NYDFS Cybersecurity Regulation (23 NYCRR 500): The Complete Compliance Guide
23 NYCRR Part 500 is the New York Department of Financial Services cybersecurity regulation. It requires banks, insurers, mortgage lenders, and other DFS-licensed entities to run a risk-based cybersecurity program, notify DFS of incidents within 72 hours, and file an annual certification signed by the highest-ranking executive and the CISO. Its Second Amendment requirements phased in fully on November 1, 2025.
- The regulation is fully in effect. The final phase landed November 1, 2025 — not May 2025 — and covers MFA for any individual accessing any information system (500.12) and a complete, documented asset inventory (500.13(a)).
- There are three tiers: standard covered entities, Class A companies ($20M+ revenue plus 2,000+ employees or $1B+ affiliate revenue) with four extra controls, and limited-exemption entities under 500.19(a) that are still bound by MFA, asset inventory, access controls, and reporting.
- Four hard deadlines run continuously: 72 hours to report a cybersecurity incident, 24 hours to report an extortion payment, 30 days for the written explanation, and April 15 for the annual certification signed by the CEO and CISO.
- Enforcement is active and expensive. DFS had secured more than $144 million from 27 entities as of October 2025, including a $19 million eight-insurer sweep, and continued into 2026 with Delta Dental ($2.25M) and Order Express ($250K).
- Under 500.20(b), every single failure to act is its own violation — which is why unenrolled accounts and uninventoried assets scale into material penalty exposure.
What Is 23 NYCRR Part 500 and Why Does It Matter in 2026?
Part 500 of Title 23 of the New York Codes, Rules and Regulations is the cybersecurity regulation issued by the New York State Department of Financial Services (NYDFS or DFS). It took effect on March 1, 2017 as the first prescriptive, state-level cybersecurity rule aimed squarely at financial services, and it has been copied widely since — the NAIC Insurance Data Security Model Law and the revised FTC Safeguards Rule both borrow its structure.
The reach is substantial. DFS supervises more than 3,000 financial institutions with nearly $10 trillion in assets, including over 1,900 insurance companies and more than 1,300 banks and financial institutions, plus money transmitters, mortgage servicers, credit reporting agencies, and virtual currency businesses. If you hold a New York license under the Banking Law, Insurance Law, or Financial Services Law, Part 500 applies to you regardless of where your headquarters sits.
What makes 2026 different is that the regulation is finally complete. The Second Amendment, adopted November 1, 2023, rewrote roughly half of Part 500 and rolled the new obligations out across a two-year transitional schedule. The last tranche — universal multi-factor authentication and a documented asset inventory — became enforceable on November 1, 2025. There is no longer any phase-in left to hide behind.
That matters because DFS examines against the text, not against intent. Section 500.20(b) states plainly that “the commission of a single act prohibited by this Part or the failure to act to satisfy an obligation required by this Part shall constitute a violation.” Every unenrolled admin account and every uninventoried server is, in principle, its own countable violation. For institutions building a broader banking compliance program, Part 500 is now the most granular cybersecurity yardstick a US regulator has published.
Who Has to Comply? Covered Entities, Class A Companies, and Exemptions
Part 500 sorts the regulated population into three tiers, and getting your tier wrong is one of the most common and most expensive mistakes in this regulation.
Covered entities (the default)
A covered entity is any person “operating under or required to operate under a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law.” That sweeps in state-chartered banks, branches of foreign banks, credit unions, licensed lenders, mortgage bankers and servicers, insurers, insurance agencies and brokers, premium finance companies, money transmitters, check cashers, and BitLicense holders. Individual licensed producers are covered too, which is why DFS publishes a separate small-business track.
Class A companies (the enhanced tier)
A Class A company is a covered entity with at least $20,000,000 in gross annual revenue in each of the last two fiscal years from its own operations plus its affiliates’ New York operations, and either over 2,000 employees averaged over the last two fiscal years (counting all affiliates worldwide) or over $1,000,000,000 in gross annual revenue in each of the last two fiscal years across the entity and all affiliates worldwide. Note the asymmetry: the $20 million test counts affiliate revenue only in New York, while the employee and $1 billion tests count affiliates everywhere. Global groups with a modest New York footprint are frequently Class A without realizing it.
Class A companies carry four extra obligations: independent audits of the cybersecurity program based on risk assessment (500.2(c)), a privileged access management solution and an automated method of blocking commonly used passwords (500.7(c)), endpoint detection and response plus a solution that centralizes logging and security event alerting (500.14(b)), and external expertise in risk assessments.
Limited-exemption entities (the small-business tier)
Under 500.19(a), an entity qualifies for a limited exemption if it has fewer than 20 employees and independent contractors (including affiliates), less than $7,500,000 in gross annual revenue in each of the last three fiscal years from its operations and its affiliates’ New York operations, or less than $15,000,000 in year-end total assets. Meeting any one of the three is enough.
A limited exemption is not a pass. It excuses you from sections 500.4, 500.5, 500.6, 500.8, 500.10, 500.14(a)(1)–(2) and (b), 500.15, and 500.16 — meaning no mandatory CISO, no penetration testing, no audit trails, no application security program, no encryption policy, and no formal incident response plan. Everything else still applies, including MFA, asset inventory, access controls, risk assessment, third-party oversight, incident reporting, and the annual certification. Entities relying on an exemption must file electronically a Notice of Exemption “within 30 days of the determination that the covered entity is exempt,” and must refile when circumstances change. Smaller institutions such as credit unions often sit right at these thresholds and drift across them without updating their filing.
When Did Each Requirement Take Effect, and Who Does It Apply To?
The Second Amendment used section 500.22 transitional periods rather than a single cliff date: 30 days for the new notification rules, one year for governance and encryption, 18 months for vulnerability scanning and access controls, and two years for MFA and asset inventory. Working from the DFS implementation timeline for covered entities, the Class A timeline, and the parallel small business timeline, here is how the phases map against each tier.
| Effective date | Requirement (section) | Standard covered entity | Limited exemption (500.19(a)) | Class A company |
|---|---|---|---|---|
| Dec 1, 2023 | Notice of ransomware deployment; 24-hour notice of extortion payment plus 30-day written explanation (500.17(c)) | Applies | Applies | Applies |
| Apr 15, 2024 (annual) | Certification of material compliance or acknowledgment of noncompliance, signed by highest-ranking executive and CISO (500.17(b)) | Applies | Applies | Applies |
| Apr 29, 2024 | Annual risk assessment refresh (500.9); senior-governing-body approval of policies (500.3); annual penetration testing (500.5(a)(1)); social-engineering training (500.14(a)(3)) | Applies | Applies except 500.5 | Applies, plus independent program audits (500.2(c)) |
| Nov 1, 2024 | CISO written report with remediation plans and board oversight duties (500.4); written encryption policy (500.15); incident response and BCDR plans with annual testing (500.16) | Applies | Exempt | Applies |
| May 1, 2025 | Automated vulnerability scans at risk-based frequency (500.5(a)(2)); access privilege limits, annual reviews, password policy, remote-control protocol restrictions (500.7); malicious code protection (500.14(a)(2)) | Applies | 500.7 only | Applies, plus PAM and automated blocking of common passwords (500.7(c)) and EDR with centralized logging (500.14(b)) |
| Nov 1, 2025 | MFA for any individual accessing any information system (500.12); complete, accurate, documented asset inventory (500.13(a)) | Applies | Applies | Applies |
One correction worth making, because it circulates widely in vendor material: the final phase was November 1, 2025, not May 1, 2025. May 2025 delivered vulnerability scanning and access controls; MFA and asset inventory landed six months later.
What Does a Compliant Cybersecurity Program Have to Include?
With the schedule closed, examiners are working through a fixed checklist. These are the provisions where deficiencies show up most often.
Multi-factor authentication (500.12)
This is the single biggest change. MFA “shall be utilized for any individual accessing any information systems of a covered entity” — not just remote access, not just privileged accounts, not just external network traffic. Internal applications, on-premises systems, and third-party portals are all in scope. The only relief is a written approval from the CISO for “reasonably equivalent or more secure compensating controls,” reviewed at least annually. Limited-exemption entities are not excused; they simply have no CISO to sign the approval, so the senior officer responsible for the program signs instead.
Asset inventory (500.13(a))
Covered entities must maintain “a complete, accurate and documented asset inventory” governed by written policies that specify tracking of owner, location, classification or sensitivity, support expiration date, and recovery time objectives, plus how often the inventory is updated and validated. The support-expiration field is the one most firms miss; it exists so that end-of-life technology is visible before it becomes an incident.
Access privileges (500.7)
Access must be limited to what a user needs to perform their job, privileged accounts must be limited further and used only when performing privileged functions, remote-control protocols must be disabled or securely configured, and access must be terminated promptly on departure. Reviews are required at least annually. A disciplined user access review process is the evidence examiners ask for first, because it is the one control that produces a dated, signed artifact.
Vulnerability management and testing (500.5)
Annual penetration testing from both inside and outside system boundaries by a qualified internal or external party, plus automated scans at a frequency set by the risk assessment, plus a documented process for timely remediation prioritized by risk.
Encryption, response, and training (500.15, 500.16, 500.14)
Encryption of nonpublic information at rest and in transit over external networks under a written policy; compensating controls at rest need documented CISO approval and annual review, and no compensating controls are permitted for data in transit. Incident response and business continuity plans must be maintained and tested annually. Awareness training must be at least annual and must cover social engineering.
Third-party service providers (500.11)
DFS published dedicated guidance on managing third-party service provider risk on October 21, 2025, clarifying expectations for due diligence, contractual protections such as MFA and encryption terms, periodic reassessment, and clean offboarding — revoking SSO tokens and obtaining certified destruction or migration of data. The guidance is blunt that senior leadership cannot delegate compliance responsibility to a vendor.
What Are the Governance and Annual Certification Obligations?
Part 500 is unusual among security regulations in that it assigns named human accountability. That design is deliberate, and it is where DFS looks when a program fails.
Section 500.4 requires a qualified CISO — who may be an employee, an affiliate’s employee, or a third party — to report in writing at least annually to the senior governing body on confidentiality and integrity of information systems, policies and procedures, material cybersecurity risks, program effectiveness, and material cybersecurity events. Since November 1, 2024 that report must also include plans for remediating material inadequacies, and the CISO must report promptly on material cybersecurity issues as they arise.
The same amendment gave the senior governing body — the board or an appropriate committee — four affirmative duties: have or obtain sufficient understanding of cybersecurity risk (including by using advisors), require executive management to develop and maintain the program, regularly receive and review management reports, and confirm that management has allocated sufficient resources. Boards that cannot show a documented cadence of cybersecurity reporting are exposed here. This is a core theme of any serious GRC program in banking.
The April 15 certification
By April 15 each year, every covered entity must file electronically either a certification of material compliance for the prior calendar year or an acknowledgment of noncompliance that identifies each section not materially complied with and provides a remediation timeline. Both must be signed by the highest-ranking executive and the CISO — or, absent a CISO, the senior officer responsible for the cybersecurity program. Supporting data and documentation must be retained for five years.
Treat the choice seriously. A certification of material compliance is a signed statement to a regulator; a false certification is itself a violation and, in past DFS matters, an aggravating factor. If MFA coverage is at 94% or the asset inventory is missing a business unit, the acknowledgment path with a credible remediation plan is the defensible option.
How Fast Do You Have to Report an Incident to NYDFS?
Part 500 runs three separate clocks, and they are shorter than most incident response plans assume.
- 72 hours — cybersecurity incident notice (500.17(a)). Notify the superintendent electronically “as promptly as possible but in no event later than 72 hours after determining that a cybersecurity incident has occurred.” The clock starts at determination, not containment.
- 24 hours — extortion payment notice (500.17(c)(1)). If you make an extortion payment in connection with a cybersecurity event, notify DFS within 24 hours of the payment.
- 30 days — extortion payment explanation (500.17(c)(2)). Provide a written description of the reasons the payment was necessary, the alternatives considered, the diligence performed to find alternatives, and the diligence performed to ensure compliance with OFAC sanctions rules.
The trigger is a “cybersecurity incident” as defined in 500.1, which is narrower than a “cybersecurity event” but broader than a breach: it covers events that require notice to any government or supervisory body, events with a reasonable likelihood of materially harming any material part of normal operations, and any event that results in the deployment of ransomware within a material part of the information systems. Incidents at affiliates and at third-party service providers count.
Late reporting is a recurring enforcement theme rather than a technicality. In the October 2025 auto insurance actions, DFS specifically called out Farmers and Infinity for failing to timely report their breaches, and the April 2026 Delta Dental consent order cited delayed reporting of cybersecurity events alongside inadequate incident response procedures. Build the 72-hour decision into your playbook with a named decision-maker, because the determination itself is what starts the clock.
What Do Recent NYDFS Enforcement Actions and Penalties Show?
DFS has moved from education to sustained enforcement, and the consent orders are the clearest statement of what “material compliance” actually means.
- As of October 2025, DFS had secured over $144 million in fines from 27 entities for cybersecurity violations.
- October 14, 2025: more than $19 million across eight auto insurers, from $1.85M (Hagerty) to $3M (Hartford Fire).
- April 30, 2026: $2.25 million from Delta Dental over the 2023 MOVEit zero-day exploitation.
- August 5, 2026: $250,000 from Order Express, a small money transmitter with limited-exemption status.
The October 2025 auto insurance sweep penalized Farmers Insurance Exchange ($2.775M), Hagerty Insurance Agency ($1.85M), Hartford Fire Insurance ($3M), Infinity Insurance ($2.25M), Liberty Mutual ($2.7M), Metromile ($2.05M), Midvale Indemnity ($2M), and State Automobile Mutual ($2.5M) after attackers harvested driver’s license numbers and dates of birth from online quoting applications and agent portals. It followed the November 2024 action in which GEICO paid $9.75 million and Travelers $1.55 million; Travelers’ agent portal was password-protected but had no MFA and no compensating controls, and the intrusion went undetected for seven months.
The $2 million PayPal settlement of January 23, 2025 is the one to read if you think written policies are enough. PayPal had change management, authentication, and access control policies on paper; the engineering team implementing changes to a data flow had not been trained on them, and credential-stuffing attackers reached customer Social Security numbers. DFS penalized the gap between the policy and its execution.
Two 2026 orders extend the pattern. Delta Dental’s $2.25 million settlement cited inadequate incident response procedures, failure to implement retention settings and controls — a data minimization finding — and delayed reporting after the MOVEit compromise exposed Social Security numbers, driver’s license numbers, financial account data, and health information. And Order Express agreed to $250,000 under a consent order effective July 31, 2026 for violations of 500.9(a), 500.2(b), and 500.3(g): its annual risk assessment covered operational and IT risk but “failed to consider cybersecurity risks and threats specific to the Company,” and its patching procedures covered only a small number of the third-party applications it actually ran. Order Express qualified for the limited exemption. Small does not mean out of scope.
Context for the exposure: according to IBM’s 2026 Cost of a Data Breach Report, published July 29, 2026, the average breach in financial services costs $6.3 million, and one in four malicious breaches is now AI-enabled — a 56% year-over-year increase. DFS reinforced that point with a May 21, 2026 industry letter on heightened cybersecurity risks from frontier AI models, urging entities to refresh risk assessments, accelerate vulnerability remediation, and add human validation of AI-generated code before deployment.
How Do You Build a Part 500 Compliance Program Step by Step?
If you are re-baselining a Part 500 program in 2026, work in this order. The sequence matters because later requirements depend on artifacts produced by earlier ones.
- Confirm your tier, in writing. Run the Class A tests and the 500.19(a) thresholds against current financials and headcount, including affiliates, and document the conclusion with the numbers you used. Refile the Notice of Exemption within 30 days if your status changed.
- Rebuild the asset inventory first. Section 500.13(a) is the foundation for MFA scoping, access reviews, vulnerability scanning, and encryption. Capture owner, location, classification, support expiration date, and recovery time objective for every asset, and write the policy that says how often it is updated and validated.
- Close MFA to 100%, then document the exceptions. Reconcile the identity provider against the asset inventory to find systems outside SSO: legacy on-premises applications, service consoles, vendor portals, break-glass accounts. Every gap needs either enrollment or a dated, CISO-signed compensating control approval.
- Refresh the risk assessment so it is entity-specific. The Order Express order turned on a generic assessment. Yours should name your threats, your systems, your nonpublic information, and an evaluation of whether existing controls are adequate.
- Instrument the recurring controls. Annual penetration test, risk-based automated scans, annual access reviews with removals evidenced, annual IR and BCDR testing, annual social-engineering training, annual board reporting. Each needs a date, an owner, and a retained artifact.
- Wire the 72/24/30 clocks into the IR plan. Name who declares a “cybersecurity incident,” and rehearse the declaration decision in a tabletop, not just the technical response.
- Reassess third parties against the October 2025 guidance. Due diligence, contract terms, periodic reassessment, and offboarding evidence — including certified data destruction.
- Assemble the certification file as you go. The April 15 filing should be a byproduct of continuous evidence, not a Q1 scramble, and everything supporting it must be retained for five years.
The practical difficulty is not understanding Part 500; it is proving compliance continuously across dozens of controls with named accountability and five-year retention. That is why most institutions of any size now run this on financial services compliance software rather than spreadsheets, mapping Part 500 to the SOC 2, ISO 27001, and NIST CSF work they already do so a single control produces evidence for all of them.
Frequently asked questions
Does 23 NYCRR 500 apply to companies based outside New York?
What is the deadline for the NYDFS annual cybersecurity certification?
What counts as a Class A company under Part 500?
Do small firms with a limited exemption still have to implement MFA?
What are the penalties for violating the NYDFS cybersecurity regulation?
When did the NYDFS MFA requirement actually take effect?
- NYDFS, 23 NYCRR Part 500 regulation text (accessed August 2026)
- NYDFS, Cybersecurity Implementation Timeline for Covered Entities
- NYDFS, Cybersecurity Implementation Timeline for Class A Companies
- NYDFS, Cybersecurity Implementation Timeline for Small Businesses
- NYDFS, Cybersecurity Resource Center
- N.Y. Comp. Codes R. & Regs. tit. 23 § 500.1 (definitions, Cornell LII)
- NYDFS, About Us — supervised institutions and assets
- NYDFS press release: $2 Million Cybersecurity Settlement with PayPal, Inc. (January 23, 2025)
- NYDFS press release: $11.3 Million from Auto Insurance Companies over Data Breaches (November 25, 2024)
- NYDFS press release: More than $19 Million from Auto Insurance Companies over Data Breaches (October 14, 2025)
- NYDFS press release: $2.25 Million Cybersecurity Settlement with Delta Dental (April 30, 2026)
- NYDFS press release and consent order: Order Express, Inc. (August 5, 2026)
- NYDFS Industry Letter: Guidance on Managing Risks Related to Third-Party Service Providers (October 21, 2025)
- NYDFS Industry Letter: Heightened Cybersecurity Risks Associated with Frontier AI Models (May 21, 2026)
- IBM, Cost of a Data Breach Report 2026 (July 29, 2026)
Prove 23 NYCRR 500 Compliance Continuously With Compyl
Compyl’s agentic GRC platform maps Part 500 to the SOC 2, ISO 27001, and NIST work you already do, then continuously monitors MFA coverage, asset inventory completeness, and access reviews so evidence is ready before an exam. Sign the April 15 certification from live data instead of a Q1 scramble.
About this guide. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.