23 NYCRR 500 Compliance Made Simple
Buffalo Sentinel helps insurance agencies, financial services firms, and regulated entities achieve and maintain NY DFS cybersecurity compliance.
NY DFS Compliance Checklist
First, let's determine your exemption status to show which requirements apply to your organization.
Do you qualify for an exemption?
Critical Compliance Deadlines
Buffalo Sentinel tracks these dates on your compliance calendar so nothing slips.
Annual Certification or Acknowledgment
CriticalFile either a certification of material compliance or an acknowledgment of noncompliance for the prior calendar year, signed by your highest-ranking executive and your CISO (500.17(b)).
April 15 (Annually)Incident Notification
CriticalNotify DFS within 72 hours after determining that a cybersecurity incident occurred, then keep DFS updated with material changes or new information (500.17(a)).
Within 72 hours of determinationExtortion Payment Notice
CriticalIf you make an extortion payment, notify DFS within 24 hours and send a written explanation of why payment was necessary, the alternatives and diligence considered, and sanctions checks within 30 days (500.17(c)).
24 hours / 30 daysNotice of Exemption
If you qualify for an exemption under 500.19, file a Notice of Exemption with DFS within 30 days of determining that you are exempt (500.19(f)).
Within 30 days of determinationCISO Report
Your CISO reports in writing to the senior governing body at least annually on the cybersecurity program (500.4(b)).
AnnuallyPenetration Testing
Complete penetration testing of information systems from inside and outside your system boundaries at least annually.
AnnuallyVulnerability Scanning
Run automated vulnerability scans (plus manual review of systems scans miss) as often as your risk assessment requires, and after material system changes.
Risk-basedRisk Assessment
Review and update your risk assessment at least annually, and whenever a change materially affects your cyber risk.
AnnuallyHow Buffalo Sentinel Helps You Comply
Policy Templates
41 policy templates with merge fields and an approval workflow. Customize, approve, and export to PDF.
Compliance Dashboard
Real-time visibility into your compliance posture with gap analysis.
Deadline Tracking
Track the April 15 certification or acknowledgment, both signatures, and your other DFS deadlines on one calendar.
Phishing Simulator
Test employees with 26 realistic phishing templates. Track who clicks and send them to an education page.
Security Training
36 text and scenario-based courses with quizzes and completion tracking for the annual awareness training in 500.14(a)(3).
Evidence Collection
Evidence is collected automatically and mapped to NY DFS sections. Export an evidence package for your examiner.
Ready to Get DFS Compliant?
Request a demo and take the first step toward DFS compliance confidence.