Regulations library · US states
NYDFS Part 500
New York DFS Cybersecurity Regulation (23 NYCRR 500)
In force New York security financial
A detailed cybersecurity program regulation with annual certification, CISO reporting, incident notice within 72 hours and personal liability exposure for certifying executives.
At a glance
- Who it applies to
- Banks, insurers and other financial services companies licensed by NYDFS.
- Who enforces it
- New York Department of Financial Services
- When
- In effect since 1 March 2017. Amended in November 2023, with the final phased requirements due by 1 November 2025.
A practical guide to this law, with scenarios and flashcards, is being written. The summary above is the reference entry.
Recent developments
Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.
Sources
Primary sources are being added to this entry.
Dates and status are from the association's inventory and are being checked against primary sources. This page explains the law for practitioners; it is not legal advice.