Unlike many laws that imply security expectations, NYDFS 500 explicitly defines what covered organizations must do - from risk assessments and technical controls to executive accountability and incident reporting.
If your organization is regulated by NYDFS, cybersecurity is a formal compliance obligation with real enforcement consequences. Limited exemptions exist for the smallest entities, but exempt is not unregulated.
23 NYCRR 500 is the New York Department of Financial Services (NYDFS) Cybersecurity Regulation - one of the most comprehensive and prescriptive cybersecurity regulations in the United States (NYDFS).
The regulation was strengthened by the Second Amendment, adopted November 1, 2023. Its transition periods have all expired - the last, covering multi-factor authentication (§500.12) and asset inventory (§500.13(a)), ended November 1, 2025 - so the full amended regulation is now in force (23 NYCRR 500 as amended). This page reflects the amended rule.
NYDFS 500 goes further than most frameworks by making specific controls mandatory, requiring executive certifications, and imposing strict incident reporting timelines.
NYDFS 500 applies to Covered Entities regulated by the New York Department of Financial Services, including:
It also impacts third-party service providers supporting NYDFS-regulated entities, and vendors with access to their systems or Nonpublic Information - covered entities must impose security requirements on you by policy and contract.
**Limited exemptions exist (§500.19(a)):** covered entities with fewer than 20 employees and independent contractors, less than $7.5 million in gross annual revenue in each of the last three fiscal years, or less than $15 million in year-end total assets qualify for limited exemptions from parts of the regulation. Full exemptions cover narrow cases, such as entities protected under a parent company's compliant program. Exempt entities still carry core obligations - and still file with DFS.
If you operate in New York's financial ecosystem, or support those who do, NYDFS expectations likely apply to you.
NYDFS focuses on protecting Nonpublic Information (NPI), which includes:
From an IT perspective, this includes nearly all business-critical systems, cloud platforms, and third-party integrations.
NYDFS 500 overlaps with, but is distinct from, the other financial data frameworks.
GLBA and the FTC Safeguards Rule set the federal baseline for financial data protection. FFIEC guidance shapes examination expectations. NIST CSF and ISO 27001 provide best-practice control structures.
NYDFS goes further than all of them in three ways: it makes specific controls mandatory, it requires executive certifications, and it imposes strict incident and extortion-payment reporting timelines.
NYDFS 500 is unusually explicit. Key requirements include:
Cybersecurity program and policies. A formal cybersecurity program supported by written policies, risk-based controls, and ongoing monitoring and improvement. Policies must reflect how systems actually operate, not theoretical controls.
Risk assessments. Regular, documented risk assessments that drive control decisions and are updated as the environment changes. Risk assessments are foundational, not optional.
A designated CISO - who may be outsourced. Each covered entity must designate a Chief Information Security Officer. Under §500.4, the CISO may be employed by an affiliate or a third-party service provider if the covered entity meets three conditions: it retains responsibility for compliance, it designates a senior member of its own personnel responsible for direction and oversight of the third party, and it requires the provider to maintain a cybersecurity program that protects the covered entity in accordance with the regulation. This is the same three-condition structure as the FTC Safeguards Rule's Qualified Individual provision - and the regulatory basis for a fractional CISO arrangement.
Identity and access management. Role-based access controls, least-privilege permissions, multi-factor authentication (§500.12, now fully in force), secure remote access, and regular access reviews.
Data security and encryption. NPI must be encrypted in transit over external networks and at rest (§500.15). For data at rest only, where the covered entity determines encryption is infeasible, the CISO may approve compensating controls in writing, reviewed at least annually. There is no compensating-controls alternative for encryption in transit. Key management, retention, and disposal controls round out the requirement.
Logging, monitoring, and incident detection. Audit logging, monitoring for cybersecurity events, the ability to detect and respond to incidents, and documentation of investigation and response activities.
Incident response and reporting - three clocks. Covered entities must maintain a written incident response plan and:
1. 72 hours: notify NYDFS as promptly as possible, and no later than 72 hours after determining that a cybersecurity incident has occurred (§500.17(a)). The clock runs from determination, not from the event itself - an operationally critical distinction. 2. 24 hours: if an extortion payment is made in connection with a cybersecurity event, notify the superintendent within 24 hours of payment (§500.17(c)). 3. 30 days: after an extortion payment, file a written description of why payment was necessary, alternatives considered, and all diligence performed - including sanctions-compliance diligence (§500.17(c)).
Third-party risk management. Vendor cybersecurity policies, due diligence before onboarding, ongoing monitoring, and contractual security requirements. Third-party failures are an enforcement focus.
Executive accountability and annual certification. Regular cybersecurity reporting to leadership, plus an annual filing to DFS signed by the covered entity's highest-ranking executive and its CISO (§500.17(b)). An entity that cannot certify material compliance files a written acknowledgment of noncompliance instead, identifying the gaps and its remediation plan. Cybersecurity is explicitly a board- and executive-level responsibility.
NYDFS actively enforces 23 NYCRR 500. Violations can result in significant financial penalties, consent orders, public enforcement actions, mandatory remediation, and reputational damage.
DFS enforcement actions have cited issues such as:
NYDFS 500 reinforces a key principle: cybersecurity is an enterprise risk that must be governed, measured, and reported.
Organizations that align NYDFS requirements with NIST CSF, ISO 27001, SOC 2, and GLBA/FTC Safeguards tend to achieve stronger, more defensible security programs overall.
The annual certification makes this concrete - a signature from your highest-ranking executive and CISO is governance, not paperwork.
Here is the key takeaway: NYDFS 500 does not ask whether you tried. It asks whether controls exist, operate, and are provable.
Most required controls are standard cybersecurity practices - widely adopted and highly effective when enforced consistently.
The difference is accountability and evidence. Someone signs, every year, and the signature has consequences.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment tests your program section by section against 23 NYCRR 500 as amended - including the certification your highest-ranking executive and CISO must sign each year.
Determine whether NYDFS regulates you, whether a §500.19 limited exemption applies, which systems and data are in scope, and which vendors are involved. Exemption tiers changed with the Second Amendment - check the current thresholds, not the ones you remember.
Document threats and vulnerabilities, existing controls, control gaps, and remediation priorities. Every other NYDFS requirement is calibrated to this assessment.
At minimum: MFA across systems (§500.12), encryption of NPI in transit and at rest (§500.15), endpoint and email security, logging and monitoring, and secure remote access. Document any at-rest compensating controls with written CISO approval and annual review.
Ensure the incident response plan exists in writing, the 72-hour, 24-hour, and 30-day reporting obligations are built into it, roles and escalation paths are clear, and documentation processes are in place before an incident tests them.
Confirm vendors meet NYDFS expectations, contracts include security requirements, and monitoring is ongoing. Your third-party service provider policy is itself a required artifact.
Prepare regular cybersecurity reports, risk summaries, and the annual certification - or, where material compliance cannot be certified, the written acknowledgment of noncompliance with its remediation plan. Decide which document you will be able to sign well before the filing is due, not while it is.
If you are licensed, chartered, or registered under New York banking, insurance, or financial services law - banks, insurers, mortgage servicers, money transmitters, virtual currency businesses - you are a Covered Entity. If you serve those entities as a vendor, the regulation reaches you through their mandatory third-party requirements.
Possibly partially. Limited exemptions apply to covered entities with fewer than 20 employees and independent contractors, less than $7.5 million in gross annual revenue in each of the last three fiscal years, or less than $15 million in year-end total assets (§500.19(a)). Limited means limited - core obligations remain, and the exemption must be filed with DFS.
As promptly as possible, and no later than 72 hours after determining that a cybersecurity incident has occurred (§500.17(a)). The clock starts at determination, not at the attack - which makes your detection and triage process part of your legal compliance.
Two more clocks start. Notice of the extortion payment goes to the superintendent within 24 hours, and within 30 days you must file a written description of why payment was necessary, what alternatives you considered, and all diligence performed - including sanctions compliance (§500.17(c)).
Yes. §500.4 expressly permits the CISO to be employed by an affiliate or a third-party service provider - if you retain responsibility for compliance, designate a senior member of your own personnel to direct and oversee the provider, and require the provider to maintain a program that protects you. A fractional CISO built on those three conditions is a compliant structure, not a workaround.
Encryption of NPI is required in transit over external networks and at rest (§500.15). Compensating controls are available only for data at rest, only where encryption is infeasible, and only with written CISO approval reviewed at least annually. There is no compensating-controls path for data in transit.
It depends on your exemption status, current controls, and how much of the required documentation exists. We publish no pricing because honest numbers require that context. Firm quote before any work begins. The conversation costs nothing.
Start by knowing what you could certify today. Our Cyber Risk & Compliance Gap Assessment tests your environment against 23 NYCRR 500 section by section and gives you the prioritized gap list - months before the annual filing asks you to sign.
Official source: New York State Department of Financial Services
Secondary source: 23 NYCRR Part 500 as amended (official text)
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25