The June 3, 2026, compliance deadline for Regulation S-P's Final Amendments is approaching. Many smaller registered investment advisers and broker-dealers are still operating under dangerous misconceptions. These myths aren't just wrong; they're compliance liabilities waiting to happen.
The myths persist because Regulation S-P has been around since 2000, and many teams assume the amendments are just minor tweaks. They're not. The Final Amendments, effective August 2, 2024, fundamentally expand what "safeguarding customer information" means and who's accountable when things go wrong. Here's what you need to unlearn before your deadline hits.
Myth 1: "We Already Have Privacy Policies, So We're 90% There"
Reality: Your existing Regulation S-P privacy policy addresses nonpublic personal information disclosure practices. The Final Amendments require a separate, detailed incident response program specifically for "customer information", and the two don't overlap as much as you think.
The amendments mandate written policies and procedures for incident detection, assessment, containment, notification, and documentation. If your current policy says "we protect customer data" without specifying how you'll detect unauthorized access within a timeframe that triggers notification obligations, you're not compliant. You need documented procedures for classifying incidents, determining whether they involve "sensitive customer information," and deciding whether notification is required.
This isn't a policy refresh. It's building a new capability with defined roles, escalation paths, and decision criteria. Start by mapping what "customer information" means in your context, it's broader than you think, covering any record containing nonpublic personal information about a customer.
Myth 2: "The Service Provider Requirements Are Their Problem, Not Ours"
Reality: You're directly liable for your service providers' failures to safeguard customer information, and the Final Amendments make this explicit.
Under the new requirements, your written policies must address oversight of service providers with access to customer information. You need contractual provisions requiring them to implement safeguards, report incidents to you, and allow you to verify their controls. If your cloud storage provider suffers a breach involving your customer data and you can't demonstrate you conducted due diligence on their security program, the SEC will hold you accountable.
For smaller entities, this is actually an advantage. You likely work with fewer service providers than a $50 billion fund complex. Use that to your benefit: create a vendor security questionnaire now, send it to every provider who touches customer information, and document their responses. When your auditor asks how you ensure third-party compliance, you'll have evidence, not excuses.
Myth 3: "We Don't Need to Notify Anyone Unless There's Confirmed Harm"
Reality: The notification trigger isn't harm, it's unauthorized access to or use of sensitive customer information that creates a reasonably likely risk of substantial harm.
This standard is lower than many teams assume. You don't wait for identity theft reports or fraudulent account activity. If an employee's laptop containing unencrypted customer Social Security numbers is stolen, that's likely a notifiable incident even if you never see evidence of misuse.
The Final Amendments require you to notify affected individuals "as soon as practicable" after becoming aware of an incident. This means you've completed your initial assessment and containment, not that you've finished a six-month forensic investigation. Build your incident classification framework now, before you're making notification decisions under pressure at 2 a.m. Define what "sensitive customer information" means (Social Security numbers, account credentials, biometric data), establish risk assessment criteria, and document who makes the final notification call.
Myth 4: "Smaller Entities Get a Lighter Set of Requirements"
Reality: You get more time, not fewer obligations. The June 3, 2026, deadline gives you an extra six months compared to larger entities, but you must meet the same substantive requirements.
The extended deadline exists because the SEC recognized that smaller entities have fewer compliance staff, not because the rules are optional or simplified for you. Every requirement that applies to a $10 billion investment adviser applies to a $500 million adviser. You need the same incident response program, the same service provider oversight, the same recordkeeping, and the same disposal procedures for customer and consumer information.
What you do have is agility. Your compliance officer probably sits ten feet from your COO, and your entire firm can meet in one conference room. Use that to your advantage: you can implement policy changes, train staff, and test incident response procedures faster than a multi-office firm with complex approval chains. The deadline is generous if you start now; it's impossibly tight if you wait until Q1 2026.
Myth 5: "This Is Just a Paperwork Exercise"
Reality: The Final Amendments require operational capabilities, not just documented policies. The SEC will test whether you can actually execute what you've written.
Your incident response program must include procedures for assessing the nature and scope of incidents, containing them, and notifying affected individuals. That means someone on your team needs to know how to pull access logs, identify which customer records were exposed, and draft notification language that meets regulatory requirements. Your information disposal procedures must address both physical and electronic records, which means your IT team needs to understand what "customer information" is and when disposal is required.
During examinations, SEC staff will ask about recent incidents, how you classified them, and what actions you took. They'll want to see evidence that your service provider oversight isn't just a contract clause, they'll ask when you last reviewed a provider's SOC 2 Type II report or conducted a security assessment. If your answer is "we haven't had any incidents" or "we trust our vendors," you're demonstrating that your program exists on paper only.
What to Do Instead
Stop treating the Final Amendments as a document update project. Treat them as an operational risk management program that requires cross-functional ownership.
Start with a gap assessment against the specific requirements: incident response capabilities, service provider oversight mechanisms, disposal procedures for both customer and consumer information, and recordkeeping for incident documentation. Identify which requirements you can't meet today, then build a project plan that addresses the hardest gaps first.
For service providers, create a tiered approach. Providers with access to sensitive customer information get full security assessments; providers with limited access get lighter reviews. Document your risk-based methodology so you can defend it during an examination.
Build your incident response playbook with specific decision trees: What constitutes unauthorized access? Who assesses whether sensitive customer information was involved? What's the threshold for "reasonably likely risk of substantial harm"? Who drafts notifications, and who approves them? Test the playbook with a tabletop exercise before you need it in production.
The June 3, 2026, deadline isn't the finish line, it's the starting gun for ongoing compliance. Build capabilities that work after the deadline, not just documentation that satisfies it.





