Home » Compliance » NYDFS 23 NYCRR 500

Compliance — NYDFS

NYDFS cybersecurity consulting for 23 NYCRR 500

If you hold a New York financial services license, Part 500 is not advisory: MFA for everyone, an asset inventory you can defend, incident reporting on a 72-hour clock, and a certification your senior-most executive signs every April. We operate the program those obligations assume.

Who Part 500 covers

23 NYCRR 500 applies to anyone operating under a license, registration, or charter under New York’s Banking Law, Insurance Law, or Financial Services Law: banks and trust companies, insurance companies and independent agencies, mortgage lenders and brokers, money transmitters, and many advisory and brokerage businesses. Size helps less than owners assume — the Second Amendment narrowed the limited exemptions, and the MFA carve-out for smaller companies ended on November 1, 2025.

The firms squeezed hardest are the ones the large finance-only IT providers never priced for: independent RIAs, family offices, insurance agencies, and small broker-dealers carrying the same obligations as a bank, without a security hire. That is the firm we built this service for — see financial services.

The Second Amendment timeline

DFS adopted the Second Amendment in November 2023 and phased it in over two years. Every tranche is now in effect — including the final one.

DateWhat took effect
Nov 1, 2023Second Amendment adopted; transition periods begin
Dec 1, 2023Amended incident reporting: notice to DFS within 72 hours of determining a reportable cybersecurity event occurred, and within 24 hours of any extortion payment
April 15, annuallyCertification of material compliance — or a written acknowledgment of noncompliance with a remediation timeline — filed with DFS, signed by the highest-ranking executive and the CISO
2024 – mid-2025Phased deadlines across governance, encryption, incident response and business continuity planning, vulnerability management, and access-privilege reviews
Nov 1, 2025Final tranche: MFA required for any individual accessing your information systems — the small-business exemption is gone — plus documented asset inventory procedures

The practical consequence: a covered firm that was arguably fine in 2024 on the strength of an exemption may be plainly out of compliance today, and will certify — or acknowledge noncompliance — next April either way.

What Stedholm operates for Part 500

Each control is run continuously and evidenced against the section of the regulation it satisfies.

  • Multi-factor authentication, universally

    MFA enforced on email, remote access, and privileged accounts across the firm, with any exceptions documented through the CISO-approved process the regulation requires.

  • Asset inventory

    A maintained inventory of information systems with owners, classifications, and end-of-support dates — current, not a spreadsheet from onboarding.

  • Access reviews and least privilege

    Periodic reviews of user access privileges, with departures and role changes reflected the day they happen.

  • Monitoring and detection

    Your environment is monitored around the clock by our tooling, with escalation to an engineer — see managed detection and response.

  • Vulnerability management and penetration testing

    Regular scanning plus annual penetration testing, with findings tracked to closure rather than filed.

  • Incident response and reporting

    A written, rehearsed plan that includes the 72-hour DFS notice and the 24-hour extortion-payment notice, so nobody is reading the regulation for the first time during an incident.

  • Risk assessment and written policies

    The risk assessment that drives the program, and policies that describe what you actually do rather than what a template hoped.

  • Training

    Periodic security awareness training, including the social-engineering component the amended rule expects.

How we take a firm to April 15

  1. Scope and gap assessment

    We establish which provisions apply to you — including an honest look at any exemption status, confirmed with your counsel — and map current controls against each section.

  2. Remediation plan

    Sequenced by regulatory deadline and risk, with pricing in writing. MFA gaps and reporting readiness come first because they are what DFS checks first.

  3. Control operation

    MFA, inventory, monitoring, access reviews, and training run as daily discipline — ours, so your team runs the business.

  4. Evidence file

    Every control produces artifacts filed against its section of the regulation as we go, not reconstructed in March.

  5. Certification support

    We assemble the record behind the certification or acknowledgment. Your executives sign with the evidence in front of them, which is the only comfortable way to sign.

The CISO requirement, filled by a vCISO

Part 500 requires a CISO: a qualified individual responsible for the program who reports on it to your board or senior officer. The regulation permits that person to come from a third-party service provider, with your senior leadership retaining oversight. Our vCISO service fills the role at a scale a twenty-person RIA can actually afford — program ownership, board reporting, and the judgment calls between the deadlines.

We prepare and operate controls; we are not a law firm or an auditor. Your counsel interprets the regulation and DFS examiners draw their own conclusions — our job is to make that examination uneventful. Note that insurance agencies are often also covered by the FTC Safeguards Rule; the control set overlaps almost entirely, so we evidence both from one program. More regimes at the compliance hub.

  • Good fit if

  • You hold a NYDFS license and have no security staff

  • The April filing has been signed on hope rather than evidence

  • MFA coverage is partial and you know it

  • A DFS exam or inquiry letter has concentrated attention

  • Your cyber-insurance renewal asks Part 500-shaped questions

Common questions

We are a small agency. Are we really covered?

If you are licensed under the Banking, Insurance, or Financial Services Law, almost certainly yes. Limited exemptions still exist but were narrowed by the Second Amendment, and the small-business MFA exemption ended November 1, 2025. Exemption status is a legal determination — confirm it with counsel, and we will build to whatever your actual status is.

What happens on April 15?

Every covered entity files one of two things with DFS, covering the prior calendar year: a certification of material compliance, or a written acknowledgment of noncompliance identifying the gaps and a remediation timeline. Both are signed by your highest-ranking executive and your CISO — which is why we insist the evidence exists before the signature does.

Can you be our CISO?

We can fill the CISO function as a vCISO, which the regulation permits when the role comes from a third-party service provider and your senior leadership retains oversight. You keep a named senior officer accountable internally; we do the operating and the reporting. See strategic IT.

How is this different from what our current IT company does?

Most IT providers enable controls; Part 500 requires operating and evidencing them — reviews on a cadence, reports mapped to sections, filings supported by artifacts. If your provider cannot show you the evidence file today, that is the difference. A co-managed arrangement also works: they keep the help desk, we run the program.

Certify with evidence, not optimism.

A Part 500 gap assessment tells you exactly where you stand against every tranche now in effect — findings are yours to keep.