The Defense Credit Union Council just threw up a pretty significant stop sign on proposed legislation that would hand the National Credit Union Administration a whole lot of new power over third-party vendors.
And their reasoning?
This bill might be using a cybersecurity concern as a Trojan horse for something much bigger.
Here’s the setup: Representative Bill Foster (D-Ill.) introduced H.R.10230, aka the Strengthening Oversight for the Financial Sector Act of 2026. On paper, it’s about beefing up cybersecurity and managing AI risks by letting the NCUA regulate and examine the companies that provide services to credit unions. Sounds reasonable enough, right?
The Problem: A Solution That’s Way Too Broad
“Our objection is not to cybersecurity as an objective,” wrote Jason Stverak, DCUC Chief Advocacy Officer, in a letter to Representative Foster. “Our concern is that the legislation is far more sweeping than the cybersecurity problem it is purportedly designed to address.”
Translation: If you’re trying to fix a leak in the kitchen, you don’t need to renovate the entire house.
Anthony Hernandez, DCUC President and CEO (and retired U.S. Air Force Colonel), put it even more bluntly: “Cybersecurity is a serious national-security, consumer-protection, and operational priority. However, granting NCUA sweeping authority over the full range of credit union service providers is not a narrowly tailored cybersecurity solution.”
What Could Go Wrong?
The DCUC isn’t just worried about regulatory overreach for the sake of it. They’ve outlined some very real operational headaches this legislation could create:
- Duplicative examinations that waste time and resources
- Increased regulatory expenses that someone has to pay for (spoiler: it’s the credit union members)
- Reduced vendor competition because smaller providers can’t handle the regulatory burden
- Slower technological innovation when everything requires multiple layers of approval
And here’s a kicker: the legislation doesn’t even distinguish between high-risk vendors handling sensitive financial data and your average, run-of-the-mill service provider. It’s a one-size-fits-all approach in a world that definitely doesn’t work that way.
The “Show Your Work” Argument
Hernandez and his team are basically asking Congress to do what we all had to do in math class: show your work. “Congress should first identify the specific regulatory gap, determine why existing authorities and interagency processes are insufficient, and consult directly with the credit unions that would bear the costs and operational consequences of this proposal.”
Stverak doubled down on this point: “It remains unclear how expanding NCUA’s jurisdiction over thousands of private companies would have prevented past cyber breaches, especially when federal agencies and federal contractors with extensive oversight and cybersecurity resources continue to experience similar incidents.”
Ouch. But he’s got a point. If organizations with massive cybersecurity budgets still get breached, is more regulatory authority really the answer? As Stverak notes, “Regulatory authority is not, by itself, a cybersecurity control.”
What’s Already in Place?
It’s not like credit unions are operating in the Wild West right now. NCUA examiners already evaluate whether credit unions are doing their homework on vendors: conducting due diligence, protecting member information, negotiating proper contracts, monitoring vendor performance, and maintaining solid cybersecurity programs.
The question becomes: why build an entirely new regulatory structure when you could potentially solve the problem through better information sharing between existing regulators, relying on examination findings that already exist, or conducting joint examinations of truly critical providers?
The Path Forward
The DCUC isn’t just complaining and walking away. They’ve offered to sit down with Representative Foster and his staff to talk through the issues and share insights from credit union executives and cybersecurity professionals who actually work in the trenches.
Their bottom line? “If cybersecurity is the problem Congress is attempting to solve, then any new authority should be limited specifically to material cybersecurity, data-protection, and operational-resilience risks involving critical service providers. A legitimate concern about cyber threats should not become an open-ended expansion of federal jurisdiction over every company that provides a service to a credit union.”
In other words: let’s solve the actual problem without creating a dozen new ones in the process.