Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeBlogCybersecurity

NYDFS 23 NYCRR 500 Compliance: A Guide for Small Firms

Lower Manhattan financial district skyline at dusk, representing New York DFS-regulated financial and insurance firms subject to 23 NYCRR Part 500

If your firm holds a New York DFS license, the full 23 NYCRR Part 500 rules are already in force. The last set of requirements took effect November 1, 2025. There's no more phase-in to wait out. Either the controls are in place or you're out of compliance.

This catches a lot of small firms off guard, because "financial services regulation" sounds like a big-bank problem. It isn't. Part 500 covers anyone operating under a DFS license or registration: small RIAs, insurance agencies, mortgage brokers, licensed lenders, and money transmitters.

Who has to comply with NYDFS Part 500?

Any Covered Entity. That means any business operating under a New York Department of Financial Services license, registration, or charter. That sweeps in a lot of small operations: independent insurance agencies, RIAs, mortgage originators, check cashers, and lenders. If you needed a DFS license to open your doors, Part 500 applies to you.

Being small doesn't get you out. It changes which parts you have to do.

What's the small-business exemption?

A limited one, under Section 500.19. "Limited" is the word that matters. You qualify if you have fewer than 20 employees and contractors, less than $7.5 million in gross annual revenue from New York operations over the past three years, or less than $15 million in year-end total assets, per NYDFS guidance.

Qualify, and you're excused from some requirements: a formal CISO, penetration testing, an audit trail. You are not excused from the core: a risk-based cybersecurity program, access controls, multi-factor authentication, encryption, an incident response plan, and the annual certification. The exemption trims the paperwork. It doesn't let you skip security.

What changed on November 1, 2025?

Two things bite hardest for small firms: multi-factor authentication and asset inventory.

MFA is now required for any user accessing any information system, not just remote logins or admins. Smaller firms under the 500.19 thresholds get a narrower version: MFA on remote access, remote access to third-party apps, and privileged accounts. But nobody gets to skip it entirely anymore.

You also need a written asset inventory. Section 500.13 requires you to track your information systems with the owner, location, classification, support-expiration date, and recovery time objective for each. If you can't say what you own, you can't defend it, and now you have to prove you know.

Start with identity. MFA and access control are the fastest of these to stand up, which is why we point every regulated client there first. Zero trust for small business covers the groundwork Part 500 now demands.

What are the reporting deadlines?

Three clocks matter, and they're tight.

You have 72 hours to report a cybersecurity event to the superintendent. You have 24 hours to report a ransom or extortion payment, plus 30 days to explain the decision in writing. And by April 15 each year, a senior officer and your CISO must sign and file either a Notice of Compliance or an Acknowledgment of Noncompliance. The certification for calendar year 2025 is due April 15, 2026, per the regulation.

That signature carries weight. A senior officer is personally attesting the program is compliant. Signing a certification you can't back up is its own exposure.

What happens if you don't comply?

DFS enforces this, and the penalties aren't theoretical. The department fined OneMain Financial $4.25 million for cybersecurity failures under Part 500. Each day a violation continues can count as a separate violation, so the exposure compounds.

The bigger risk for a small firm is a breach without a program in place: regulatory penalties on top of the breach cost, plus clients and carriers asking why you weren't compliant. Your cyber insurance carrier will ask the same questions Part 500 does.

Frequently asked questions

Does Part 500 apply if I'm licensed in New York but based elsewhere?

Yes. Part 500 follows the DFS license, not your office address. If you hold a New York DFS license or registration, you're a Covered Entity regardless of where you're headquartered. Out-of-state firms serving New York clients get caught by this regularly.

What's a Class A company?

The largest tier: over $20 million in gross annual revenue in each of the last two years, plus either 2,000-plus employees or over $1 billion in revenue. Class A firms face extra requirements like independent audits and endpoint detection. Most small firms aren't Class A, but it's worth confirming where you land.

Do I need a CISO?

If you qualify for the 500.19 exemption, not a formal one, but you still need someone accountable for the program. Larger covered entities must designate a qualified CISO who reports to the board. A small firm can meet the intent with a vCISO instead of a full-time hire.

How is this different from SEC Reg S-P?

Different regulator, overlapping controls. Reg S-P is the SEC's federal rule for broker-dealers and RIAs; Part 500 is New York's. A New York RIA can be subject to both. We break down the federal side in SEC Reg S-P for RIAs.

How long does it take to get compliant?

For a small firm starting from basic IT hygiene, a few months. MFA and asset inventory go fast, while the written program, risk assessment, and incident response plan take longer to document properly. The clock's already run, so the honest answer is: start now and file an Acknowledgment of Noncompliance if you're not there yet.

The NetSys Group builds Part 500 programs for financial and insurance firms across New York: the MFA, the asset inventory, the written policies, and the certification you can actually sign. Book a complimentary cybersecurity assessment and we'll show you exactly where you stand.


About the author: Joel Baum leads cybersecurity and compliance strategy at The NetSys Group, which has delivered managed IT, cybersecurity, and cloud services since 1998. NetSys engineers hold degrees in electrical and computer engineering and are certified Microsoft and Cisco instructors, serving businesses across NY, NJ, CT, PA, and Southwest Florida.

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.