Free 23 NYCRR Part 500 Self-Assessment:
Which DFS Tier Are You In?
- 9 quick questions
- Takes about 2 minutes
- No sign-up to see your result
Your top next moves
Use the interactive risk check below to see where your business actually stands against New York’s cybersecurity regulation, 23 NYCRR Part 500.
Answer 8 quick questions covering which of the four DFS tiers fits you, whether the November 2025 MFA mandate is closed everywhere it needs to be, and whether your April 15 certification is something you can safely sign, and get your risk level in about 2 minutes: your risk band, the specific gaps to close, and a printable checklist you can hand to your team or IT provider.
No sign-up to see your result.
What 23 NYCRR Part 500 Actually Covers (the short version)
23 NYCRR Part 500, the New York Department of Financial Services’ cybersecurity regulation, applies to any person or business operating under a license, registration, charter, or similar authorization under New York’s Banking, Insurance, or Financial Services Law. That reaches well beyond banks: mortgage bankers and brokers, licensed lenders, money transmitters, and insurance and title insurance agents and agencies are all in scope if they hold a covered license.
The regulation sorts covered businesses into tiers:
- Full-Scope “Covered Entity”
- Limited “Exempt Small Business”
- “Class A Company” (Extra Requirements, Audit, etc.)
It also sets specific, dated technical requirements, most recently that multi-factor authentication has been required for every individual accessing every information system since November 1, 2025, and it requires an annual certification of compliance, personally signed by your top executive and your CISO, due April 15 each year. The Second Amendment (finalized in late 2023, phased in through 2025 and 2026) is what added the Class A tier, the MFA-everywhere mandate, and the dual-signature certification.
The Full 23 NYCRR Part 500 Checklist
Work through each area below. Anything you can’t confirm is a gap. If you can’t prove it, a DFS examiner can’t either.
- 1. Which Tier Applies to You:
✓ Confirmed whether your business holds a license, registration, or charter under NY Banking, Insurance, or Financial Services Law that puts you in scope at all.
✓ Confirmed which category you fall into: not covered, exempt small business, standard Covered Entity, or Class A Company.
✓ Checked whether an affiliate’s revenue or headcount (not just your own) pushes you into the Class A tier, since that calculation counts affiliates. - 2. Small Business Exemption (If You’re Claiming One):
✓ Pulled your actual employee/contractor count, gross annual revenue, and year-end total assets, including affiliates.
✓ Checked those numbers against the current exemption thresholds rather than assuming your size qualifies you.
✓ Confirmed, in writing, which baseline requirements still apply even if you qualify (a cybersecurity program, a cybersecurity policy, and access privilege limits are not waived by the exemption). - 3. Multi-Factor Authentication (Fully Enforceable Since November 2025)
✓ MFA required for every individual accessing every information system, not just email or a core application.
✓ Remote access, third-party access, and legacy systems specifically checked, not assumed covered.
✓ Any exceptions to MFA documented and approved in writing, not just skipped informally. - 4. Written Cybersecurity Policy and Program:
✓ A documented policy covering how you protect nonpublic information (NPI), reviewed or updated in the last 12 months.
✓ A risk assessment behind it that identifies where NPI lives and what could go wrong.
✓ Access controls on a least-privilege basis, with unique logins and no shared accounts. - 5. Chief Information Security Officer:
✓ A formally designated CISO, whether an employee or a qualified third party (including a managed IT provider) acting in that role under a written arrangement.
✓ Regular reporting from the CISO to the board or a senior officer on the cybersecurity program’s state. - 6. Incident Response and Notification:
✓ A written, tested incident response plan covering internal escalation and roles.
✓ Known DFS notification obligations and timelines (generally within 72 hours of determining a reportable cybersecurity event occurred).
✓ A designated point of contact responsible for making that notification. - 7. Third-Party Service Oversight:
✓ A current inventory of every vendor (IT provider, core system, cloud storage) that can access your NPI.
✓ Contract language setting security requirements and incident-notification obligations for each vendor.
✓ Periodic review of vendor security, not a one-time check at signing. - 8. Annual Certification (The Personal One)
✓ Confirmed whether your company owes DFS a Certification of Material Compliance, or an Acknowledgment of Noncompliance, by April 15.
✓ Confirmed exactly who signs it (typically your highest-ranking executive and your CISO) and understands the personal responsibility that signature carries.
✓ Data and documentation on file sufficient to actually support whatever gets certified, not just a verbal “we’re fine.”
How to read your gaps?
- 0 – 2 Gaps (No Tier Confirmation Gaps)
Strong Shape
- 3 – 6 Gaps (Or 1 Critical Gap)
Real, findable gaps that would draw attention in a DFS review
- 7+ Gaps (Or 2+ Critical Gaps)
You likely haven’t nailed down which tier applies to you or closed MFA everywhere it’s required, and someone is about to sign a certification without the evidence behind it
Most of the technical items above (MFA, access controls, endpoint monitoring, vendor oversight) live in your IT setup, not a policy binder, which is the half of Part 500 a managed IT and cybersecurity partner operates for you.
23 NYCRR Part 500 FAQ
It’s the New York Department of Financial Services’ cybersecurity regulation, requiring covered businesses to maintain a written cybersecurity program, a named CISO, access controls including MFA, incident response planning, third-party oversight, and an annual certification of compliance. It was significantly expanded by the “Second Amendment,” phased in from 2023 through 2025 and 2026.
Often, yes. Part 500 covers anyone operating under a license, registration, charter, or similar authorization under New York’s Banking, Insurance, or Financial Services Law. That includes insurance and title insurance agents and agencies, mortgage bankers and brokers, licensed lenders, and money transmitters, not only banks and large financial institutions. A plain accounting or bookkeeping firm with no DFS license generally is not in scope on its own, which is exactly the kind of tier confusion worth confirming rather than assuming either way.
The largest tier: generally a covered entity with at least $20 million in gross annual revenue in each of the last two fiscal years, combined with either at least 2,000 employees or over $1 billion in gross annual revenue, all counted including affiliates. Class A Companies face extra requirements beyond standard Covered Entities, including an annual independent audit of the cybersecurity program, endpoint detection and response, and a privileged access management solution.
Possibly, but don’t assume it. The small-business exemption generally requires falling under specific thresholds for employees and contractors, gross annual revenue, and year-end total assets, counted including affiliates. And even a qualifying exempt business still has to maintain baseline items: a cybersecurity program, a cybersecurity policy, and access privilege limits. Exempt is not the same as “nothing applies.”
Yes. As of November 1, 2025, MFA is required for any individual accessing any information system of a covered entity, with only limited exceptions, and DFS has already cited failures to fully implement MFA in recent enforcement actions.
The certification is a personal attestation, typically signed by your highest-ranking executive and your CISO, and it has to be backed by data and documentation sufficient to actually demonstrate the compliance being certified. Signing it without that evidence behind it is the exposure, not a formality.
Yes, DFS has a real, active enforcement record against regulated financial and cryptocurrency companies, including multiple eight-figure settlements in recent years, and it has separately and specifically penalized a covered entity over a million dollars for failing to have MFA enabled before a phishing-driven breach.
Ready to close your gaps?
If your result flagged gaps in MFA, your cybersecurity policy, or who’s signing your certification, most of that is technical and process work an IT and cybersecurity partner handles day to day.
LeadingIT helps Chicagoland financial services, insurance, and title businesses build the cybersecurity program, access controls, and documentation 23 NYCRR Part 500 expects. We deliver this FOR clients, not as a certifying or regulatory body.
Email yourself the full result from the tool above, book a free 30-minute gap review, or contact us and see how we deliver this as a managed service.