Guide

NCUA, FFIEC, or GLBA: Which Framework Actually Applies to You

Credit union, bank, or neither — a plain breakdown of which financial cybersecurity framework actually governs your institution, and why the answer isn't always obvious.

Talk to a CISO

The business problem

"Financial institution" is not one category — it's a set of overlapping jurisdictions, and which one applies to you determines which rule an examiner actually shows up with. Federally insured credit unions answer to the NCUA, examined against 12 CFR Part 748 Appendix A and NCUA's own ACET. Banks and their holding companies are examined by the FFIEC member agencies (the OCC, FDIC, and Federal Reserve, among others) using the shared FFIEC IT Examination Handbook booklets. And a much broader group — mortgage brokers, non-bank lenders, financial advisors, dealers extending credit, and similar businesses that don't think of themselves as "financial institutions" at all — fall under the FTC's GLBA Safeguards Rule, 16 CFR Part 314, because the FTC's definition of the term is far broader than the industry's everyday usage of it.

Confusing which of these actually governs you leads to a specific, avoidable failure: preparing for exam questions that will never be asked, while missing the ones that will.

Why it matters

Each framework has its own vocabulary, its own specific expectations, and its own examiner. A credit union that benchmarks itself against the FFIEC handbook instead of Part 748 Appendix A and ACET is studying for the wrong exam. A fintech that assumes GLBA doesn't apply because it isn't a bank may be wrong — the FTC's Safeguards Rule reaches many non-bank businesses that never expected to be in scope.

“The examiner who shows up asks for evidence that maps to a specific regulation, not a generic cybersecurity best-practice framework. Getting that framework right is where readiness starts, not where it ends.”

Signs the organization should pay attention now

  • Leadership isn't sure whether NCUA, an FFIEC-member agency, or the FTC is the institution's primary examiner
  • The organization has grown into overlapping categories through a subsidiary, a bank partnership, or a change in charter
  • Compliance documentation cites "cybersecurity best practices" generically rather than a specific regulatory citation
  • No one has actually walked through 12 CFR 748 Appendix A, the FFIEC IT Handbook booklets, or 16 CFR 314 and confirmed which one governs the institution
  • A recent exam or audit referenced a control expectation the team didn't recognize

What good looks like

Organizations that get this right have confirmed their actual regulator — or regulators, since overlap is possible — in writing, and their program documentation cites the specific rule and section that applies, not generic industry language borrowed from a framework that isn't the one an examiner will actually use.

Not sure which framework actually governs you?

Explore Financial Institution Cybersecurity Readiness Review

Practical guidance

Start by confirming charter and insurer status — federally insured credit union, chartered bank, or neither. Then check holding company and subsidiary structure, since a single corporate family can straddle more than one framework. Finally, take the specific free assessment that matches what you've confirmed — NCUA, FFIEC, or GLBA — to see where the actual program stands today, rather than relying on an assumption that's never been tested.

My CISO Partner's perspective

We start every financial institution engagement by confirming the actual regulator and rule in writing before doing anything else — it's a five-minute conversation that prevents months of work aimed at the wrong target.

Where to go from here

If leadership can't say, in one sentence, which regulator actually examines your institution and against which rule, that's worth resolving before the next exam does it for you.

FAQ

Questions, answered directly.

Yes — a bank holding company with a mortgage subsidiary, or a fintech partnering with a chartered bank, can face overlapping FFIEC and GLBA obligations depending on structure.

Yes. The FTC's definition of "financial institution" under GLBA is broad and includes many non-bank entities — mortgage lenders, financial advisors, and dealers that extend financing, among others.

They're related but distinct. ACET is NCUA's own tool, modeled on the former FFIEC Cybersecurity Assessment Tool, but administered separately for federally insured credit unions.

By confirming the actual regulator and applicable rule in writing, then mapping the current program against that specific framework — not a generic best-practice checklist.

Talk to a CISO about your regulatory scope.

30 minutes. No obligation. No sales pitch.

Talk to a CISO