Free tool · Updated September 30, 2026 · For RIAs and private fund advisers

SEC cybersecurity exam checklist: how ready is your evidence?

Amended Reg S-P now applies to every SEC-registered adviser, and examiners will check that the new policies were developed, implemented and maintained. Mark the 34 items examiners ask to see. Your score, area by area, updates as you go.

By Dipan Mann, Founder, CloudskopeAbout 10 minutesNo sign-up to see your scoreGeneral information, not legal advice

We use this to send your results and the tracker. No newsletter sign-up. Privacy policy

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
How it works

What the 2026 exam priorities mean for your cyber evidence

Dec 3, 2025
Reg S-P compliance date for advisers with $1.5B or more in AUM
June 3, 2026
Reg S-P compliance date for every other registered adviser
30 days
to notify affected individuals after you become aware of an incident
72 hours
for your service providers to tell you about a breach of your data

The SEC withdrew its proposed adviser cybersecurity rule in June 2025. That did not lower the bar. Examiners test cyber through Reg S-P, Reg S-ID and the compliance program rule, and the FY2026 priorities name what they will look at: policies and procedures, governance, data loss prevention, access controls, account management, and incident response and recovery, including ransomware.

In November 2025 the SEC fined a dual registrant $325,000 after email account takeovers exposed customer data and the multi-factor authentication its own policy called for was not enforced. The problem was not a missing policy. It was a policy nobody could show was working.

This checklist turns the rules into 34 pieces of evidence in 10 areas. Each item names the rule or SEC publication behind it. Have it scores 2 points, Partial 1, and Missing or blank 0. N/A items drop out. An area at 80% or above is Ready, 50 to 79% has Gaps, and under 50% is Exposed.

Your answers stay in your browser. If you ask for the Excel tracker, it arrives pre-filled with your answers, with columns for owners, target dates and where the evidence lives, and a scorecard that recalculates as you close items.

FAQ

SEC cybersecurity exam questions, answered

What does the SEC look at in a cybersecurity exam?

The FY2026 Examination Priorities name policies and procedures, governance, data loss prevention, access controls, account management, and incident response and recovery, including ransomware. Examiners will also check that firms have developed, implemented and maintained policies under the amended Reg S-P, and review identity theft red flags programs under Reg S-ID.

When did amended Reg S-P take effect for advisers?

Advisers with $1.5 billion or more in assets under management had to comply by December 3, 2025. Every other SEC-registered adviser had to comply by June 3, 2026.

Is there an SEC cybersecurity rule for investment advisers?

The SEC withdrew proposed Rule 206(4)-9 in June 2025. Cyber is examined through Reg S-P, Reg S-ID, the compliance program rule, Rule 206(4)-7, and the books and records rule.

What records does amended Reg S-P require an adviser to keep?

Written records documenting compliance with the safeguards and disposal requirements, including the incident response program, notification decisions and service provider oversight. Advisers keep them for five years, the first two in an easily accessible place.

Do you see my answers?

No, unless you ask for the tracker. Your answers stay in your browser. If you request the tracker, we receive your contact details, your scores and your answers so we can send your results.

Is this legal advice?

No. It is a readiness tool built from public SEC rules, releases and risk alerts as of September 30, 2026. Confirm your obligations with counsel.

Ground truth. Not story.

Cloudskope is a security-only advisory firm based in Dallas, Texas. We run forensic audits of Microsoft 365 and Azure, cyber due diligence for deals, and a fixed-fee six-day assessment and remediation program for firms and their portfolio companies. We are independent of your IT provider and compliance consultant, and we work alongside both.

Since May 1, 2026, our forensic audits have prevented $2.2M in wire fraud, none of it flagged first by the client's IT team, managed service provider, bank or security tools.