NY DFS 23 NYCRR Part 500 At A Glance
- Who: Entities licensed, registered or chartered by the NY DFS, including banks, insurers, mortgage companies, money transmitters and virtual currency businesses (§ 500.1).
- When: The Second Amendment took effect November 1, 2023. The last phased requirements, MFA for all access and the asset inventory, took effect November 1, 2025 (§ 500.22).
- Annual filing: By April 15 each year, a Certification of Material Compliance or an Acknowledgment of Noncompliance, signed by the highest-ranking executive and the CISO (§ 500.17(b)).
- Deadlines: 72 hours to notify DFS of a cybersecurity incident, and 24 hours to report an extortion payment, with a written explanation within 30 days (§ 500.17).
- Frameworks: NIST CSF 2.0 and ISO 27001/27002 do not specify these deadlines, testing frequencies or Class A requirements, so using them for Part 500 takes significant customization.
- Recommendation: ComplianceForge recommends the Secure Controls Framework (SCF), which publishes a Set Theory Relationship Mapping (STRM) for the 2023 amended Part 500.
- Assurance: An SCR certification for NY DFS 23 NYCRR Part 500, issued by an independent SCR 3PAO, gives the CISO third-party evidence before signing.
Executive Liability: The Annual Compliance Filing
Each covered entity must submit one of two filings to DFS by April 15 each year, covering the prior calendar year: a Certification of Material Compliance, if it materially complied with Part 500, or an Acknowledgment of Noncompliance, which identifies every section it did not materially comply with, describes the nature and extent of the noncompliance and provides a remediation timeline (§ 500.17(b)(1)).
Under § 500.17(b)(2), the filing must be signed by the covered entity's highest-ranking executive and its CISO. If there is no CISO, the highest-ranking executive and the senior officer responsible for the cybersecurity program sign. A certification must be based on data and documentation sufficient to accurately determine and demonstrate material compliance, and that support must be kept for five years (§ 500.17(b)(3)).
That is why the evidence matters as much as the controls. Our program produces a documented compliance record that supports a credible filing and protects the executives who sign it.
Certification Of Material Compliance
Path A: Compliant entities. Filed when the entity materially complied with Part 500 during the prior calendar year. It must rest on data and documentation sufficient to demonstrate that compliance.
Acknowledgment Of Noncompliance
Path B: Gaps remain. Filed when material compliance cannot be certified. It must identify each noncompliant section, describe the nature and extent of the noncompliance and give a remediation timeline or confirm that remediation is complete.
Legal Exposure Beyond DFS
A certification must be based on data and documentation sufficient to accurately determine and demonstrate material compliance (§ 500.17(b)(1)). Signing one without that support is a Part 500 problem first.
Officers who knowingly sign a false filing may also face exposure under other New York laws, such as the New York False Claims Act. How those laws apply to your filing is a question for your legal counsel.
Two Filing Paths, One Deadline
Certify material compliance or acknowledge noncompliance by April 15. Both are signed by the highest-ranking executive and the CISO, or by the senior officer responsible for the cybersecurity program if there is no CISO (§ 500.17(b)(2)).
Unsupported Certification Is A Violation
A certification must be based on data and documentation sufficient to demonstrate material compliance (§ 500.17(b)(1)). Filing one without that support exposes the entity and its signers to enforcement.
5-Year Documentation Retention
Records, schedules and data supporting the filing, including remediation efforts and plans, must be kept for five years and provided to DFS on request (§ 500.17(b)(3)).
Acknowledge & Remediate
If you cannot certify material compliance, an Acknowledgment of Noncompliance with a credible remediation timeline is the path the regulation provides, and it is far better than an unsupported certification.
"Annually each covered entity shall submit to the superintendent electronically by April 15 either" a written certification of material compliance or a written acknowledgment of noncompliance.
What Is 23 NYCRR Part 500?
23 NYCRR Part 500, Cybersecurity Requirements for Financial Services Companies, is the NY DFS cybersecurity regulation. It first took effect on March 1, 2017, and the Second Amendment, effective November 1, 2023, substantially expanded it. It applies to any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the New York Banking Law, Insurance Law or Financial Services Law.
Unlike general cybersecurity frameworks, Part 500 sets legally binding requirements with specific deadlines, testing frequencies, technology requirements for larger companies, officer signatures and incident reporting obligations. The commission of a single prohibited act, or the failure to satisfy a single obligation, is a violation (§ 500.20).
Our program addresses the full scope of Part 500: mapping every requirement to SCF controls, assessing your implementation against the regulation and producing the evidence that supports your annual filing.
- Cybersecurity program based on your risk assessment (§ 500.2)
- Written cybersecurity policies approved at least annually by a senior officer or the senior governing body (§ 500.3)
- A qualified CISO who reports in writing at least annually to the senior governing body (§ 500.4)
- Annual penetration testing and risk-based automated vulnerability scanning (§ 500.5)
- Audit trail systems (§ 500.6)
- Access privilege limits with at least annual access reviews (§ 500.7)
- Application security procedures (§ 500.8)
- Risk assessment reviewed at least annually (§ 500.9)
- Third-party service provider security policy (§ 500.11)
- Multi-factor authentication for any individual accessing any information system (§ 500.12)
- Asset inventory and secure disposal of nonpublic information (§ 500.13)
- Monitoring and at least annual cybersecurity awareness training (§ 500.14)
- Encryption of nonpublic information in transit and at rest (§ 500.15)
- Incident response and business continuity plans, tested at least annually (§ 500.16)
- 72-hour incident notice, extortion payment reporting and the annual filing (§ 500.17)
Does Part 500 Apply To Your Entity?
Part 500 applies to any person operating under, or required to operate under, a DFS license, registration, charter, certificate, permit, accreditation or similar authorization, including:
- State-chartered banks and trust companies
- Insurance companies licensed in New York
- Mortgage bankers, servicers and brokers
- Money transmitters and check cashers
- Premium finance agencies and budget planners
- Virtual currency businesses (BitLicense holders)
Limited exemptions exist for smaller entities (§ 500.19), but they must still meet the sections that are not exempted and file a Notice of Exemption within 30 days of determining they qualify.
2023 Amendment: What Changed
The Second Amendment substantially expanded Part 500:
- "Class A" companies with additional requirements (§ 500.1)
- Independent audits for Class A companies (§ 500.2(c))
- Senior governing body oversight duties (§ 500.4(d))
- MFA for any individual accessing any information system (§ 500.12)
- Asset inventory requirements (§ 500.13)
- 24-hour extortion payment notice and 30-day explanation (§ 500.17(c))
- Incident notice that covers events at affiliates and third-party service providers (§ 500.17(a))
- A choice of certification or acknowledgment, signed by the highest-ranking executive and the CISO (§ 500.17(b))
Why NIST CSF 2.0 And ISO 27001/27002 Aren't Enough For Part 500
NIST CSF 2.0 and ISO 27001/27002 are not sufficient on their own to comply with NY DFS 23 NYCRR Part 500. Both are good foundations, but neither was written for Part 500, so neither specifies its deadlines, testing frequencies, Class A requirements or the signed annual filing. NIST says the CSF "does not prescribe how outcomes should be achieved," and ISO 27001 leaves control selection to your risk assessment and Statement of Applicability. To use either one for Part 500, you have to add and track the Part 500 requirements yourself.
Where Part 500 is specific and the general frameworks are not:
This is not a knock on either framework. NIST CSF 2.0 is a strong way to organize cybersecurity outcomes, and ISO 27001 is a strong management system. The issue is the gap between what they describe and what Part 500 requires, which means you would build and maintain your own Part 500 crosswalk on top of them. Learn more in our NIST CSF 2.0 and ISO 27001/27002 guides.
What Is The Best Framework For NY DFS 23 NYCRR Part 500 Compliance?
ComplianceForge recommends the Secure Controls Framework (SCF) as the best framework for Part 500 compliance. The SCF is a free metaframework with 1,500+ controls across 34 domains, mapped to 200+ laws, regulations and frameworks, including the 2023 amended Part 500, NIST CSF 2.0, ISO 27001:2022, GLBA and the FFIEC IT Examination Handbook. You implement one control set and show compliance with Part 500 and the other frameworks your examiners, auditors and customers expect.
Part 500 Mapped With STRM
The SCF publishes a Set Theory Relationship Mapping (STRM) for Part 500 (2023 Amendment 2), based on NIST IR 8477. Each Part 500 requirement is mapped to SCF controls with a stated relationship and strength, so you can show an examiner which controls meet which section.
Built For Prescriptive Requirements
Where Part 500 sets a deadline or a frequency, the SCF gives you a specific control to implement and evidence, such as penetration testing (VPM-18) or privileged user monitoring (MON-14.2), instead of a broad outcome you have to interpret.
Class A Requirements Covered
Class A requirements, such as independent audits (§ 500.2(c)) and privileged access management (§ 500.7(c)), are mapped to specific SCF controls in the Part 500 STRM, so larger companies use the same control set as everyone else.
One Control Set, Many Obligations
Most financial institutions answer to more than Part 500. The SCF also maps GLBA, the FFIEC IT Examination Handbook, NIST CSF 2.0, ISO 27001 and state privacy laws, so evidence you collect once can support all of them. See our GLBA guide.
Certifiable Through The SCR CAP
An accredited SCR 3PAO can assess your SCF controls for an SCR certification for NY DFS 23 NYCRR Part 500, giving your CISO independent evidence before the April 15 filing. See how it works.
Free To Use
The SCF is free to use under a Creative Commons license, so there is no framework licensing cost to adopt it as your common control set.
ComplianceForge is an authorized SCF Licensed Content Provider (LCP). Our SCF-based policies and standards (SCRP) and procedures (CSOP) give you editable documentation already aligned to SCF controls, so your evidence traces back to Part 500 sections through the SCF's Part 500 STRM. For program-level requirements, pair them with our Third-Party Risk Management (TPRM) Program for § 500.11, Cybersecurity Risk Assessment (CRA) Template for § 500.9, Vulnerability & Patch Management Program (VPMP) for § 500.5, Integrated Incident Response Program (IIRP) for § 500.16 and Continuity Of Operations Plan (COOP) for business continuity and disaster recovery.
Independent Assurance For The CISO: SCR Certified - NY DFS 23 NYCRR Part 500
The CISO and the highest-ranking executive sign the annual filing, but they rarely test every control themselves. The Secure, Compliant & Resilient Conformity Assessment Program (SCR CAP) gives them independent evidence. An accredited SCR Third-Party Assessment Organization (3PAO) assesses your SCF controls against the SCR assessment guide for NY DFS 23 NYCRR Part 500 and, if you conform, issues an SCR certification for Part 500.
The Cyber AB is the Accreditation Body for the SCR CAP. It accredits SCR 3PAOs and oversees conflict-of-interest governance, which is meant to keep the organization that certifies you independent of the one that helped you prepare. SCR certification is not a DFS requirement and does not replace your annual filing. It is third-party evidence that your controls are in place and operating, which the people who sign the filing can rely on.
Certification follows a three-year lifecycle. An SCR 3PAO performs the initial assessment. In years two and three, you perform an internal assessment and provide a self-attestation that you continue to conform, and a new 3PAO assessment is required at the end of year three. That rhythm lines up with the annual April 15 filing.
Our assessment process is pre-aligned to SCF controls, so the evidence gathered for your Part 500 readiness assessment is organized the way a 3PAO will evaluate it.
What The SCR CAP Assesses For Part 500
The SCR assessment guide for NY DFS 23 NYCRR Part 500 defines the SCF controls in scope, the assessment objectives a 3PAO evaluates, the evidence expected and how conformity is scored.
Who Performs The Assessment
An SCR 3PAO accredited by The Cyber AB. You can find accredited 3PAOs in the SCF Marketplace.
How It Supports The April 15 Filing
A certification must rest on data and documentation sufficient to demonstrate material compliance (§ 500.17(b)(1)). An independent report on conformity is strong support for that record, alongside your internal evidence.
Why Not Self-Attestation Alone?
Self-assessments are easy to challenge after an incident. An independent assessment against a documented methodology is harder to dispute and is useful for DFS examinations, cyber insurance underwriting and customer due diligence.
The Part 500 Cybersecurity Requirements, Section By Section
Part 500 sets specific, enforceable obligations with defined scope, technical requirements, personnel requirements and filing obligations. Our assessment program is structured section by section around these requirements, so every deliverable maps directly to the regulation.
PROGRAM & GOVERNANCE: Program, Policy & CISO
Program, policy and accountability requirements
- § 500.2 Cybersecurity Program. Maintain a cybersecurity program, based on your risk assessment, that protects the confidentiality, integrity and availability of your information systems and nonpublic information. Class A companies must also conduct independent audits of the program (§ 500.2(c)).
- § 500.3 Cybersecurity Policy. Written policies, approved at least annually by a senior officer or the senior governing body, covering 15 areas, from information security and data governance to asset inventory, access controls, business continuity, vendor management, incident response and vulnerability management.
- § 500.4 CISO & Board Oversight. Designate a qualified CISO who reports in writing at least annually to the senior governing body on the program, material risks and plans for remediating material inadequacies. The senior governing body must exercise oversight, including having sufficient understanding of cybersecurity matters and confirming that adequate resources are allocated.
- § 500.9 Risk Assessment. Conduct a periodic risk assessment, reviewed and updated at least annually and whenever a material change to cyber risk occurs.
- § 500.15 Encryption. A written policy requiring encryption that meets industry standards for nonpublic information in transit over external networks and at rest. Where encryption at rest is infeasible, the CISO may approve effective compensating controls in writing.
- § 500.17(b) Annual Compliance Filing. By April 15, a Certification of Material Compliance or an Acknowledgment of Noncompliance, signed by the highest-ranking executive and the CISO, with supporting records kept for five years.
TECHNICAL CONTROLS: Testing, Access & Monitoring
Testing frequencies, access controls and monitoring requirements
- § 500.5 Vulnerability Management. Penetration testing from inside and outside your system boundaries by a qualified internal or external party at least annually, automated vulnerability scans at a frequency your risk assessment sets plus manual review of systems the scans do not cover, and timely, risk-prioritized remediation.
- § 500.6 Audit Trail. Systems designed to reconstruct material financial transactions and audit trails designed to detect and respond to cybersecurity events, with records retained as § 500.6 requires (at least five years for transaction records).
- § 500.7 Access Privileges. Limit access to what each user needs to perform their job and review all user access privileges at least annually. Class A companies must also monitor privileged access, implement privileged access management and automatically block commonly used passwords.
- § 500.12 Multi-Factor Authentication. MFA for any individual accessing any of your information systems, with narrower requirements for entities that qualify for a limited exemption.
- § 500.13 Asset Management & Data Retention. A complete, accurate and documented asset inventory that tracks owner, location, classification or sensitivity, support expiration date and recovery time objectives, plus secure disposal of nonpublic information that is no longer needed.
- § 500.14 Monitoring & Training. Risk-based monitoring of authorized user activity, controls against malicious code in web traffic and email, and cybersecurity awareness training that includes social engineering at least annually. Class A companies must also implement endpoint detection and response and centralized logging and security event alerting.
INCIDENT RESPONSE: Notification & Business Continuity
Response planning, DFS notification and resilience requirements
- § 500.16 Incident Response Plan. Written incident response plans that address how you respond to and recover from cybersecurity events, including roles, communications and remediation.
- § 500.16 Business Continuity & Disaster Recovery. Written business continuity and disaster recovery (BCDR) plans to keep critical operations running and to recover from disruptions.
- § 500.16(d) Plan Testing. Test incident response and BCDR plans at least annually with all staff and management critical to the response, and revise them as needed.
- § 500.17(a) 72-Hour Incident Notice. Notify the Superintendent electronically as promptly as possible, and no later than 72 hours after determining that a cybersecurity incident occurred at the covered entity, its affiliates or a third-party service provider.
- § 500.17(c) Extortion Payments. Within 24 hours of an extortion payment, notify DFS of the payment. Within 30 days, provide a written description of why it was necessary, the alternatives considered and the diligence performed, including sanctions compliance.
THIRD-PARTY & APP SECURITY: Vendors, Applications & People
Vendor oversight, application security and personnel requirements
- § 500.11 Third-Party Service Provider Security Policy. Written policies covering the identification and risk assessment of third-party service providers, the minimum cybersecurity practices they must meet, due diligence and periodic assessment based on risk.
- § 500.8 Application Security. Written procedures, guidelines and standards for secure development of in-house applications, and procedures for evaluating, assessing or testing the security of externally developed applications.
- § 500.10 Cybersecurity Personnel & Intelligence. Employ or designate qualified cybersecurity personnel (internal staff or service providers) and use cybersecurity threat intelligence from internal or external sources.
- § 500.19 Limited Exemptions. Covered entities with fewer than 20 employees and independent contractors, less than $7.5 million in gross annual revenue in each of the last three fiscal years, or less than $15 million in year-end total assets (as calculated under § 500.19(a)) are exempt from certain sections. They must file a Notice of Exemption within 30 days of determining they qualify.
DFS Enforcement: Why Non-Compliance Is Not An Option
DFS enforces Part 500 through public consent orders with civil penalties and required remediation. A single prohibited act or a single unmet obligation is a violation (§ 500.20), whether or not a breach caused harm. Recent actions show where covered entities fall short.
Recent Part 500 Enforcement Actions
In November 2024, DFS and the New York Attorney General announced $11.3 million in penalties against GEICO ($9.75 million) and Travelers ($1.55 million) over data breaches affecting about 120,000 New Yorkers. DFS found that Travelers' agent portal did not use MFA or other compensating controls. In August 2025, DFS fined Healthplex $2 million after finding no MFA on its email environment, no email data retention policy and notice to DFS more than four months after it learned of the incident.
Unsupported Certification Risk
A certification must be based on data and documentation sufficient to demonstrate material compliance (§ 500.17(b)(1)). If you cannot support it, the regulation provides the Acknowledgment of Noncompliance instead.
72-Hour Notification Failure
Missing the 72-hour notice is a violation on its own. Healthplex waited more than four months after learning of a phishing incident before notifying DFS, well beyond the 72-hour requirement.
DFS Examination Exposure
DFS can examine covered entities and request the records that support your annual filing, which you must keep for five years (§ 500.17(b)(3)). Missing penetration test reports, risk assessments or CISO reports are hard to explain after the fact.
Third-Party & Contract Risk
Covered entities must assess their third-party service providers and set the minimum cybersecurity practices those providers must meet (§ 500.11). If you serve banks, insurers or other DFS-regulated firms, expect to show Part 500-aligned controls during due diligence.
SCR Certification Advantage
An SCR certification for NY DFS 23 NYCRR Part 500 is a verifiable, third-party-validated credential you can share with DFS examiners, cyber insurers and counterparties, and it supports the evidence behind your § 500.17(b) filing.
The 23 NYCRR Part 500 Assessment Process
Our assessment program is structured around every applicable section of 23 NYCRR Part 500 and aligned to the Secure Controls Framework. Each phase produces deliverables that support your § 500.17(b) annual filing and prepare you for an independent SCR CAP assessment. ComplianceForge prepares you; the certification assessment itself is performed by an independent SCR 3PAO.
Scoping & Covered Entity Classification (§§ 500.1, 500.19)
We determine which Part 500 obligations apply to your entity, including whether you qualify for a limited exemption under § 500.19, whether you are a Class A company, and which sections require dedicated assessment. We inventory the information systems, nonpublic information and third-party service providers in scope.
Cybersecurity Program & Risk Assessment Review (§§ 500.2, 500.3, 500.9)
We assess your written cybersecurity program (§ 500.2), cybersecurity policies (§ 500.3) and risk assessment (§ 500.9) against Part 500. We confirm the policies cover all required areas, including access controls, data governance, asset inventory, business continuity, vendor management and incident response, and that they are approved at least annually.
Penetration Testing & Vulnerability Management (§ 500.5)
We conduct or coordinate the annual penetration testing and the risk-based automated vulnerability scanning required by § 500.5. Testing is performed by qualified internal or external parties from both inside and outside your system boundaries. Findings are documented with severity ratings and mapped to remediation priorities.
Technical Controls Assessment (§§ 500.6 To 500.15)
We assess the required technical controls: audit trail systems (§ 500.6), access privileges and annual access reviews (§ 500.7), application security (§ 500.8), multi-factor authentication (§ 500.12), asset inventory (§ 500.13), monitoring and training (§ 500.14) and encryption of nonpublic information (§ 500.15), including the added requirements for Class A companies.
CISO, Third-Party & Incident Response Review (§§ 500.4, 500.10, 500.11, 500.16)
We assess CISO qualifications and the annual written report to the senior governing body (§ 500.4), cybersecurity personnel and threat intelligence (§ 500.10), third-party service provider security policies and due diligence (§ 500.11), and incident response and BCDR plans and testing (§ 500.16), including readiness for the 72-hour incident notice and the 24-hour extortion payment notice (§ 500.17).
Annual Compliance Filing & CISO Board Report (§§ 500.4, 500.17(b))
We prepare the supporting package for your annual filing: either a Certification of Material Compliance or an Acknowledgment of Noncompliance with a remediation timeline. Under § 500.17(b)(2), the filing is signed by your highest-ranking executive and CISO (or, if there is no CISO, the senior officer responsible for the cybersecurity program) by April 15. We also prepare the CISO's annual written report to the senior governing body required by § 500.4(b) and organize the supporting records you must keep for five years under § 500.17(b)(3).
Remediation & Annual Compliance Cycle Management
We help you prioritize remediation of assessment findings, track progress to closure and set up the annual cycle Part 500 requires: penetration testing, risk assessment updates, access reviews, plan testing, training and the April 15 filing calendar.
Editable Policies, Standards & Procedures For Part 500
Part 500 requires written cybersecurity policies (§ 500.3) and a documented cybersecurity program (§ 500.2), and DFS can request the records behind your annual filing. Examiners expect documented policies, standards and procedures that govern how nonpublic information is protected and how the program runs day to day.
ComplianceForge provides professionally written, editable cybersecurity and data privacy documentation mapped to Secure Controls Framework (SCF) controls. Because the SCF maps those controls to Part 500, your documentation lines up with the same control set used in your Part 500 assessment, creating a connected evidence chain from policy to practice to certification.
SCF Control Mapping
Every policy, standard and procedure maps to SCF controls, the same framework used in your Part 500 assessment, so you do not need to build your own crosswalk for § 500.3.
Fully Editable & Customizable
Delivered in editable formats so you can tailor policies to your operating environment, technology stack, DFS license type and organizational structure.
Broad Regulatory Coverage
Covers Part 500 alongside NIST CSF 2.0, ISO 27001, SOC 2, GLBA and more, so one documentation investment supports multiple obligations.
Integrated With Your Assessment
Documentation is selected and implemented as part of your Part 500 remediation, directly addressing policy gaps found in your § 500.3 assessment.
- SCF Policies & Standards (SCRP): cybersecurity policies and standards (§ 500.3)
- SCF Procedures (CSOP): control procedures, including access management (§ 500.7)
- Integrated Incident Response Program (IIRP): incident response planning (§ 500.16)
- Continuity Of Operations Plan (COOP): business continuity and disaster recovery (§ 500.16)
- Third-Party Risk Management (TPRM) Program: third-party service provider security (§ 500.11)
- Cybersecurity Risk Assessment (CRA) Template: risk assessment (§ 500.9)
- Vulnerability & Patch Management Program (VPMP): vulnerability management (§ 500.5)
The SCR CAP Ecosystem For Part 500
Part 500 compliance and SCR certification involve several independent roles. Knowing who does what helps you keep preparation and certification separate.
The Cyber AB
The Accreditation Body for the SCR CAP. It accredits SCR 3PAOs and oversees conflict-of-interest governance across the program.
SCR Third-Party Assessment Organizations (3PAOs)
Accredited, independent assessors that perform SCR CAP assessments and issue certifications. Find an SCR 3PAO.
RPOs & Implementation Support
Registered Provider Organizations (RPOs) help organizations implement SCF controls and prepare for assessment. Find an RPO. ComplianceForge, an SCF Licensed Content Provider, provides SCF-based documentation and Part 500 readiness services.
GRC Platforms
GRC platforms such as SCF Connect, which is built natively for the SCF, and Cyturus help you manage controls, evidence and remediation in one place. See our partners.
Frequently-Asked Questions
Here are answers to common questions about NY DFS 23 NYCRR Part 500:
