Skip to content

NYDFS Cybersecurity Regulation (Part 500)

Amended New York · In force Mar 1, 2017 · no upcoming deadlines

Deadlines

DateWhat happens
Mar 1, 2017Part 500 effective9.6 years ago
Nov 1, 2023Second Amendment effective2.9 years ago
Dec 1, 2023Amended notification requirements (500.17)2.8 years ago
Apr 15, 2024Annual compliance notification2.4 years ago
Apr 29, 2024General 180-day transition ends2.4 years ago
Nov 1, 2024Governance, encryption, IR/BCDR, exemptions23 months ago
May 1, 2025Vulnerability scans, access privileges, malware controls, Class A monitoring17 months ago
Nov 1, 2025Universal MFA and asset inventory11 months ago
Apr 15, 2026Annual compliance notification5 months ago

Summaries for reference, not legal advice. Check the official text.

What it does

DFS-licensed financial companies must keep a risk-based cybersecurity program, CISO, policies, access controls, MFA, encryption, an asset inventory, and incident response and business continuity plans. They must notify DFS within 72 hours of a cybersecurity event and within 24 hours of any extortion payment, and certify compliance or acknowledge non-compliance each April 15. The 2023 Second Amendment added governance duties, Class A company requirements and phased controls through November 1, 2025.

Who it applies to
Covered entities: persons operating under a DFS license, registration, charter or similar authorization (banks, insurers, money transmitters, etc.). Class A companies: at least $20,000,000 gross annual revenue in each of the last two fiscal years from NY business, and either over 2,000 employees averaged over two years or over $1,000,000,000 gross annual revenue in each of the last two fiscal years. Limited exemption for fewer than 20 employees and contractors, under $7,500,000 gross annual revenue in each of the last 3 fiscal years, or under $15,000,000 year-end total assets.
Penalties
Penalties under the Banking Law, Insurance Law and Financial Services Law. 500.20 lists the factors DFS weighs; the regulation sets no fixed maximum. A single act or failure, including failing to comply for any 24-hour period, is a violation.
Enforced by
New York State Department of Financial Services (DFS)
Official name
New York DFS Cybersecurity Requirements for Financial Services Companies (23 NYCRR Part 500), Second Amendment
Citation
23 NYCRR Part 500 (Second Amendment effective 2023-11-01)
Topics
cybersecurity, breach-notification, financial
Verified 2026-09-22 dfs.ny.gov
Research notes

Dates are computed from the 500.22 transitional periods (30 days, 180 days, 1 year, 18 months and 2 years from the November 1, 2023 Second Amendment) and match DFS guidance. DFS also issued 2026 industry letters on frontier-AI cyber risk (May 21, 2026) and risk assessment (September 10, 2026); these are guidance, not rule changes.

Related

Questions about NYDFS Cybersecurity Regulation (Part 500)
What are the NYDFS Cybersecurity Regulation (Part 500) compliance deadlines?
Mar 1, 2017: Part 500 effective. Nov 1, 2023: Second Amendment effective. Dec 1, 2023: Amended notification requirements (500.17). Apr 15, 2024: Annual compliance notification. Apr 29, 2024: General 180-day transition ends. Nov 1, 2024: Governance, encryption, IR/BCDR, exemptions. May 1, 2025: Vulnerability scans, access privileges, malware controls, Class A monitoring. Nov 1, 2025: Universal MFA and asset inventory. Apr 15, 2026: Annual compliance notification.
When does NYDFS Cybersecurity Regulation (Part 500) take effect?
NYDFS Cybersecurity Regulation (Part 500) took effect on Mar 1, 2017.
Who does NYDFS Cybersecurity Regulation (Part 500) apply to?
Covered entities: persons operating under a DFS license, registration, charter or similar authorization (banks, insurers, money transmitters, etc.). Class A companies: at least $20,000,000 gross annual revenue in each of the last two fiscal years from NY business, and either over 2,000 employees averaged over two years or over $1,000,000,000 gross annual revenue in each of the last two fiscal years. Limited exemption for fewer than 20 employees and contractors, under $7,500,000 gross annual revenue in each of the last 3 fiscal years, or under $15,000,000 year-end total assets.
What are the penalties under NYDFS Cybersecurity Regulation (Part 500)?
Penalties under the Banking Law, Insurance Law and Financial Services Law. 500.20 lists the factors DFS weighs; the regulation sets no fixed maximum. A single act or failure, including failing to comply for any 24-hour period, is a violation.

When the rules change: new data, privacy and AI laws and deadlines, the next morning.