Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Who Must Comply With NY DFS 23 NYCRR Part 500?

August 11, 2026
hero-who-must-comply-with-ny-dfs-500-1.png

NY DFS 23 NYCRR Part 500 applies to any business licensed under New York Banking, Insurance, or Financial Services Law. It does not matter where the company is headquartered. Hold a qualifying New York license, and you are a Covered Entity under this rule. That holds true whether you are a bank in Manhattan or a mortgage broker in Chicago with New York clients.

The official definition is broad. It covers anyone operating under a license, registration, charter, permit, or similar authorization. That authorization must come from NY Banking, Insurance, or Financial Services Law. In practice, that reaches far beyond banks and insurers. It includes agencies, brokers, and licensed lenders across the state.

Key Takeaways

  • Any business licensed under NY Banking, Insurance, or Financial Services Law is a Covered Entity under Part 500, regardless of headquarters location.
  • Common license types in scope: banks, insurers, insurance agents and brokers, mortgage lenders and servicers, consumer lenders, money transmitters, and virtual currency businesses.
  • You do not need a New York office. You just need a New York license.
  • Meeting all three limited-exemption thresholds (under 20 employees, under $7.5 million NY revenue, under $15 million in assets) narrows your obligations, but does not remove them.
  • A Class A Company designation counts affiliates everywhere, so a small NY office of a large parent can land in the strictest tier.

Which NY Licenses Trigger Part 500 Compliance

Cornell’s regulation text lists a wide range of qualifying licenses. Here are the license types that come up most often.

License TypeWho It CoversNeeds a NY Office?
Banking Law licenseBanks and trust companiesNo
Insurance Law licenseInsurance companies, including health insurersNo
Insurance producer licenseInsurance agents and brokersNo
Mortgage banking licenseMortgage lenders and mortgage servicersNo
Consumer lending licenseLicensed consumer lendersNo
Money transmitter licenseMoney transmission businessesNo
Virtual currency licenseDFS-licensed virtual currency businessesNo

This list covers the license types that come up most often. It is not a complete list of every Banking, Insurance, or Financial Services Law license DFS issues. If your license type is not listed here, check DFS’s own cybersecurity page or ask your compliance counsel.

The Out-of-State Trap

A firm does not need a New York office to be a Covered Entity. It just needs a New York license. That is the detail most out-of-state businesses miss.

Say you run an insurance agency based in Chicago. If you hold a New York producer license, even for a few New York clients, Part 500 applies to you. The regulation follows the license, not the address.

Three Tiers: Standard, Limited Exemption, and What You Still Owe

Most Covered Entities fall under the standard version of Part 500. That means the full program: a designated CISO, written policies, risk assessments, MFA, encryption, and more.

A smaller entity may qualify for the limited exemption under 500.19(a). But it is an all-or-nothing test. You must meet every threshold, not just one or two.

ThresholdLimitHow It’s Counted
Employees and independent contractorsFewer than 20Entity and its affiliates combined

Qualifying for the exemption does not mean you are off the hook. Even exempt entities still must:

  • Maintain a cybersecurity program and a written policy
  • Conduct periodic risk assessments
  • Limit and review user access privileges
  • Use MFA for remote access and privileged accounts
  • Report reportable cybersecurity incidents to DFS within 72 hours
  • File an annual compliance certification

For the full requirement-by-requirement breakdown, see our 23 NYCRR 500 compliance checklist.

The Class A Trap: When a Small Office Counts as a Giant

There is a stricter tier above standard Covered Entity status. It is called a Class A Company, and it catches some businesses by surprise.

Class A Company thresholds under NY DFS Part 500: over 2,000 employees, over one billion in average revenue over three years, counting affiliates everywhere.

A Covered Entity is a Class A Company if it has over 2,000 employees. It also qualifies if it has over $1 billion in average revenue over three years. Here is the catch: that count includes affiliates, wherever they are located. It is not just the New York entity itself.

A small New York office owned by a large parent can land in the strictest DFS tier without being large itself.

The Three Tiers at a Glance

TierWho QualifiesWhat’s Required
Standard Covered EntityDoes not meet the exemption thresholdsFull program: CISO, written policy, risk assessments, MFA, encryption, and more
Limited Exemption (500.19(a))Meets all three thresholds (employees, revenue, assets)Program, policy, risk assessments, access limits, MFA for remote and privileged access, 72-hour incident reporting, annual certification
Class A CompanyOver 2,000 employees or over $1 billion in revenue (counting affiliates)Everything above, plus independent audits and automated endpoint and access monitoring tools

Class A Companies carry extra obligations on top of the standard program. These include independent audits of the cybersecurity program. They also include automated tools for endpoint detection, response, and privileged access monitoring.

What Being Covered Actually Means Day to Day

Once you know you are a Covered Entity, the real work starts. Part 500 requires a designated CISO. It also requires a board-approved written policy and ongoing risk assessments.

Spec block listing the four core NY DFS Part 500 requirements: a designated CISO, a board-approved written policy, annual penetration testing, and a written incident response plan.

Beyond that baseline, the regulation covers a wider set of technical controls:

  • Multifactor authentication, on a scope that widened under the Second Amendment
  • Encryption of sensitive data at rest and in transit
  • Annual penetration testing and periodic vulnerability assessments
  • A written incident response plan

That is a lot to stand up and maintain.

How to Confirm Your Status

  1. Check whether you hold a license under NY Banking, Insurance, or Financial Services Law.
  2. If you do, check whether you meet all three limited-exemption thresholds above.
  3. If you do not meet them, or you have over 2,000 employees or $1 billion in revenue counting affiliates, plan for the fuller program.
Confirm Your Compliance Status

This page covers who must comply. For the full picture of what the regulation requires, read our complete guide to NY DFS 23 NYCRR Part 500.

See Where You Stand

Not sure which of the four DFS tiers applies to you? Our free 2-minute NY DFS 23 NYCRR 500 Risk-Check confirms your tier. It also tells you whether the limited exemption really applies. No sign-up is required to see your result.

Take the free 2-minute NY DFS 23 NYCRR 500 Risk-Check

Frequently Asked Questions

No. A New York office is not required. You just need a license issued under NY Banking, Insurance, or Financial Services Law. Any firm holding one of those licenses is a Covered Entity, no matter where it is headquartered.

The limited exemption applies only if you meet all three thresholds. You need fewer than 20 employees and contractors. You also need under $7.5 million in New York revenue and under $15 million in year-end assets. Meeting just one or two of the three does not qualify you.

No. Exempt entities still must maintain a cybersecurity program and written policy. They still need risk assessments and limited access privileges. They also need MFA for remote access and privileged accounts. Finally, they must report incidents within 72 hours and file an annual certification.

A Class A Company has over 2,000 employees, or over $1 billion in average revenue over three years. That count includes affiliates wherever they are located, not just the New York entity. A small New York office of a large parent company can land in this tier.

Yes, if your license is issued under NY Banking, Insurance, or Financial Services Law. Location does not matter. Having any qualifying New York license, even for a small book of business, brings you into scope.

This page covers the general rules, but your situation may be more complex. For a definitive determination, talk to your compliance counsel or check DFS’s own guidance directly. LeadingIT can help with the technical requirements, but does not make legal compliance determinations.

Get the Technical Controls in Place

Figuring out if you are a Covered Entity is the first step. Building out MFA, encryption, monitoring, and incident response is the harder part.

LeadingIT’s IT compliance services for financial services firms build and run that backbone for firms with New York operations.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.