← All News

Foster Bill Would Restore NCUA Authority Over CU Vendors

By CU Today Staff —

WASHINGTON—Rep. Bill Foster (D-IL) has reintroduced legislation that would grant NCUA authority to examine and regulate third-party vendors serving credit unions, reviving a long-running and contentious issue as the credit union system continues to face growing cybersecurity threats.

This authority, which is available to other federal financial regulators, had been temporarily granted to the NCUA, but has since expired, leaving a “dangerous gap” in oversight, Foster said.

The Strengthening Oversight for the Financial Sector Act of 2026 also would grant the Federal Housing Finance Agency comparable authority over service providers used by Fannie Mae, Freddie Mac, the Federal Home Loan banks and the Office of Finance. According to the three-page bill, companies performing activities for a regulated entity would be subject to regulation and examination to the same extent as if the work were performed by the institution itself. The bill also would require regulated entities to report new service relationships within 30 days.

“As AI makes cyberattacks more sophisticated, it is even more important to ensure that third-party vendors don’t become a weak link in our financial system,” Foster said. “We have learned the hard way how much damage supply chain vulnerabilities can cause, and third-party vendors are attractive targets. This bill will give regulators the tools they need to better protect Americans’ money and sensitive data as AI-assisted cyber threats grow.”

The bill has been reintroduced while TruStage continues recovering from one of the largest and most disruptive cyber incidents to affect credit unions and their members. As CUToday.info most recently reported, the July 11 attack disrupted claims processing, payments, call centers and other insurance and retirement services used through credit unions. TruStage has reopened its Claims Contact Center and restored additional services, but it has not yet determined whether credit union member or employee information was accessed or compromised.

Cybersecurity firm Mandiant has said TruStage’s operating environment is clean, the incident has been contained and no active intrusion has been detected since July 11. However, TruStage previously cautioned that its forensic review could take another two to three months, according to CUToday.info’s continuing coverage. At least 14 proposed class-action lawsuits had been filed as of Aug. 12, although their allegations remain unproven.

The NCUA has repeatedly argued that its inability to examine third-party providers represents a major regulatory blind spot. Former Chairman Todd Harper told Congress that credit unions holding approximately 90% of industry assets rely on key services from vendors the agency cannot directly supervise. He also cited a single vendor cyber incident that disrupted 60 credit unions and said restored authority would allow the agency to use risk-based examinations focused on cybersecurity, information security, consumer protection and threats to the National Credit Union Share Insurance Fund, as CUToday.info reported.

Congress temporarily granted the NCUA vendor-examination authority in 1998, but the authority expired at the end of 2001. Foster’s bill would remove that expiration provision from the Federal Credit Union Act.

DCUC Comments, Sends Letter To Foster

Defense Credit Union Council Chief Advocacy Officer Jason Stverak told CUToday.info that DCUC has consistently opposed granting NCUA broad third-party vendor examination authority—"for good reason.”

“It remains unclear how expanding a regulator’s jurisdiction over credit union service providers would have prevented the cyber breaches that continue to affect federal agencies, major corporations, and some of the most heavily regulated institutions in the country,” Stverak said. “More regulatory authority does not automatically produce better cybersecurity. Congress should not confuse expanding government power with strengthening operational resilience. Credit unions are already responsible for conducting vendor due diligence, protecting member information, managing third-party risk, and maintaining robust cybersecurity and incident-response programs. NCUA already evaluates those responsibilities through the examination process.”

Granting NCUA sweeping new authority would create another layer of federal oversight, increase compliance costs, duplicate examinations conducted by other regulators, and potentially reduce the number of technology providers willing or able to serve smaller credit unions, Stverak contended.

“Those costs would ultimately be borne by credit union members,” he emphasized. “Congress should focus on solutions that address actual vulnerabilities: better threat-information sharing, stronger coordination among federal regulators, clear cybersecurity standards, timely notification of emerging threats, and accountability when sensitive information is compromised. Third-party vendor authority is not a substitute for an effective national cybersecurity strategy. DCUC will continue to oppose any proposal whether introduced as stand-alone legislation or added to a must-pass bill that grants NCUA broad and unnecessary authority over credit union vendors.”

DCUC sent a letter to Foster Thursday morning.

Originally reported by CU Today.