In the first year after NCUA’s cyber incident notification rule took effect, federally insured credit unions reported 1,072 cyber incidents. Seventy percent of those incidents were traced to third-party vendors.
That single data point reframes the vendor risk conversation for credit unions. The threat is not primarily internal. It is arriving through the relationships credit unions depend on such as core processors, payment platforms, cloud providers, fintech partners. The NCUA has made clear that managing those relationships is the credit union’s responsibility, not the vendor’s.
The challenge NCUA acknowledges openly: unlike banking regulators (who have FFIEC specific third-party risk management requirements for banks), the NCUA cannot directly examine or regulate third-party service providers. It cannot walk into a core processor and conduct an examination. That supervisory gap means credit unions must demonstrate vendor risk management that functions without regulatory backstop on the vendor side. When something goes wrong, the 72-hour notification clock starts and the question examiners ask is whether the credit union had adequate ongoing due diligence in place before the incident occurred.
The NCUA Regulatory Framework for Third-Party Risk Management
NCUA’s foundational TPRM document is Supervisory Letter 07-01, issued in 2007, the oldest governing vendor risk guidance still in force among the major financial regulators.
While it predates the current threat landscape by nearly two decades, its three core principles remain the examination standard:
- Initial risk assessment and planning before entering third-party relationships
- Due diligence in selecting and contracting with third parties
- Ongoing risk measurement, monitoring, and control for the life of the relationship
What has changed significantly is how NCUA examiners apply the ongoing monitoring standard in the current threat environment. The 2024 and 2025 supervisory priorities have progressively tightened expectations around third-party cybersecurity specifically; moving from general vendor oversight language toward explicit requirements for programs that protect against third-party cyber incidents.
It is crucial for your credit union to manage its information security programs and continuity of operations plans proactively, and to conduct ongoing due diligence of your critical service providers.
- NCUA 2025 Supervisory Priorities, Letter 25-CU-01
The 2025 supervisory priorities also reinforced the Cyber Incident Notification Requirements (Letter 25-CU-02), which require credit unions to notify NCUA within 72 hours when they (or a third-party provider) experience a reportable cyber incident. That requirement changed the stakes of vendor monitoring from a compliance documentation exercise to an active operational responsibility with a hard regulatory deadline.
The Supervisory Gap NCUA Cannot Close: What it Means for Your Program
The NCUA has acknowledged a structural limitation that distinguishes credit union vendor risk management from bank TPRM: NCUA lacks direct supervisory authority over third-party service providers. It cannot examine core processors, cloud providers, or fintech partners directly. Both the Government Accountability Office and the Financial Stability Oversight Council have urged Congress to restore this authority, but until that changes, credit unions are operating without a regulatory backstop on the vendor side.
The practical implication is significant. When a bank’s vendor fails a regulatory examination, the banking regulator can take corrective action directly. When a credit union’s vendor fails, the NCUA can only evaluate whether the credit union’s own due diligence and monitoring program was adequate. The liability stays with the credit union regardless of what the vendor did or didn’t do.
This makes ongoing technical monitoring, not just due diligence at onboarding, the critical differentiating factor in examination outcomes. Examiners evaluating a vendor incident will look at what the credit union knew, when they knew it, and whether their monitoring program would have detected a change in vendor posture before the incident occurred.
Where Most Credit Union Vendor Risk Programs Fall Short
Most credit union vendor risk programs are built around the due diligence and contracting stages. Including collecting SOC 2 reports at onboarding, completing vendor questionnaires annually, reviewing contracts at renewal. These activities satisfy the documentation requirement of Supervisory Letter 07-01 but do not satisfy the ongoing monitoring standard as examiners are applying it in 2025 and 2026.
The gap becomes visible when examiners ask three questions most programs cannot answer with current data:
- How would your credit union detect a change in a critical vendor’s security posture between annual reviews?
- When your vendor experienced this incident, what did your monitoring data show in the 30 days prior?
- How do you tier your vendors by criticality, and does your monitoring depth reflect those tiers?
A questionnaire completed last October cannot answer any of those questions. Neither can a SOC 2 report issued eight months ago.
The 70% third-party incident rate tells you that the vendor risk is continuous; the monitoring program needs to be continuous to match it.
TPRM Platforms for NCUA-compliant Credit Union Vendor Risk Programs
FortifyData
Built around direct, non-intrusive scanning of vendor security posture rather than questionnaire workflows or aggregated ratings. For credit unions operating without NCUA’s supervisory backstop on vendors, FortifyData produces live technical data on vendor posture; findings attributed correctly, updated continuously, and exportable in examiner-ready format. The practical difference is the ability to demonstrate what your monitoring program detected before a vendor incident occurred, not just that you collected a questionnaire response last year. Credit unions have used FortifyData to establish NCUA-examination-ready vendor risk programs within 45 days of implementation, including vendor tiering, continuous monitoring methodology, and 72-hour incident response documentation support. Pricing is structured for credit unions that need defensible, regulator-ready TPRM without enterprise platform cost.
Venminder
Workflow-heavy platform with strong documentation capability across the vendor lifecycle — due diligence, contract management, and ongoing assessment tracking. Well established in the credit union market specifically. Primary methodology relies on questionnaire and assessment workflows rather than continuous technical monitoring. Strong for programs where documentation and process management are the primary requirement. Less suited for demonstrating continuous technical visibility into vendor security posture between assessment cycles.
Ncontracts (Nvendor)
Purpose-built for community financial institutions including credit unions. Strong regulatory alignment with NCUA and FFIEC examination expectations. Combines vendor risk workflow management with compliance tracking. Monitoring approach incorporates third-party data feeds. Well suited for credit unions that prioritize regulatory workflow documentation and want a platform with deep financial institution context.
BitSight
Ratings-based platform using aggregated external signals to produce vendor security scores. Strong at portfolio-level visibility across large vendor inventories. Primary limitation for credit union NCUA examinations: aggregated scores can lag real-world changes and misattribute findings, making the evidentiary basis for monitoring harder to defend. Pricing scales with vendor count, mid-market credit unions with moderate vendor inventories may find better value in platforms purpose-built for their scale.
What NCUA Examiners are Actually Evaluating
Supervisory Letter 07-01 is nearly 20 years old. The threat environment it was written for no longer exists. What NCUA examiners are applying in 2025 and 2026 is the ongoing monitoring standard from that foundational guidance interpreted against a world where 70% of credit union cyber incidents originate from vendors and the notification clock starts within 72 hours of detection.
The credit union that handles that environment well is not the one with the most complete questionnaire archive. It is the one that can show continuous technical visibility into critical vendor posture and demonstrate what that monitoring detected before the examiner arrived.
FortifyData is built for credit unions that need to close that gap with current data, not documentation of last year’s vendor self-assessments. Security and compliance teams at credit unions have used it to establish NCUA-defensible vendor risk programs within 45 days; including the monitoring methodology, vendor tiering, and incident response documentation that examiners look for.
If your current vendor risk program relies primarily on annual questionnaires and SOC 2 collection, it is worth understanding what continuous technical monitoring looks like before your next NCUA examination cycle.


