Skip to content

NYDFS Cybersecurity Regulation (Part 500)

Amended New York · In force Mar 1, 2017 · no upcoming deadlines

Deadlines

DateWhat happens
Apr 15, 20265 months agoAnnual compliance notification
Nov 1, 202510 months agoUniversal MFA and asset inventory
May 1, 20251 year agoVulnerability scans, access privileges, malware controls, Class A monitoring
Nov 1, 20241 year agoGovernance, encryption, IR/BCDR, exemptions
Apr 29, 20242 years agoGeneral 180-day transition ends
Apr 15, 20242 years agoAnnual compliance notification
Dec 1, 20232 years agoAmended notification requirements (500.17)
Nov 1, 20232 years agoSecond Amendment effective
Mar 1, 20179 years agoPart 500 effective

Summaries for reference, not legal advice. Check the official text.

What it does

DFS-licensed financial companies must keep a risk-based cybersecurity program, CISO, policies, access controls, MFA, encryption, an asset inventory, and incident response and business continuity plans. They must notify DFS within 72 hours of a cybersecurity event and within 24 hours of any extortion payment, and certify compliance or acknowledge non-compliance each April 15. The 2023 Second Amendment added governance duties, Class A company requirements and phased controls through November 1, 2025.

Who it applies to
Covered entities: persons operating under a DFS license, registration, charter or similar authorization (banks, insurers, money transmitters, etc.). Class A companies: at least $20,000,000 gross annual revenue in each of the last two fiscal years from NY business, and either over 2,000 employees averaged over two years or over $1,000,000,000 gross annual revenue in each of the last two fiscal years. Limited exemption for fewer than 20 employees and contractors, under $7,500,000 gross annual revenue in each of the last 3 fiscal years, or under $15,000,000 year-end total assets.
Penalties
Penalties under the Banking Law, Insurance Law and Financial Services Law. 500.20 lists the factors DFS weighs; the regulation sets no fixed maximum. A single act or failure, including failing to comply for any 24-hour period, is a violation.
Enforced by
New York State Department of Financial Services (DFS)
Official name
New York DFS Cybersecurity Requirements for Financial Services Companies (23 NYCRR Part 500), Second Amendment
Citation
23 NYCRR Part 500 (Second Amendment effective 2023-11-01)
Topics
cybersecurity, breach-notification, financial
Verified 2026-09-22 dfs.ny.gov
Research notes

Dates are computed from the 500.22 transitional periods (30 days, 180 days, 1 year, 18 months and 2 years from the November 1, 2023 Second Amendment) and match DFS guidance. DFS also issued 2026 industry letters on frontier-AI cyber risk (May 21, 2026) and risk assessment (September 10, 2026); these are guidance, not rule changes.

Related

Questions about NYDFS Cybersecurity Regulation (Part 500)
What are the NYDFS Cybersecurity Regulation (Part 500) compliance deadlines?
Mar 1, 2017: Part 500 effective. Nov 1, 2023: Second Amendment effective. Dec 1, 2023: Amended notification requirements (500.17). Apr 15, 2024: Annual compliance notification. Apr 29, 2024: General 180-day transition ends. Nov 1, 2024: Governance, encryption, IR/BCDR, exemptions. May 1, 2025: Vulnerability scans, access privileges, malware controls, Class A monitoring. Nov 1, 2025: Universal MFA and asset inventory. Apr 15, 2026: Annual compliance notification.
When does NYDFS Cybersecurity Regulation (Part 500) take effect?
NYDFS Cybersecurity Regulation (Part 500) took effect on Mar 1, 2017.
Who does NYDFS Cybersecurity Regulation (Part 500) apply to?
Covered entities: persons operating under a DFS license, registration, charter or similar authorization (banks, insurers, money transmitters, etc.). Class A companies: at least $20,000,000 gross annual revenue in each of the last two fiscal years from NY business, and either over 2,000 employees averaged over two years or over $1,000,000,000 gross annual revenue in each of the last two fiscal years. Limited exemption for fewer than 20 employees and contractors, under $7,500,000 gross annual revenue in each of the last 3 fiscal years, or under $15,000,000 year-end total assets.
What are the penalties under NYDFS Cybersecurity Regulation (Part 500)?
Penalties under the Banking Law, Insurance Law and Financial Services Law. 500.20 lists the factors DFS weighs; the regulation sets no fixed maximum. A single act or failure, including failing to comply for any 24-hour period, is a violation.

Rule changes by email

The morning after a new data, privacy or AI law, or a deadline change; nothing in quiet weeks.

Double opt-in. Unsubscribe any time.