NY DFS 23 NYCRR 500 Compliance

Choose by How Much Automation You Need

Every plan includes full compliance coverage. Upgrade for operations tools and automation.

All plans are billed annually and include unlimited admin users.

Each plan is available in an edition tailored to your regulation (NY DFS, SOC 2, HIPAA, ISO 27001, PCI DSS).

Core Compliance

Full NY DFS compliance for small teams. Everything you need to be audit-ready.

$500/year
Includes 3 employees (more available per seat)
Unlimited admin users
Request a Demo
  • NY DFS requirements dashboard
  • Policy library (41 templates)
  • Policy acknowledgment tracking
  • Evidence vault & collection
  • Training tracking & reports
  • Phishing simulation campaigns
  • Vendor risk assessments
  • Vulnerability remediation tracking
  • Risk register
  • Incident tracking
  • Audit log & activity trail
  • Annual certification or acknowledgment tracking
  • Email support
Most Popular

Operations Pack

Everything in Core plus operations tools for device oversight and remediation.

$900/year
Includes 10 employees (more available per seat)
Unlimited admin users
Request a Demo
  • Everything in Core Compliance
  • Device inventory & fleet overview
  • Endpoint security agents (Windows and Linux)
  • Encryption monitoring (BitLocker)
  • Patch approval workflow
  • Drift detection & alerts
  • Device compliance audits
  • MFA status tracking (via Microsoft 365, Okta, or Duo)
  • Priority support

Premium Automation

Full automation suite for teams that want hands-off compliance operations.

$1,200/year
Includes 15 employees (more available per seat)
Unlimited admin users
Request a Demo
  • Everything in Operations Pack
  • Live terminal access (Linux; Windows coming soon)
  • Remote desktop (MeshCentral integration)
  • Runbooks & scheduled scripts (coming soon)
  • Automated remediation (coming soon)
  • Premium integrations (SIEM, ticketing such as ConnectWise Manage, and advanced providers such as NinjaOne, SentinelOne, CrowdStrike)
  • Dedicated onboarding
  • Phone support

Compare Plans

See exactly what's included in each plan.

FeatureCore ComplianceOperations PackPremium Automation
Price$500/year$900/year$1,200/year
Compliance Coverage
NY DFS requirements dashboard
Policy library (41 templates)
Policy acknowledgments
Evidence vault
Training tracking
Certification deadlines
Audit log
Security Practices
Phishing campaigns
Vendor assessments
Vulnerability tracking
Risk register
Incident tracking
Operations
Device inventory
Endpoint agent
Encryption monitoring
Patch workflow
Drift detection
Automation
Live terminal
Remote desktop (MeshCentral)
Runbooks (coming soon)
Premium integrations
Automated remediation (coming soon)
Capacity
Employees included31015
Admin usersUnlimitedUnlimitedUnlimited
Additional employees$30/yr each$25/yr each$20/yr each
Support
Email support
Priority support
Phone support
Dedicated onboarding

Professional Services Add-Ons

Meet NY DFS requirements that go beyond software. Virtual CISO, penetration testing, and vulnerability scanning.

Virtual CISO

Required by NY DFS 500.04 (unless limited-exempt)

Qualified CISO oversight without the full-time hire. Perfect for small businesses that need expert guidance.

Advisory

$750/month

4 hours/month

Monthly review, policy guidance, board reporting

Active

$1,500/month

10 hours/month

Hands-on management, incident response, vendor reviews

Full-Service

$3,000/month

20 hours/month

Dedicated CISO coverage, audit support, strategic planning

Penetration Testing

Required annually by NY DFS 500.05(a)(1)

Annual penetration testing with a detailed report and remediation guidance. NY DFS requires testing from both inside and outside your system boundaries, so most covered entities add internal network testing. Scope and pricing based on your environment.

Starting at

$1,500

External network test

External vulnerability assessment, network perimeter testing, detailed report

Additional services available:

  • Internal network testing
  • Web application testing
  • Social engineering / phishing
  • Wireless network assessment
  • Cloud environment review

Custom scoping based on your environment

Vulnerability Scanning

Required by NY DFS 500.05(a)(2)

Vulnerability scanning delivered by our team as a professional service. We scan your environment each quarter and send a written report for your DFS compliance records.

Quarterly

$750/quarter

One scan each quarter

Quarterly scan with a written report and remediation guidance, billed each quarter

Annual

$2,400/year

One scan each quarter

The same quarterly scans and reports, billed once a year at a lower total cost

One-Time Services

Gap Assessment

$1,500

Comprehensive review of your current compliance posture with remediation roadmap.

Policy Development

$2,500

Custom policy writing for all 15 NY DFS required policy areas, tailored to your business.

Audit Preparation

$3,500

Hands-on support preparing for your NY DFS examination. Evidence review and mock audit.

Integrations

Standard integrations are available on all plans, including Microsoft 365 / Entra, Google Workspace, Okta, Duo, and basic endpoint security sync. Premium integrations (SIEM, ticketing such as ConnectWise Manage, and advanced providers such as NinjaOne, SentinelOne, and CrowdStrike) are included with Premium Automation or available as an add-on for $200/year.

Pricing Questions

What's the difference between the plans?

All plans include full NY DFS compliance coverage. Core Compliance gives you everything needed to be audit-ready. Operations Pack adds device management and endpoint monitoring. Premium Automation adds remote tools (live terminal and remote desktop) and premium integrations, with runbooks and automated remediation coming soon.

What's an employee vs an admin?

Employees are the people in your organization who complete security training, acknowledge policies, and are tracked for compliance purposes. Admins are the people who manage the compliance program — they set up policies, run phishing tests, review reports, and manage the platform. Admin users are unlimited on every plan.

How do I know if I qualify for the Limited Exemption?

You qualify for the NY DFS 500.19(a) limited exemption if you meet ANY ONE of three tests: fewer than 20 employees and independent contractors (including affiliates), less than $7.5 million in gross annual revenue in each of the last three fiscal years, or less than $15 million in year-end total assets. Use our free exemption calculator to check your status. It is general guidance, not legal advice.

Do I need a CISO even as a small business?

Only if you don't qualify for the limited exemption. NY DFS 500.04 requires covered entities to designate a qualified CISO. This doesn't have to be a full-time employee — our Virtual CISO service can serve as your designated CISO at a fraction of the cost, while your company keeps responsibility for compliance. If you qualify for the limited exemption, you're exempt from this requirement.

Is penetration testing really required?

Yes, NY DFS 500.05(a)(1) requires penetration testing from both inside and outside your system boundaries at least annually for covered entities that don't qualify for the limited exemption. Our penetration testing service includes a detailed report you can keep with your compliance records.

Can I add more employees?

Yes. Additional employees beyond your plan's included count are $30/year each on Core, $25/year each on Operations, or $20/year each on Premium. Contact us for volume pricing.

How do I get started?

Request a demo and our team will walk you through the platform, confirm the right plan for your business, and set up your account. Buffalo Sentinel does not offer a self-serve trial; every customer gets a guided onboarding instead.

Do you offer monthly billing?

Our plans are priced annually to provide the best value for compliance programs that require year-round monitoring. Contact us if you need flexible payment options.

Employee vs Admin: Employees are end users who complete security training and acknowledge policies. Admins are the compliance managers, IT administrators, and business owners who manage the platform. Admin users are unlimited on all plans.

Ready to Get Compliant?

Request a demo to see the platform in action, or call us to discuss your needs.