Compliance — NYDFS
NYDFS cybersecurity consulting for 23 NYCRR 500
If you hold a New York financial services license, Part 500 is not advisory: MFA for everyone, an asset inventory you can defend, incident reporting on a 72-hour clock, and a certification your senior-most executive signs every April. We operate the program those obligations assume.
Who Part 500 covers
23 NYCRR 500 applies to anyone operating under a license, registration, or charter under New York’s Banking Law, Insurance Law, or Financial Services Law: banks and trust companies, insurance companies and independent agencies, mortgage lenders and brokers, money transmitters, and many advisory and brokerage businesses. Size helps less than owners assume — the Second Amendment narrowed the limited exemptions, and the MFA carve-out for smaller companies ended on November 1, 2025.
The firms squeezed hardest are the ones the large finance-only IT providers never priced for: independent RIAs, family offices, insurance agencies, and small broker-dealers carrying the same obligations as a bank, without a security hire. That is the firm we built this service for — see financial services.
The Second Amendment timeline
DFS adopted the Second Amendment in November 2023 and phased it in over two years. Every tranche is now in effect — including the final one.
| Date | What took effect |
|---|---|
| Nov 1, 2023 | Second Amendment adopted; transition periods begin |
| Dec 1, 2023 | Amended incident reporting: notice to DFS within 72 hours of determining a reportable cybersecurity event occurred, and within 24 hours of any extortion payment |
| April 15, annually | Certification of material compliance — or a written acknowledgment of noncompliance with a remediation timeline — filed with DFS, signed by the highest-ranking executive and the CISO |
| 2024 – mid-2025 | Phased deadlines across governance, encryption, incident response and business continuity planning, vulnerability management, and access-privilege reviews |
| Nov 1, 2025 | Final tranche: MFA required for any individual accessing your information systems — the small-business exemption is gone — plus documented asset inventory procedures |
The practical consequence: a covered firm that was arguably fine in 2024 on the strength of an exemption may be plainly out of compliance today, and will certify — or acknowledge noncompliance — next April either way.
What Stedholm operates for Part 500
Each control is run continuously and evidenced against the section of the regulation it satisfies.
Multi-factor authentication, universally
MFA enforced on email, remote access, and privileged accounts across the firm, with any exceptions documented through the CISO-approved process the regulation requires.
Asset inventory
A maintained inventory of information systems with owners, classifications, and end-of-support dates — current, not a spreadsheet from onboarding.
Access reviews and least privilege
Periodic reviews of user access privileges, with departures and role changes reflected the day they happen.
Monitoring and detection
Your environment is monitored around the clock by our tooling, with escalation to an engineer — see managed detection and response.
Vulnerability management and penetration testing
Regular scanning plus annual penetration testing, with findings tracked to closure rather than filed.
Incident response and reporting
A written, rehearsed plan that includes the 72-hour DFS notice and the 24-hour extortion-payment notice, so nobody is reading the regulation for the first time during an incident.
Risk assessment and written policies
The risk assessment that drives the program, and policies that describe what you actually do rather than what a template hoped.
Training
Periodic security awareness training, including the social-engineering component the amended rule expects.
How we take a firm to April 15
Scope and gap assessment
We establish which provisions apply to you — including an honest look at any exemption status, confirmed with your counsel — and map current controls against each section.
Remediation plan
Sequenced by regulatory deadline and risk, with pricing in writing. MFA gaps and reporting readiness come first because they are what DFS checks first.
Control operation
MFA, inventory, monitoring, access reviews, and training run as daily discipline — ours, so your team runs the business.
Evidence file
Every control produces artifacts filed against its section of the regulation as we go, not reconstructed in March.
Certification support
We assemble the record behind the certification or acknowledgment. Your executives sign with the evidence in front of them, which is the only comfortable way to sign.
The CISO requirement, filled by a vCISO
Part 500 requires a CISO: a qualified individual responsible for the program who reports on it to your board or senior officer. The regulation permits that person to come from a third-party service provider, with your senior leadership retaining oversight. Our vCISO service fills the role at a scale a twenty-person RIA can actually afford — program ownership, board reporting, and the judgment calls between the deadlines.
We prepare and operate controls; we are not a law firm or an auditor. Your counsel interprets the regulation and DFS examiners draw their own conclusions — our job is to make that examination uneventful. Note that insurance agencies are often also covered by the FTC Safeguards Rule; the control set overlaps almost entirely, so we evidence both from one program. More regimes at the compliance hub.
Good fit if
You hold a NYDFS license and have no security staff
The April filing has been signed on hope rather than evidence
MFA coverage is partial and you know it
A DFS exam or inquiry letter has concentrated attention
Your cyber-insurance renewal asks Part 500-shaped questions
Common questions
We are a small agency. Are we really covered?
If you are licensed under the Banking, Insurance, or Financial Services Law, almost certainly yes. Limited exemptions still exist but were narrowed by the Second Amendment, and the small-business MFA exemption ended November 1, 2025. Exemption status is a legal determination — confirm it with counsel, and we will build to whatever your actual status is.
What happens on April 15?
Every covered entity files one of two things with DFS, covering the prior calendar year: a certification of material compliance, or a written acknowledgment of noncompliance identifying the gaps and a remediation timeline. Both are signed by your highest-ranking executive and your CISO — which is why we insist the evidence exists before the signature does.
Can you be our CISO?
We can fill the CISO function as a vCISO, which the regulation permits when the role comes from a third-party service provider and your senior leadership retains oversight. You keep a named senior officer accountable internally; we do the operating and the reporting. See strategic IT.
How is this different from what our current IT company does?
Most IT providers enable controls; Part 500 requires operating and evidencing them — reviews on a cadence, reports mapped to sections, filings supported by artifacts. If your provider cannot show you the evidence file today, that is the difference. A co-managed arrangement also works: they keep the help desk, we run the program.
Certify with evidence, not optimism.
A Part 500 gap assessment tells you exactly where you stand against every tranche now in effect — findings are yours to keep.