NY DFS Compliance Resources

Free guides, templates, tools, and articles to help your business achieve and maintain NY DFS 23 NYCRR 500 compliance.

Policy & Document Templates

Buffalo Sentinel's policy generator builds these documents from your company details to jumpstart your NY DFS program. All templates are designed to meet 23 NYCRR 500 requirements.

Pro Tip

These templates are a starting point. Customize them to reflect your organization's specific risks, systems, and processes.

See Policy Management

Available Templates

Information Security Policy
500.03
Incident Response Plan
500.16
Business Continuity Plan
500.16
Access Control Policy
500.07
Data Retention Policy
500.13
Encryption Policy
500.15
Vendor Management Policy
500.11
Asset Inventory Template
500.13
Training Acknowledgment Form
500.14
Annual Certification Checklist
500.17
Risk Assessment Template
500.09
Penetration Test Scope Document
500.05

Key Compliance Dates & Deadlines

Important dates to keep on your calendar for NY DFS compliance.

April 15

Annual Filing Deadline

Submit a certification of material compliance or an acknowledgment of noncompliance for the prior calendar year

Within 72 hours

Cybersecurity Incident Notification

Notify DFS within 72 hours after determining a cybersecurity incident occurred

24 hours / 30 days

Extortion Payment Notice

Notify DFS within 24 hours of any extortion payment; written explanation within 30 days

Within 30 days

Notice of Exemption

File within 30 days of determining that you qualify for an exemption

Annually

Penetration Testing

Complete annual penetration test (not required for limited-exemption entities)

Annually

Risk Assessment Update

Review and update risk assessment

Annually

Security Awareness Training

Complete training, including social engineering, for all personnel

Annually

Policy Approval

Policies approved by a senior officer or the senior governing body

Frequently Asked Questions

Common questions about NY DFS 23 NYCRR 500 compliance.

Who needs to comply with NY DFS 23 NYCRR 500?

All entities operating under a license, registration, or authorization under New York Banking Law, Insurance Law, or Financial Services Law. This includes banks, insurance companies, mortgage brokers, money transmitters, and other financial services companies.

What is the limited exemption and who qualifies?

The limited exemption (Section 500.19(a)) is available to covered entities that meet any ONE of three tests: fewer than 20 employees and independent contractors (including affiliates); less than $7.5 million in gross annual revenue in each of the last three fiscal years (from all business operations plus affiliates' New York operations); or less than $15 million in year-end total assets (including affiliates). It exempts you only from 500.4, 500.5, 500.6, 500.8, 500.10, 500.14(a)(1)-(2), 500.14(b), 500.15 and 500.16. You must file a Notice of Exemption within 30 days of your determination.

When is the annual certification due?

Each April 15th you file either a certification of material compliance or an acknowledgment of noncompliance covering the prior calendar year, signed by your highest-ranking executive and your CISO (or, with no CISO, the senior officer responsible for the cybersecurity program). The filing is submitted electronically through the DFS portal.

Do I need a CISO if I qualify for limited exemption?

No. Entities that qualify for the limited exemption are exempt from all of Section 500.04, including the CISO requirement. However, someone must still be responsible for your cybersecurity program, and without a CISO that senior officer co-signs your annual filing.

How often do I need penetration testing?

Section 500.05 requires penetration testing from both inside and outside your system boundaries, by a qualified internal or external party, at least annually. Limited-exemption entities are exempt from all of 500.05, but vulnerability scanning is still recommended.

What are the penalties for non-compliance?

Penalties are set under the Banking Law, Insurance Law and Financial Services Law. Under Section 500.20, a single act or failure to act is a violation, including failing to secure nonpublic information because of noncompliance, or materially failing to comply with any section for any 24-hour period. DFS weighs factors such as cooperation, good faith, history and harm to consumers. Non-compliance can also lead to public enforcement actions and reputational damage.

Can I use a virtual CISO instead of hiring one?

Yes. Under Section 500.04(a) the CISO may be employed by your company, an affiliate or a third-party service provider. If you use an affiliate or provider, you keep responsibility for compliance, must designate a senior staff member to oversee the provider, and must require the provider to maintain a cybersecurity program that protects you.

What training is required for employees?

Section 500.14(a)(3) requires cybersecurity awareness training for all personnel at least annually. It must include social engineering and be updated to reflect the risks in your risk assessment. This applies to limited-exemption entities too. Phishing simulations are a good way to reinforce it.

Have more questions?

Contact Our Team

Ready to Simplify Your Compliance?

Buffalo Sentinel automates evidence collection, tracks your compliance status, and keeps you audit-ready year-round.