Back to Blog
Compliance
4 min read

NYDFS Part 500 as Amended: What Covered Entities Must Now Evidence

Annual certification signed by senior leadership, tighter MFA and inventory requirements, and incident reporting on a short clock.

GuardsArm Team

Security Experts

September 25, 2026

NYDFS Part 500 cybersecurity requirements

New York's cybersecurity regulation for financial services was among the first to make specific technical controls legally mandatory rather than advisory, and amendments have tightened it considerably. Covered entities now face more prescriptive requirements, stronger governance obligations and a personal signature on the annual certification.

Signed by leadership
The certification puts a name on the record
Inventory cannot be retrofitted
The item entities most often lack
Reporting in hours
A detection and decision problem, not a legal one

Governance carries personal weight

The regulation requires a designated CISO responsible for overseeing the programme and reporting to the board or equivalent governing body. That reporting is not a formality — it must address the programme, material risks and any material inadequacies.

The annual certification of compliance is signed by senior leadership. That signature changes the internal conversation about security budget more effectively than any risk register, because an individual is attesting on the record.

Where full compliance cannot be certified, there is a route to acknowledge non-compliance with remediation plans. Using it honestly is a far better position than certifying inaccurately.


The technical requirements that bite

Part 500 requirements by difficulty to retrofitMulti-factor authentication, asset inventory and a current risk assessment are the hardest to produce at short notice.Multi-factor authenticationBroadened; exceptions need documented compensating controlsAsset inventory, maintainedCannot be produced retrospectivelyRisk assessment, kept currentDrives the rest of the programmeAccess privilege reviewPeriodic, with privileged accounts limitedThird-party service provider policyDue diligence and contractual minimumsTraining and monitoringIncluding phishing-resistant practice
The top three are where examinations concentrate.

Multi-factor authentication requirements have broadened. Assume MFA is expected for remote network access, third-party application access and privileged accounts, and that exceptions need documented approval and a compensating control rather than an informal decision.

Asset inventory requirements are more specific than many entities expect — maintaining an inventory with defined attributes, kept current. Entities that have never completed an inventory find this the most demanding single item, because it cannot be produced retrospectively.

Access privilege management requires periodic review and limits on privileged accounts. See privileged access management.


Incident reporting on a short clock

Covered entities must report qualifying cybersecurity events to the department promptly — a window measured in hours rather than days from determination. Additional reporting obligations apply to events such as extortion payments.

Certify accurately, or use the non-compliance route
Where an entity cannot certify full compliance, the regulation provides for acknowledging that with remediation plans. An inaccurate certification signed by a named executive is a materially worse position than a candid acknowledgement with a credible plan attached.

The short clock is a detection and decision problem. You cannot report something you have not noticed, and you cannot report within hours if the decision to report requires a meeting that takes two days to convene.

What the clock requires you to have:

  • Monitoring that surfaces events promptly
  • A defined threshold for what constitutes a reportable event
  • A named decision-maker reachable out of hours
  • A pre-drafted reporting format
  • Legal and communications aligned in advance

See breach notification for how this compares with Canadian regimes, and incident communications.


Third-party service provider policy

Covered entities must maintain policies governing third-party service providers with access to information systems or non-public information — covering due diligence, minimum practices, contractual protections and periodic assessment.

This is where entities with long vendor lists find the most work, because it requires knowing which vendors actually have access. See vendor risk scoring.


Smaller entities and limited exemptions

Limited exemptions exist based on size, revenue and asset thresholds, but they are partial. An exempt entity is still subject to a core set of requirements, and entities often assume the exemption is broader than it is.

Check the specific exemption criteria against your current position, and re-check when you grow — exemption status changes with the business.


What examiners actually ask for

Part 500 examinations follow a fairly consistent pattern, and the requests are predictable enough to prepare for:

RequestWhat weak entities produce
The current risk assessmentOne dated three years ago
The asset inventoryA partial list from a project, not maintained
Access review evidenceAn assertion that reviews happen
MFA coverage, with exceptionsNo record of which systems are excepted or why
Board reporting on the programmeA single slide, or nothing minuted
Penetration test and vulnerability scan resultsTests performed, findings never remediated
Third-party provider assessmentsA vendor list with no assessment attached

The pattern is the same throughout: the activity happened, and there is no evidence it happened. That is indistinguishable, from an examiner's position, from it not having happened.


Sequencing a programme from behind

For an entity that has not kept pace with the amendments:

  1. Risk assessment refresh — everything else derives from it
  2. Asset inventory, because it cannot be produced quickly later
  3. MFA gaps closed, with documented exceptions and compensating controls
  4. Access review cycle started, with evidence captured from the first round
  5. Incident reporting runbook, including the out-of-hours decision-maker
  6. Third-party assessment for providers with access
  7. Board reporting cadence established and minuted

That order front-loads the items an examiner asks for first and the ones that take longest to build.


Where to start

Build the asset inventory. It is the requirement that cannot be produced at short notice, it is a precondition for several others, and its absence is visible immediately to an examiner.

GuardsArm supports covered entities with programme development and certification readiness. See NYDFS cybersecurity compliance or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.