HomeBlogCybersecurity

SEC Reg S-P for RIAs: The Deadline Passed, Now What?

Empty modern investment advisory boardroom at sunset with a closed laptop and a brass padlock resting on a stack of compliance documents, city skyline beyond the windows

The SEC Reg S-P compliance deadline for smaller RIAs was June 3, 2026. It has passed. If your firm still doesn't have a written incident response program, a 30-day client notification process, and documented vendor oversight, you're out of compliance right now — and the fix is a documentation problem before it's a technology problem.

Updated September 2026 to reflect that the smaller-entity compliance date has passed.

The short version:

  • Smaller RIAs — under $1.5 billion in regulatory assets under management — had until June 3, 2026.
  • Larger firms had until December 3, 2025. Both dates are behind us.
  • Three obligations drive everything else: a written incident response program, client notification within 30 days, and formal oversight of service providers.
  • Late is recoverable. Undocumented is not. Write the plan and log the gaps before you start buying tools.

What the 2024 amendments actually added

A mandatory incident response program: written procedures to detect, respond to, and recover from unauthorized access to customer information. The SEC adopted the amendments in May 2024, with compliance phased in over 18 months for larger entities and 24 months for smaller ones.

The rule also sets a hard customer-notification deadline and requires formal oversight of the providers that touch client data. Reg S-P itself isn't new — it has governed how financial firms handle customer data since 2000.

Smaller entity means under $1.5 billion in RAUM

A smaller entity is a registered investment adviser with less than $1.5 billion in regulatory assets under management. If that describes your firm, the rule applies to you today.

"Smaller" never meant "exempt." A two-person advisory running its practice through a handful of SaaS platforms carries the same core obligations as a national firm, scaled to its own size and risk.

What the incident response program must cover

Four things, and your written program has to address each one:

  1. Assess the nature and scope of an incident.
  2. Contain and control it.
  3. Notify affected clients.
  4. Keep records of what happened and what you decided.

This isn't a document you write once and file away. The program has to match how your firm actually operates — your systems, your custodian, your vendors. A generic template with someone else's tech stack in it won't hold up.

When do we have to tell clients?

You have to notify affected clients no later than 30 days after becoming aware that sensitive customer information was, or was likely, accessed without authorization — and as soon as reasonably practicable before that. The notice has to explain the incident, the data involved, and what clients can do to protect themselves.

Thirty days moves fast when you're also investigating and containing an attack. That's the whole argument for writing the response down before you need it.

Vendor contracts need a 72-hour breach clause

The amendments require written policies for service provider oversight, and they cover three things:

  • Due diligence when you select a vendor.
  • Ongoing monitoring once they're in place.
  • Contract terms requiring the vendor to notify you within 72 hours of discovering a breach. The adopting release puts it as "no later than 72 hours after becoming aware that an applicable breach has occurred."

Every provider holding client data can start your notification clock — your custodian, your CRM, your portfolio management platform, your email host. That is the part that catches firms off guard.

Vendor agreements signed before 2024 generally weren't written with a 72-hour clause in mind, so contracts need a second look. The same discipline pays off at cyber insurance renewal, where carriers ask for most of the same things.

You missed June 3. Here's the order to fix it in

Document first, then remediate. A firm that can hand an examiner a real plan and a dated remediation log is in a very different position from one with nothing on paper, even when both are late.

Reg S-P obligates you to be able to produce a specific set of artifacts. Build them in this order:

  1. A data map — where client information lives and which providers touch it.
  2. The written incident response program, covering the four elements above.
  3. Your client notification procedure, with the 30-day clock built in.
  4. A vendor inventory, plus the due diligence and monitoring policy behind it.
  5. Updated contracts carrying the 72-hour notification term.
  6. A dated gap log — what's missing, who owns it, when it closes.

Then remediate: tighten access controls and multi-factor authentication, and run a tabletop exercise so the plan isn't theoretical. Keep the records the rule requires as you go, because recordkeeping obligations attach to both the incident response program and your vendor oversight.

A firm without in-house security staff usually leans on a virtual CISO to own the program and a managed security partner to run detection and response.

For the day-to-day IT behind these controls, see our IT services for wealth managers and RIAs.

If your firm needs the program built rather than described, see our Regulation S-P compliance help for RIAs, which covers the incident response program, service provider oversight and evidence organized for an SEC exam.

Frequently asked questions

Does Reg S-P apply to state-registered advisers?

The amendments apply to SEC-registered investment advisers, broker-dealers, and investment companies. State-registered advisers fall under their state's rules, but those states often mirror federal expectations, and many custodians impose similar requirements by contract. Treating Reg S-P as a baseline is the safer posture.

We already have a WISP. Is that enough?

Usually not. A written information security program is a strong start, but Reg S-P specifically requires incident response procedures, the 30-day notification process, and documented vendor oversight. Most existing WISPs need to be extended to cover those elements explicitly rather than by implication.

What are the penalties for missing the deadline?

Reg S-P is enforced through SEC examinations and enforcement actions. Deficiencies can lead to findings, remediation orders, fines, and reputational damage. An unprepared incident response also tends to cost more, and do more damage to client trust, than the compliance work would have.

How long does it take to get compliant?

A small firm with clean systems and a short vendor list can get the documentation in place in weeks rather than months. Firms with scattered data, aging infrastructure, or thin vendor contracts should budget longer. The date has passed, so this is overdue work rather than optional work.

NetSys has supported financial services firms across the New York metro and beyond since 1998. For a clear read on where your RIA stands against Reg S-P, book a complimentary risk assessment and we'll map the gaps.

Cyber Security

Discuss cyber security for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.