NY DFS 23 NYCRR Part 500 At A Glance
- Who: Entities licensed, registered or chartered by the NY DFS, including banks, insurers, mortgage companies, money transmitters and virtual currency businesses (§ 500.1).
- When: The Second Amendment took effect November 1, 2023. The last phased requirements, MFA for all access and the asset inventory, took effect November 1, 2025 (§ 500.22).
- Annual filing: By April 15 each year, a Certification of Material Compliance or an Acknowledgment of Noncompliance, signed by the highest-ranking executive and the CISO (§ 500.17(b)).
- Deadlines: 72 hours to notify DFS of a cybersecurity incident, and 24 hours to report an extortion payment, with a written explanation within 30 days (§ 500.17).
- Frameworks: NIST CSF 2.0 and ISO 27001/27002 do not specify these deadlines, testing frequencies or Class A requirements, so using them for Part 500 takes significant customization.
- Recommendation: ComplianceForge recommends the Secure Controls Framework (SCF), which publishes a Set Theory Relationship Mapping (STRM) for the 2023 amended Part 500.
- Assurance: An SCR certification for NY DFS 23 NYCRR Part 500, issued by an independent SCR 3PAO, gives the CISO third-party evidence before signing.
Executive Liability: The Annual Compliance Filing
Each covered entity must submit one of two filings to DFS by April 15 each year, covering the prior calendar year: a Certification of Material Compliance, if it materially complied with Part 500, or an Acknowledgment of Noncompliance, which identifies every section it did not materially comply with, describes the nature and extent of the noncompliance and provides a remediation timeline (§ 500.17(b)(1)).
Under § 500.17(b)(2), the filing must be signed by the covered entity's highest-ranking executive and its CISO. If there is no CISO, the highest-ranking executive and the senior officer responsible for the cybersecurity program sign. A certification must be based on data and documentation sufficient to accurately determine and demonstrate material compliance, and that support must be kept for five years (§ 500.17(b)(3)).
That is why the evidence matters as much as the controls. Our program produces a documented compliance record that supports a credible filing and protects the executives who sign it.
Certification Of Material Compliance
Path A: Compliant entities. Filed when the entity materially complied with Part 500 during the prior calendar year. It must rest on data and documentation sufficient to demonstrate that compliance.
Acknowledgment Of Noncompliance
Path B: Gaps remain. Filed when material compliance cannot be certified. It must identify each noncompliant section, describe the nature and extent of the noncompliance and give a remediation timeline or confirm that remediation is complete.
"Annually each covered entity shall submit to the superintendent electronically by April 15 either" a written certification of material compliance or a written acknowledgment of noncompliance.
Legal Exposure Beyond DFS
A certification must be based on data and documentation sufficient to accurately determine and demonstrate material compliance (§ 500.17(b)(1)). Signing one without that support is a Part 500 problem first.
Officers who knowingly sign a false filing may also face exposure under other New York laws, such as the New York False Claims Act. How those laws apply to your filing is a question for your legal counsel.
Two Filing Paths, One Deadline
Certify material compliance or acknowledge noncompliance by April 15. Both are signed by the highest-ranking executive and the CISO, or by the senior officer responsible for the cybersecurity program if there is no CISO (§ 500.17(b)(2)).
Unsupported Certification Is A Violation
A certification must be based on data and documentation sufficient to demonstrate material compliance (§ 500.17(b)(1)). Filing one without that support exposes the entity and its signers to enforcement.
5-Year Documentation Retention
Records, schedules and data supporting the filing, including remediation efforts and plans, must be kept for five years and provided to DFS on request (§ 500.17(b)(3)).
Acknowledge & Remediate
If you cannot certify material compliance, an Acknowledgment of Noncompliance with a credible remediation timeline is the path the regulation provides, and it is far better than an unsupported certification.
What Is 23 NYCRR Part 500?
23 NYCRR Part 500, Cybersecurity Requirements for Financial Services Companies, is the NY DFS cybersecurity regulation. It first took effect on March 1, 2017, and the Second Amendment, effective November 1, 2023, substantially expanded it. It applies to any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the New York Banking Law, Insurance Law or Financial Services Law.
Unlike general cybersecurity frameworks, Part 500 sets legally binding requirements with specific deadlines, testing frequencies, technology requirements for larger companies, officer signatures and incident reporting obligations. The commission of a single prohibited act, or the failure to satisfy a single obligation, is a violation (§ 500.20).
Our program addresses the full scope of Part 500: mapping every requirement to SCF controls, assessing your implementation against the regulation and producing the evidence that supports your annual filing.
- Cybersecurity program based on your risk assessment (§ 500.2)
- Written cybersecurity policies approved at least annually by a senior officer or the senior governing body (§ 500.3)
- A qualified CISO who reports in writing at least annually to the senior governing body (§ 500.4)
- Annual penetration testing and risk-based automated vulnerability scanning (§ 500.5)
- Audit trail systems (§ 500.6)
- Access privilege limits with at least annual access reviews (§ 500.7)
- Application security procedures (§ 500.8)
- Risk assessment reviewed at least annually (§ 500.9)
- Third-party service provider security policy (§ 500.11)
- Multi-factor authentication for any individual accessing any information system (§ 500.12)
- Asset inventory and secure disposal of nonpublic information (§ 500.13)
- Monitoring and at least annual cybersecurity awareness training (§ 500.14)
- Encryption of nonpublic information in transit and at rest (§ 500.15)
- Incident response and business continuity plans, tested at least annually (§ 500.16)
- 72-hour incident notice, extortion payment reporting and the annual filing (§ 500.17)
Does Part 500 Apply To Your Entity?
Part 500 applies to any person operating under, or required to operate under, a DFS license, registration, charter, certificate, permit, accreditation or similar authorization, including:
- State-chartered banks and trust companies
- Insurance companies licensed in New York
- Mortgage bankers, servicers and brokers
- Money transmitters and check cashers
- Premium finance agencies and budget planners
- Virtual currency businesses (BitLicense holders)
Limited exemptions exist for smaller entities (§ 500.19), but they must still meet the sections that are not exempted and file a Notice of Exemption within 30 days of determining they qualify.
2023 Amendment: What Changed
The Second Amendment substantially expanded Part 500:
- "Class A" companies with additional requirements (§ 500.1)
- Independent audits for Class A companies (§ 500.2(c))
- Senior governing body oversight duties (§ 500.4(d))
- MFA for any individual accessing any information system (§ 500.12)
- Asset inventory requirements (§ 500.13)
- 24-hour extortion payment notice and 30-day explanation (§ 500.17(c))
- Incident notice that covers events at affiliates and third-party service providers (§ 500.17(a))
- A choice of certification or acknowledgment, signed by the highest-ranking executive and the CISO (§ 500.17(b))
Why NIST CSF 2.0 And ISO 27001/27002 Aren't Enough For Part 500
NIST CSF 2.0 and ISO 27001/27002 are not sufficient on their own to comply with NY DFS 23 NYCRR Part 500. Both are good foundations, but neither was written for Part 500, so neither specifies its deadlines, testing frequencies, Class A requirements or the signed annual filing. NIST says the CSF "does not prescribe how outcomes should be achieved," and ISO 27001 leaves control selection to your risk assessment and Statement of Applicability. To use either one for Part 500, you have to add and track the Part 500 requirements yourself.
Where Part 500 is specific and the general frameworks are not:
This is not a knock on either framework. NIST CSF 2.0 is a strong way to organize cybersecurity outcomes, and ISO 27001 is a strong management system. The issue is the gap between what they describe and what Part 500 requires, which means you would build and maintain your own Part 500 crosswalk on top of them. Learn more in our NIST CSF 2.0 and ISO 27001/27002 guides.
What Is The Best Framework For NY DFS 23 NYCRR Part 500 Compliance?
ComplianceForge recommends the Secure Controls Framework (SCF) as the best framework for Part 500 compliance. The SCF is a free metaframework with 1,500+ controls across 34 domains, mapped to 200+ laws, regulations and frameworks, including the 2023 amended Part 500, NIST CSF 2.0, ISO 27001:2022, GLBA and the FFIEC IT Examination Handbook. You implement one control set and show compliance with Part 500 and the other frameworks your examiners, auditors and customers expect.
Part 500 Mapped With STRM
The SCF publishes a Set Theory Relationship Mapping (STRM) for Part 500 (2023 Amendment 2), based on NIST IR 8477. Each Part 500 requirement is mapped to SCF controls with a stated relationship and strength, so you can show an examiner which controls meet which section.
Built For Prescriptive Requirements
Where Part 500 sets a deadline or a frequency, the SCF gives you a specific control to implement and evidence, such as penetration testing (VPM-18) or privileged user monitoring (MON-14.2), instead of a broad outcome you have to interpret.
Class A Requirements Covered
Class A requirements, such as independent audits (§ 500.2(c)) and privileged access management (§ 500.7(c)), are mapped to specific SCF controls in the Part 500 STRM, so larger companies use the same control set as everyone else.
One Control Set, Many Obligations
Most financial institutions answer to more than Part 500. The SCF also maps GLBA, the FFIEC IT Examination Handbook, NIST CSF 2.0, ISO 27001 and state privacy laws, so evidence you collect once can support all of them. See our GLBA guide.
Certifiable Through The SCR CAP
An accredited SCR 3PAO can assess your SCF controls for an SCR certification for NY DFS 23 NYCRR Part 500, giving your CISO independent evidence before the April 15 filing. See how it works.
Free To Use
The SCF is free to use under a Creative Commons license, so there is no framework licensing cost to adopt it as your common control set.
ComplianceForge is an authorized SCF Licensed Content Provider (LCP). Our SCF-based policies and standards (SCRP) and procedures (CSOP) give you editable documentation already aligned to SCF controls, so your evidence traces back to Part 500 sections through the SCF's Part 500 STRM. For program-level requirements, pair them with our Third-Party Risk Management (TPRM) Program for § 500.11, Cybersecurity Risk Assessment (CRA) Template for § 500.9, Vulnerability & Patch Management Program (VPMP) for § 500.5, Integrated Incident Response Program (IIRP) for § 500.16 and Continuity Of Operations Plan (COOP) for business continuity and disaster recovery.
Independent Assurance For The CISO: SCR Certified - NY DFS 23 NYCRR Part 500
The CISO and the highest-ranking executive sign the annual filing, but they rarely test every control themselves. The Secure, Compliant & Resilient Conformity Assessment Program (SCR CAP) gives them independent evidence. An accredited SCR Third-Party Assessment Organization (3PAO) assesses your SCF controls against the SCR assessment guide for NY DFS 23 NYCRR Part 500 and, if you conform, issues an SCR certification for Part 500.
The Cyber AB is the Accreditation Body for the SCR CAP. It accredits SCR 3PAOs and oversees conflict-of-interest governance, which is meant to keep the organization that certifies you independent of the one that helped you prepare. SCR certification is not a DFS requirement and does not replace your annual filing. It is third-party evidence that your controls are in place and operating, which the people who sign the filing can rely on.
Certification follows a three-year lifecycle. An SCR 3PAO performs the initial assessment. In years two and three, you perform an internal assessment and provide a self-attestation that you continue to conform, and a new 3PAO assessment is required at the end of year three. That rhythm lines up with the annual April 15 filing.
Our assessment process is pre-aligned to SCF controls, so the evidence gathered for your Part 500 readiness assessment is organized the way a 3PAO will evaluate it.
What The SCR CAP Assesses For Part 500
The SCR assessment guide for NY DFS 23 NYCRR Part 500 defines the SCF controls in scope, the assessment objectives a 3PAO evaluates, the evidence expected and how conformity is scored.
Who Performs The Assessment
An SCR 3PAO accredited by The Cyber AB. You can find accredited 3PAOs in the SCF Marketplace.
How It Supports The April 15 Filing
A certification must rest on data and documentation sufficient to demonstrate material compliance (§ 500.17(b)(1)). An independent report on conformity is strong support for that record, alongside your internal evidence.
Why Not Self-Attestation Alone?
Self-assessments are easy to challenge after an incident. An independent assessment against a documented methodology is harder to dispute and is useful for DFS examinations, cyber insurance underwriting and customer due diligence.
The Part 500 Cybersecurity Requirements, Section By Section
Part 500 sets specific, enforceable obligations with defined scope, technical requirements, personnel requirements and filing obligations. Our assessment program is structured section by section around these requirements, so every deliverable maps directly to the regulation.
PROGRAM & GOVERNANCE: Program, Policy & CISO
Program, policy and accountability requirements
- § 500.2 Cybersecurity Program. Maintain a cybersecurity program, based on your risk assessment, that protects the confidentiality, integrity and availability of your information systems and nonpublic information. Class A companies must also conduct independent audits of the program (§ 500.2(c)).
- § 500.3 Cybersecurity Policy. Written policies, approved at least annually by a senior officer or the senior governing body, covering 15 areas, from information security and data governance to asset inventory, access controls, business continuity, vendor management, incident response and vulnerability management.
- § 500.4 CISO & Board Oversight. Designate a qualified CISO who reports in writing at least annually to the senior governing body on the program, material risks and plans for remediating material inadequacies. The senior governing body must exercise oversight, including having sufficient understanding of cybersecurity matters and confirming that adequate resources are allocated.
- § 500.9 Risk Assessment. Conduct a periodic risk assessment, reviewed and updated at least annually and whenever a material change to cyber risk occurs.
- § 500.15 Encryption. A written policy requiring encryption that meets industry standards for nonpublic information in transit over external networks and at rest. Where encryption at rest is infeasible, the CISO may approve effective compensating controls in writing.
- § 500.17(b) Annual Compliance Filing. By April 15, a Certification of Material Compliance or an Acknowledgment of Noncompliance, signed by the highest-ranking executive and the CISO, with supporting records kept for five years.
TECHNICAL CONTROLS: Testing, Access & Monitoring
Testing frequencies, access controls and monitoring requirements
- § 500.5 Vulnerability Management. Penetration testing from inside and outside your system boundaries by a qualified internal or external party at least annually, automated vulnerability scans at a frequency your risk assessment sets plus manual review of systems the scans do not cover, and timely, risk-prioritized remediation.
- § 500.6 Audit Trail. Systems designed to reconstruct material financial transactions and audit trails designed to detect and respond to cybersecurity events, with records retained as § 500.6 requires (at least five years for transaction records).
- § 500.7 Access Privileges. Limit access to what each user needs to perform their job and review all user access privileges at least annually. Class A companies must also monitor privileged access, implement privileged access management and automatically block commonly used passwords.
- § 500.12 Multi-Factor Authentication. MFA for any individual accessing any of your information systems, with narrower requirements for entities that qualify for a limited exemption.
- § 500.13 Asset Management & Data Retention. A complete, accurate and documented asset inventory that tracks owner, location, classification or sensitivity, support expiration date and recovery time objectives, plus secure disposal of nonpublic information that is no longer needed.
- § 500.14 Monitoring & Training. Risk-based monitoring of authorized user activity, controls against malicious code in web traffic and email, and cybersecurity awareness training that includes social engineering at least annually. Class A companies must also implement endpoint detection and response and centralized logging and security event alerting.
INCIDENT RESPONSE: Notification & Business Continuity
Response planning, DFS notification and resilience requirements
- § 500.16 Incident Response Plan. Written incident response plans that address how you respond to and recover from cybersecurity events, including roles, communications and remediation.
- § 500.16 Business Continuity & Disaster Recovery. Written business continuity and disaster recovery (BCDR) plans to keep critical operations running and to recover from disruptions.
- § 500.16(d) Plan Testing. Test incident response and BCDR plans at least annually with all staff and management critical to the response, and revise them as needed.
- § 500.17(a) 72-Hour Incident Notice. Notify the Superintendent electronically as promptly as possible, and no later than 72 hours after determining that a cybersecurity incident occurred at the covered entity, its affiliates or a third-party service provider.
- § 500.17(c) Extortion Payments. Within 24 hours of an extortion payment, notify DFS of the payment. Within 30 days, provide a written description of why it was necessary, the alternatives considered and the diligence performed, including sanctions compliance.
THIRD-PARTY & APP SECURITY: Vendors, Applications & People
Vendor oversight, application security and personnel requirements
- § 500.11 Third-Party Service Provider Security Policy. Written policies covering the identification and risk assessment of third-party service providers, the minimum cybersecurity practices they must meet, due diligence and periodic assessment based on risk.
- § 500.8 Application Security. Written procedures, guidelines and standards for secure development of in-house applications, and procedures for evaluating, assessing or testing the security of externally developed applications.
- § 500.10 Cybersecurity Personnel & Intelligence. Employ or designate qualified cybersecurity personnel (internal staff or service providers) and use cybersecurity threat intelligence from internal or external sources.
- § 500.19 Limited Exemptions. Covered entities with fewer than 20 employees and independent contractors, less than $7.5 million in gross annual revenue in each of the last three fiscal years, or less than $15 million in year-end total assets (as calculated under § 500.19(a)) are exempt from certain sections. They must file a Notice of Exemption within 30 days of determining they qualify.
DFS Enforcement: Why Non-Compliance Is Not An Option
DFS enforces Part 500 through public consent orders with civil penalties and required remediation. A single prohibited act or a single unmet obligation is a violation (§ 500.20), whether or not a breach caused harm. Recent actions show where covered entities fall short.
Recent Part 500 Enforcement Actions
In November 2024, DFS and the New York Attorney General announced $11.3 million in penalties against GEICO ($9.75 million) and Travelers ($1.55 million) over data breaches affecting about 120,000 New Yorkers. DFS found that Travelers' agent portal did not use MFA or other compensating controls. In August 2025, DFS fined Healthplex $2 million after finding no MFA on its email environment, no email data retention policy and notice to DFS more than four months after it learned of the incident.
MFA gaps appear in multiple recent actions
Unsupported Certification Risk
A certification must be based on data and documentation sufficient to demonstrate material compliance (§ 500.17(b)(1)). If you cannot support it, the regulation provides the Acknowledgment of Noncompliance instead.
Signers need evidence, not assumptions
72-Hour Notification Failure
Missing the 72-hour notice is a violation on its own. Healthplex waited more than four months after learning of a phishing incident before notifying DFS, well beyond the 72-hour requirement.
Late notice is a separate violation
DFS Examination Exposure
DFS can examine covered entities and request the records that support your annual filing, which you must keep for five years (§ 500.17(b)(3)). Missing penetration test reports, risk assessments or CISO reports are hard to explain after the fact.
Keep the evidence behind every filing
Third-Party & Contract Risk
Covered entities must assess their third-party service providers and set the minimum cybersecurity practices those providers must meet (§ 500.11). If you serve banks, insurers or other DFS-regulated firms, expect to show Part 500-aligned controls during due diligence.
Part 500 reaches service providers through contracts
SCR Certification Advantage
An SCR certification for NY DFS 23 NYCRR Part 500 is a verifiable, third-party-validated credential you can share with DFS examiners, cyber insurers and counterparties, and it supports the evidence behind your § 500.17(b) filing.
Third-party validation behind the filing
The 23 NYCRR Part 500 Assessment Process
Our assessment program is structured around every applicable section of 23 NYCRR Part 500 and aligned to the Secure Controls Framework. Each phase produces deliverables that support your § 500.17(b) annual filing and prepare you for an independent SCR CAP assessment. ComplianceForge prepares you; the certification assessment itself is performed by an independent SCR 3PAO.
Scoping & Covered Entity Classification (§§ 500.1, 500.19)
We determine which Part 500 obligations apply to your entity, including whether you qualify for a limited exemption under § 500.19, whether you are a Class A company, and which sections require dedicated assessment. We inventory the information systems, nonpublic information and third-party service providers in scope.
Cybersecurity Program & Risk Assessment Review (§§ 500.2, 500.3, 500.9)
We assess your written cybersecurity program (§ 500.2), cybersecurity policies (§ 500.3) and risk assessment (§ 500.9) against Part 500. We confirm the policies cover all required areas, including access controls, data governance, asset inventory, business continuity, vendor management and incident response, and that they are approved at least annually.
Penetration Testing & Vulnerability Management (§ 500.5)
We conduct or coordinate the annual penetration testing and the risk-based automated vulnerability scanning required by § 500.5. Testing is performed by qualified internal or external parties from both inside and outside your system boundaries. Findings are documented with severity ratings and mapped to remediation priorities.
Technical Controls Assessment (§§ 500.6 To 500.15)
We assess the required technical controls: audit trail systems (§ 500.6), access privileges and annual access reviews (§ 500.7), application security (§ 500.8), multi-factor authentication (§ 500.12), asset inventory (§ 500.13), monitoring and training (§ 500.14) and encryption of nonpublic information (§ 500.15), including the added requirements for Class A companies.
CISO, Third-Party & Incident Response Review (§§ 500.4, 500.10, 500.11, 500.16)
We assess CISO qualifications and the annual written report to the senior governing body (§ 500.4), cybersecurity personnel and threat intelligence (§ 500.10), third-party service provider security policies and due diligence (§ 500.11), and incident response and BCDR plans and testing (§ 500.16), including readiness for the 72-hour incident notice and the 24-hour extortion payment notice (§ 500.17).
Annual Compliance Filing & CISO Board Report (§§ 500.4, 500.17(b))
We prepare the supporting package for your annual filing: either a Certification of Material Compliance or an Acknowledgment of Noncompliance with a remediation timeline. Under § 500.17(b)(2), the filing is signed by your highest-ranking executive and CISO (or, if there is no CISO, the senior officer responsible for the cybersecurity program) by April 15. We also prepare the CISO's annual written report to the senior governing body required by § 500.4(b) and organize the supporting records you must keep for five years under § 500.17(b)(3).
Remediation & Annual Compliance Cycle Management
We help you prioritize remediation of assessment findings, track progress to closure and set up the annual cycle Part 500 requires: penetration testing, risk assessment updates, access reviews, plan testing, training and the April 15 filing calendar.
Editable Policies, Standards & Procedures For Part 500
Part 500 requires written cybersecurity policies (§ 500.3) and a documented cybersecurity program (§ 500.2), and DFS can request the records behind your annual filing. Examiners expect documented policies, standards and procedures that govern how nonpublic information is protected and how the program runs day to day.
ComplianceForge provides professionally written, editable cybersecurity and data privacy documentation mapped to Secure Controls Framework (SCF) controls. Because the SCF maps those controls to Part 500, your documentation lines up with the same control set used in your Part 500 assessment, creating a connected evidence chain from policy to practice to certification.
SCF Control Mapping
Every policy, standard and procedure maps to SCF controls, the same framework used in your Part 500 assessment, so you do not need to build your own crosswalk for § 500.3.
Fully Editable & Customizable
Delivered in editable formats so you can tailor policies to your operating environment, technology stack, DFS license type and organizational structure.
Broad Regulatory Coverage
Covers Part 500 alongside NIST CSF 2.0, ISO 27001, SOC 2, GLBA and more, so one documentation investment supports multiple obligations.
Integrated With Your Assessment
Documentation is selected and implemented as part of your Part 500 remediation, directly addressing policy gaps found in your § 500.3 assessment.
- SCF Policies & Standards (SCRP): cybersecurity policies and standards (§ 500.3)
- SCF Procedures (CSOP): control procedures, including access management (§ 500.7)
- Integrated Incident Response Program (IIRP): incident response planning (§ 500.16)
- Continuity Of Operations Plan (COOP): business continuity and disaster recovery (§ 500.16)
- Third-Party Risk Management (TPRM) Program: third-party service provider security (§ 500.11)
- Cybersecurity Risk Assessment (CRA) Template: risk assessment (§ 500.9)
- Vulnerability & Patch Management Program (VPMP): vulnerability management (§ 500.5)
The SCR CAP Ecosystem For Part 500
Part 500 compliance and SCR certification involve several independent roles. Knowing who does what helps you keep preparation and certification separate.
The Cyber AB
The Accreditation Body for the SCR CAP. It accredits SCR 3PAOs and oversees conflict-of-interest governance across the program.
SCR Third-Party Assessment Organizations (3PAOs)
Accredited, independent assessors that perform SCR CAP assessments and issue certifications. Find an SCR 3PAO.
RPOs & Implementation Support
Registered Provider Organizations (RPOs) help organizations implement SCF controls and prepare for assessment. Find an RPO. ComplianceForge, an SCF Licensed Content Provider, provides SCF-based documentation and Part 500 readiness services.
GRC Platforms
GRC platforms such as SCF Connect, which is built natively for the SCF, and Cyturus help you manage controls, evidence and remediation in one place. See our partners.
NY DFS 23 NYCRR Part 500: Common Questions
What is 23 NYCRR Part 500?
23 NYCRR Part 500, Cybersecurity Requirements for Financial Services Companies, is the New York Department of Financial Services (NY DFS) cybersecurity regulation. It requires covered entities to maintain a risk-based cybersecurity program, written policies, a CISO, specific technical controls, incident notification and an annual compliance filing. The Second Amendment took effect on November 1, 2023, with requirements phased in through November 1, 2025.
Who must comply with NY DFS Part 500?
Any person operating under, or required to operate under, a DFS license, registration, charter, certificate, permit, accreditation or similar authorization is a covered entity (§ 500.1). That includes state-chartered banks, insurance companies, mortgage bankers and servicers, money transmitters, check cashers, premium finance agencies and virtual currency businesses. Third-party service providers are affected through the vendor requirements in § 500.11.
What changed in the 2023 Part 500 amendment?
The Second Amendment added Class A requirements for larger companies (independent audits, privileged access management, endpoint detection and response and centralized logging), senior governing body oversight duties, MFA for any individual accessing any information system, asset inventory requirements, a 24-hour extortion payment notice with a 30-day written explanation, and a choice between a certification and an acknowledgment of noncompliance, signed by the highest-ranking executive and the CISO.
What is a Class A company under Part 500?
A Class A company is a covered entity with at least $20 million in gross annual revenue in each of the last two fiscal years from all of its business operations and the New York business operations of its affiliates, and either more than 2,000 employees averaged over the last two fiscal years, including affiliates, or more than $1 billion in gross annual revenue in each of the last two fiscal years from all business operations of the covered entity and its affiliates (§ 500.1(d)).
Are small companies exempt from Part 500?
Partially. A covered entity with fewer than 20 employees and independent contractors, less than $7.5 million in gross annual revenue in each of the last three fiscal years, or less than $15 million in year-end total assets (as calculated under § 500.19(a)) is exempt from certain sections, including the CISO, penetration testing, audit trail, application security, encryption and incident response plan requirements. It must still meet the remaining sections and file a Notice of Exemption within 30 days of determining it qualifies.
Is NIST CSF 2.0 enough to comply with NY DFS Part 500?
No, not on its own. NIST CSF 2.0 describes cybersecurity outcomes and, in NIST's words, "does not prescribe how outcomes should be achieved." It has no 72-hour regulator notice, no extortion payment reporting, no Class A requirements and no signed annual filing, so you would need significant customization to cover Part 500. ComplianceForge recommends implementing the SCF, which maps to both NIST CSF 2.0 and Part 500.
Does ISO 27001 or SOC 2 satisfy Part 500?
Not automatically. ISO 27001 certifies an information security management system in which you choose your controls through your risk assessment and Statement of Applicability, and a SOC 2 report attests to controls against the AICPA Trust Services Criteria. Neither maps directly to Part 500 requirements such as annual penetration testing, MFA for any individual, Class A requirements or the April 15 filing. Existing evidence can often be reused, but the gaps need additional work.
What is the best framework for NY DFS Part 500 compliance?
ComplianceForge recommends the Secure Controls Framework (SCF). It is a free metaframework with 1,500+ controls across 34 domains, mapped to 200+ laws, regulations and frameworks, and it publishes a Set Theory Relationship Mapping (STRM) for the 2023 amended Part 500. One SCF control set can cover Part 500, NIST CSF 2.0, ISO 27001, GLBA and the FFIEC IT Examination Handbook, and it can be independently certified through the SCR CAP.
What is the annual compliance filing and when is it due?
By April 15 each year, every covered entity must submit to DFS either a Certification of Material Compliance for the prior calendar year or an Acknowledgment of Noncompliance that identifies each noncompliant section, describes the nature and extent of the noncompliance and provides a remediation timeline. Both are signed by the highest-ranking executive and the CISO (§ 500.17(b)(2)), and supporting records must be kept for five years (§ 500.17(b)(3)).
What happens if we can't certify full compliance?
You still must file. If you cannot certify material compliance, you file an Acknowledgment of Noncompliance that acknowledges you did not materially comply, identifies every noncompliant section, describes the nature and extent of the noncompliance and provides a remediation timeline or confirms that remediation is complete. A transparent acknowledgment is the path the regulation provides. Filing nothing, or filing an unsupported certification, creates far greater regulatory risk.
What are the 72-hour and 24-hour DFS notification requirements?
Under § 500.17(a), you must notify the Superintendent as promptly as possible and no later than 72 hours after determining that a cybersecurity incident occurred at your company, an affiliate or a third-party service provider. Under § 500.17(c), you must report an extortion payment within 24 hours of making it and provide a written explanation within 30 days. Our incident response program sets up the workflows to meet both deadlines.
What does § 500.5 require for penetration testing?
Penetration testing of your information systems at least annually, from both inside and outside the system boundaries, by a qualified internal or external party, plus automated vulnerability scans at a frequency set by your risk assessment and manual review of systems the scans do not cover. Vulnerabilities must be remediated in a timely, risk-prioritized way. Our program conducts or coordinates both.
Can an SCR certification support the annual Part 500 filing?
Yes, as evidence. An SCR certification for NY DFS 23 NYCRR Part 500 is issued by an independent SCR 3PAO accredited by The Cyber AB after it assesses your SCF controls. It does not replace the DFS filing, and DFS does not require it, but it gives the highest-ranking executive and the CISO third-party evidence that the controls are in place and operating before they sign.
Do Class A companies need an independent audit under Part 500?
Yes. Each Class A company must design and conduct independent audits of its cybersecurity program based on its risk assessment (§ 500.2(c)). Other covered entities do not have this specific audit requirement, but they must still maintain a risk-based cybersecurity program. A ComplianceForge readiness assessment can help you prepare for the audit, and an SCR certification can add independent evidence that your SCF controls are in place and operating.
Request A Part 500 Readiness Assessment
Contact ComplianceForge to schedule a no-obligation discovery call. We will scope your Part 500 obligations, explain the SCR certification pathway and show how our documentation and assessment services make your annual DFS filing defensible and affordable.
- Every applicable section: Full Part 500 coverage
- April 15: Annual filing deadline
- SCR Certified - NY DFS 23 NYCRR Part 500: Independent certification
