Regulations › US states › New York

NYDFS Part 500

New York DFS Cybersecurity Regulation (23 NYCRR 500)

In force security financial
WhenIn effect since 1 March 2017
Who enforces itNew York Department of Financial Services
Who it applies toBanks, insurers and other financial services companies licensed by NYDFS.

A detailed cybersecurity program regulation with annual certification, CISO reporting, incident notice within 72 hours and personal liability exposure for certifying executives.

The law in brief

Part 500 is the New York Department of Financial Services' cybersecurity regulation for the banks, insurers and other financial companies it licenses. It is one of the most prescriptive cybersecurity rules in the United States: it names the controls a covered entity must have, requires a chief information security officer who reports to the board, and requires an annual certification of compliance signed by the chief executive and the CISO.

Its second amendment, adopted in November 2023, phased in stricter requirements through November 2025, including multi-factor authentication for all access to information systems and a complete asset inventory. All of those phases now apply.

Who it applies to

  • Covered entities: any person operating, or required to operate, under a license, registration, charter or similar authorization under New York's Banking Law, Insurance Law or Financial Services Law, including many out-of-state and foreign institutions with New York licenses.
  • Class A companies, the largest covered entities by New York revenue and headcount or global revenue, carry extra duties such as independent audits and privileged access management.
  • Limited exemptions apply to small covered entities below employee, revenue or asset thresholds, and to some entities that hold no nonpublic information. Exempt entities must still file a notice of exemption and meet the parts of the rule that still apply to them (500.19).

What it requires

A cybersecurity program and policies

Maintain a cybersecurity program based on a risk assessment, with written policies approved by a senior officer or the senior governing body at least annually.

A CISO who reports to the board

Designate a qualified chief information security officer who reports in writing at least annually to the senior governing body, which must have sufficient understanding to oversee cybersecurity risk.

Named technical controls

Run penetration testing and vulnerability management, limit and review access privileges, require multi-factor authentication for any individual accessing any information system, keep an asset inventory, encrypt nonpublic information, and train staff.

Third-party service provider security

Keep policies for assessing and overseeing service providers that access your systems or nonpublic information, including due diligence and contractual protections.

Notice to DFS within 72 hours

Notify the Superintendent within 72 hours of determining that a cybersecurity incident has occurred, and within 24 hours of any extortion payment, with a written explanation within 30 days.

Annual certification by 15 April

Submit a certification of material compliance, or a written acknowledgment of noncompliance with a remediation plan, signed by the highest-ranking executive and the CISO.

Enforcement and penalties

DFS enforces under the Banking, Insurance and Financial Services Laws. The regulation treats a single act prohibited by the rule, or a failure to comply for any 24-hour period with a requirement, as a violation (500.20). DFS has reached multimillion-dollar settlements, often citing inaccurate compliance certifications, and the certification makes the signing executives personally accountable for its accuracy.

What to do first

  1. Confirm your status: covered entity, Class A company, or eligible for a limited exemption.
  2. Map your program to each section of Part 500 and assign an owner to each.
  3. Check multi-factor authentication covers every individual accessing any information system, and document any approved compensating controls.
  4. Complete the asset inventory and the annual risk assessment, and keep both current.
  5. Brief the board at least annually through the CISO's written report.
  6. Rehearse the 72-hour notice and the 24-hour notice for extortion payments.
  7. Build the evidence file that supports the annual certification before it is signed.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources