Regulations library · US states

NYDFS Part 500

New York DFS Cybersecurity Regulation (23 NYCRR 500)

In force New York security financial

A detailed cybersecurity program regulation with annual certification, CISO reporting, incident notice within 72 hours and personal liability exposure for certifying executives.

At a glance

Who it applies to
Banks, insurers and other financial services companies licensed by NYDFS.
Who enforces it
New York Department of Financial Services
When
In effect since 1 March 2017. Amended in November 2023, with the final phased requirements due by 1 November 2025.

A practical guide to this law, with scenarios and flashcards, is being written. The summary above is the reference entry.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources

Primary sources are being added to this entry.

Dates and status are from the association's inventory and are being checked against primary sources. This page explains the law for practitioners; it is not legal advice.