Free Download for Credit Unions

2026 Credit Union Cybersecurity Readiness Checklist

85 auditable controls mapped to NCUA Part 748, the FTC Safeguards Rule, and FFIEC guidance. One sit-down view your board, your CISO, and your examiner can all read from the same page.

Free 12-page PDF (Edition 6.2026). No cost and no sales call required.

Built for your next NCUA exam

  • Mapped to NCUA Part 748, 16 CFR 314, and FFIEC guidance
  • Aligned to the NCUA 2026 Supervisory Priorities
  • Covers the 72-hour rule and third-party vendor risk
  • Built by TorchLight, nearly two decades securing credit unions
85Auditable controls across 15 domains
72 hrsNCUA cyber incident notification rule, covered
73%Of sector incidents originate with third-party vendors
~20 yrsSecuring and managing IT for credit unions
Why exam readiness changed in 2026

The next round of NCUA exams will not look like the last ones

On January 14, 2026, the NCUA published its supervisory priorities and, for the first time, named annual board cybersecurity training as an examination priority. This checklist turns the new expectations into 85 evidence-backed controls you can score in about 15 minutes.

1

Board training is now an exam priority

Examiners look for evidence that directors have received structured cybersecurity education and can provide meaningful oversight. A verbal assurance is no longer enough.

2

The FFIEC CAT is gone

The Cybersecurity Assessment Tool retired on August 31, 2025. Examiners now expect a documented mapping to a successor framework such as the CRI Profile, NIST CSF 2.0, or the CISA Cybersecurity Performance Goals.

3

Vendor risk is the sharpest edge

Roughly 73% of reported incidents in the sector now originate with third-party vendors. Expect documented due diligence on your core processor and every critical provider.

4

New areas of scrutiny

IT risk assessments, vulnerability management with measurable targets, scenario-specific incident response playbooks, payment-system fraud controls, and a written position on AI governance.

What is inside the checklist

A board-ready PDF anyone from a CISO to a director can use

Every one of the 85 controls comes with a box a board member can ask about and a CISO can answer with evidence, plus the regulatory authority behind it for your audit workpapers.

  • Part I, Regulatory Requirements. 45 auditable controls across eight domains: information security program, authentication and access, 72-hour incident notification, member breach response, vendor oversight, identity theft red flags, governance, and exam readiness.
  • Part II, Beyond Compliance. 40 forward-looking controls: phishing-resistant identity, AI-era fraud defense, ransomware resilience, supply chain and SaaS security, FedNow and RTP fraud controls, threat intel and cloud posture, and board cyber literacy.
  • Two executive visuals. A controls-by-domain breakdown and an emerging-risk priority matrix that shows where to focus before examiners ask.
  • A built-in readiness self-score. Rate Part I and Part II in one sitting and set your next reassessment date.
Download the Readiness Checklist
Executive boardroom displaying a credit union cybersecurity readiness checklist with regulatory documentation prepared for an NCUA Information Security Examination and board review.
Who the checklist is for

Built for the people who answer to examiners

Designed for credit unions with roughly $1M to $500M in assets. The organizations that carry enterprise-grade regulatory expectations without an enterprise-sized security team.

CIOs and IT Directors

The ones who own the controls and need a defensible, prioritized punch list.

ISOs and CISOs

Those who have to produce evidence on demand, control by control.

CEOs and Boards

The ones who want confidence that the institution will pass its next exam.

Compliance and Risk Leaders

Those assembling examiner-ready documentation and board reporting.

When a box comes up unchecked, TorchLight can help you close it: credit union IT and security services, vCISO and vCIO leadership, audits, assessments and compliance, and penetration testing.

Why credit unions choose TorchLight

We do not hand you a checklist and walk away

“TorchLight has been more than a vendor to our multi-branch credit union, they are more like our partner … delivered for almost 20 years.”

— Annettee Babb, CEO, PrimeSource Credit Union
  • Nearly two decades securing and managing IT for credit unions
  • The Advantage Method: from a Stability Foundation, through a Compliance Accelerator, to a Proof Point backed by a virtual CISO
  • A 24/7/365 security operations center behind every engagement
  • Walk into your next NCUA exam with every control documented, defensible, and owned
Book a 30-Minute Readiness Review
Questions

Credit union cybersecurity and NCUA exam FAQ

What are NCUA’s 2026 cybersecurity priorities?

The NCUA’s 2026 Supervisory Priorities, published January 14, 2026, emphasize annual board cybersecurity training for the first time, alongside IT risk assessments, vulnerability management with measurable targets, scenario-specific incident response playbooks, third-party and vendor risk management, payment-system fraud controls, and AI governance. The Information Security Examination (ISE) program remains the examination framework.

What replaced the FFIEC Cybersecurity Assessment Tool (CAT)?

The FFIEC retired the CAT on August 31, 2025, with no single mandated replacement. Examiners expect credit unions to map their program to a recognized successor framework, such as the CRI Profile, the NIST Cybersecurity Framework 2.0, or the CISA Cybersecurity Performance Goals, and to document that mapping.

What is the NCUA 72-hour cyber incident notification rule?

A federally insured credit union must notify the NCUA as soon as possible, and no later than 72 hours after it reasonably believes it has experienced a reportable cyber incident. The clock starts at reasonable belief, which is why a tested notification workflow and call tree matter.

Does the NCUA require board cybersecurity training?

For 2026, the NCUA named annual board-level cybersecurity training as an examination priority. Examiners look for evidence that directors have received structured cybersecurity education and understand enough to provide meaningful oversight. The checklist includes the governance and board-oversight controls examiners will ask about.

How do I prepare for an NCUA IT examination?

Start by mapping your program to the controls examiners actually test: a written, board-approved information security program, a current risk assessment, multifactor authentication, a tested incident response plan that meets the 72-hour rule, documented vendor oversight, and board reporting. This checklist lays out all 85 controls so you can find and close gaps before the examiner arrives. If you want help closing them, TorchLight’s audit, assessment and compliance services map directly to the exam.

Is the checklist free, and what do I get?

Yes. The download is a free 12-page PDF (Edition 6.2026) with 85 auditable controls across regulatory requirements and forward-looking threats, two executive visuals, a built-in readiness self-score, and a full authority and reference list for your workpapers. No cost and no sales call required.

Find every gap before your examiner does

Download the free checklist, score yourself in about 15 minutes, and know exactly where you stand before the next exam cycle.

Download the Readiness Checklist