The NY DFS MFA Requirement: Are You Actually Compliant Yet?
The NY DFS MFA requirement now covers every login, not just remote access. As of November 1, 2025, 23 NYCRR 500.12 requires multifactor authentication for any individual accessing any information system. That deadline has already passed.
If you’re reading this, you probably suspect a gap. Maybe MFA covers remote logins but not internal access. Maybe contractors slipped through the cracks. The April 15, 2026 certification is the first one that must attest this gap is actually closed.
This page covers exactly what changed, who still gets a narrower scope, and what the CISO compensating-controls exception does and doesn’t cover.
Key Takeaways
- Universal MFA now applies to any individual, on any information system. It replaced the 2017 rule that only covered remote access and privileged accounts.
- Entities that qualify for the Part 500.19 limited exemption still owe MFA. They just owe it on a narrower three-part scope, not zero.
- A CISO can approve written compensating controls instead of MFA for one system. That approval must be reviewed at least once a year.
- MFA gaps have already triggered multimillion-dollar NY DFS penalties. Healthplex paid $2 million after a phishing attack hit systems with no MFA.
- April 15, 2026 is the first certification that must truthfully attest to full compliance with the universal MFA rule.
What Changed From the Original 2017 Rule
The MFA rule used to be narrow. Under the original March 1, 2017 rule, Covered Entities only needed MFA for remote access and privileged accounts.

It phased in new requirements over a two-year rollout that ended November 1, 2025. The final two provisions were universal MFA and a written asset inventory policy.
Universal MFA covers more than the old rule did. It now reaches:
- Internal system logins, not just remote ones
- Contractors and vendors, not just employees
- On-premises systems, not just the cloud
Unless your entity qualifies for the limited exemption. That’s the two-track reality covered next.
The Two-Track Reality: Universal MFA vs. the Limited Exemption
Not every Covered Entity owes the full universal-MFA scope. A narrower Part 500.19 exemption exists for smaller entities. To qualify, an entity must meet all three thresholds at once.
Qualifying for the exemption doesn’t mean skipping MFA. It means a narrower scope applies instead. Here’s the difference between the two tracks:
| MFA Scope | Standard Covered Entity | Limited-Exemption Entity |
|---|---|---|
| Internal system logins | Required | Not required |
| Remote access to entity systems | Required | Required |
| Remote access to third-party/cloud apps touching nonpublic information | Required | Required |
| Privileged accounts (excluding non-interactive service accounts) | Required | Required |
There’s a stricter tier too: the Class A Company. It’s the strictest classification under the rule. A Covered Entity lands in Class A if either applies:
Affiliate headcount and revenue both count toward that threshold. A small New York office owned by a large parent company can land in Class A. That’s true even if the local office itself is small. Class A Companies face extra obligations, including independent audits and automated endpoint monitoring tools.
Not sure which tier you’re in? Confirm your tier and whether the limited exemption applies to you before you assume either scope fits your business.
The CISO Compensating-Controls Escape Hatch, Explained Precisely
There is one legitimate way to skip MFA on a specific system: a CISO-approved compensating control. It’s narrower than most companies assume.
The rule lets a CISO approve, in writing, controls that are “reasonably equivalent or more secure” than MFA. That approval isn’t permanent. DFS requires it be reviewed at least once a year.
This only works under three conditions:
- A real CISO is in place. This isn’t a decision an IT manager or business owner can make informally.
- The approval is written and dated. Verbal sign-off or an assumed exception doesn’t count.
- The approval is reviewed at minimum annually. An approval from two years ago with no review is stale, not valid.
This is not a general-purpose workaround for systems where MFA is inconvenient. It’s a documented, CISO-signed exception for one specific system. Treat it that way when your April 15 certification comes up.
Common Half-Implementations That Still Fail an Exam
Most companies that get flagged aren’t ignoring MFA entirely. They’ve implemented it partially, and partial doesn’t satisfy the universal-MFA rule. Watch for these gaps:
- MFA enforced on remote access, but not on internal system logins
- MFA required for employees, but not for contractors or vendors
- MFA enforced in cloud applications, but not on-premises systems
- Shared credentials among agents or contractors that bypass MFA entirely
- No written, dated CISO approval backing any compensating-control exception
Each one of these was a real cause behind an actual NY DFS penalty, covered below.
Why This Shows Up on Your April 15 Certification, Not Just an Exam

Every year, non-exempt Covered Entities file one of two things with DFS. That’s a Certification of Material Compliance or an Acknowledgment of Noncompliance. The CEO and CISO personally sign the certification.
There’s no safe harbor for filing a noncompliance acknowledgment instead of a clean certification. DFS has stated this directly.
As of November 1, 2025, 23 NYCRR 500.12 requires multifactor authentication for any individual accessing any information system of a Covered Entity, not just remote access and privileged accounts.
The deadline is April 15 every year. The April 15, 2026 filing is the first one required to attest full compliance with every Second Amendment rule. That includes universal MFA and the asset inventory requirement.
Your CEO or CISO might sign a certification claiming full MFA coverage. If that claim isn’t true, the signature becomes a personal liability. Want the full mechanics of what the certification covers? See the April 15 deadline guide.
What Enforcement Actually Looks Like
Statutory caps are low:
In practice, DFS negotiates far larger consent-order settlements. Several have named MFA or access-control failures directly.
| Date | Company | Penalty | Cause |
|---|---|---|---|
| January 2025 | PayPal | $2 million | Gaps in required controls and untimely cybersecurity event reporting |
| — | LeadingIT (MSP) | Not applicable | LeadingIT is not a DFS-licensed Covered Entity and cannot be fined under Part 500. It’s the vendor Covered Entities hire to keep the controls above from failing. |
The Healthplex case is the most direct MFA warning here. DFS tied that $2 million penalty specifically to a threat actor exploiting systems where MFA was missing.
DFS has also run sweeps that hit multiple companies at once. All eight breaches involved online quoting applications.
| Company | Penalty |
|---|---|
| Hartford Fire Insurance | $3 million |
| Midvale Indemnity | $2 million |
| LeadingIT (MSP) | Not applicable, not a DFS-licensed entity |
Want the full penalty framework, not just the highlights? See the penalties and enforcement page.
Closing the MFA Gap: What It Actually Takes
Fixing a partial MFA rollout is a sequencing problem, not a single toggle. Here’s the order that actually closes the gap:

- Inventory every access path into every information system: remote, internal, cloud, on-premises, contractor, and vendor.
- Enforce MFA at every access point the inventory turns up, not just the ones that were easy to cover first.
- For any system where MFA genuinely can’t be deployed yet, get a written, dated CISO approval of a compensating control, with an annual review date set.
- Fold the completed coverage into your asset inventory, monitoring, and incident response documentation, so it’s evidenced, not just implemented.
- Confirm the coverage is actually complete before your CEO and CISO sign the April 15 certification.
That last step is where most gaps get caught. It’s also where most companies would rather not be surprised.
LeadingIT is a Chicagoland managed IT and cybersecurity provider.
For a New York DFS-regulated client, LeadingIT’s managed IT service handles the technical backbone Part 500 requires day to day:
- Enforcing MFA on every login, not just remote access
- Maintaining encryption and a current asset inventory
- Running the vulnerability scans and monitoring that support your audit trail
- Building and testing the incident response plan your CISO has to stand behind
LeadingIT doesn’t sign or file your certification. That’s on your CEO and CISO. LeadingIT’s job is making sure what they’re signing is actually true.
For the done-for-you path, see LeadingIT’s IT compliance services for financial services firms.
Or work through the full 23 NYCRR 500 compliance checklist yourself first.
See Where You Stand
Not sure if your MFA coverage actually clears the universal mandate, or just looks like it does on paper? Find out in two minutes, no sign-up required.
Take the free 2-minute NY DFS 23 NYCRR 500 Risk-Check
Related Guides
- Who Must Comply With NY DFS 23 NYCRR Part 500?
- NY DFS Annual Certification: The April 15 Deadline Explained
- NY DFS Part 500 Penalties and Enforcement: What Non-Compliance Actually Costs
- NY DFS Risk-Check: Which of the Four Compliance Tiers Are You In?
Frequently Asked Questions
Is MFA required for all NY DFS covered entities?
Most Covered Entities now need MFA on any individual accessing any information system, effective November 1, 2025. Entities that qualify for the Part 500.19 limited exemption owe a narrower scope instead. That covers remote access, remote access to third-party or cloud apps touching nonpublic information, and privileged accounts. No qualifying entity is fully exempt from MFA.
That deadline has already passed. The next major checkpoint is the April 15, 2026 annual certification. It’s the first one that must attest to full compliance with the new rule.</p> </details>
Does the CISO compensating controls exception let us skip MFA entirely?
No. It only applies system by system. It also requires a written, dated approval from an actual CISO. That approval has to be reviewed at least annually. It is not a general exception a company can apply on its own judgment without a CISO’s signature.
What happens if my company doesn’t have MFA in place for the April 15 certification?
You would file an Acknowledgment of Noncompliance instead of a Certification of Material Compliance. That filing lists what wasn’t met, plus a remediation timeline. DFS has stated there is no enforcement safe harbor for filing a noncompliance acknowledgment rather than a clean certification.
Are contractors and vendors covered by the MFA requirement?
Yes. The universal MFA rule took effect November 1, 2025. It covers any individual accessing any information system, including contractors and vendors, not just employees. It applies on-premises and in the cloud alike.
What’s the difference between the limited exemption and full compliance for MFA?
A limited-exemption entity owes MFA in three places, not everywhere. Those are remote access, remote access to third-party or cloud apps with nonpublic information, and most privileged accounts. A standard Covered Entity needs MFA on every login, including internal system access that the exemption scope leaves out.
In practice, negotiated consent-order settlements run much higher. Healthplex paid $2 million over an MFA gap.
Ready to Confirm Your MFA Coverage Is Actually Complete?
A partial MFA rollout looks fine until an exam or a certification signature forces the question. LeadingIT can help you find and close the gaps through its IT compliance services for financial services firms.
Book a call with LeadingIT to get started.
Or reach out through the contact page with questions.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
