NYDFS Cybersecurity Regulation (Part 500)
Amended New York · In force Mar 1, 2017 · no upcoming deadlines
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
DFS-licensed financial companies must keep a risk-based cybersecurity program, CISO, policies, access controls, MFA, encryption, an asset inventory, and incident response and business continuity plans. They must notify DFS within 72 hours of a cybersecurity event and within 24 hours of any extortion payment, and certify compliance or acknowledge non-compliance each April 15. The 2023 Second Amendment added governance duties, Class A company requirements and phased controls through November 1, 2025.
- Who it applies to
- Covered entities: persons operating under a DFS license, registration, charter or similar authorization (banks, insurers, money transmitters, etc.). Class A companies: at least $20,000,000 gross annual revenue in each of the last two fiscal years from NY business, and either over 2,000 employees averaged over two years or over $1,000,000,000 gross annual revenue in each of the last two fiscal years. Limited exemption for fewer than 20 employees and contractors, under $7,500,000 gross annual revenue in each of the last 3 fiscal years, or under $15,000,000 year-end total assets.
- Penalties
- Penalties under the Banking Law, Insurance Law and Financial Services Law. 500.20 lists the factors DFS weighs; the regulation sets no fixed maximum. A single act or failure, including failing to comply for any 24-hour period, is a violation.
- Enforced by
- New York State Department of Financial Services (DFS)
- Official name
- New York DFS Cybersecurity Requirements for Financial Services Companies (23 NYCRR Part 500), Second Amendment
- Citation
- 23 NYCRR Part 500 (Second Amendment effective 2023-11-01)
- Topics
- cybersecurity, breach-notification, financial
Research notes
Dates are computed from the 500.22 transitional periods (30 days, 180 days, 1 year, 18 months and 2 years from the November 1, 2023 Second Amendment) and match DFS guidance. DFS also issued 2026 industry letters on frontier-AI cyber risk (May 21, 2026) and risk assessment (September 10, 2026); these are guidance, not rule changes.
Related
Questions about NYDFS Cybersecurity Regulation (Part 500)
- What are the NYDFS Cybersecurity Regulation (Part 500) compliance deadlines?
- Mar 1, 2017: Part 500 effective. Nov 1, 2023: Second Amendment effective. Dec 1, 2023: Amended notification requirements (500.17). Apr 15, 2024: Annual compliance notification. Apr 29, 2024: General 180-day transition ends. Nov 1, 2024: Governance, encryption, IR/BCDR, exemptions. May 1, 2025: Vulnerability scans, access privileges, malware controls, Class A monitoring. Nov 1, 2025: Universal MFA and asset inventory. Apr 15, 2026: Annual compliance notification.
- When does NYDFS Cybersecurity Regulation (Part 500) take effect?
- NYDFS Cybersecurity Regulation (Part 500) took effect on Mar 1, 2017.
- Who does NYDFS Cybersecurity Regulation (Part 500) apply to?
- Covered entities: persons operating under a DFS license, registration, charter or similar authorization (banks, insurers, money transmitters, etc.). Class A companies: at least $20,000,000 gross annual revenue in each of the last two fiscal years from NY business, and either over 2,000 employees averaged over two years or over $1,000,000,000 gross annual revenue in each of the last two fiscal years. Limited exemption for fewer than 20 employees and contractors, under $7,500,000 gross annual revenue in each of the last 3 fiscal years, or under $15,000,000 year-end total assets.
- What are the penalties under NYDFS Cybersecurity Regulation (Part 500)?
- Penalties under the Banking Law, Insurance Law and Financial Services Law. 500.20 lists the factors DFS weighs; the regulation sets no fixed maximum. A single act or failure, including failing to comply for any 24-hour period, is a violation.