Skip to main content

FINANCIAL SERVICES

What Is NYDFS Part 500 (23 NYCRR 500)?

DEFINITION

NYDFS Part 500 (23 NYCRR 500) is the New York Department of Financial Services cybersecurity regulation covering banks, insurers, and other financial services companies licensed in New York. It requires a risk-based cybersecurity program, a designated CISO, broad multifactor authentication, asset inventories, 72-hour incident reporting, and an annual compliance certification, with amended requirements fully phased in as of November 1, 2025.

NYDFS Part 500 was the first state-level cybersecurity regulation for financial services and remains one of the most prescriptive. It requires covered entities to maintain a cybersecurity program grounded in a documented risk assessment, designate a CISO who reports to the board, implement access controls and encryption, test incident response and business continuity plans, manage third-party service provider risk, report qualifying cybersecurity events to NYDFS within 72 hours, and certify compliance annually.

The regulation applies to entities operating under New York banking, insurance, or financial services licenses, which sweeps in state-chartered banks, insurance companies, mortgage lenders, money transmitters, and many fintech and virtual currency businesses. Larger Class A companies carry additional obligations, while limited exemptions reduce, but do not eliminate, requirements for the smallest firms.

The practical reality in 2026 is that the grace periods are over. The amended regulation's phased requirements, including broadly required multifactor authentication and complete asset inventories, are fully in effect as of November 1, 2025, and NYDFS is actively enforcing in 2026. Covered entities certifying compliance without evidence behind each requirement are taking on personal and institutional risk. For a plain-language breakdown, see what NYDFS Part 500 requires, and see how Z Cyber supports covered entities on our financial services page.

Running a program that has to satisfy this?

A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.

Meet Your Security Team →