Back to Resources
CompliancePublished Updated 12 min read

Annual Compliance Certification: A Step-by-Step Guide

What you need to prepare for your annual certification or acknowledgment filing by April 15th.

Key Deadline: April 15th

The annual certification or acknowledgment must be filed electronically by April 15th of each year, covering the prior calendar year. Late filings can result in penalties and regulatory scrutiny.

Section 500.17(b) of NY DFS 23 NYCRR 500 requires every covered entity to file, each year, either a certification of material compliance or an acknowledgment of noncompliance. This guide walks you through the process, from preparation to filing.

Understanding the Certification

The annual certification is a formal attestation that your organization materially complied with the requirements of 23 NYCRR 500 during the prior calendar year, based on data and documentation sufficient to show it. The filing must be signed by your highest-ranking executive and your CISO. If you have no CISO, the second signer is the senior officer responsible for your cybersecurity program.

You have two options:

  • Certification of Material Compliance - You materially complied with the requirements of Part 500 during the prior calendar year
  • Acknowledgment of Noncompliance - You did not materially comply with every requirement; you identify each section, describe the nature and extent of the noncompliance, and give a remediation timeline or confirm remediation is complete

Step 1: Determine Applicable Requirements

First, identify which requirements apply to your organization:

Limited Exemption Entities (500.19(a))

If you qualify for the limited exemption, you are exempt only from 500.4, 500.5, 500.6, 500.8, 500.10, 500.14(a)(1)–(2), 500.14(b), 500.15 and 500.16. Everything else still applies, including MFA (in a narrower scope), annual awareness training and this annual filing. File a Notice of Exemption within 30 days of determining that you are exempt, if you haven't already.

Full Compliance Entities

If you don't qualify for an exemption, every requirement of Part 500 applies to you. Class A companies (500.1(d)) have additional requirements, including independent audits of the cybersecurity program, privileged access management, and endpoint detection and response with centralized logging.

Step 2: Gather Evidence

Before certifying, gather documentation that demonstrates compliance for each applicable requirement:

Evidence Checklist

Policies & Procedures

  • • Cybersecurity policy (500.03)
  • • Incident response plan (500.16)
  • • Third-party policy (500.11)
  • • Access control policy (500.07)

Technical Controls

  • • MFA enrollment reports (500.12)
  • • Asset inventory (500.13)
  • • Encryption status (500.15)
  • • Penetration test results (500.05)
  • • Vulnerability scan reports (500.05)

Governance

  • • CISO designation (500.04)
  • • CISO reports to the senior governing body (500.04)
  • • Risk assessment (500.09)

Training & Awareness

  • • Training completion records (500.14)
  • • Phishing test results
  • • Policy acknowledgments

Step 3: Conduct Internal Review

Perform a thorough review of your compliance status:

  1. Review each applicable section of the regulation
  2. Document evidence of compliance for each requirement
  3. Identify any gaps or areas of noncompliance
  4. Develop remediation plans for any identified gaps
  5. Have your CISO or compliance officer sign off on the review

Step 4: Executive and CISO Sign-Off

The certification or acknowledgment must be signed by both:

  • Your highest-ranking executive
  • Your CISO (or, if you have no CISO, the senior officer responsible for the cybersecurity program)

Both signers are attesting to the organization's compliance position for the prior year. They should review the evidence before signing.

Step 5: File the Certification or Acknowledgment

You file electronically, in the form on the DFS website, through the DFS portal:

  1. Log in to the DFS Portal
  2. Select your entity and the calendar year covered
  3. Choose a certification of material compliance or an acknowledgment of noncompliance
  4. Complete the form, including both signers
  5. Submit by April 15th

What If You Can't Certify Compliance?

If you did not materially comply with every requirement, you file an Acknowledgment of Noncompliance instead (500.17(b)(1)(ii)). It must:

  • • Acknowledge that you did not materially comply with all requirements for the prior calendar year
  • • Identify every section you did not materially comply with, and describe the nature and extent of the noncompliance
  • • Give a remediation timeline, or confirm that remediation is complete

Step 6: Maintain Records

Keep all records, schedules and data supporting the certification or acknowledgment for five years (500.17(b)(3)). This includes:

  • All evidence gathered during the review process
  • Internal review documentation
  • Areas, systems and processes that needed material improvement, and your remediation efforts, plans and timelines
  • Copy of the filed certification or acknowledgment

Certification Timeline

Jan

Begin Evidence Gathering

Start collecting documentation for the prior year

Feb

Internal Review

Complete compliance review and identify any gaps

Mar

Signer Review

Highest-ranking executive and CISO review the evidence before signing

Apr 15

Filing Deadline

Submit the certification or acknowledgment through the DFS portal

Simplify Your Annual Certification

Buffalo Sentinel tracks your compliance year-round, including your annual certification or acknowledgment and both required signatures.

Request a Demo