What Is NYDFS 23 NYCRR 500 and Why It Matters

Unlike many laws that imply security expectations, NYDFS 500 explicitly defines what covered organizations must do - from risk assessments and technical controls to executive accountability and incident reporting.

If your organization is regulated by NYDFS, cybersecurity is a formal compliance obligation with real enforcement consequences. Limited exemptions exist for the smallest entities, but exempt is not unregulated.

What It Is

23 NYCRR 500 is the New York Department of Financial Services (NYDFS) Cybersecurity Regulation - one of the most comprehensive and prescriptive cybersecurity regulations in the United States (NYDFS).

The regulation was strengthened by the Second Amendment, adopted November 1, 2023. Its transition periods have all expired - the last, covering multi-factor authentication (§500.12) and asset inventory (§500.13(a)), ended November 1, 2025 - so the full amended regulation is now in force (23 NYCRR 500 as amended). This page reflects the amended rule.

NYDFS 500 goes further than most frameworks by making specific controls mandatory, requiring executive certifications, and imposing strict incident reporting timelines.

Who It Applies To

NYDFS 500 applies to Covered Entities regulated by the New York Department of Financial Services, including:

  • Banks and credit unions: chartered or licensed in New York.
  • Insurance companies and brokers: the largest covered population.
  • Mortgage lenders and servicers: licensed under New York banking law.
  • Money transmitters: including payments businesses.
  • Virtual currency businesses: BitLicense holders are covered entities.
  • Financial institutions licensed or chartered in New York: the catch-all that defines scope.

It also impacts third-party service providers supporting NYDFS-regulated entities, and vendors with access to their systems or Nonpublic Information - covered entities must impose security requirements on you by policy and contract.

**Limited exemptions exist (§500.19(a)):** covered entities with fewer than 20 employees and independent contractors, less than $7.5 million in gross annual revenue in each of the last three fiscal years, or less than $15 million in year-end total assets qualify for limited exemptions from parts of the regulation. Full exemptions cover narrow cases, such as entities protected under a parent company's compliant program. Exempt entities still carry core obligations - and still file with DFS.

If you operate in New York's financial ecosystem, or support those who do, NYDFS expectations likely apply to you.

What Information Is Regulated

NYDFS focuses on protecting Nonpublic Information (NPI), which includes:

  • Personally identifiable information (PII): names combined with identifying data elements.
  • Financial account and transaction data: the core of the covered business.
  • Business confidential information: whose disclosure would cause material harm.
  • Health information: where covered entities hold it.
  • Authentication data and credentials: the keys attackers actually want.

From an IT perspective, this includes nearly all business-critical systems, cloud platforms, and third-party integrations.

Relation to Other Frameworks

NYDFS 500 overlaps with, but is distinct from, the other financial data frameworks.

GLBA and the FTC Safeguards Rule set the federal baseline for financial data protection. FFIEC guidance shapes examination expectations. NIST CSF and ISO 27001 provide best-practice control structures.

NYDFS goes further than all of them in three ways: it makes specific controls mandatory, it requires executive certifications, and it imposes strict incident and extortion-payment reporting timelines.

IT Requirements

NYDFS 500 is unusually explicit. Key requirements include:

Cybersecurity program and policies. A formal cybersecurity program supported by written policies, risk-based controls, and ongoing monitoring and improvement. Policies must reflect how systems actually operate, not theoretical controls.

Risk assessments. Regular, documented risk assessments that drive control decisions and are updated as the environment changes. Risk assessments are foundational, not optional.

A designated CISO - who may be outsourced. Each covered entity must designate a Chief Information Security Officer. Under §500.4, the CISO may be employed by an affiliate or a third-party service provider if the covered entity meets three conditions: it retains responsibility for compliance, it designates a senior member of its own personnel responsible for direction and oversight of the third party, and it requires the provider to maintain a cybersecurity program that protects the covered entity in accordance with the regulation. This is the same three-condition structure as the FTC Safeguards Rule's Qualified Individual provision - and the regulatory basis for a fractional CISO arrangement.

Identity and access management. Role-based access controls, least-privilege permissions, multi-factor authentication (§500.12, now fully in force), secure remote access, and regular access reviews.

Data security and encryption. NPI must be encrypted in transit over external networks and at rest (§500.15). For data at rest only, where the covered entity determines encryption is infeasible, the CISO may approve compensating controls in writing, reviewed at least annually. There is no compensating-controls alternative for encryption in transit. Key management, retention, and disposal controls round out the requirement.

Logging, monitoring, and incident detection. Audit logging, monitoring for cybersecurity events, the ability to detect and respond to incidents, and documentation of investigation and response activities.

Incident response and reporting - three clocks. Covered entities must maintain a written incident response plan and:

1. 72 hours: notify NYDFS as promptly as possible, and no later than 72 hours after determining that a cybersecurity incident has occurred (§500.17(a)). The clock runs from determination, not from the event itself - an operationally critical distinction. 2. 24 hours: if an extortion payment is made in connection with a cybersecurity event, notify the superintendent within 24 hours of payment (§500.17(c)). 3. 30 days: after an extortion payment, file a written description of why payment was necessary, alternatives considered, and all diligence performed - including sanctions-compliance diligence (§500.17(c)).

Third-party risk management. Vendor cybersecurity policies, due diligence before onboarding, ongoing monitoring, and contractual security requirements. Third-party failures are an enforcement focus.

Executive accountability and annual certification. Regular cybersecurity reporting to leadership, plus an annual filing to DFS signed by the covered entity's highest-ranking executive and its CISO (§500.17(b)). An entity that cannot certify material compliance files a written acknowledgment of noncompliance instead, identifying the gaps and its remediation plan. Cybersecurity is explicitly a board- and executive-level responsibility.

Why It Matters

NYDFS actively enforces 23 NYCRR 500. Violations can result in significant financial penalties, consent orders, public enforcement actions, mandatory remediation, and reputational damage.

DFS enforcement actions have cited issues such as:

  • Inadequate risk assessments: the document every other control decision depends on.
  • Missing or weak MFA: now fully mandatory with the §500.12 transition period expired.
  • Poor vendor oversight: third-party policies that exist on paper only.
  • Insufficient logging and monitoring: incidents that could not be reconstructed.
  • Failure to report incidents on time: the 72-hour clock is checked against the evidence.
  • Gaps between policy and reality: certifying compliance a later exam disproves.

How It Fits Into Cyber Risk Management

NYDFS 500 reinforces a key principle: cybersecurity is an enterprise risk that must be governed, measured, and reported.

Organizations that align NYDFS requirements with NIST CSF, ISO 27001, SOC 2, and GLBA/FTC Safeguards tend to achieve stronger, more defensible security programs overall.

The annual certification makes this concrete - a signature from your highest-ranking executive and CISO is governance, not paperwork.

How We Help With NYDFS Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment tests your program section by section against 23 NYCRR 500 as amended - including the certification your highest-ranking executive and CISO must sign each year.

How to Prepare

  1. 01Confirm applicability and scope

    Determine whether NYDFS regulates you, whether a §500.19 limited exemption applies, which systems and data are in scope, and which vendors are involved. Exemption tiers changed with the Second Amendment - check the current thresholds, not the ones you remember.

  2. 02Conduct a formal cyber risk assessment

    Document threats and vulnerabilities, existing controls, control gaps, and remediation priorities. Every other NYDFS requirement is calibrated to this assessment.

  3. 03Implement the required technical controls

    At minimum: MFA across systems (§500.12), encryption of NPI in transit and at rest (§500.15), endpoint and email security, logging and monitoring, and secure remote access. Document any at-rest compensating controls with written CISO approval and annual review.

  4. 04Formalize incident response and the three reporting clocks

    Ensure the incident response plan exists in writing, the 72-hour, 24-hour, and 30-day reporting obligations are built into it, roles and escalation paths are clear, and documentation processes are in place before an incident tests them.

  5. 05Strengthen vendor risk management

    Confirm vendors meet NYDFS expectations, contracts include security requirements, and monitoring is ongoing. Your third-party service provider policy is itself a required artifact.

  6. 06Establish executive oversight and certification readiness

    Prepare regular cybersecurity reports, risk summaries, and the annual certification - or, where material compliance cannot be certified, the written acknowledgment of noncompliance with its remediation plan. Decide which document you will be able to sign well before the filing is due, not while it is.

Frequently Asked Questions

Does NYDFS 23 NYCRR 500 apply to my business?

If you are licensed, chartered, or registered under New York banking, insurance, or financial services law - banks, insurers, mortgage servicers, money transmitters, virtual currency businesses - you are a Covered Entity. If you serve those entities as a vendor, the regulation reaches you through their mandatory third-party requirements.

We are a small firm. Are we exempt?

Possibly partially. Limited exemptions apply to covered entities with fewer than 20 employees and independent contractors, less than $7.5 million in gross annual revenue in each of the last three fiscal years, or less than $15 million in year-end total assets (§500.19(a)). Limited means limited - core obligations remain, and the exemption must be filed with DFS.

When do we have to report an incident to NYDFS?

As promptly as possible, and no later than 72 hours after determining that a cybersecurity incident has occurred (§500.17(a)). The clock starts at determination, not at the attack - which makes your detection and triage process part of your legal compliance.

What if we pay a ransom?

Two more clocks start. Notice of the extortion payment goes to the superintendent within 24 hours, and within 30 days you must file a written description of why payment was necessary, what alternatives you considered, and all diligence performed - including sanctions compliance (§500.17(c)).

Can our CISO be outsourced?

Yes. §500.4 expressly permits the CISO to be employed by an affiliate or a third-party service provider - if you retain responsibility for compliance, designate a senior member of your own personnel to direct and oversee the provider, and require the provider to maintain a program that protects you. A fractional CISO built on those three conditions is a compliant structure, not a workaround.

Is encryption mandatory, or can we use compensating controls?

Encryption of NPI is required in transit over external networks and at rest (§500.15). Compensating controls are available only for data at rest, only where encryption is infeasible, and only with written CISO approval reviewed at least annually. There is no compensating-controls path for data in transit.

What does NYDFS compliance cost?

It depends on your exemption status, current controls, and how much of the required documentation exists. We publish no pricing because honest numbers require that context. Firm quote before any work begins. The conversation costs nothing.

Where do we start?

Start by knowing what you could certify today. Our Cyber Risk & Compliance Gap Assessment tests your environment against 23 NYCRR 500 section by section and gives you the prioritized gap list - months before the annual filing asks you to sign.

Official source

Official source: New York State Department of Financial Services

Secondary source: 23 NYCRR Part 500 as amended (official text)

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25