Guides
In-depth resources to help you understand and implement NY DFS compliance requirements.
NY DFS 23 NYCRR 500 Requirements Overview
Every section of the regulation as amended in November 2023, which requirements apply to your organization, and the key compliance deadlines.
Limited Exemption: Are You Eligible?
Check the three limited exemption tests under Section 500.19(a) and see which sections still apply, then file your Notice of Exemption within 30 days.
Free Compliance Tools
Interactive tools to help you assess, track, and manage your compliance program.
NY DFS Compliance Checklist
Interactive checklist covering the requirements of NY DFS 23 NYCRR 500. Track your compliance progress.
Start ChecklistExemption Eligibility Calculator
Answer a few questions to see whether your business may qualify for the limited exemption under 500.19(a).
Check EligibilityCompliance Calendar
Key dates and deadlines for NY DFS compliance including certification, training, and testing requirements.
View CalendarRisk Assessment Template
Downloadable risk assessment template that meets Section 500.09 requirements.
Download TemplatePolicy & Document Templates
Buffalo Sentinel's policy generator builds these documents from your company details to jumpstart your NY DFS program. All templates are designed to meet 23 NYCRR 500 requirements.
Pro Tip
These templates are a starting point. Customize them to reflect your organization's specific risks, systems, and processes.
Available Templates
Latest Articles
Stay informed with the latest NY DFS compliance news, tips, and best practices.
Understanding NY DFS Penetration Testing Requirements
Section 500.05 requires annual penetration testing. Learn what's required and how to prepare.
Multi-Factor Authentication: Meeting 500.12 Requirements
Since November 2025, MFA is required for anyone accessing any information system. Here's how to implement it effectively.
Annual Compliance Certification: A Step-by-Step Guide
What you need to prepare for your annual certification filing by April 15th.
Incident Response Planning for Small Businesses
How to create an incident response plan that meets NY DFS requirements without enterprise complexity.
Third-Party Vendor Management Under NY DFS
Section 500.11 requires written policies for third-party service providers. Here's what you need.
CISO Requirements: In-House vs Virtual
Understanding the CISO requirement and whether a virtual CISO is right for your organization.
Key Compliance Dates & Deadlines
Important dates to keep on your calendar for NY DFS compliance.
Annual Filing Deadline
Submit a certification of material compliance or an acknowledgment of noncompliance for the prior calendar year
Cybersecurity Incident Notification
Notify DFS within 72 hours after determining a cybersecurity incident occurred
Extortion Payment Notice
Notify DFS within 24 hours of any extortion payment; written explanation within 30 days
Notice of Exemption
File within 30 days of determining that you qualify for an exemption
Penetration Testing
Complete annual penetration test (not required for limited-exemption entities)
Risk Assessment Update
Review and update risk assessment
Security Awareness Training
Complete training, including social engineering, for all personnel
Policy Approval
Policies approved by a senior officer or the senior governing body
Frequently Asked Questions
Common questions about NY DFS 23 NYCRR 500 compliance.
Who needs to comply with NY DFS 23 NYCRR 500?
All entities operating under a license, registration, or authorization under New York Banking Law, Insurance Law, or Financial Services Law. This includes banks, insurance companies, mortgage brokers, money transmitters, and other financial services companies.
What is the limited exemption and who qualifies?
The limited exemption (Section 500.19(a)) is available to covered entities that meet any ONE of three tests: fewer than 20 employees and independent contractors (including affiliates); less than $7.5 million in gross annual revenue in each of the last three fiscal years (from all business operations plus affiliates' New York operations); or less than $15 million in year-end total assets (including affiliates). It exempts you only from 500.4, 500.5, 500.6, 500.8, 500.10, 500.14(a)(1)-(2), 500.14(b), 500.15 and 500.16. You must file a Notice of Exemption within 30 days of your determination.
When is the annual certification due?
Each April 15th you file either a certification of material compliance or an acknowledgment of noncompliance covering the prior calendar year, signed by your highest-ranking executive and your CISO (or, with no CISO, the senior officer responsible for the cybersecurity program). The filing is submitted electronically through the DFS portal.
Do I need a CISO if I qualify for limited exemption?
No. Entities that qualify for the limited exemption are exempt from all of Section 500.04, including the CISO requirement. However, someone must still be responsible for your cybersecurity program, and without a CISO that senior officer co-signs your annual filing.
How often do I need penetration testing?
Section 500.05 requires penetration testing from both inside and outside your system boundaries, by a qualified internal or external party, at least annually. Limited-exemption entities are exempt from all of 500.05, but vulnerability scanning is still recommended.
What are the penalties for non-compliance?
Penalties are set under the Banking Law, Insurance Law and Financial Services Law. Under Section 500.20, a single act or failure to act is a violation, including failing to secure nonpublic information because of noncompliance, or materially failing to comply with any section for any 24-hour period. DFS weighs factors such as cooperation, good faith, history and harm to consumers. Non-compliance can also lead to public enforcement actions and reputational damage.
Can I use a virtual CISO instead of hiring one?
Yes. Under Section 500.04(a) the CISO may be employed by your company, an affiliate or a third-party service provider. If you use an affiliate or provider, you keep responsibility for compliance, must designate a senior staff member to oversee the provider, and must require the provider to maintain a cybersecurity program that protects you.
What training is required for employees?
Section 500.14(a)(3) requires cybersecurity awareness training for all personnel at least annually. It must include social engineering and be updated to reflect the risks in your risk assessment. This applies to limited-exemption entities too. Phishing simulations are a good way to reinforce it.
Have more questions?
Contact Our TeamReady to Simplify Your Compliance?
Buffalo Sentinel automates evidence collection, tracks your compliance status, and keeps you audit-ready year-round.