What It Is

23 NYCRR 500 is the New York Department of Financial Services (NYDFS) Cybersecurity Regulation - one of the most comprehensive and prescriptive cybersecurity regulations in the United States (NYDFS).

The regulation was strengthened by the Second Amendment, adopted November 1, 2023. Its transition periods have all expired - the last, covering multi-factor authentication (§500.12) and asset inventory (§500.13(a)), ended November 1, 2025 - so the full amended regulation is now in force (23 NYCRR 500 as amended). This page reflects the amended rule.

NYDFS 500 goes further than most frameworks by making specific controls mandatory, requiring executive certifications, and imposing strict incident reporting timelines.

What Information Is Regulated

NYDFS focuses on protecting Nonpublic Information (NPI), which includes:

  • Personally identifiable information (PII): names combined with identifying data elements.
  • Financial account and transaction data: the core of the covered business.
  • Business confidential information: whose disclosure would cause material harm.
  • Health information: where covered entities hold it.
  • Authentication data and credentials: the keys attackers actually want.

From an IT perspective, this includes nearly all business-critical systems, cloud platforms, and third-party integrations.

IT Requirements

NYDFS 500 is unusually explicit. Key requirements include:

Cybersecurity program and policies. A formal cybersecurity program supported by written policies, risk-based controls, and ongoing monitoring and improvement. Policies must reflect how systems actually operate, not theoretical controls.

Risk assessments. Regular, documented risk assessments that drive control decisions and are updated as the environment changes. Risk assessments are foundational, not optional.

A designated CISO - who may be outsourced. Each covered entity must designate a Chief Information Security Officer. Under §500.4, the CISO may be employed by an affiliate or a third-party service provider if the covered entity meets three conditions: it retains responsibility for compliance, it designates a senior member of its own personnel responsible for direction and oversight of the third party, and it requires the provider to maintain a cybersecurity program that protects the covered entity in accordance with the regulation. This is the same three-condition structure as the FTC Safeguards Rule's Qualified Individual provision - and the regulatory basis for a fractional CISO arrangement.

Identity and access management. Role-based access controls, least-privilege permissions, multi-factor authentication (§500.12, now fully in force), secure remote access, and regular access reviews.

Data security and encryption. NPI must be encrypted in transit over external networks and at rest (§500.15). For data at rest only, where the covered entity determines encryption is infeasible, the CISO may approve compensating controls in writing, reviewed at least annually. There is no compensating-controls alternative for encryption in transit. Key management, retention, and disposal controls round out the requirement.

Logging, monitoring, and incident detection. Audit logging, monitoring for cybersecurity events, the ability to detect and respond to incidents, and documentation of investigation and response activities.

Incident response and reporting - three clocks. Covered entities must maintain a written incident response plan and:

1. 72 hours: notify NYDFS as promptly as possible, and no later than 72 hours after determining that a cybersecurity incident has occurred (§500.17(a)). The clock runs from determination, not from the event itself - an operationally critical distinction. 2. 24 hours: if an extortion payment is made in connection with a cybersecurity event, notify the superintendent within 24 hours of payment (§500.17(c)). 3. 30 days: after an extortion payment, file a written description of why payment was necessary, alternatives considered, and all diligence performed - including sanctions-compliance diligence (§500.17(c)).

Third-party risk management. Vendor cybersecurity policies, due diligence before onboarding, ongoing monitoring, and contractual security requirements. Third-party failures are an enforcement focus.

Executive accountability and annual certification. Regular cybersecurity reporting to leadership, plus an annual filing to DFS signed by the covered entity's highest-ranking executive and its CISO (§500.17(b)). An entity that cannot certify material compliance files a written acknowledgment of noncompliance instead, identifying the gaps and its remediation plan. Cybersecurity is explicitly a board- and executive-level responsibility.

How It Fits Into Cyber Risk Management

NYDFS 500 reinforces a key principle: cybersecurity is an enterprise risk that must be governed, measured, and reported.

Organizations that align NYDFS requirements with NIST CSF, ISO 27001, SOC 2, and GLBA/FTC Safeguards tend to achieve stronger, more defensible security programs overall.

The annual certification makes this concrete - a signature from your highest-ranking executive and CISO is governance, not paperwork.

How We Help With NYDFS Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment tests your program section by section against 23 NYCRR 500 as amended - including the certification your highest-ranking executive and CISO must sign each year.

How to Prepare

  1. Confirm applicability and scope

    Determine whether NYDFS regulates you, whether a §500.19 limited exemption applies, which systems and data are in scope, and which vendors are involved. Exemption tiers changed with the Second Amendment - check the current thresholds, not the ones you remember.

  2. Conduct a formal cyber risk assessment

    Document threats and vulnerabilities, existing controls, control gaps, and remediation priorities. Every other NYDFS requirement is calibrated to this assessment.

  3. Implement the required technical controls

    At minimum: MFA across systems (§500.12), encryption of NPI in transit and at rest (§500.15), endpoint and email security, logging and monitoring, and secure remote access. Document any at-rest compensating controls with written CISO approval and annual review.

  4. Formalize incident response and the three reporting clocks

    Ensure the incident response plan exists in writing, the 72-hour, 24-hour, and 30-day reporting obligations are built into it, roles and escalation paths are clear, and documentation processes are in place before an incident tests them.

  5. Strengthen vendor risk management

    Confirm vendors meet NYDFS expectations, contracts include security requirements, and monitoring is ongoing. Your third-party service provider policy is itself a required artifact.

  6. Establish executive oversight and certification readiness

    Prepare regular cybersecurity reports, risk summaries, and the annual certification - or, where material compliance cannot be certified, the written acknowledgment of noncompliance with its remediation plan. Decide which document you will be able to sign well before the filing is due, not while it is.

Official source

Official source: New York State Department of Financial Services

Secondary source: 23 NYCRR Part 500 as amended (official text)

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25