ALEXANDRIA, Va. — The National Credit Union Administration is seeking public comment on renewing a key information collection requirement that governs how federally insured credit unions safeguard member information and manage security incidents, while reporting that the overall compliance burden has declined because of the industry’s continued consolidation.
In a notice published in the Federal Register, the NCUA said it is submitting several previously approved information collections to the Office of Management and Budget for renewal under the Paperwork Reduction Act. Among the collections is the agency’s security program requirement under Part 748 of its regulations.

The regulation requires all federally insured credit unions to maintain a written security program designed to protect sensitive member information and respond to incidents involving unauthorized access or use. The agency said the requirement is intended to help prevent substantial harm or serious inconvenience to members following data security incidents.
More Than 77,758 Responses Expected
According to the filing, the NCUA estimates 4,287 federally insured credit unions will be subject to the requirement. Those institutions are expected to generate approximately 77,758 annual responses, resulting in an estimated annual paperwork burden of 206,368 hours.
The agency said the estimated burden has fallen from 240,398 hours under the previous approval because the number of federally insured credit unions has continued to decline. The revised estimate is based on data from the December 2025 NCUA Call Report.
The Federal Register notice also includes renewal of the agency’s information collection related to member business loans and commercial lending under Part 723 of the NCUA’s regulations, among other collections being forwarded to OMB for review.
The NCUA is accepting comments on the proposed renewals through Aug. 27. Interested parties may submit comments through the Office of Management and Budget’s public comment portal.




