DCUC Opposes Sweeping Third-Party Vendor Authority Legislation
By DCUC Staff —
WASHINGTON, D.C. — Today, the Defense Credit Union Council expressed its opposition to H.R.10230, Strengthening Oversight for the Financial Sector Act of 2026, legislation introduced by Representative Bill Foster (D-Ill.) that would grant the National Credit Union Administration (NCUA) broad authority to regulate and examine third-party companies providing services to credit unions.
In a letter to Representative Foster, DCUC warned that the legislation’s operative language extends well beyond the cybersecurity and artificial-intelligence risks cited as justification for the proposal. “Our objection is not to cybersecurity as an objective…Our concern is that the legislation is far more sweeping than the cybersecurity problem it is purportedly designed to address,” wrote Jason Stverak, DCUC Chief Advocacy Officer. “Cybersecurity is a serious national-security, consumer-protection, and operational priority,” says Anthony Hernandez, DCUC President/CEO, Ret. U.S. Air Force Colonel. “However, granting NCUA sweeping authority over the full range of credit union service providers is not a narrowly tailored cybersecurity solution. Congress should first identify the specific regulatory gap, determine why existing authorities and interagency processes are insufficient, and consult directly with the credit unions that would bear the costs and operational consequences of this proposal.” DCUC has consistently raised concerns about granting NCUA unrestricted third-party vendor authority, and expressed concerns about potential duplicative examinations, increased regulatory expenses, reduced vendor competition, slower technological innovation, and additional costs ultimately borne by credit union members. In its comments, DCUC also expressed concern that the legislation lacks clear thresholds and does not distinguish between a critical technology provider with access to sensitive financial information and an ordinary, low-risk vendor. DCUC noted the legislation does not expressly require NCUA to rely on examination findings produced by other federal or state regulators before conducting an additional examination. “It remains unclear how expanding NCUA’s jurisdiction over thousands of private companies would have prevented past cyber breaches, especially when federal agencies and federal contractors with extensive oversight and cybersecurity resources continue to experience similar incidents. Regulatory authority is not, by itself, a cybersecurity control,” Stverak states. “If cybersecurity is the problem Congress is attempting to solve, then any new authority should be limited specifically to material cybersecurity, data-protection, and operational-resilience risks involving critical service providers. A legitimate concern about cyber threats should not become an open-ended expansion of federal jurisdiction over every company that provides a service to a credit union.” NCUA examiners currently evaluate whether credit unions conduct appropriate due diligence, protect member information, negotiate adequate contractual safeguards, monitor vendor performance, and maintain effective cybersecurity and incident-response programs. Stverak adds, “Congress should first determine whether greater information sharing among federal financial regulators, reliance on existing examination findings, stronger threat-information sharing, or joint examinations of genuinely critical providers could address identified vulnerabilities without creating a new and duplicative regulatory structure.” DCUC has offered to meet with Representative Foster and his staff to discuss the legislation and provide operational perspectives from credit union executives and cybersecurity professionals.
1627 Eye Street, NWSuite 935Washington, DC 20006202.734.5007[email protected]
ALERT NewsletterArmed Forces Financial NetworkFinancial Education ResourcesVeterans Benefits Banking Program
Copyright Defense Credit Union Council. All Rights Reserved.
Originally reported by DCUC.