GRCCopilot
Sign In
New York State Department of Financial Services (NYDFS)

NYDFS Cybersecurity Regulation (23 NYCRR 500)

New York's stringent cybersecurity regulation for financial services — with personal CISO accountability and senior officer certification

Start Assessment Create Free Account
16
Controls
48
Questions
Active
Status
May 2029
Expires

About this Framework

23 NYCRR 500 (amended November 2023) mandates a comprehensive cybersecurity program for all financial services companies licensed by the NYDFS. The 2023 amendments introduced Class A entity requirements, mandatory CISO annual reporting to the board, required annual penetration testing, 72-hour reporting for ransom payments, and personal certification by senior officers of compliance. NYDFS has imposed fines exceeding $100 million including against First American Financial, Carnival Corp and Twitter/X.

Key Control Domains

Cybersecurity Program & Policy
CISO Designation & Board Reporting
Penetration Testing & Vulnerability Management
Access Privileges & Multi-Factor Authentication
Application Security
Risk Assessment
Incident Response & Reporting
Third-Party Service Provider Security
Encryption
Audit Trail Management

Who Needs This?

  • Banks and financial institutions licensed by NYDFS
  • Insurance companies operating in New York State
  • Mortgage companies, brokers and servicers
  • Money transmitters and virtual currency businesses

Compliance Benefits

  • NYDFS regulatory compliance and multi-million dollar penalty avoidance
  • Senior management accountability with board-level visibility
  • Comprehensive cybersecurity program aligned to modern standards
  • Widely used as a model for other U.S. state cybersecurity regulations

Official Reference

NYDFS Cybersecurity Regulation
https://www.dfs.ny.gov/industry_guidance/cybersecurity

Assessment Details

Issuer / AuthorityNew York State Department of Financial Services (NYDFS)
FrameworkNYDFS Cybersecurity Regulation (23 NYCRR 500)
Controls16
Questions48
StatusActive
Assessment Start25 May 2026
Assessment Expires25 May 2029

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/nydfs-cybersecurity-regulation-23-nycrr-500

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.