Free NAIC Insurance Data Security Self-Assessment:
Does This Law Apply to Your Agency?
- 9 quick questions
- Takes about 2 minutes
- No sign-up to see your result
Your top next moves
Use the interactive risk check below to see where your insurance or title agency actually stands against the NAIC Insurance Data Security Model Law.
Answer 8 quick questions covering which states’ versions apply to you, whether your small-agency exemption really holds up, and how ready your WISP and incident response plan are, and get your risk level in about 2 minutes: your risk band, the specific gaps to close, and a printable checklist you can hand to your team or IT provider.
No sign-up to see your result.
What the NAIC Insurance Data Security Model Law Actually Covers
(the short version)
The NAIC Insurance Data Security Model Law (Model #668) was adopted by the National Association of Insurance Commissioners in 2017, modeled closely on New York’s cybersecurity regulation for financial services and insurance companies (23 NYCRR 500).
It requires “licensees”, insurers, agents, and other businesses licensed by a state Department of Insurance, to build and maintain a written Information Security Program (an ISP, commonly called a WISP) covering risk assessment, access controls and encryption, employee training, incident response, and oversight of any outside vendor that touches nonpublic personal information.
It also sets rules for investigating a cybersecurity event and reporting it to the state insurance commissioner, and in many adopting states it requires a written annual certification of compliance. The catch is that it isn’t one national law: each state decides whether to adopt it, and when a state does, it’s free to change the exemption thresholds, the notification timelines, or other details. What applies to you depends on exactly which states you’re licensed in, not on the original model text.
The Full NAIC Insurance Data Security Checklist
Work through each area below. Anything you can’t confirm is a gap. If you can’t prove it, a state examiner can’t either.
- 1. Applicability State by State
✓ Confirmed whether your state(s) of licensure have adopted the Model Law, or their own version of it.
✓ Checked this separately for every state where you hold a license, not just your home state.
✓ Confirmed which state’s specific rules (exemption thresholds, deadlines, notification requirements) apply to you in each state where you’re licensed. - 2. Small Agency Exemption
✓ Pulled your actual employee count, gross revenue, and total assets.
✓ Checked those numbers against the specific exemption thresholds in each relevant state’s version, not the original model’s “fewer than 10 employees” language.
✓ Confirmed in writing, not just assumed, whether you qualify for the exemption in each state, since even an exempt licensee generally still owes basic data-security hygiene and breach-notification duties. - 3. A Written Information Security Program (WISP)
✓ A documented WISP describing administrative, technical, and physical safeguards for nonpublic personal information.
✓ A risk assessment behind it, reviewed or updated in the last 12 months.
✓ Board or senior-management oversight, with a named person responsible for the program. - 4. Access Controls and Encryption
✓ A unique login for every user, no shared accounts.
✓ Multi-factor authentication required on systems and remote access to nonpublic information.
✓ Encryption of nonpublic information at rest and in transit. - 5. Third-Party Vendor Oversight
✓ A current inventory of every vendor (IT provider, agency management system, cloud apps) that can access nonpublic information.
✓ Contract language setting security expectations and incident-notification obligations for each vendor.
✓ Periodic review of vendor security, not a one-time check at signing. - 6. Incident Response and Notification
✓ A written, tested incident response plan.
✓ Known notification obligations and timelines to your state insurance commissioner if a cybersecurity event occurs.
✓ A designated point of contact responsible for reporting. - 7. Annual Certification
✓ Confirmed whether your company owes a written annual certification of compliance to your commissioner (commonly due February 15 where required).
✓ Records kept on file to support that certification if asked to produce them. - 8. Workforce Training
✓ Employees trained on the information security program at least annually.
✓ Records kept of who was trained and when.
How to read your gaps?
- 0 – 2 Gaps (none in applicability, the exemption, or your WISP)
Strong Shape
- 3 – 6 Gaps (or 1 Critical)
Real, findable gaps that would draw attention in a state review.
- 7+ Gaps (Or 2+ Critical)
You likely haven’t confirmed the law applies to you correctly, and you may be carrying real exposure right now.
Most of the technical items above (MFA, encryption, vendor oversight) live in your IT setup, not a policy binder, which is the half of this law a managed IT and cybersecurity partner operates for you.
NAIC Insurance Data Security Model Law FAQ
It’s a model law, Model #668, that the National Association of Insurance Commissioners adopted in 2017 to set minimum data-security standards for insurers, agents, and other state-licensed insurance businesses. States choose whether to enact it, and can adjust it when they do, so it takes effect state by state rather than as one federal rule.
Often, yes. Most adopting states define “licensee” broadly enough to cover insurance agents and, in many states, title insurance agents, not just carriers. The specific definition varies by state, which is exactly why checking your own state’s text matters more than assuming based on what you’ve heard about the law generally.
NAIC adopted the model in 2017, and a substantial and still-growing number of states have enacted some version of it since. Coverage isn’t uniform: some states adopted language close to the original model, some changed the exemption thresholds or timelines, and some haven’t adopted anything like it yet.
Maybe, but don’t assume it. The original model exempts licensees with fewer than 10 employees, but many states raised that number or added revenue and total-asset thresholds when they adopted the law. An agency that’s exempt under one state’s version can fail to qualify under a neighboring state’s version. And in most states, even an exempt licensee still has basic breach-notification duties.
Where an adopting state requires it, the written certification of compliance to the state insurance commissioner is commonly due February 15 each year, with supporting records kept on file. Not every licensee owes this certification in every state, so confirm your own obligation rather than assuming the date applies to you.
No, though they’re closely related. New York’s Department of Financial Services cybersecurity regulation came first, and the NAIC modeled its Insurance Data Security Model Law on it. New York continues to enforce its own regulation directly rather than adopting the NAIC model, so if you’re licensed in New York, 23 NYCRR 500 is the rule that applies to you there, not Model #668.
The NAIC’s Cybersecurity Working Group has draft amendments to the Model Law in development, with the clearest direction so far being tighter, more specific language on third-party vendor oversight. Nothing has been adopted by any state yet, and any real compliance impact is likely still a year or more away. It’s worth knowing this is a moving target rather than a settled law, but there’s nothing urgent to act on today beyond the current version’s requirements.
Ready to close your gaps?
If your result flagged gaps in your WISP, MFA, or vendor contracts, most of that is technical and process work an IT and cybersecurity partner handles day to day.
LeadingIT helps Chicagoland insurance agencies and title agencies build the information security program, access controls, and vendor oversight the NAIC Insurance Data Security Model Law expects. We deliver this FOR agencies, not as a certifying or regulatory body.
Email yourself the full result from the tool above, book a free 30-minute gap review, or contact us and see how we deliver this as a managed service.