NY DFS Compliance Calendar
Key dates, deadlines, and recurring requirements for NY DFS 23 NYCRR 500 compliance. Never miss an important deadline.
Critical Deadlines
Annual Certification or Acknowledgment
File either a certification of material compliance or an acknowledgment of noncompliance for the prior calendar year. It must be signed by your highest-ranking executive and your CISO (or, with no CISO, the senior officer responsible for the cybersecurity program).
Cybersecurity Incident Notification
Notify the DFS Superintendent electronically as promptly as possible, and no later than 72 hours after determining that a cybersecurity incident occurred at your company, an affiliate or a third-party service provider.
Extortion Payment Notice
If you make an extortion payment, notify DFS within 24 hours of the payment. Within 30 days, send a written description of why payment was necessary, the alternatives and diligence considered, and your sanctions (OFAC) compliance checks.
Notice of Exemption
If you qualify for an exemption, file a Notice of Exemption with DFS within 30 days of determining that you are exempt.
Recurring Requirements
Penetration Testing
Conduct penetration testing from both inside and outside your system boundaries, by a qualified internal or external party, at least annually.
Vulnerability Scanning
Run automated vulnerability scans, and manually review systems they miss, at the frequency your risk assessment sets and after material system changes.
Risk Assessment Review
Review and update your risk assessment at least annually, and whenever a change in your business or technology materially changes your cyber risk.
Security Awareness Training
Provide cybersecurity awareness training that includes social engineering to all personnel at least annually, updated for the risks in your risk assessment.
CISO Board Reporting
The CISO must report in writing at least annually to the senior governing body (such as the board) on the cybersecurity program, including material risks and plans for remediating material inadequacies.
Incident Response Plan Testing
Test your incident response and business continuity plans, and your ability to restore critical data from backups, at least annually.
Access Privilege Review
Review all user access privileges at least annually and remove or disable accounts and access that are no longer necessary.
Policy Approval
Have your cybersecurity policies approved at least annually by a senior officer or the senior governing body, and update them when your risks change.
Asset Inventory Updates
Update and validate your asset inventory (owner, location, classification, support expiration date, recovery time objective) as often as your written policy requires.
Suggested Quarterly Schedule
Use this quarterly breakdown to spread your compliance activities throughout the year. Adjust based on your organization's specific needs and fiscal calendar.
Q1 (Jan-Mar)
Prepare annual certification or acknowledgment
By April 15
Review Q4 security metrics
January
Update risk assessment if needed
March
Q2 (Apr-Jun)
File certification or acknowledgment (executive + CISO sign)
April 15
Automated vulnerability scan review (frequency per risk assessment)
June
Review training completion rates
May
Q3 (Jul-Sep)
Annual penetration test planning
July
Conduct penetration test
August-September
Third-party vendor reviews
September
Q4 (Oct-Dec)
Automated vulnerability scan review (frequency per risk assessment)
December
Annual security awareness training
November
CISO annual board report
December
Begin filing prep for next year
December
Incident Notification Timeline
When a cybersecurity incident occurs, you must notify NY DFS according to this timeline. The 72-hour clock starts when you determine that an incident occurred, not when you first notice something unusual.
Immediately
Activate your incident response plan, begin containment, and investigate promptly to determine whether a cybersecurity incident (500.1(g)) has occurred.
Within 72 Hours of Determination
CRITICAL: Notify the DFS Superintendent electronically through the DFS portal (500.17(a)(1)). This includes incidents at your affiliates and third-party service providers.
Extortion Payment: 24 Hours and 30 Days
If you make an extortion payment, notify DFS within 24 hours of paying, and within 30 days send a written explanation of why payment was necessary, the alternatives and diligence considered, and your sanctions compliance checks (500.17(c)).
Ongoing
Promptly give DFS any information it requests about the incident, and keep DFS updated with material changes or new information (500.17(a)(2)).
Never Miss a Compliance Deadline
Buffalo Sentinel tracks your compliance deadlines and sends reminders, and its incident tracker runs the 72-hour clock from your determination.