Back to blog
US & Americas

NYDFS Part 500: the cybersecurity rule with a personal signature attached

New York's financial services cybersecurity regulation requires named accountability, annual certification and short breach reporting. What it demands, who it covers, and why the certification requirement changes behaviour.
GRC Copilot Team
NYDFS Part 500: the cybersecurity rule with a personal signature attached

What distinguishes NYDFS Part 500 from most cybersecurity regulation is accountability with a name on it. A senior officer or the board must certify compliance annually, in writing. That single requirement changes how seriously the rest of the rule is treated internally.

Who it covers

Entities operating under a New York banking, insurance or financial services licence — which reaches far beyond New York-headquartered firms, capturing many institutions and insurers licensed to operate in the state. Limited exemptions exist for smaller entities based on headcount, revenue and asset thresholds, but exemptions are partial rather than total, and claiming one requires filing a notice.

The core requirements

  • A cybersecurity programme and written policy, approved by a senior governing body.
  • A designated CISO — who may be a third party, but accountability stays with the covered entity — reporting in writing to the board periodically.
  • Risk assessment that is actually used to drive the programme, and kept current.
  • Multi-factor authentication, with expectations that have broadened over successive amendments.
  • Access management with periodic review and limits on privileged accounts.
  • Encryption of non-public information in transit and at rest.
  • Penetration testing and vulnerability management on defined cadences.
  • Audit trails designed to reconstruct material transactions and detect events.
  • Incident response and business continuity plans, tested.
  • Third-party service provider policy with due diligence and contractual security requirements.
  • Training and awareness, including phishing exercises.
The obligation that catches firms out is reporting speed: notification to the regulator within 72 hours of determining a reportable cybersecurity event. That runs from determination, so you need a triage process capable of reaching a decision quickly — and a definition of what counts, agreed in advance.

Evidence the programme, not just the policy

GRC Copilot tracks controls, risk assessments and evidence continuously, so annual certification rests on records rather than recollection.

Why the certification matters

Annual certification is a written statement, signed at a senior level, that the entity is compliant. Where full compliance cannot be certified, an acknowledgement of non-compliance with a remediation plan is filed instead.

Two consequences follow. First, someone senior has to be personally comfortable with the evidence — which raises the bar on documentation quality far more effectively than any control requirement. Second, certifying compliance you cannot evidence is a materially worse problem than filing an acknowledgement of a known gap. Enforcement has focused on exactly that gap between assertion and reality.

How it relates to what you may hold

An organisation running ISO 27001 or aligned to the NIST CSF will find most of the control substance already covered. What does not transfer: the named CISO and board reporting cadence, the annual certification mechanics, the specific 72-hour reporting duty, and the prescriptive MFA expectations. Map your existing control set to Part 500 rather than building a parallel programme.

Preparing for the annual cycle

  1. Keep the risk assessment current — it is the document everything else is supposed to follow from.
  2. Evidence continuously so certification is a review, not a reconstruction.
  3. Confirm MFA coverage against current expectations, including exceptions.
  4. Test the incident plan and keep the results.
  5. Refresh third-party due diligence and contract terms.
  6. Brief the certifying officer on gaps well before the filing date.

Frequently asked questions

Can the CISO be outsourced?

Yes — a third party or affiliate may fill the role, but the covered entity retains responsibility and must provide appropriate oversight.

Are we exempt if we are small?

Exemptions are partial and threshold-based, and must be claimed by filing a notice. Several core obligations still apply.

What is a reportable event?

Broader than a confirmed data breach — it includes events with a reasonable likelihood of materially harming a material part of normal operations. Agree your interpretation before an incident.

Does ISO 27001 satisfy Part 500?

It covers much of the control substance but not the governance, certification and reporting mechanics. Map, do not substitute.

Key takeaways

  • Annual certification puts a named signature on your compliance claim.
  • 72 hours runs from determination — you need fast, agreed triage.
  • Filing a known gap beats certifying something you cannot evidence.
  • Map an existing ISO or CSF programme rather than building in parallel.
#nydfs #part-500 #financial-services #ciso #certification #mfa