The New York State Department of Financial Services (DFS) finalized its second amendment to 23 NYCRR Part 500, the state's cybersecurity regulation for financial services, on November 1, 2023. The changes phase in over two years, with compliance dates running through November 1, 2025. The next two deadlines are close. Covered entities must file their annual compliance submission by April 15, 2024, and most of the amendment's new requirements apply from April 29, 2024. Later phases add stronger governance, encryption, access and vulnerability management requirements, and finally universal multi-factor authentication and an asset inventory.

Below is a date-by-date view of what's due, followed by the changes that matter most for CISOs, boards and larger "Class A" companies.

Who does NYDFS Part 500 apply to?

Part 500 applies to covered entities: any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under New York's Banking Law, Insurance Law or Financial Services Law. That includes banks, insurers, insurance agencies and brokers, mortgage companies, money transmitters and many others.

Smaller covered entities may qualify for a limited exemption. Under the amended rule, the thresholds are fewer than 20 employees and independent contractors, less than $7.5 million in gross annual revenue in each of the last three fiscal years, or less than $15 million in year-end total assets. Each threshold is measured with affiliates included, as the rule specifies. A limited exemption removes some requirements but not all of them, and the updated thresholds apply from November 1, 2024.

What are the NYDFS Part 500 amendment deadlines?

The amendment took effect November 1, 2023. By default, covered entities have 180 days to comply with its new requirements, with specific exceptions set out in section 500.22.

Date What applies
November 1, 2023 Amendment effective. Enforcement provisions (500.20) and certain other sections apply immediately
December 1, 2023 New notice requirements in section 500.17, including the 72-hour incident notice
April 15, 2024 Annual submission for calendar year 2023: certification of material compliance or acknowledgment of noncompliance
April 29, 2024 End of the 180-day transitional period. All new requirements not listed below apply
November 1, 2024 Cybersecurity governance (500.4), encryption (500.15), incident response and business continuity (500.16), updated exemption thresholds (500.19(a))
May 1, 2025 Automated vulnerability scans (500.5(a)(2)), access privileges and management (500.7), malicious code controls (500.14(a)(2)), Class A monitoring (500.14(b))
November 1, 2025 Multi-factor authentication (500.12) and asset inventory (500.13(a))

Requirements from the original 2017 regulation remain in force throughout. The phase-in applies only to what the amendment added or changed.

What's due by April 2024?

The annual compliance submission

Every covered entity must submit a filing to DFS by April 15 each year covering the prior calendar year. The amendment changed what that filing can be. A covered entity now submits either:

  • a written certification that it materially complied with Part 500 during the prior calendar year, or
  • a written acknowledgment that it did not materially comply, identifying the sections it did not comply with, describing the nature and extent of the noncompliance, and giving a remediation timeline or confirming that remediation is complete.

The submission must be signed by the covered entity's highest-ranking executive and its CISO, or the senior officer responsible for cybersecurity if there is no CISO. The certification must also rest on data and documentation sufficient to show material compliance. If you plan to certify, gather that evidence now rather than in the first week of April.

Everything in the 180-day bucket

Any new requirement not assigned a different date applies from April 29, 2024. That includes several changes security teams will feel directly:

  • Policies. Cybersecurity policies must be approved at least annually by a senior officer or the senior governing body, and the list of topics they must address has grown.
  • Risk assessment. The risk assessment must be reviewed and updated at least annually, and whenever a change in the business or technology causes a material change to cyber risk.
  • Penetration testing. Covered entities must conduct penetration testing at least annually, from both inside and outside the information systems' boundaries, by a qualified internal or external party.
  • Training. Cybersecurity awareness training is required for all personnel at least annually.
  • Class A independent audits. Class A companies must conduct independent audits of their cybersecurity programs based on their risk assessment.

What are the new incident notification rules?

The notification changes applied from December 1, 2023. A covered entity must notify DFS electronically "as promptly as possible but in no event later than 72 hours after determining that a cybersecurity incident has occurred." That now includes incidents at the covered entity, its affiliates or a third-party service provider.

The amendment introduced "cybersecurity incident" as a defined term, distinct from the broader "cybersecurity event." It includes events with a reasonable likelihood of materially harming normal operations and events that must be reported to another government body, self-regulatory agency or supervisory body. After the initial notice, covered entities must promptly provide any information DFS requests and keep it updated.

Covered entities that make an extortion payment in connection with a cybersecurity event must notify DFS within 24 hours of the payment and, within 30 days, provide a written explanation of why it was necessary and what alternatives were considered.

How do the amendments change CISO reporting and board oversight?

The governance requirements in section 500.4 apply from November 1, 2024.

CISO reporting. The CISO's written report to the senior governing body, required at least annually, must cover the program as a whole, including to the extent applicable: the confidentiality of nonpublic information and the integrity and security of information systems, policies and procedures, material cyber risks, overall program effectiveness, material cybersecurity events, and plans for remediating material inadequacies. The CISO must also report material cybersecurity issues to the board or senior officers in a timely way, such as significant events or significant changes to the program.

Board oversight. The senior governing body must exercise oversight of cybersecurity risk management. That means having sufficient understanding of cybersecurity-related matters, which may include using advisors, requiring executive management to develop, implement and maintain the program, regularly receiving and reviewing management reports, and confirming that management has allocated sufficient resources to implement and maintain an effective program.

For many organizations the practical question is whether board materials today would show that oversight. Minutes that record questions asked and decisions made carry more weight than a slide deck filed away.

What else is phased in through 2025?

November 1, 2024

Beyond governance, two technical sections tighten. Encryption of nonpublic information in transit over external networks and at rest is required, and where encryption at rest is infeasible, compensating controls must be approved in writing by the CISO. Incident response and business continuity plans must meet more detailed requirements and be tested at least annually, and covered entities must test their ability to restore critical data and systems from backups at least annually.

May 1, 2025

Covered entities must run automated vulnerability scans of information systems, with manual review of systems the scans don't cover, at a frequency set by the risk assessment and promptly after material system changes. The access privileges section requires limiting privileged accounts, reviewing all user access at least annually, promptly terminating access on departure and maintaining a written password policy where passwords are used. Risk-based controls to protect against malicious code also apply from this date.

November 1, 2025

Multi-factor authentication must be used for any individual accessing any of the covered entity's information systems, unless the CISO has approved reasonably equivalent or more secure compensating controls in writing. Covered entities also need written policies and procedures for a complete, accurate and documented asset inventory, tracking details such as owner, location, classification or sensitivity, support expiration date and recovery time objectives.

What extra requirements apply to Class A companies?

A Class A company is a covered entity with at least $20 million in gross annual revenue in each of the last two fiscal years from its own operations and its affiliates' New York operations, and either:

  • over 2,000 employees averaged over the last two fiscal years, including all affiliates, or
  • over $1 billion in gross annual revenue in each of the last two fiscal years from all operations of the company and its affiliates.

Class A companies must meet the following additional requirements:

Requirement Section Applies from
Independent audits of the cybersecurity program, based on the risk assessment 500.2(c) April 29, 2024
Monitoring of privileged access activity, a privileged access management solution, and automated blocking of commonly used passwords 500.7(c) May 1, 2025
Endpoint detection and response, and centralized logging and security event alerting 500.14(b) May 1, 2025

How does NYDFS enforce Part 500?

The amended section 500.20, effective immediately on November 1, 2023, clarifies that a single act or failure to act can be a violation. That includes failing to secure or prevent unauthorized access to nonpublic information because of noncompliance with any section, and materially failing to comply with any section for any 24-hour period. It also lists factors DFS will weigh when setting penalties, such as cooperation, good faith, prior violations and the extent of harm to consumers.

This makes the accuracy of the April 15 filing important. Certifying compliance that the documentation doesn't support is a risk in its own right.

Frequently asked questions

When is the next NYDFS Part 500 deadline?

The annual submission is due April 15, 2024, covering calendar year 2023. The 180-day transitional period ends April 29, 2024.

Can we file if we weren't fully compliant in 2023?

Yes. The amendment added an acknowledgment of noncompliance as an alternative to certification. It must identify the sections not complied with, describe the gaps and include a remediation timeline or confirm remediation is complete.

When does universal MFA apply?

November 1, 2025. Until then, the MFA requirements of the original regulation continue to apply.

Are small covered entities exempt from the amendments?

Only partly. Entities that meet the limited exemption thresholds are relieved of some sections but must still comply with others, including the notification requirements and the annual submission.

Next steps

  • Gather evidence for the April 15, 2024 submission and decide early whether you'll certify or acknowledge noncompliance.
  • Confirm your policies, risk assessment, penetration testing and training meet the new requirements by April 29, 2024.
  • Update your incident response plan for the 72-hour notice and the expanded scope to affiliates and third-party service providers.
  • Brief the board on its new oversight role before the November 1, 2024 governance requirements apply.
  • Start planning for MFA and the asset inventory now. November 2025 is closer than it looks for large or complex environments.

This article summarizes the amended regulation and isn't legal advice. Confirm your specific obligations with counsel and DFS's published guidance.