Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

The NY DFS MFA Requirement: Are You Actually Compliant Yet?

August 11, 2026
hero-ny-dfs-500-mfa-requirement-1.png

The NY DFS MFA requirement now covers every login, not just remote access. As of November 1, 2025, 23 NYCRR 500.12 requires multifactor authentication for any individual accessing any information system. That deadline has already passed.

If you’re reading this, you probably suspect a gap. Maybe MFA covers remote logins but not internal access. Maybe contractors slipped through the cracks. The April 15, 2026 certification is the first one that must attest this gap is actually closed.

This page covers exactly what changed, who still gets a narrower scope, and what the CISO compensating-controls exception does and doesn’t cover.

Key Takeaways

  • Universal MFA now applies to any individual, on any information system. It replaced the 2017 rule that only covered remote access and privileged accounts.
  • Entities that qualify for the Part 500.19 limited exemption still owe MFA. They just owe it on a narrower three-part scope, not zero.
  • A CISO can approve written compensating controls instead of MFA for one system. That approval must be reviewed at least once a year.
  • MFA gaps have already triggered multimillion-dollar NY DFS penalties. Healthplex paid $2 million after a phishing attack hit systems with no MFA.
  • April 15, 2026 is the first certification that must truthfully attest to full compliance with the universal MFA rule.

What Changed From the Original 2017 Rule

The MFA rule used to be narrow. Under the original March 1, 2017 rule, Covered Entities only needed MFA for remote access and privileged accounts.

Comparison of NY DFS MFA scope under the original 2017 rule versus the current universal MFA rule, contrasting remote-access and privileged-account coverage with the newly added internal-login and on-premises coverage.

It phased in new requirements over a two-year rollout that ended November 1, 2025. The final two provisions were universal MFA and a written asset inventory policy.

Universal MFA covers more than the old rule did. It now reaches:

  • Internal system logins, not just remote ones
  • Contractors and vendors, not just employees
  • On-premises systems, not just the cloud

Unless your entity qualifies for the limited exemption. That’s the two-track reality covered next.

The Two-Track Reality: Universal MFA vs. the Limited Exemption

Not every Covered Entity owes the full universal-MFA scope. A narrower Part 500.19 exemption exists for smaller entities. To qualify, an entity must meet all three thresholds at once.

Qualifying for the exemption doesn’t mean skipping MFA. It means a narrower scope applies instead. Here’s the difference between the two tracks:

MFA ScopeStandard Covered EntityLimited-Exemption Entity
Internal system loginsRequiredNot required
Remote access to entity systemsRequiredRequired
Remote access to third-party/cloud apps touching nonpublic informationRequiredRequired
Privileged accounts (excluding non-interactive service accounts)RequiredRequired

There’s a stricter tier too: the Class A Company. It’s the strictest classification under the rule. A Covered Entity lands in Class A if either applies:

Affiliate headcount and revenue both count toward that threshold. A small New York office owned by a large parent company can land in Class A. That’s true even if the local office itself is small. Class A Companies face extra obligations, including independent audits and automated endpoint monitoring tools.

Not sure which tier you’re in? Confirm your tier and whether the limited exemption applies to you before you assume either scope fits your business.

The CISO Compensating-Controls Escape Hatch, Explained Precisely

There is one legitimate way to skip MFA on a specific system: a CISO-approved compensating control. It’s narrower than most companies assume.

The rule lets a CISO approve, in writing, controls that are “reasonably equivalent or more secure” than MFA. That approval isn’t permanent. DFS requires it be reviewed at least once a year.

This only works under three conditions:

  • A real CISO is in place. This isn’t a decision an IT manager or business owner can make informally.
  • The approval is written and dated. Verbal sign-off or an assumed exception doesn’t count.
  • The approval is reviewed at minimum annually. An approval from two years ago with no review is stale, not valid.

This is not a general-purpose workaround for systems where MFA is inconvenient. It’s a documented, CISO-signed exception for one specific system. Treat it that way when your April 15 certification comes up.

Common Half-Implementations That Still Fail an Exam

Most companies that get flagged aren’t ignoring MFA entirely. They’ve implemented it partially, and partial doesn’t satisfy the universal-MFA rule. Watch for these gaps:

  • MFA enforced on remote access, but not on internal system logins
  • MFA required for employees, but not for contractors or vendors
  • MFA enforced in cloud applications, but not on-premises systems
  • Shared credentials among agents or contractors that bypass MFA entirely
  • No written, dated CISO approval backing any compensating-control exception

Each one of these was a real cause behind an actual NY DFS penalty, covered below.

Why This Shows Up on Your April 15 Certification, Not Just an Exam

April Certification Basics

Every year, non-exempt Covered Entities file one of two things with DFS. That’s a Certification of Material Compliance or an Acknowledgment of Noncompliance. The CEO and CISO personally sign the certification.

There’s no safe harbor for filing a noncompliance acknowledgment instead of a clean certification. DFS has stated this directly.

As of November 1, 2025, 23 NYCRR 500.12 requires multifactor authentication for any individual accessing any information system of a Covered Entity, not just remote access and privileged accounts.

The deadline is April 15 every year. The April 15, 2026 filing is the first one required to attest full compliance with every Second Amendment rule. That includes universal MFA and the asset inventory requirement.

Your CEO or CISO might sign a certification claiming full MFA coverage. If that claim isn’t true, the signature becomes a personal liability. Want the full mechanics of what the certification covers? See the April 15 deadline guide.

What Enforcement Actually Looks Like

Statutory caps are low:

In practice, DFS negotiates far larger consent-order settlements. Several have named MFA or access-control failures directly.

DateCompanyPenaltyCause
January 2025PayPal$2 millionGaps in required controls and untimely cybersecurity event reporting
LeadingIT (MSP)Not applicableLeadingIT is not a DFS-licensed Covered Entity and cannot be fined under Part 500. It’s the vendor Covered Entities hire to keep the controls above from failing.

The Healthplex case is the most direct MFA warning here. DFS tied that $2 million penalty specifically to a threat actor exploiting systems where MFA was missing.

DFS has also run sweeps that hit multiple companies at once. All eight breaches involved online quoting applications.

CompanyPenalty
Hartford Fire Insurance$3 million
Midvale Indemnity$2 million
LeadingIT (MSP)Not applicable, not a DFS-licensed entity

Want the full penalty framework, not just the highlights? See the penalties and enforcement page.

Closing the MFA Gap: What It Actually Takes

Fixing a partial MFA rollout is a sequencing problem, not a single toggle. Here’s the order that actually closes the gap:

Closing the MFA Gap
  1. Inventory every access path into every information system: remote, internal, cloud, on-premises, contractor, and vendor.
  2. Enforce MFA at every access point the inventory turns up, not just the ones that were easy to cover first.
  3. For any system where MFA genuinely can’t be deployed yet, get a written, dated CISO approval of a compensating control, with an annual review date set.
  4. Fold the completed coverage into your asset inventory, monitoring, and incident response documentation, so it’s evidenced, not just implemented.
  5. Confirm the coverage is actually complete before your CEO and CISO sign the April 15 certification.

That last step is where most gaps get caught. It’s also where most companies would rather not be surprised.

LeadingIT is a Chicagoland managed IT and cybersecurity provider.

For a New York DFS-regulated client, LeadingIT’s managed IT service handles the technical backbone Part 500 requires day to day:

  • Enforcing MFA on every login, not just remote access
  • Maintaining encryption and a current asset inventory
  • Running the vulnerability scans and monitoring that support your audit trail
  • Building and testing the incident response plan your CISO has to stand behind

LeadingIT doesn’t sign or file your certification. That’s on your CEO and CISO. LeadingIT’s job is making sure what they’re signing is actually true.

For the done-for-you path, see LeadingIT’s IT compliance services for financial services firms.

Or work through the full 23 NYCRR 500 compliance checklist yourself first.

See Where You Stand

Not sure if your MFA coverage actually clears the universal mandate, or just looks like it does on paper? Find out in two minutes, no sign-up required.

Take the free 2-minute NY DFS 23 NYCRR 500 Risk-Check

Frequently Asked Questions

Is MFA required for all NY DFS covered entities?

Most Covered Entities now need MFA on any individual accessing any information system, effective November 1, 2025. Entities that qualify for the Part 500.19 limited exemption owe a narrower scope instead. That covers remote access, remote access to third-party or cloud apps touching nonpublic information, and privileged accounts. No qualifying entity is fully exempt from MFA.

That deadline has already passed. The next major checkpoint is the April 15, 2026 annual certification. It’s the first one that must attest to full compliance with the new rule.</p> </details>

Does the CISO compensating controls exception let us skip MFA entirely?

No. It only applies system by system. It also requires a written, dated approval from an actual CISO. That approval has to be reviewed at least annually. It is not a general exception a company can apply on its own judgment without a CISO’s signature.

What happens if my company doesn’t have MFA in place for the April 15 certification?

You would file an Acknowledgment of Noncompliance instead of a Certification of Material Compliance. That filing lists what wasn’t met, plus a remediation timeline. DFS has stated there is no enforcement safe harbor for filing a noncompliance acknowledgment rather than a clean certification.

Are contractors and vendors covered by the MFA requirement?

Yes. The universal MFA rule took effect November 1, 2025. It covers any individual accessing any information system, including contractors and vendors, not just employees. It applies on-premises and in the cloud alike.

What’s the difference between the limited exemption and full compliance for MFA?

A limited-exemption entity owes MFA in three places, not everywhere. Those are remote access, remote access to third-party or cloud apps with nonpublic information, and most privileged accounts. A standard Covered Entity needs MFA on every login, including internal system access that the exemption scope leaves out.

In practice, negotiated consent-order settlements run much higher. Healthplex paid $2 million over an MFA gap.

Ready to Confirm Your MFA Coverage Is Actually Complete?

A partial MFA rollout looks fine until an exam or a certification signature forces the question. LeadingIT can help you find and close the gaps through its IT compliance services for financial services firms.

Book a call with LeadingIT to get started.

Or reach out through the contact page with questions.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.