Field Guide

NYDFS Cybersecurity Compliance (23 NYCRR 500): A Practitioner's Guide

The short version

23 NYCRR Part 500 is the New York Department of Financial Services cybersecurity rule. An entity holding a New York banking, insurance, or financial-services license is a Covered Entity and owes a written, risk-based cybersecurity program and policy, a qualified CISO, a periodic risk assessment, multi-factor authentication, encryption of nonpublic information, penetration testing and vulnerability scanning, a tested incident response plan, due diligence over third-party service providers, a 72-hour notice to the Department when a cybersecurity event occurs, and an annual filing that the highest-ranking executive and the CISO both sign. There is no blanket small-company carve-out. The limited exemptions reduce the list of obligations without removing it.

23 NYCRR Part 500 imposes cybersecurity program, governance, control, reporting, and certification obligations on every entity licensed by the New York Department of Financial Services. The New York authorization is the trigger for coverage; the question that follows is which version of the obligations the entity carries. The regulation reaches beyond the technology function, placing named duties on the board or senior governing body and on the certifying executive.

This guide takes the regulation in the order a practitioner applies it: who is covered, where the limited exemptions sit, the program and the policy, the CISO, the risk assessment, the technical controls the rule names by hand, the incident response plan, the 72-hour notice, third-party security, and the annual certification. The underlying structure is the identify-protect-detect-respond-recover model used across cybersecurity practice, and Part 500's requirements map onto it.

Who is a Covered Entity

A Covered Entity is any person or business operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation, or similar authorization under New York's Banking Law, Insurance Law, or Financial Services Law. The definition is broad. It covers state-chartered banks, branches of foreign banks licensed in New York, insurers and producers, mortgage bankers and brokers, money transmitters, check cashers, and licensed virtual-currency businesses, among others.

The obligation tracks the New York authorization, not where the company sits. A firm headquartered elsewhere that holds a New York license is a Covered Entity for that licensed activity. A firm with several licenses carries the obligation across all of them. The first step is an authorization inventory listing every New York license the entity holds, since each authorization independently establishes Covered Entity status.

The limited exemptions, and what they do not remove

There is no exemption for being small in the everyday sense. What the rule provides is a set of limited exemptions, and the most common one turns on size. A Covered Entity can claim it when it falls under the thresholds the rule sets for employee count, gross annual revenue from New York operations, and year-end total assets. Other limited exemptions cover entities that do not operate their own information systems and do not control or possess nonpublic information, certain captive insurers, and certain reinsurers.

A limited exemption reduces the scope of the obligations rather than removing them. An entity that qualifies still owes the core of the regulation, and to claim any exemption it must file a notice of exemption with the Department. The term "exemption" in Part 500 does not signify that the rule ceases to apply.

Still applies under the common limited exemptionRelief the limited exemption provides
A written cybersecurity program based on the risk assessmentSome staffing and program-depth requirements scale down for the smallest entities
A written cybersecurity policyCertain ongoing-monitoring and testing obligations are eased
Access controls and limitations on access privilegesThe full penetration-testing and continuous-monitoring program may not be required at the same depth
The periodic risk assessmentSome training and awareness obligations are reduced
Third-party service provider oversightNo relief. The obligation stands.
The 72-hour notice of a cybersecurity eventNo relief. The obligation stands.
The annual filing with the DepartmentNo relief. The obligation stands.

The 72-hour notice and the annual filing survive every limited exemption. The size-based exemption affects the required depth of the program; it does not affect the entity's supervisory status with the Department.

The cybersecurity program and the cybersecurity policy

The regulation requires two distinct documents. The cybersecurity program is the working set of controls and processes that protect the confidentiality, integrity, and availability of the Covered Entity's information systems. It has to be built on the risk assessment and it has to perform the core security functions: identify cyber risks, use defensive infrastructure and policies to protect against them, detect cybersecurity events, respond to those events to mitigate harm, recover and restore normal operations, and fulfill the regulatory reporting obligations. That list is the identify-protect-detect-respond-recover model written into a regulation.

The cybersecurity policy is the written governance layer that sits above the program. It has to be approved by a senior officer or the board, and it has to address the areas the rule names: information security, data governance and classification, asset inventory and device management, access controls and identity management, business continuity and disaster recovery, systems operations and availability, network security and monitoring, physical security, customer data privacy, vendor and third-party management, risk assessment, and incident response. The program is the set of controls the institution operates; the policy is the institution's written commitment to those controls, carried at senior sign-off.

The CISO

Every Covered Entity has to designate a qualified individual responsible for overseeing, implementing, and enforcing the cybersecurity program and policy. The rule calls this person the Chief Information Security Officer, and the role can be filled by an employee, an affiliate, or a third-party service provider. When the function is outsourced, the Covered Entity keeps responsibility, has to designate a senior member of its own staff to direct and oversee the third party, and has to require that the third party maintains a program meeting the regulation.

The CISO has to report in writing to the senior governing body, at least annually, on the cybersecurity program and on material cybersecurity risks. Under the amended rule the CISO also has to have adequate authority to act, including the ability to put plans in front of the board and to direct sufficient resources to manage the risks. The report also serves an evidentiary function: it is the record that the institution's governing body was informed of the risks.

The risk assessment

The risk assessment is the foundational document. The cybersecurity program, the policy, and the controls are all required to be based on it, so a stale or shallow assessment weakens every requirement built on it. It has to be conducted periodically and updated when business or technology changes materially. It has to be carried out under written policies and procedures, and it has to produce criteria for evaluating identified risks, criteria for assessing how existing controls address them, and a description of how the entity will mitigate or accept the risks that remain.

In practice the assessment is the likelihood-times-impact analysis used across cybersecurity programs generally. The entity catalogs the assets and the nonpublic information, identifies the threats and vulnerabilities, scores the residual risk after existing controls, and decides for each risk whether to mitigate, transfer, accept, or avoid it. The regulation adds the requirement that those decisions be documented and that the program trace back to them.

The controls the rule names by hand

Most of Part 500 is risk-based, meaning the depth of a control varies with what the risk assessment shows. A subset of controls is written closer to a flat requirement, with limited scope for the entity's own judgment about whether to implement them.

ControlWhat the regulation requires
Multi-factor authenticationMFA for any individual accessing the Covered Entity's information systems. The CISO may approve a reasonably equivalent or more secure compensating control in writing, under narrow conditions. Stolen single-factor credentials are a recurring breach entry point, which is the basis for the narrow drafting of this control.
EncryptionEncryption of nonpublic information both in transit over external networks and at rest. Where encryption is infeasible, the entity may use effective alternative controls reviewed and approved by the CISO, with that determination revisited over time.
Penetration testingPenetration testing of information systems based on the risk assessment, conducted at the cadence the rule sets, by qualified internal or external testers.
Vulnerability assessmentsAutomated scans and manual review of systems designed to detect new vulnerabilities, run on a regular basis and after material changes, with timely remediation.
Access privilegesLimit and periodically review access privileges, apply the principle of least privilege, and give particular scrutiny to privileged accounts.
Audit trailMaintain systems that can reconstruct material financial transactions and detect and respond to cybersecurity events, with records retained for the periods the rule sets.
Training and monitoringRegular cybersecurity awareness training for all personnel, updated to reflect current risks, plus monitoring of authorized user activity.
Data retention and disposalPolicies for the secure disposal of nonpublic information that is no longer needed, except where retention is otherwise required.

Incident response and the 72-hour notice to DFS

The Covered Entity has to maintain a written incident response plan designed to respond to and recover from any cybersecurity event that materially affects the confidentiality, integrity, or availability of its information systems or the continuing functionality of its business. The amended rule adds a written business continuity and disaster recovery plan and periodic testing of the response capability. An untested plan does not satisfy the testing requirement, and examiners review the records of exercises the entity has conducted.

The notice obligation is frequently misread. A Covered Entity must notify the Superintendent of the Department as promptly as possible and no later than 72 hours after determining that a cybersecurity event has occurred. The clock starts on the determination, not the discovery, but a Covered Entity cannot sit on a determination to delay the clock. A reportable event includes:

The amended rule also requires notice to the Department when the entity makes an extortion or ransom payment connected to a cybersecurity event, with a follow-on written description of the reasons within a set window. The 72-hour notice is the most widely known of these obligations, and the related filing obligations that accompany it are the ones more often missed.

Third-party service provider security

A cybersecurity event at a vendor holding the Covered Entity's nonpublic information remains the Covered Entity's obligation. The regulation requires written third-party service provider policies and procedures, based on the risk assessment, that govern the security practices of the vendors that have access to the entity's information systems or nonpublic information. Those policies have to address how the entity identifies and risk-assesses its vendors, the minimum security practices a vendor must meet to do business, the due diligence used to evaluate them, and the periodic reassessment of their adequacy.

The rule points specifically at the contract terms a Covered Entity should require where applicable: the vendor's use of multi-factor authentication and encryption, notice to the Covered Entity when a cybersecurity event affects its data, and representations about the vendor's own cybersecurity. Because the Covered Entity does not directly operate a vendor's controls, the regulation addresses this supply-chain exposure through documented policies and contract terms.

The annual certification of compliance

Each year a Covered Entity has to submit a written statement to the Department covering the prior calendar year. Under the amended rule the entity either certifies material compliance with the regulation or, where it was not in compliance, submits a written acknowledgment of noncompliance that identifies the areas, systems, or processes that did not comply and a remediation timeline. The submission has to be signed by the highest-ranking executive and the CISO, and the entity has to keep the records, schedules, and supporting data that back it for the period the rule requires.

The certification attaches named individual signatures to the entity's compliance position, and a filing unsupported by retained evidence creates exposure if the position is later tested. The acknowledgment option added by the amended rule is the route available to an entity with known gaps: an accurate acknowledgment paired with a remediation timeline, rather than a certification of compliance the entity cannot evidence.

The phased compliance timeline

The Second Amendment to 23 NYCRR Part 500, adopted on November 1, 2023, phased its new requirements across two years rather than switching them on at once. CISO board reporting (500.4), encryption (500.15), and incident-response and business-continuity testing (500.16) took effect on November 1, 2024. A further set took effect on May 1, 2025. The final phase took effect on November 1, 2025: expanded multi-factor authentication for any individual accessing any information system (500.12), and the asset-inventory requirement (500.13). Those were covered in the annual certification due April 15, 2026, so they are in force now, not pending.

A readiness checklist

The items a Covered Entity confirms before the next annual filing, and again after any material change to the business or systems:

Part 500 is assessed on documented evidence. A program that is documented, tested, and traceable to a current risk assessment satisfies the standard; a set of policies with no record of exercise does not. The regulation is long and detailed, and its two operative requirements are that the Covered Entity protect the nonpublic information it holds and retain the records demonstrating that it did.

Common questions

Who has to comply with 23 NYCRR Part 500?
Any Covered Entity, meaning any person or business operating under a license, registration, charter, certificate, permit, accreditation, or similar authorization under New York's Banking Law, Insurance Law, or Financial Services Law. That sweeps in banks, insurers, mortgage companies, money transmitters, virtual-currency businesses, and many others regulated by the New York Department of Financial Services. The obligation follows the New York authorization, not the location of the headquarters.
What is the 72-hour notification requirement under the NYDFS Cybersecurity Regulation?
A Covered Entity must notify the Superintendent of the Department of Financial Services as promptly as possible and no later than 72 hours after determining that a cybersecurity event has occurred. The clock runs from the determination that a qualifying event happened, which includes events reportable to another regulator, events with a reasonable likelihood of materially harming normal operations, and, under the amended rule, events where unauthorized access to a privileged account occurred or ransomware was deployed in a material part of the systems.
Does the NYDFS Cybersecurity Regulation require multi-factor authentication?
Yes. The amended regulation requires multi-factor authentication for any individual accessing the Covered Entity's information systems, with narrow conditions under which the CISO may approve a reasonably equivalent or more secure compensating control in writing. MFA is one of the few controls written as a near-flat requirement rather than purely risk-based, which reflects how often stolen single-factor credentials are the entry point in financial-sector breaches.
What is the annual certification of compliance under Part 500?
Each year a Covered Entity submits a written statement to the Department covering the prior calendar year. Under the amended rule the entity either certifies material compliance with the regulation or submits an acknowledgment of noncompliance that identifies the gaps and a remediation timeline. The submission must be signed by the highest-ranking executive and the CISO, and the entity must keep the records and schedules that support it. A false certification carries real exposure, so evidence has to stand behind the submission before it goes out.
Are small companies exempt from the NYDFS Cybersecurity Regulation?
There is no blanket small-company exemption. There are limited exemptions, the most common being for a Covered Entity that meets size thresholds tied to employee count, gross annual revenue from New York operations, and year-end total assets. A limited exemption relieves the entity of some requirements but never all of them. The core obligations, including the risk assessment, the limited cybersecurity program, the 72-hour notice, and the annual filing, still apply, and the entity must file a notice of exemption to claim it.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.

Primary sources

The authoritative texts this guide is grounded in. Government sites may block automated access but resolve in a browser.