Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Regulations & Laws

NYDFS Cybersecurity Regulation

Also known as: NYDFS Cybersecurity Regulation, 23 NYCRR Part 500, Title 23 NYCRR Part 500, Cybersecurity Requirements for Financial Services Companies, Part 500
Simply put

The NYDFS Cybersecurity Regulation is a binding rule issued by the New York State Department of Financial Services that requires financial services companies it oversees to protect customer information and their information technology systems from cyber threats. It generally requires covered entities to maintain a cybersecurity program, adopt a written security policy, and have an incident response plan that includes notifying regulators of certain breaches. Because it is law rather than a voluntary standard, it applies specifically to entities regulated by the Department in New York and carries legal force.

Formal definition

Codified at Title 23 NYCRR Part 500, the NYDFS Cybersecurity Regulation is a principles-based regulatory framework promulgated by the New York State Department of Financial Services to promote the protection of customer information and the information technology systems of regulated entities. It imposes obligations on 'Covered Entities' — persons operating under a license, registration, charter, or similar authorization under New York banking, insurance, or financial services law — to establish and maintain a documented cybersecurity program, adopt a written cybersecurity policy, and implement an incident response plan with breach notification procedures to the Department. As a jurisdiction-specific legal instrument, its reach is defined by DFS regulatory authority in New York rather than by voluntary adoption; it should not be conflated with voluntary standards such as ISO/IEC 27001 or the NIST Cybersecurity Framework, though covered entities may draw on such frameworks to support compliance. The regulation has been amended over time (including a Second Amendment), so specific requirements, effective dates, thresholds, and any exemptions should be verified against the current official text published by the NYDFS. This entry is informational and does not address the fact-specific application of these requirements to any particular organization.

Why it matters

The NYDFS Cybersecurity Regulation is significant because it is binding law, not a voluntary standard, and it targets a concentrated and systemically important sector: the banks, insurers, and financial services companies operating under New York regulatory authority. New York's status as a major financial center means that a rule issued by the Department of Financial Services can reach a wide range of institutions, and non-compliance carries legal consequences rather than merely the loss of a certification or contractual benefit. For compliance officers and legal counsel, this distinction matters: obligations under Part 500 are enforceable by the Department, whereas alignment with frameworks such as ISO/IEC 27001 or the NIST Cybersecurity Framework remains voluntary unless separately incorporated by law or contract.

Who it's relevant to

Financial services compliance officers
Compliance personnel at banks, insurers, and other institutions authorized under New York banking, insurance, or financial services law are directly responsible for determining whether their organization is a Covered Entity and for maintaining the cybersecurity program, written policy, and incident response plan the regulation generally requires. Because the rule has been amended, they should track changes against the official DFS text and reassess applicability, since thresholds and exemptions may affect specific obligations.
Legal counsel and regulatory affairs teams
In-house and external counsel advising New York-regulated financial firms need to interpret Part 500 as binding law with enforcement consequences, distinct from voluntary standards. Their work includes assessing breach notification obligations to the Department and advising on how application depends on the entity's specific facts, licensing status, and any applicable exemptions — matters that require professional judgment rather than reliance on a general definition.
Information security and incident response leaders
CISOs and security teams at covered institutions translate the regulation's principles-based requirements into operational controls, a written cybersecurity policy, and an incident response plan with breach notification procedures. They may map their programs to voluntary frameworks such as ISO/IEC 27001 or the NIST Cybersecurity Framework to support compliance, while recognizing that such frameworks do not by themselves satisfy the legal obligations under Part 500.
Auditors and third-party assessors
Internal auditors and external assessors evaluating a covered entity's posture must distinguish an assessment of program design and operation from any formal certification, since Part 500 is a regulatory obligation rather than a certification scheme. Given the amendments to the regulation, assessors should confirm they are testing against the current version of the official text.
Vendors and service providers to regulated entities
Third-party service providers supporting New York financial institutions may be affected indirectly, as covered entities often address third-party risk within their cybersecurity programs. Whether and how specific obligations flow to a provider depends on contractual arrangements and the covered entity's own program, so providers should verify expectations with their financial services clients and against the current regulatory text.

Inside NYDFS Cybersecurity Regulation

Scope and Covered Entities
The regulation, codified at 23 NYCRR Part 500, generally applies to entities operating under a license, registration, charter, certificate, permit, accreditation, or similar authorization under New York banking, insurance, or financial services law. It is a binding regulation issued by the New York State Department of Financial Services, not a voluntary framework. Its reach is limited to the financial services sector regulated by NYDFS, though covered entities may have operations or affiliates outside New York.
Cybersecurity Program and Policy
Covered entities are generally required to maintain a documented cybersecurity program and written policies designed to protect the confidentiality, integrity, and availability of information systems. The specifics are risk-based, meaning requirements are calibrated to the entity's risk assessment rather than applied uniformly.
Chief Information Security Officer (CISO)
The regulation generally requires designation of a qualified individual responsible for overseeing and enforcing the cybersecurity program, a role commonly referred to as a CISO. This function may be fulfilled by an employee, an affiliate, or a third-party service provider, subject to conditions in the regulation.
Risk Assessment
A periodic risk assessment generally underpins the program, informing the controls the entity implements. Many obligations are expressly tied to the results of this assessment rather than prescribed as fixed technical mandates.
Incident Notification Obligations
Covered entities are generally required to notify NYDFS of certain cybersecurity events within a specified timeframe after determining a reportable event has occurred. This is a distinct legal reporting duty separate from any breach-notification obligations arising under other laws or in other jurisdictions. Practitioners should verify the current notification triggers and deadlines against the official text, as these have been subject to amendment.
Technical and Organizational Controls
The regulation addresses areas such as access controls, multi-factor authentication, encryption, penetration testing and vulnerability assessment, audit trails, third-party service provider security, and data retention limits. Applicability of specific controls can depend on the entity's risk profile and on available limited exemptions.
Certification or Compliance Attestation
Covered entities are generally required to submit a periodic filing to NYDFS regarding their compliance. This is a self-attestation to the regulator, not an independent third-party certification comparable to schemes such as ISO/IEC 27001 or SOC 2 reporting.
Limited Exemptions
The regulation provides limited exemptions, often based on factors such as size, number of employees, or gross revenue, which may relieve smaller covered entities from certain but not all requirements. Exemption status must generally be filed and reassessed, and does not remove all obligations.

Common questions

Answers to the questions practitioners most commonly ask about NYDFS Cybersecurity Regulation.

Is the NYDFS Cybersecurity Regulation a voluntary framework like ISO/IEC 27001 or the NIST Cybersecurity Framework?
No. The NYDFS Cybersecurity Regulation (23 NYCRR Part 500) is a binding regulation issued by the New York State Department of Financial Services, not a voluntary standard. Covered entities must comply as a matter of law; noncompliance can expose an organization to enforcement action by the Department. This distinguishes it from frameworks such as ISO/IEC 27001 or the NIST Cybersecurity Framework, which are voluntary unless adopted contractually or incorporated by reference. An organization may use such frameworks to help structure its controls, but doing so does not by itself satisfy the regulation's specific obligations. Confirm current requirements against the official text published by NYDFS.
Does the NYDFS Cybersecurity Regulation apply only to banks headquartered in New York?
Not necessarily. The regulation generally applies to entities operating under a license, registration, charter, certificate, permit, accreditation, or similar authorization under New York's Banking Law, Insurance Law, or Financial Services Law — a population that includes many types of financial institutions beyond banks, and that is not limited to firms headquartered in the state. An organization based elsewhere may still be a covered entity if it holds the relevant New York authorization. Whether a particular firm is in scope is fact-specific and depends on its regulatory status; readers should verify applicability against the current regulatory text and their own licensing situation, and seek professional judgment for their circumstances.
How should a covered entity approach the required risk assessment under the regulation?
The regulation generally contemplates a periodic risk assessment that informs the design of the cybersecurity program and the selection of controls, rather than a one-time exercise. In most cases the assessment should be documented, reflect the organization's specific information systems and the nonpublic information it handles, and be updated to account for changes in technology, threats, and business operations. The precise cadence, content, and documentation expectations are set out in the regulatory text and have been subject to amendment, so covered entities should confirm the current requirements and align the assessment methodology to their actual risk profile rather than to a generic template.
What is the role of the CISO or equivalent responsible person under the regulation?
The regulation generally requires that a qualified individual be designated to oversee and implement the cybersecurity program and enforce the cybersecurity policy — a function often described as the Chief Information Security Officer, though the person may be employed by the covered entity, an affiliate, or a third-party service provider subject to conditions. This individual is typically expected to report periodically to the governing body or senior leadership on the program and material cybersecurity matters. The specific reporting content and frequency are defined in the regulatory text, which has been amended over time; verify the current expectations against the authoritative source.
What are a covered entity's obligations when a cybersecurity event occurs?
The regulation generally requires notification to the Department of certain cybersecurity events within a prescribed timeframe, and includes provisions addressing events involving other regulators or law enforcement and, in some cases, extortion-related payments. Which events trigger notification, the applicable deadlines, and the reporting mechanics are specified in the regulatory text and have been the subject of amendment. Because these obligations are time-sensitive and the exact triggers and timelines are fact-specific, covered entities should map their incident-response procedures to the current official requirements and confirm deadlines before an event rather than during one. This entry does not provide the specific timeframes.
Does compliance with the NYDFS regulation involve any annual attestation or certification?
The regulation generally requires covered entities to submit a periodic filing to the Department attesting to compliance or acknowledging areas of noncompliance, signed by appropriate senior personnel. This is a self-attestation to the regulator, and should not be confused with third-party certification schemes such as SOC 2 reports or ISO/IEC 27001 certification, which are independent assurance mechanisms rather than regulatory filings. The required form, signatories, and submission process are defined by NYDFS and have changed with amendments to the regulation; verify the current filing requirements, deadlines, and format against the Department's official instructions.

Common misconceptions

Aligning with a framework like the NIST Cybersecurity Framework or achieving an ISO/IEC 27001 certification automatically satisfies the NYDFS Cybersecurity Regulation.
The NYDFS regulation is a binding legal requirement, whereas those frameworks and standards are voluntary or contractual. Mapping to a recognized framework may support compliance efforts, but it does not by itself discharge the regulation's specific legal obligations, such as the required NYDFS filings and event notifications. The two operate on different footings.
The regulation applies to any company doing business in New York.
Its scope is limited to entities authorized under New York's banking, insurance, and financial services laws as administered by NYDFS. Businesses outside that regulated financial sector are generally not covered, though they may face other obligations under separate state, federal, or international rules. Jurisdictional and sectoral scope should be confirmed against the current text.
The annual filing to NYDFS is a certification that proves the entity is secure.
The filing is a self-attestation of compliance submitted to the regulator, not an independent certification of security and not equivalent to an external audit or a third-party assessment. It reflects the entity's own representation and does not guarantee the adequacy of controls in the event of an incident or examination.

Best practices

Confirm whether your organization is a covered entity and whether any limited exemption applies, and document the basis for that determination, refiling exemption notices on the schedule required by NYDFS.
Base your cybersecurity program on a current, documented risk assessment so that implemented controls are demonstrably tied to identified risks, as the regulation's requirements are largely risk-based.
Formally designate a qualified individual to serve the CISO function and clearly define reporting lines and accountability, whether that role is internal, affiliated, or outsourced.
Establish an incident-response and notification process that can identify reportable cybersecurity events and meet NYDFS notification deadlines, keeping it distinct from breach-notification duties under other laws or jurisdictions.
Maintain evidence supporting your periodic compliance filing, and treat that self-attestation as separate from any voluntary certification or independent audit your organization may also pursue.
Verify current requirements, notification triggers, deadlines, and filing formats against the latest official NYDFS text, since the regulation has been amended over time and interpretations continue to evolve.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps