NY DFS Annual Certification: What the April 15 Deadline Actually Requires
Every non-exempt Covered Entity under 23 NYCRR Part 500 owes New York’s Department of Financial Services one certification a year. It’s due April 15. This isn’t a form you fill out and forget. It’s a signed statement from your top executive and your Chief Information Security Officer (CISO). DFS checks it against what your systems actually do.
The April 15, 2026 filing carries extra weight. Two of its toughest requirements only became mandatory on November 1, 2025: universal multifactor authentication and a written asset inventory. This is the first April 15 where regulators can hold every firm to both.
Why the April 15, 2026 Certification Is Different

The rollout ended November 1, 2025, when the last two pieces took effect: MFA on every login, not just remote access, and a documented inventory tracking each system’s owner, location, and end-of-life status.
DFS can hold every Covered Entity to universal MFA and a documented asset inventory for the first time this filing season. Both have been mandatory since November 1, 2025.
Before this year, a firm could file a clean certification while still finishing its MFA rollout or backfilling its asset inventory. Both requirements were still phasing in. That excuse is gone for the 2026 filing. If either control isn’t actually in place, a “clean” certification is no longer a defensible one.
Who Has to File, and Which Path You Take
A Covered Entity is any business operating under a license, registration, charter, permit, or similar authorization from DFS under New York’s Banking, Insurance, or Financial Services Law. In practice, that reaches well beyond banks:
- Banks and trust companies
- Insurance companies, agents, and brokers
- Mortgage lenders, brokers, and servicers
- Licensed consumer lenders and money transmitters
- Virtual currency businesses licensed by DFS
Your firm doesn’t need to be headquartered in New York. If DFS licenses you to do business here, you’re in scope, wherever your home office sits.
To qualify, a firm has to meet all three of these:
Even an exempt firm still has to run a cybersecurity program, do risk assessments, use MFA for remote and privileged access, and file the annual certification.
Two Ways to File
| Filing Path | What You’re Certifying | What Happens Next |
|---|---|---|
| Certification of Material Compliance | Your highest-ranking executive and CISO attest, in writing, that the firm met every applicable Part 500 requirement during the prior year | DFS accepts the filing; no further action unless an exam or incident says otherwise |
| Acknowledgment of Noncompliance | You identify, in writing, exactly which provisions weren’t met | You attach a remediation timeline, or confirm the gaps are already closed |
Filing an Acknowledgment doesn’t buy legal cover. DFS has said plainly there’s no enforcement safe harbor for choosing the second path instead of actually complying. An honest Acknowledgment can still draw scrutiny if the gaps are large or slow to close.
Who Signs, and What “Personal” Really Means
The certification isn’t signed by “the company.” It’s signed by two named people: your highest-ranking executive, think CEO, president, or equivalent, and your CISO. Both sign in their own names, not just their titles.

That’s what “personal” means here. DFS can hold each of them individually accountable if the filing turns out not to match reality. Neither signer gets to say later that IT handled it, or that a vendor was responsible.
A few things follow from that:
- The signature is a personal representation, not a corporate formality.
- Both signers need direct visibility into whether the controls they’re certifying are actually in place, not just documented on paper.
- Once filed, the certification becomes part of that year’s compliance record, one DFS can pull during an exam or after an incident.
Before either name goes on that filing, the controls behind it have to be real, current, and something both signers have actually reviewed, not assumed.
What DFS Checks Before Anyone Signs
A signature on the certification isn’t a formality. It’s a promise the underlying controls are real, documented, and working today.
DFS checks that promise against six areas of your program:
| Requirement | What “In Place” Actually Looks Like | In Force Since |
|---|---|---|
| Universal MFA | Every login triggers a second factor, not just remote access or privileged accounts | November 1, 2025 |
| Asset inventory | A written record of each system’s owner, location, classification, and end-of-life status | November 1, 2025 |
| Risk assessment | Reviewed at least once a year, and current enough to reflect this year’s actual systems | Ongoing, minimum annual |
| Incident response plan | Written and tested, not just drafted and filed away | Ongoing |
| Access privilege limits | User access reviewed and trimmed to what each role actually needs | Ongoing |
| Third-party oversight | A written policy governing what security your vendors have to meet | Ongoing |
Two of those six, MFA and the asset inventory, only became fully mandatory this cycle.
Your CISO is also expected to report in writing to your board, or a senior governing body, at least once a year. That report is part of the evidence trail DFS can ask to see. If the CISO can’t produce it, the certification’s credibility takes a hit before anyone even asks about MFA.
What It Costs to Get This Wrong
DFS doesn’t treat a mismatched certification as paperwork. It treats it as proof the underlying control failed.
| Date | Company | Penalty | What DFS Cited |
|---|---|---|---|
| Jan 2025 | PayPal | $2 million | Control gaps plus untimely cybersecurity event reporting |
None of these cases started as a paperwork problem. Each one traces back to a control gap that existed long before DFS ever opened an inquiry. The certification is simply the moment that gap gets a signature attached to it.
Getting Ready Before You Sign: A Q1 Timeline
Don’t wait until the second week of April to find out what’s actually true. A realistic prep sequence looks like this:

- January: Pull last year’s certification and asset inventory. Confirm every listed system still matches what’s actually running.
- February: Audit MFA coverage across every login, not just remote access, and close any gaps you find.
- Early March: Refresh the risk assessment if it’s more than a year old. Update the incident response plan to match your current systems.
- Mid-March: Have your CISO walk the highest-ranking executive through the evidence behind each requirement, not just a checklist summary.
- Early April: Decide, in writing, whether you’re filing a Certification of Material Compliance or an Acknowledgment of Noncompliance. File by April 15.
Keep the records behind your certification for five years. DFS can request them during an exam or after an incident, and “we filed it” isn’t a substitute for being able to show your work.
See Where You Stand
Before your CISO or CEO signs anything, it helps to know exactly where the gaps are. This free 2-minute check shows whether your MFA coverage is actually complete since the November 2025 mandate, and whether this year’s certification is one you can safely sign. No sign-up required to see your result.
Take the Free NY DFS 23 NYCRR 500 Risk-Check
Related Guides
- What Is the NY DFS Cybersecurity Regulation (23 NYCRR Part 500)?
- NY DFS Risk-Check: Which of the Four Compliance Tiers Are You In?
Frequently Asked Questions
Two people sign it personally: your highest-ranking executive, such as a CEO or president, and your Chief Information Security Officer. Both sign in their own names, not just their titles. Neither can point to IT or a vendor if the filing later turns out not to match reality.
The regulation ties compliance to an annual certification filed by April 15, and DFS treats a missed or inaccurate filing as evidence of a program failure, the same way it does with the enforcement cases tied to control gaps. There is no stated grace period in the rule itself. Firms that know they can’t file a clean certification should prepare an honest Acknowledgment of Noncompliance with a remediation timeline instead of missing the date entirely.
A Certification of Material Compliance is a signed statement that the firm met every applicable requirement during the prior year. An Acknowledgment of Noncompliance identifies exactly which provisions weren’t met, along with a remediation timeline or confirmation the gaps are already closed. DFS has said there’s no enforcement safe harbor for choosing the second path instead of actually complying.
Most do. The exemption narrows what you have to do. It doesn’t remove the filing requirement.
The April 15, 2026 filing is the first certification that has to attest to full compliance with universal MFA, which became mandatory November 1, 2025. Before this year, a firm could still be finishing its MFA rollout while filing a clean certification, because the requirement was phasing in. That’s no longer true. If MFA isn’t covering every login today, a clean certification is hard to defend.
DFS expects a firm to be able to document the evidence behind its certification, including risk assessments, MFA coverage, the asset inventory, and the incident response plan, for several years after filing. If an exam or an incident happens, DFS can ask to see that evidence directly. A signed certification with no supporting documentation behind it doesn’t hold up well under review.
Get Ahead of April 15
LeadingIT helps New York DFS-regulated firms make sure the controls behind their certification are actually true, not just written down. If you’d rather have this handled for you, explore LeadingIT’s IT compliance services for financial services firms or book a call to talk through your filing before April 15.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
