What Is the NY DFS Cybersecurity Regulation (23 NYCRR Part 500)?
23 NYCRR Part 500 is New York’s cybersecurity regulation for financial services firms. The New York Department of Financial Services issued it on March 1, 2017. It requires each regulated firm to run a written, risk-based cybersecurity program, not just buy some security software and call it done.
DFS updated the rule heavily with a Second Amendment, adopted November 1, 2023. That update phased in new requirements over two years. The last phase took effect November 1, 2025, so by 2026 the full amended rule is in force.
If your firm holds a New York banking, insurance, or financial services license, this regulation likely applies to you. How closely depends on your size. DFS sorts every regulated firm into one of four tiers, and the tier you land in decides how much of the rule you actually have to build.
Who Has to Comply: The Covered Entity Definition
DFS calls every regulated firm a “Covered Entity.” That term covers any person or business operating under a license, registration, charter, certificate, permit, accreditation, or similar authorization issued under New York Banking Law, Insurance Law, or Financial Services Law.
That definition reaches far past traditional banks. In practice, it covers:
- State-chartered banks and trust companies
- Insurance companies, including health insurers
- Insurance agents and brokers
- Mortgage lenders and mortgage servicers
- Licensed consumer lenders
- Money transmitters
- Virtual currency businesses licensed by DFS
You don’t need a New York office to be a Covered Entity. Any firm DFS licenses to do business in New York is in scope. It doesn’t matter where the home office sits.
The Four Tiers of NY DFS Regulation
Not every Covered Entity has to build the full program. DFS sets three thresholds that decide your tier: how many people you employ, how much New York revenue you bring in, and how many assets you hold. Two extra rules apply at the top end for the largest firms.

A firm has to clear all three exemption tests to qualify as limited-exemption. Miss even one, and you’re a standard Covered Entity with the full program to build.
The Class A threshold counts affiliates, not just your own office. A small New York branch owned by a large parent company can land in the Class A tier even though the local office is modest. It’s the parent’s headcount and revenue that push it over the line.
Qualifying for the limited exemption doesn’t mean walking away free. Exempt firms still have to run a real cybersecurity program. They just get a narrower list of specific technical requirements than a standard or Class A firm.
What the Regulation Actually Requires
Part 500’s requirements break into four practical groups. None of them are optional once you’re a Covered Entity above the exemption line.

Governance and leadership. Every Covered Entity needs a designated Chief Information Security Officer (CISO) who reports to the board, or a senior governing body, in writing at least once a year. The firm needs a written cybersecurity policy approved at that same board or senior-officer level. And it needs a risk assessment done at minimum annually, since the whole program is supposed to be built around actual risk, not a generic checklist.
Technical controls. As of November 1, 2025, multifactor authentication is required for any individual accessing any information system, not just remote access and privileged accounts like the original 2017 rule required. Nonpublic information needs encryption at rest and in transit, or a DFS-approved compensating control where encryption isn’t practical. On top of that, firms need annual penetration testing and periodic vulnerability assessments to catch what encryption and MFA don’t.
Response and recovery. Every Covered Entity needs a written incident response plan, tested before it’s needed, not drafted after a breach. As of November 1, 2025, firms also need a documented asset inventory. It has to track each system’s owner, location, data classification, support and end-of-life status, and recovery objectives.
Access and oversight. User access privileges need periodic review and limits, so far more employees than actually need access to sensitive systems don’t have it. Firms need a written policy governing third-party service providers, since a vendor’s weak security is still the firm’s exposure. Audit trail systems have to be able to reconstruct material financial transactions. And every employee needs annual cybersecurity awareness training that covers social engineering specifically, since phishing remains the way most of these programs actually get tested for real.
What Changed in the Second Amendment (and Why 2026 Is Different)
The original 2017 version of Part 500 was lighter than what exists today. DFS rewrote large parts of it through the Second Amendment, adopted November 1, 2023. That amendment phased in over two years, not all at once.
By November 1, 2025, every phase had taken effect. As of 2026, the full amended rule is in force.
| Change | Effective | What It Means |
|---|---|---|
| Universal MFA | November 1, 2025 | MFA required for anyone accessing any system, not just remote access or privileged accounts |
| Asset inventory | November 1, 2025 | A written policy tracking owner, location, classification, and recovery objectives for every system |
| Class A audits | Added by the Second Amendment | Independent audits and automated endpoint and access monitoring for the largest firms |
The MFA rule is the one most firms underestimate. If your firm doesn’t qualify for the limited exemption, MFA now has to cover every login, not just remote and privileged ones. If you do qualify for the exemption, the older, narrower rule still applies: MFA on remote access, remote access to third-party apps carrying nonpublic information, and privileged accounts.
There’s one more carve-out worth knowing. A firm’s CISO can approve a compensating control in place of MFA for a specific system, in writing. That approval has to get reviewed at least once a year. It’s not a way around MFA. It’s a documented exception, and DFS expects to see the paperwork behind it.
How DFS Finds Out, and What Enforcement Has Cost Firms
Two clocks start running the moment something goes wrong.

- 72 hours. Once you determine a cybersecurity event meets the regulation’s reporting criteria, you have 72 hours to notify the DFS Superintendent. 2. 24 hours. If your firm pays a ransom, you have to notify DFS within 24 hours of the payment. 3. It has to explain why the payment was necessary, what alternatives you considered, and what sanctions screening you ran.
In practice, DFS doesn’t apply that cap mechanically. It negotiates consent orders instead, weighing how the firm cooperated and whether the violation looked unintentional, reckless, or intentional.
Those negotiated numbers have gotten large. Here’s what DFS has actually collected:
The pattern across nearly every row is the same. It’s rarely one catastrophic failure. It’s a missing MFA rule, a shared login, or a slow report that turns an incident into a penalty.
What Day-to-Day Compliance Looks Like for a Smaller Firm
Reading the regulation is step one. Running it day to day is a different job entirely.
For a smaller Covered Entity, that day-to-day work usually breaks down into a short, repeatable list:
- Enforcing MFA on every login, not just the ones that feel sensitive
- Keeping encryption and the asset inventory current as systems change
- Running vulnerability scans and coordinating the annual penetration test
- Monitoring and logging continuously enough to support the audit trail requirement
- Keeping the incident response plan tested, not just written and filed away
That list is also what your CISO or CEO has to be able to stand behind before signing the annual certification. Each year, Covered Entities file either a Certification of Material Compliance or an Acknowledgment of Noncompliance with DFS by April 15. There’s no safe harbor for filing the honest version instead of the clean one, so the underlying controls have to actually be true on the day someone signs. The annual certification deadline guide walks through exactly what that filing requires.
If you want the full requirement-by-requirement breakdown, the 23 NYCRR 500 compliance checklist covers every provision in one place. And if you’d rather have someone else run the technical side of this day to day, that’s the gap LeadingIT’s IT compliance services for financial services firms are built to fill.
See Where You Stand
Which of the four DFS tiers are you actually in? Most firms misjudge their MFA coverage and their certification readiness too. Take two minutes and find out for real, no sign-up required.
Take the free 2-minute NY DFS Risk-Check
Related Guides
- NY DFS Annual Certification: The April 15 Deadline Explained
- NY DFS Risk-Check: Which of the Four Compliance Tiers Are You In?
Frequently Asked Questions
It’s New York’s cybersecurity rule for financial services firms. It requires a written, risk-based security program instead of ad hoc security spending. DFS first issued it in 2017 and significantly updated it through 2025.
Any firm licensed under New York Banking, Insurance, or Financial Services Law. That includes banks, insurance agencies and brokers, mortgage lenders, and licensed consumer lenders. You don’t need a New York office, only a New York license.
A Covered Entity is any person or business operating under a license, registration, charter, certificate, permit, or accreditation issued under New York Banking, Insurance, or Financial Services Law. Most DFS-licensed firms fall into this definition automatically.
It’s a reduced compliance path for small firms. To qualify, a firm needs fewer than 20 employees and contractors, under $7.5 million in New York revenue, and under $15 million in year-end assets. Exempt firms still need a program, MFA, and annual certification, just a narrower version.
It’s the strictest tier, reserved for the largest regulated firms. Class A Companies face extra requirements, including independent audits.
April 15 each year. Covered Entities file either a Certification of Material Compliance or an Acknowledgment of Noncompliance. The certification has to be signed personally by the firm’s highest-ranking executive and its CISO.
DFS has issued multimillion-dollar penalties tied directly to control failures like missing MFA, weak access limits, and late incident reporting. Penalties are negotiated as consent orders, not applied on a fixed formula.
Get Your Part 500 Program Built Right
Part 500 isn’t a document you file once and forget. It’s a program that has to keep running, get tested, and hold up under a signature every April. LeadingIT’s IT compliance services for financial services firms build and run that technical backbone so your CISO can sign with confidence.
Book a call to talk through where your firm stands, or contact us with questions.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
