Who Must Comply With NY DFS 23 NYCRR Part 500?
NY DFS 23 NYCRR Part 500 applies to any business licensed under New York Banking, Insurance, or Financial Services Law. It does not matter where the company is headquartered. Hold a qualifying New York license, and you are a Covered Entity under this rule. That holds true whether you are a bank in Manhattan or a mortgage broker in Chicago with New York clients.
The official definition is broad. It covers anyone operating under a license, registration, charter, permit, or similar authorization. That authorization must come from NY Banking, Insurance, or Financial Services Law. In practice, that reaches far beyond banks and insurers. It includes agencies, brokers, and licensed lenders across the state.
Key Takeaways
- Any business licensed under NY Banking, Insurance, or Financial Services Law is a Covered Entity under Part 500, regardless of headquarters location.
- Common license types in scope: banks, insurers, insurance agents and brokers, mortgage lenders and servicers, consumer lenders, money transmitters, and virtual currency businesses.
- You do not need a New York office. You just need a New York license.
- Meeting all three limited-exemption thresholds (under 20 employees, under $7.5 million NY revenue, under $15 million in assets) narrows your obligations, but does not remove them.
- A Class A Company designation counts affiliates everywhere, so a small NY office of a large parent can land in the strictest tier.
Which NY Licenses Trigger Part 500 Compliance
Cornell’s regulation text lists a wide range of qualifying licenses. Here are the license types that come up most often.
| License Type | Who It Covers | Needs a NY Office? |
|---|---|---|
| Banking Law license | Banks and trust companies | No |
| Insurance Law license | Insurance companies, including health insurers | No |
| Insurance producer license | Insurance agents and brokers | No |
| Mortgage banking license | Mortgage lenders and mortgage servicers | No |
| Consumer lending license | Licensed consumer lenders | No |
| Money transmitter license | Money transmission businesses | No |
| Virtual currency license | DFS-licensed virtual currency businesses | No |
This list covers the license types that come up most often. It is not a complete list of every Banking, Insurance, or Financial Services Law license DFS issues. If your license type is not listed here, check DFS’s own cybersecurity page or ask your compliance counsel.
The Out-of-State Trap
A firm does not need a New York office to be a Covered Entity. It just needs a New York license. That is the detail most out-of-state businesses miss.
Say you run an insurance agency based in Chicago. If you hold a New York producer license, even for a few New York clients, Part 500 applies to you. The regulation follows the license, not the address.
Three Tiers: Standard, Limited Exemption, and What You Still Owe
Most Covered Entities fall under the standard version of Part 500. That means the full program: a designated CISO, written policies, risk assessments, MFA, encryption, and more.
A smaller entity may qualify for the limited exemption under 500.19(a). But it is an all-or-nothing test. You must meet every threshold, not just one or two.
| Threshold | Limit | How It’s Counted |
|---|---|---|
| Employees and independent contractors | Fewer than 20 | Entity and its affiliates combined |
Qualifying for the exemption does not mean you are off the hook. Even exempt entities still must:
- Maintain a cybersecurity program and a written policy
- Conduct periodic risk assessments
- Limit and review user access privileges
- Use MFA for remote access and privileged accounts
- Report reportable cybersecurity incidents to DFS within 72 hours
- File an annual compliance certification
For the full requirement-by-requirement breakdown, see our 23 NYCRR 500 compliance checklist.
The Class A Trap: When a Small Office Counts as a Giant
There is a stricter tier above standard Covered Entity status. It is called a Class A Company, and it catches some businesses by surprise.

A Covered Entity is a Class A Company if it has over 2,000 employees. It also qualifies if it has over $1 billion in average revenue over three years. Here is the catch: that count includes affiliates, wherever they are located. It is not just the New York entity itself.
A small New York office owned by a large parent can land in the strictest DFS tier without being large itself.
The Three Tiers at a Glance
| Tier | Who Qualifies | What’s Required |
|---|---|---|
| Standard Covered Entity | Does not meet the exemption thresholds | Full program: CISO, written policy, risk assessments, MFA, encryption, and more |
| Limited Exemption (500.19(a)) | Meets all three thresholds (employees, revenue, assets) | Program, policy, risk assessments, access limits, MFA for remote and privileged access, 72-hour incident reporting, annual certification |
| Class A Company | Over 2,000 employees or over $1 billion in revenue (counting affiliates) | Everything above, plus independent audits and automated endpoint and access monitoring tools |
Class A Companies carry extra obligations on top of the standard program. These include independent audits of the cybersecurity program. They also include automated tools for endpoint detection, response, and privileged access monitoring.
What Being Covered Actually Means Day to Day
Once you know you are a Covered Entity, the real work starts. Part 500 requires a designated CISO. It also requires a board-approved written policy and ongoing risk assessments.

Beyond that baseline, the regulation covers a wider set of technical controls:
- Multifactor authentication, on a scope that widened under the Second Amendment
- Encryption of sensitive data at rest and in transit
- Annual penetration testing and periodic vulnerability assessments
- A written incident response plan
That is a lot to stand up and maintain.
How to Confirm Your Status
- Check whether you hold a license under NY Banking, Insurance, or Financial Services Law.
- If you do, check whether you meet all three limited-exemption thresholds above.
- If you do not meet them, or you have over 2,000 employees or $1 billion in revenue counting affiliates, plan for the fuller program.

This page covers who must comply. For the full picture of what the regulation requires, read our complete guide to NY DFS 23 NYCRR Part 500.
See Where You Stand
Not sure which of the four DFS tiers applies to you? Our free 2-minute NY DFS 23 NYCRR 500 Risk-Check confirms your tier. It also tells you whether the limited exemption really applies. No sign-up is required to see your result.
Take the free 2-minute NY DFS 23 NYCRR 500 Risk-Check
Related Guides
- What Is the NY DFS Cybersecurity Regulation (23 NYCRR Part 500)?
- The NY DFS MFA Requirement: What You Need to Know Now
- NY DFS Annual Certification: The April 15 Deadline Explained
- NY DFS Risk-Check: Which of the Four Compliance Tiers Are You In?
Frequently Asked Questions
No. A New York office is not required. You just need a license issued under NY Banking, Insurance, or Financial Services Law. Any firm holding one of those licenses is a Covered Entity, no matter where it is headquartered.
The limited exemption applies only if you meet all three thresholds. You need fewer than 20 employees and contractors. You also need under $7.5 million in New York revenue and under $15 million in year-end assets. Meeting just one or two of the three does not qualify you.
No. Exempt entities still must maintain a cybersecurity program and written policy. They still need risk assessments and limited access privileges. They also need MFA for remote access and privileged accounts. Finally, they must report incidents within 72 hours and file an annual certification.
A Class A Company has over 2,000 employees, or over $1 billion in average revenue over three years. That count includes affiliates wherever they are located, not just the New York entity. A small New York office of a large parent company can land in this tier.
Yes, if your license is issued under NY Banking, Insurance, or Financial Services Law. Location does not matter. Having any qualifying New York license, even for a small book of business, brings you into scope.
This page covers the general rules, but your situation may be more complex. For a definitive determination, talk to your compliance counsel or check DFS’s own guidance directly. LeadingIT can help with the technical requirements, but does not make legal compliance determinations.
Get the Technical Controls in Place
Figuring out if you are a Covered Entity is the first step. Building out MFA, encryption, monitoring, and incident response is the harder part.
LeadingIT’s IT compliance services for financial services firms build and run that backbone for firms with New York operations.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
