What is NYDFS Part 500? New York's Cybersecurity Regulation for Financial Services
NYDFS Part 500 is the most prescriptive state cybersecurity regulation in the US. Universal MFA, asset inventory, 72-hour notice, CEO and CISO certification: what it requires and who is exposed.
Who Is Covered
Any person operating under a license, registration, charter, certificate, permit, or similar authorization under New York's Banking Law, Insurance Law, or Financial Services Law. The list is long and includes many businesses that do not think of themselves as financial institutions: independent insurance agencies, mortgage brokers, premium finance companies, and fintech platforms holding a New York money transmitter or BitLicense.
Class A Companies
The Second Amendment created a tier for large entities: at least $20 million in New York gross annual revenue and either more than 2,000 employees or more than $1 billion in gross annual revenue across affiliates. Class A companies face additional obligations: an annual independent audit of the cybersecurity program, privileged access management, endpoint detection and response with centralized logging, and monitoring of privileged access activity.
Limited Exemptions
Entities with fewer than 20 employees, under $7.5 million in New York gross annual revenue, or under $15 million in year-end total assets qualify for a limited exemption that removes several requirements, including the CISO designation, penetration testing, and audit trail obligations. The exemption is narrow, must be filed, and does not remove the core requirements, the notification duties, or the annual certification.
What Part 500 Requires
Governance
A cybersecurity program based on a documented risk assessment. Written policies approved at least annually by the senior governing body. A CISO, in-house or outsourced, with adequate authority who reports in writing to the board at least annually on the program, material risks, and remediation plans. The board or its equivalent must have sufficient understanding of cybersecurity risk to exercise oversight, which DFS has made clear is a requirement about the board, not about the CISO.
Technical Controls
Universal MFA for any individual accessing any information system, effective November 1, 2025, with CISO-approved written compensating controls permitted and reviewed annually. A written asset inventory with owner, location, classification, support expiration, and recovery objectives for each asset. Access privileges limited to what is necessary, with privileged accounts reviewed at least annually and disabled or removed when no longer needed. Encryption of nonpublic information in transit and at rest, with compensating controls only where encryption is infeasible. Vulnerability management including annual penetration testing, automated scanning, and prompt remediation of material vulnerabilities. Audit trails able to reconstruct material financial transactions and detect and respond to incidents, retained for five and three years respectively. Monitoring of user activity, email filtering, and annual training including social engineering.
Response and Recovery
A written incident response plan and a business continuity and disaster recovery plan, both tested annually, with backups maintained, isolated from the production environment, and tested for restoration. Root cause analysis after incidents.
Notification and Certification
Seventy-Two Hours and Twenty-Four Hours
A covered entity must notify DFS within 72 hours after determining that a cybersecurity incident has occurred, at the entity, an affiliate, or a third-party service provider. An incident includes unauthorized access to an information system that has a reasonable likelihood of materially harming normal operations, or that results in ransomware deployment in a material part of the system. If an extortion payment is made, DFS must be notified within 24 hours, with a written explanation within 30 days of why payment was necessary, what alternatives were considered, and the sanctions diligence performed.
The April 15 Certification
Every year by April 15, each covered entity must file either a certification of material compliance for the prior calendar year or a written acknowledgment of non-compliance identifying the provisions not met and a remediation timeline. Under the Second Amendment, the filing must be signed by the highest-ranking executive and the CISO. The certification must be based on data and documentation sufficient to demonstrate compliance, retained for five years. That is a personal signature on a statement about the environment. DFS has penalized entities whose certifications were not supported by what an examination later found.
How Part 500 Maps to Other Frameworks
Part 500 is a regulation, not a control catalog, but its requirements correspond closely to NIST SP 800-53 families: access control and MFA (AC, IA), asset inventory (CM-8), audit trails (AU), encryption (SC), vulnerability management (RA-5, SI-2), incident response (IR), and contingency planning (CP). DFS's own guidance points covered entities toward NIST frameworks as acceptable structures. A risk register built on 800-53 produces the Part 500 crosswalk mechanically, and the universal MFA requirement is checked by the same CIS Benchmark recommendations any Microsoft 365 assessment already runs.
Where Covered Entities Fail
The enforcement record is consistent. MFA is enabled for remote access but not for an internal application that holds nonpublic information, or is enabled but with exceptions nobody reviewed. The asset inventory is a spreadsheet last updated at the previous examination. The risk assessment is dated. The CISO is a title held by the IT director without the authority or the board access the regulation requires. And the certification was signed because it had been signed the year before, not because anyone reconciled it to the environment.
Part 500 in Private Equity
Insurance distribution, mortgage servicing, specialty lending, and fintech are all active consolidation theses, and every New York-licensed target is a covered entity. Three diligence questions follow. What did the target certify on its last April 15 filing, and can the documentation support it? A certification of compliance that an assessment contradicts is a DFS enforcement exposure that transfers with the entity, and the executives who signed it may be the executives the sponsor is retaining. Is universal MFA actually enforced on every information system, including the agency management system, the loan origination platform, and the internal applications a technical reviewer will test first? Has the target ever been assessed for active compromise, or would the 72-hour clock start when a customer calls?
Post-close, Part 500's program-level requirements consolidate well across a platform: one CISO function, one policy set, one risk assessment methodology, one certification process. The technical requirements, MFA and asset inventory and audit trails on every location's systems, are the remediation cost the sponsor should have priced before signing.
Executive Implications
For a CEO of a covered entity, Part 500 is unusual in requiring your signature. The April 15 certification is a personal representation to a regulator that has shown it will examine the environment behind it. For a CISO, the regulation grants authority and demands a written annual report to the board; both are protective if used and damning if not. For a board, Part 500 requires that the board itself have sufficient understanding to oversee cybersecurity risk. DFS has said in enforcement actions that a board cannot delegate that understanding away.
Related Reading
Real-World Example: The Certification That Did Not Match
DFS enforcement actions follow a recognizable arc. An entity files its annual certification of compliance. An incident occurs, or an examination begins. DFS finds that MFA was not enforced on systems the regulation covers, that the risk assessment was stale or absent, that the asset inventory did not exist in the form required, or that nonpublic information was stored unencrypted. DFS then charges not only the underlying control failures but the false certification, because the entity represented compliance it did not have.
The penalties in these actions have ranged from the low millions for mid-sized insurers and lenders to more than $30 million for large entities, and the consent orders require independent audits, remediation plans, and in several cases changes to governance. The recurring lesson is not about any single control. It is that the certification is read against the environment after the fact, and the entities that fared worst were the ones whose executives signed without reconciling the two.
The annual date by which every NYDFS-covered entity must file a certification of compliance, or an acknowledgment of non-compliance with a remediation plan, signed by both the CEO and the CISO. The Second Amendment made the signature personal. The certification is a representation about the environment, and DFS has fined entities whose certifications did not match it.
How Cloudskope Can Help
Cloudskope’s register is built on NIST SP 800-53, so the Part 500 crosswalk is mechanical, and every MFA, asset inventory, audit trail, and encryption finding carries the control the regulation cites. Cloudskope SARTUS™ assesses the environment behind the April 15 certification in three days, identity, cloud, endpoint, credential exposure, and active compromise, and closes the universal MFA, logging, and access gaps in the next three, producing the dated evidence a CEO and CISO can sign against. For sponsors acquiring New York-licensed entities, the same engagement reconciles the target’s last certification to its environment before the signature becomes the buyer’s. See how the register maps across frameworks.
.png)