicle meet strict criteria. The vehicle must weigh less than 14,000 pounds, be designed for public road use, be newly placed in service by t...

What Gen Z Is Really Looking For In A Credit Union

  Gen Z’s faith in traditional institutions gives credit unions a rich opportunity to serve as a key source of financial guidance. Sponsored Content By Adrenaline, Inc. Credit unions can strengthen loyalty with the influential Generation Z by connecting their brand’s purpose, financial guidance, and in-branch experience. Widely described as digital natives, Gen Z meets many of their everyday banking needs with mobile apps and digital tools across multiple providers. While younger consumers certainly expect seamless digital functionality from their primary financial provider, what they value even more is meaningful advice and trusting relationships. Because beneath Gen Z’s technological savvy is a measurable confidence gap —  one that impacts every aspect of their financial lives. According to  Adrenaline’s 2026 Gen Z research  conducted with Alexander Babbage, 36% of Gen Z say they find financial matters confusing, and one in three report feeling overwhelmed by money...

Sunday Reading - What happened after the Civil War?

  Rebuilding the Union:  What happened after the Civil War? The Reconstruction era, lasting from 1865 to 1877, was the period when the US federal government sought to reunite the nation after the Civil War. Key issues included how to punish Confederates, readmit Southern states, and secure rights for newly freed Black Americans ( read Lincoln's original plan ). Following Abraham Lincoln's assassination days after the war's end, President Andrew Johnson—a pro-Union, pro-states' rights Southerner—pursued a lenient approach to reconciliation. He pardoned former Confederates , restored their property, and allowed Southern states to govern with little federal oversight. Those states quickly enacted laws restricting the freedoms of formerly enslaved pe...

GAC 2026: In Debut GAC Speech, Simpson Calls On Movement To Protect Cooperative Model

WASHINGTON—America’s Credit Unions President and CEO Scott Simpson told attendees at the 2026 Governmental Affairs Conference that what’s truly at stake in Washington isn’t just policy — it’s the “transformational experiences” credit unions create in people’s lives every day. Scott Simpson addresses the meeting. Credit unions exist—Simpson reminded the record crowd as he delivered his first GAC address as ACU’s leader—because Congress chose nearly a century ago to expand access to financial services for Americans who were being left behind. The Federal Credit Union Act wasn’t about creating another financial institution model — it was about ensuring middle America could be served. That mission remains intact, but Simpson warned it cannot be taken for granted. For years, Simpson said he has asked credit union leaders a simple question: Why do credit unions exist? The typical answer — that they are not-for-profit financial cooperatives — is true, but incomplete. Credit unions and their t...

The NCUA just published its stablecoin playbook: Here’s what credit unions need to know

The National Credit Union Administration (NCUA) has begun answering a key question for credit unions since the GENIUS Act became law last July: What is the stablecoin licensing process? On February 11, 2026, the NCUA published a  22-page proposed rule , "Investments in and Licensing of Permitted Payment Stablecoins Issuers," in the Federal Register. This document outlines the framework for credit union participation under the new Act. The NCUA has a deadline of July 18, 2026, to finalize this rule. Here’s what credit unions need to know now. Quick background: The GENIUS Act and the NCUA’s role The GENIUS Act designated the NCUA as a primary federal regulator of stablecoin, alongside the FDIC, the OCC, and the Federal Reserve. Credit unions can't issue stablecoins directly; they must operate through subsidiaries, typically CUSOs, that apply for and obtain an NCUA-issued Permitted Payment Stablecoin Issuer (PPSI) license. The newly proposed rule covers the application and l...

Sunday Reading - Self-driving formula cars race in the Abu Dhabi Autonomous Racing League

The league and high-speed versions of traditional cars help to showcase the capabilities of driverless vehicles and the reliability of their AI systems. Leonardo da Vinci first imagined the idea for such machines in the 16th century. ================================================= Remember, you're not alone with  NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

Stablecoins Moving from Crypto Curiosity to Payments Infrastructure

At the 2026 Governmental Affairs Conference (GAC), credit union leaders heard a clear message: stablecoins are rapidly evolving from a niche crypto tool into a core component of modern payments infrastructure. Stablecoins are digital tokens typically pegged to a fiat currency like the U.S. dollar and backed by reserves such as cash or short-term Treasury securities. Initially used mostly inside cryptocurrency markets, they are now increasingly being viewed as a faster and more efficient way to move money globally . Why Stablecoins Matter The technology offers several potential advantages over traditional payment systems: 24/7 settlement instead of banking-hour restrictions Faster cross-border payments with fewer intermediaries Lower transaction costs compared with legacy payment rails Greater transparency and programmability in how funds move These capabilities are why banks, fintechs, and large financial institutions are beginning to explore stablecoins as part o...

NCUA - Hauptman Covers Stablecoins, Solo Board And Agency Overhaul In Wide-Ranging Talk

WASHINGTON—Appearing on stage during the America’s Credit Unions Governmental Affairs Conference, NCUA Chairman Kyle Hauptman joined ACU President/CEO Scott Simpson for a wide-ranging discussion that zeroed in on what he sees as defining issues for the agency: the emergence of stablecoins, the current dynamic of serving as NCUA’s lone board member, and the accomplishments he believes will shape his legacy before   departing   for the Public Company Accounting Oversight Board. Scott Simpson (L) with Kyle Hauptman. The most forward-looking portion of Monday’s discussion centered on stablecoins, which Hauptman described as a practical, real-world application of blockchain technology rather than a speculative bet on crypto prices. He framed dollar-backed stablecoins as a payments innovation that could streamline cross-border transfers, allow recipients to hold funds in dollars, and enable more automated settlement of transactions such as loan participations. By allowing all partie...

TruStage To Launch TSDA, Bringing Stablecoin Infrastructure To Community FIs

MADISON, Wis.— TruStage Tuesday today announced the planned launch of TruStage Stablecoin (TSDA), a fully reserved U.S. dollar stablecoin. At its core, TSDA is designed to broaden access to digital payment infrastructure for community-based financial institutions, TruStage explained. “A trusted partner of credit unions for more than 90 years, TruStage currently works with more than 93% of 4,300+ credit unions nationwide, which collectively hold more than $2 trillion in assets. TruStage Stablecoin will be among the very first stablecoins specific to community based financial institutions and is supported by decades of industry relationships, financial strength, and operational excellence,” TruStage said. “In my career working with credit unions, I’ve never witnessed the level of engagement surrounding any technology advancement similar to what I’m seeing with stablecoin solutions right now,” said Brian Kaas, president and managing director of TruStage Ventures, the venture capital arm o...