The Complete Guide to the NYDFS Cybersecurity Regulation and Compliance (23 NYCRR Part 500)

Table of Contents

Cybersecurity threats continue to grow, and financial services firms are paying the price more than most. In 2024, the average cost of a data breach in the financial industry rose to $6.08 million—over 20% higher than the global average, according to IBM’s annual report.

What is 23 NYCRR Part 500?

To help reduce risk and protect customer data, the New York Department of Financial Services (NYDFS) introduced the cybersecurity regulation known as 23 NYCRR Part 500. This New York cybersecurity law sets clear standards for licensed financial and insurance businesses operating in the state.

Part 500 became law in 2017 and was updated in 2023 to address today’s more complex and costly cyber risks. The regulation outlines what a strong cybersecurity program should include, such as written policies, access controls, risk assessments, vendor oversight, employee training, and incident reporting. It also requires companies to file an annual cybersecurity certificate of compliance.

At its core, this regulation is about raising the baseline of cybersecurity for the financial services sector and making sure organizations are prepared to act when something goes wrong.

About the Guide

There’s a lot of legal and technical language surrounding the NYDFS Cybersecurity Regulation. We’ve created this guide to make it easier to understand, so you can focus on keeping your business secure and compliant.
Inside, you’ll find:

  • What the NYDFS Cybersecurity Regulation is.
  • Who must comply.
  • What section 500.19 exemptions are and how to qualify.
  • The key cybersecurity requirements, explained.
  • How and when to file with NYDFS.
  • How to approach compliance as expectations continue to evolve.
People working in the financial services industry.

Who Needs to Comply with the NYDFS Cybersecurity Regulation?

If your business holds a license or certificate from the New York Department of Financial Services, you may be required to comply with 23 NYCRR Part 500.

The regulation uses the term “covered entity” to describe organizations and individuals that fall under NYDFS oversight. This includes a range of financial and insurance providers, such as:

  • Banks and credit unions.
  • Insurance companies and brokers.
  • Mortgage lenders and loan servicers.
  • Investment advisors and financial planners.
  • Trust companies.
  • Health insurers.

It also applies to some solo practitioners and small firms.

The deciding factor isn’t just size or structure. If your business is authorized by NYDFS and uses technology to operate or manage non-public information, you are likely within scope.

Understanding whether you qualify as a covered entity is the first step toward meeting the regulation’s requirements. It also allows you to confirm whether you’re eligible for an exemption under section 500.19, which we’ll cover next.

Financial services team reviewing exemptions under the NYDFS cybersecurity regulation.

Section 500.19 Exemptions Under the NYDFS Cybersecurity Regulation

Just because your business is regulated by NYDFS doesn’t mean you have to follow every single part of 23 NYCRR Part 500. Section 500.19 outlines a few ways businesses can qualify for exemptions.

These are usually based on your size, the type of license you hold, or whether you actually work with non-public information.

They fall into two main categories: full exemptions and limited exemptions.

Full Exemptions

A full exemption means you’re not required to comply with most of the regulation. These apply in cases like:

  • Your business is fully covered under the cybersecurity program of a parent or affiliate company.
  • You hold an inactive license and don’t use information systems or handle non-public data.
  • You’re a qualifying reinsurer or annuity society with limited data exposure.

Limited Exemptions (Section 500.19(a))

A limited exemption allows smaller businesses to follow only certain parts of the regulation. You may qualify if your organization meets any of the following:

  • Fewer than 20 employees and independent contractors.
  • Less than $7.5 million in gross annual revenue over the past three years.
  • Less than $15 million in total year-end assets.

Even if you qualify for a limited exemption, you’re still required to:

  • Maintain a basic cybersecurity program, with written policies to protect data and systems.
  • Oversee third-party vendors and conduct vendor risk management.
  • Manage access control and user privileges.
  • Submit annual filings and incident reports.

How to Know If You’re Exempt

NYDFS provides an exemption flowchart to help you determine your status. If you qualify, you must file a notice of exemption within 30 days of becoming eligible.

If you’re not sure which category applies to your business or how to file for a notice of exemption, it may help to speak with a cybersecurity partner who understands the NYDFS Cybersecurity Regulation and can guide you through the technical and operational requirements.

CISO working with a client to comply with the NYDFS cybersecurity regulation.

What Is a CISO?

A Chief Information Security Officer (CISO) is the person responsible for managing a company’s cybersecurity program. Under the NYDFS Cybersecurity Regulation, every covered entity must designate a qualified individual to oversee its cybersecurity policies, systems, and risk management practices.

This doesn’t mean you need to hire a full-time executive. For smaller businesses, you can assign the role to someone internal or contract it out to a third party. What matters is that the person in this role is experienced, has the authority to enforce security practices, and reports regularly to senior leadership or the board.

The CISO is also responsible for reviewing key policies, approving exceptions to technical requirements, and filing an annual cybersecurity report with leadership.

Checking off the requirements of 23 NYCRR Part 500.

What are the Requirements of 23 NYCRR Part 500?

The NYDFS Cybersecurity Regulation outlines specific actions that covered entities must take to protect their systems and data. These requirements apply unless you’re fully exempt and are designed to reflect the level of risk your organization faces.

Here’s what those requirements look like in practice:

Cybersecurity Program (Section 500.2)

Every covered entity must implement a written cybersecurity program that’s tailored to its specific risks. This program should be able to detect, respond to, and recover from cybersecurity events. It also must protect both your information systems and any non-public information you store or transmit. It forms the foundation of your NYDFS cybersecurity compliance.

Cybersecurity Policies (Section 500.3)

You’re required to adopt and implement a set of formal, written cybersecurity policies that align with your program and address areas such as:

  • Data governance and classification.
  • Access controls and identity management.
  • System and network security.
  • Incident response.
  • Business continuity and disaster recovery.
  • Third-party service provider management.
  • Application development and vulnerability management.

These policies must be approved by a senior officer or the board of directors and reviewed annually.

CISO Oversight (Section 500.4)

Your designated CISO must oversee the cybersecurity program and provide a written annual report to executive leadership or the board. The report should highlight program effectiveness, key risks, and any changes made during the year.

Penetration Testing and Vulnerability Assessments (Section 500.5)

You’re expected to test your defenses. This includes:

  • Annual penetration testing to simulate real-world cyber attacks.
  • Regular vulnerability assessments to catch weak spots before attackers do.

Audit Trail (Section 500.6)

Your systems must be able to log and recreate material transactions and security events. Audit trails must be preserved for at least five years and must support both internal reviews and regulatory investigations.

Access Privileges (Section 500.7)

Only the right people should have access to sensitive data. This section requires that access rights be based on job duties and reviewed regularly, especially for users with administrative or privileged access.

Application Security (Section 500.8)

If you develop software in-house or use third-party applications, they must be built and tested with security in mind. That means secure coding practices, software reviews, and vulnerability testing before deployment.

Risk Assessments (Section 500.9)

You’re required to conduct periodic risk assessments to identify vulnerabilities in your systems and processes. These assessments should guide how you design and update your cybersecurity program.

Cybersecurity Personnel and Intelligence (Section 500.10)

Whether your cybersecurity team is internal or outsourced, you need qualified people managing it. You’re also expected to stay informed about new and evolving threats by using up-to-date threat intelligence or working with knowledgeable partners.

Third-Party Service Provider Security Policy (Section 500.11)

Vendors and partners can introduce risk. That’s why covered entities are required to implement a third-party security policy that includes:

  • Risk assessments of vendors.
  • Contractual obligations that require security standards.
  • Ongoing monitoring of vendor access and behavior.

Vendor integrations are common in the financial services space, which makes this especially critical.

Multi-Factor Authentication (Section 500.12)

You must use multi-factor authentication for remote access and for any system that contains non-public information. An alternative can be approved in writing by your CISO, but it must offer comparable protection.

Limitations on Data Retention (Section 500.13)

Don’t keep sensitive data longer than you need to. This section requires that non-public information be securely disposed of once it’s no longer needed for business or legal reasons.

Training and Monitoring (Section 500.14)

Employees must receive cybersecurity awareness training at least once a year. You’re also required to monitor systems and user activity to detect unauthorized access.

Encryption of Non-public Information (Section 500.15)

Data must be encrypted in transit and at rest. If that’s not possible, your CISO must approve alternative control. Those controls must be documented and reviewed regularly.

Incident Response Plan (Section 500.16)

You’re required to maintain a cybersecurity incident response plan that outlines:

  • How you’ll detect, respond to, and recover from cybersecurity events.
  • Who is responsible for what.
  • How communication will be handled internally and externally.
  • How incidents will be reported to regulators and stakeholders.

This plan should be tested and updated regularly.

Annual Certification and Reporting (Section 500.17)

Two key obligations fall under this section:

  1. Cybersecurity Certificate of Compliance – Filed annually with NYDFS by April 15 to confirm you’re meeting the requirements of the regulation
  2. NYDFS 72-Hour Reporting Rule – Certain types of cybersecurity events must be reported to the Superintendent within 72 hours of discovery

Timely reporting and accurate documentation are critical parts of your compliance obligations.

Record Maintenance – New as of 2023 (Section 500.18)

You must maintain detailed records of your cybersecurity program, risk assessments, incident response activities, training logs, and other compliance efforts. These records must be retained for at least five years and made available to NYDFS upon request.

Team reviewing changes of the NYDFS cybersecurity regulation.

What Changed in the 2023 NYDFS Cybersecurity Regulation Amendments

In late 2023, the NYDFS made important updates to 23 NYCRR Part 500. These changes reflect how fast cybersecurity risks are advancing and how much more is expected of regulated businesses today.

Here’s what’s new:

1. Greater Accountability at the Executive Level

The NYDFS Cybersecurity Regulation now requires more direct involvement from company leadership:

  • The CISO’s annual report must now include detailed information on the company’s risk posture, cybersecurity program effectiveness, and material changes or incidents.
  • Boards of directors must have enough cybersecurity knowledge to understand what’s being reported and ask informed questions.

This reinforces that cybersecurity is a shared responsibility, from the IT department to the boardroom.

2. New Requirements for Large Companies (Class A Designation)

If your organization has over 2,000 employees or more than $1 billion in annual gross revenue across all affiliates, it’s now classified as a Class A company. This comes with added compliance requirements, including:

  • Independent audits of your cybersecurity program.
  • Biannual penetration testing instead of annual.
  • Formal, written plans for incident response and business continuity.
  • Additional documentation and review obligations for senior leadership.

3. Tighter Technical Safety Measures

Several technical requirements under 23 NYCRR Part 500 have been tightened or clarified:

  • Multi-factor authentication (MFA) is now mandatory for all remote access, privileged accounts, and access to third-party applications.
  • Companies must maintain a complete and up-to-date asset inventory, including hardware and software.
  • Encryption requirements are more explicit. If encryption at rest or in transit isn’t feasible, compensating controls must be documented and approved by the CISO.

4. Clarification for Exempt Entities

Even if your business qualifies for a limited exemption under Section 500.19(a), you’re still expected to maintain a baseline level of cybersecurity. That includes:

  • Implementing multi-factor authentication.
  • Providing annual cybersecurity awareness training.
  • Overseeing third-party vendors with access to non-public information.
  • Filing an annual cybersecurity certificate of compliance.

Failure to meet these obligations can still result in enforcement action, even if you’re partially exempt.

5. Certification Now Covers the Full Calendar Year

One of the most important changes involves the cybersecurity certificate of compliance due each April. Previously, the filing confirmed your organization was compliant at the time of submission.

Now, you’re certifying that you were materially compliant throughout the entire prior calendar year. If your organization was not fully compliant, you’re required to file an Acknowledgment of Noncompliance. This must include an explanation of what was missed and your remediation plan.

6. Additional Filing and Compliance Dates

Several new deadlines were introduced as part of the 2023 updates to 23 NYCRR Part 500. These apply to all covered entities, including those with a Section 500.19 exemption:

  • By April 29, your cybersecurity policies and risk assessments must be reviewed and approved by a senior officer or the board.
  • By November 1, all employees must complete their annual cybersecurity awareness training.
  • Starting May 1, 2025, your organization must review user access privileges at least once per year.
  • Starting November 1, 2025, you must maintain a current inventory of your information systems.

Staying ahead of these deadlines is critical not just for compliance, but for protecting your business and building trust with regulators and customers alike.

Person getting expert help from an MSP for the NYDFS cybersecurity regulation.

When to Seek Expert Help for 23 NYCRR Part 500

The requirements in the NYDFS Cybersecurity Regulation are meant to scale with your business, but that doesn’t always make them easy to manage, especially for smaller teams or businesses without in-house cybersecurity staff.

You may want to bring in outside help if:

  • You’re unsure whether your existing systems meet the regulation’s requirements.
  • You don’t have the resources to handle risk assessments, policy reviews, or user access audits internally.
  • You need to build or formalize your cybersecurity program from the ground up.
  • You want help reviewing your compliance posture before the next annual certification.

Support can come from many places: internal IT teams, legal counsel, or a managed service provider (MSP) that understands both the technical side of cybersecurity and the expectations of NYDFS cybersecurity compliance.

Even if you’re confident in your day-to-day operations, working with an experienced partner can help you stay ahead of deadlines, avoid blind spots, and focus on what you do best.

Conclusion

Cybersecurity expectations are higher than ever, and the NYDFS cybersecurity regulations continue to evolve to meet the risks. Whether you’re reviewing your current program, filing for a Section 500.19 exemption, or preparing your next cybersecurity certificate of compliance, the key is staying organized, informed, and proactive.

This guide gave you the essentials; what the regulation covers, who it applies to, and what steps to take. From here, the next move is making sure your cybersecurity program not only checks the boxes but protects your business.

Frequently Asked Questions

Section 500.15 requires companies to protect non-public information by using encryption, which means turning data into a code so only authorized people can read it. This applies to data that’s stored and data that’s being sent. If encryption isn’t possible, another strong method can be used, but it must be approved by the CISO.

The 72-hour rule means that covered entities must notify NYDFS within 72 hours after determining a cybersecurity event must be reported. This includes incidents that impact business operations, expose non-public information, or require notice to another regulator. The clock starts when the organization confirms the event is reportable, not when the breach occurs.

Penalties for noncompliance can include fines, public enforcement actions, and ongoing regulatory oversight. NYDFS has the authority to investigate cybersecurity failures and issue penalties if a company fails to meet the regulation’s requirements, delays reporting an incident, or files inaccurate certifications.

Non-public information includes data that could cause harm if exposed—like Social Security numbers, driver’s license details, account numbers, or health information. “Material” refers to data that is especially sensitive or essential to customers or the business. Protecting this information is a core goal of the regulation.

Under 23 NYCRR Part 500, multi-factor authentication (MFA) is required for remote access and sensitive systems. MFA adds a second layer of security, like a code sent to your phone or a fingerprint, on top of a password. The 2023 update expanded this requirement to cover more use cases, including access to cloud apps and administrative accounts.

SPECIALIZED SUPPORT FOR FINANCIAL SERVICES

Compliance Made Simple

Expert services to help you meet every requirement accurately, on time, and with less effort from your team.

Contact us to learn more.

Compliance Doesn’t Have to Be Complicated.

At SOHO Solutions, we build and maintain cybersecurity programs that align with 23 NYCRR Part 500, including the documentation, policies, and processes you need to stay compliant.

Our team supports financial and insurance organizations with practical services and expert guidance, so you can meet requirements with confidence.

Fill out the form and we’ll get back to you to talk through how we can support your team.

Contact Us to Learn More.

We’re Here to Help with
NY DFS Compliance.

Fill out the form and we’ll get back to you to talk through how we can support your team.