RegPing
Primary sources, polled every 30 minutesJSON · Sitemap · llms.txt · Status

Financial · guide

NYDFS Part 500 Cybersecurity Checklist for Smaller Covered Entities

Updated

Who is covered

23 NYCRR Part 500 applies to any "covered entity," defined as a person operating under or required to operate under a license, registration, charter, certificate, permit, accreditation or similar authorization under New York's Banking Law, Insurance Law or Financial Services Law (23 NYCRR 500.1). That reaches insurance agencies, mortgage brokers, money transmitters, licensed lenders and many firms with only a handful of staff. The regulation took effect March 1, 2017; the Second Amendment became effective November 1, 2023 (NYDFS Cybersecurity Resource Center).

The Second Amendment's phased dates

Section 500.22 phases the Second Amendment in by counting from November 1, 2023 (23 NYCRR 500.22):

Date What became required
November 1, 2023 Sections 500.19(e)-(h), 500.20, 500.21, 500.22 and 500.24
December 1, 2023 (30 days) Section 500.17, the amended notice and annual filing requirements
April 29, 2024 (180 days) Everything not assigned a later date
November 1, 2024 (one year) Sections 500.4 (governance), 500.15 (encryption), 500.16 (incident response and business continuity), 500.19(a) (the revised limited exemption)
May 1, 2025 (18 months) Sections 500.5(a)(2), 500.7, 500.14(a)(2) and 500.14(b)
November 1, 2025 (two years) Sections 500.12 (multi-factor authentication) and 500.13(a) (asset inventory)

At time of writing (September 2026) every phase is in force, so a smaller entity should treat the full amended text as current.

The limited exemption under 500.19(a)

A covered entity qualifies for the limited exemption if it meets any one of three tests: fewer than 20 employees and independent contractors, counting the covered entity and its affiliates; less than $7,500,000 in gross annual revenue in each of the last three fiscal years, counting all operations of the covered entity plus the New York operations of its affiliates; or less than $15,000,000 in year-end total assets, including affiliates (23 NYCRR 500.19). The Second Amendment raised these from 10 employees, $5 million and $10 million, so some firms that were fully in scope before now qualify.

A limited-exempt entity is excused from sections 500.4, 500.5, 500.6, 500.8, 500.10, 500.14(a)(1)-(2) and (b), 500.15 and 500.16, and must file a Notice of Exemption within 30 days of determining that it qualifies (23 NYCRR 500.19). The exemption is limited, not total, and DFS requires filers to certify that they understand this (DFS Cybersecurity Submissions).

What limited-exempt entities must still do

Working by subtraction from the exemption list, a limited-exempt entity still has to:

  • Maintain a cybersecurity program (500.2) and a written cybersecurity policy (500.3).
  • Limit user access privileges and review them (500.7).
  • Conduct and update a risk assessment (500.9).
  • Maintain a third-party service provider security policy (500.11).
  • Use multi-factor authentication in the scoped-down form described below (500.12).
  • Keep an asset inventory and dispose of unneeded nonpublic information (500.13).
  • File incident and extortion notices and the annual April 15 submission (500.17).
  • File and, if circumstances change, revisit the Notice of Exemption (500.19).

MFA and asset inventory since November 1, 2025

The general rule in 500.12 is that multi-factor authentication "shall be utilized for any individual accessing any information systems of a covered entity." For entities relying on the 500.19(a) limited exemption, the requirement is narrowed to three cases: remote access to the covered entity's information systems; remote access to third-party applications, including cloud-based ones, from which nonpublic information is accessible; and all privileged accounts other than service accounts that prohibit interactive login. A CISO, where one exists, may approve in writing reasonably equivalent or more secure compensating controls, reviewed at least annually (23 NYCRR 500.12).

Section 500.13(a) requires written policies that produce "a complete, accurate and documented asset inventory of the covered entity's information systems," tracking for each asset its owner, location, classification or sensitivity, support expiration date and recovery time objectives, and stating how often the inventory is updated and validated. Section 500.13(b) requires periodic secure disposal of nonpublic information no longer needed for business operations, unless retention is required by law or targeted disposal is not reasonably feasible (23 NYCRR 500.13). A spreadsheet with those five columns is enough for a small firm if it is kept current.

Notices: 72 hours and 24 hours

Section 500.17(a) requires notice to the superintendent "as promptly as possible but in no event later than 72 hours after determining that a cybersecurity incident has occurred." A cybersecurity incident is a cybersecurity event at the covered entity, an affiliate or a third-party service provider that (1) requires notice to any government body, self-regulatory agency or supervisory body, (2) has a reasonable likelihood of materially harming any material part of the entity's normal operations, or (3) results in the deployment of ransomware within a material part of its information systems (23 NYCRR 500.1). The entity must then provide requested information and update DFS on material changes.

If an extortion payment is made in connection with a cybersecurity event, 500.17(c) requires notice of the payment within 24 hours and, within 30 days, a written description of why payment was necessary, the alternatives considered, the diligence performed to find alternatives, and the diligence performed to ensure compliance with applicable rules, including those of the Office of Foreign Assets Control (23 NYCRR 500.17).

The annual filing due April 15

Each year by April 15, every covered entity, including limited-exempt ones, must file either a written certification that it materially complied with Part 500 during the prior calendar year or a written acknowledgment of noncompliance that identifies the sections not met, describes the nature and extent of the shortfall, and gives a remediation timeline. Both are signed by the highest-ranking executive and the CISO, or by the senior officer responsible for cybersecurity if there is no CISO, and supporting records must be kept for five years (23 NYCRR 500.17). DFS notes that limited-exempt entities certify only against the sections that apply to them (DFS Cybersecurity Submissions).

Where to file

All Part 500 filings go through the DFS Portal at myportal.dfs.ny.gov, using DFS ID credentials with multi-factor authentication. The portal offers three paths: an exemption filing, a compliance filing, and reporting a cybersecurity incident (DFS Cybersecurity Submissions).

RegPing's financial-regulation bot delivers new NYDFS guidance and industry letters into Discord.

Where to verify

This guide is general information, not legal advice. Verify against the primary source and consult counsel before acting.

Questions people ask

What are the NYDFS Part 500 limited exemption thresholds?

Under 23 NYCRR 500.19(a), a covered entity qualifies if it has fewer than 20 employees and independent contractors (including affiliates), less than $7.5 million in gross annual revenue in each of the last three fiscal years, or less than $15 million in year-end total assets. Meeting any one test is enough.

Do limited-exempt entities still have to file the April 15 certification?

Yes. Every covered entity must file either a Certification of Material Compliance or an Acknowledgment of Noncompliance through the DFS Portal by April 15 each year, though limited-exempt entities certify only against the sections that apply to them.

How fast must a cybersecurity incident be reported to NYDFS?

Within 72 hours of determining that a cybersecurity incident occurred, filed electronically through the DFS Portal. An extortion payment must be reported within 24 hours, with a written explanation due within 30 days.

Not legal advice. RegPing republishes and summarizes public regulator notices and links to the original. Summaries are produced with a language model and can be wrong; the regulator's text controls. Not legal advice. Consult counsel before acting.