← Back to Resources

NY DFS Compliance Calendar

Key dates, deadlines, and recurring requirements for NY DFS 23 NYCRR 500 compliance. Never miss an important deadline.

Critical Deadlines

April 15Section 500.17(b)

Annual Certification or Acknowledgment

File either a certification of material compliance or an acknowledgment of noncompliance for the prior calendar year. It must be signed by your highest-ranking executive and your CISO (or, with no CISO, the senior officer responsible for the cybersecurity program).

Within 72 HoursSection 500.17(a)

Cybersecurity Incident Notification

Notify the DFS Superintendent electronically as promptly as possible, and no later than 72 hours after determining that a cybersecurity incident occurred at your company, an affiliate or a third-party service provider.

Within 24 Hours / 30 DaysSection 500.17(c)

Extortion Payment Notice

If you make an extortion payment, notify DFS within 24 hours of the payment. Within 30 days, send a written description of why payment was necessary, the alternatives and diligence considered, and your sanctions (OFAC) compliance checks.

Within 30 DaysSection 500.19(f)

Notice of Exemption

If you qualify for an exemption, file a Notice of Exemption with DFS within 30 days of determining that you are exempt.

Recurring Requirements

AnnuallySection 500.05Limited Exempt

Penetration Testing

Conduct penetration testing from both inside and outside your system boundaries, by a qualified internal or external party, at least annually.

Risk-basedSection 500.05Limited Exempt

Vulnerability Scanning

Run automated vulnerability scans, and manually review systems they miss, at the frequency your risk assessment sets and after material system changes.

AnnuallySection 500.09

Risk Assessment Review

Review and update your risk assessment at least annually, and whenever a change in your business or technology materially changes your cyber risk.

AnnuallySection 500.14(a)(3)

Security Awareness Training

Provide cybersecurity awareness training that includes social engineering to all personnel at least annually, updated for the risks in your risk assessment.

AnnuallySection 500.04Limited Exempt

CISO Board Reporting

The CISO must report in writing at least annually to the senior governing body (such as the board) on the cybersecurity program, including material risks and plans for remediating material inadequacies.

AnnuallySection 500.16Limited Exempt

Incident Response Plan Testing

Test your incident response and business continuity plans, and your ability to restore critical data from backups, at least annually.

AnnuallySection 500.07

Access Privilege Review

Review all user access privileges at least annually and remove or disable accounts and access that are no longer necessary.

AnnuallySection 500.03

Policy Approval

Have your cybersecurity policies approved at least annually by a senior officer or the senior governing body, and update them when your risks change.

Per Your PolicySection 500.13(a)

Asset Inventory Updates

Update and validate your asset inventory (owner, location, classification, support expiration date, recovery time objective) as often as your written policy requires.

Suggested Quarterly Schedule

Use this quarterly breakdown to spread your compliance activities throughout the year. Adjust based on your organization's specific needs and fiscal calendar.

Q1 (Jan-Mar)

  • Prepare annual certification or acknowledgment

    By April 15

  • Review Q4 security metrics

    January

  • Update risk assessment if needed

    March

Q2 (Apr-Jun)

  • File certification or acknowledgment (executive + CISO sign)

    April 15

  • Automated vulnerability scan review (frequency per risk assessment)

    June

  • Review training completion rates

    May

Q3 (Jul-Sep)

  • Annual penetration test planning

    July

  • Conduct penetration test

    August-September

  • Third-party vendor reviews

    September

Q4 (Oct-Dec)

  • Automated vulnerability scan review (frequency per risk assessment)

    December

  • Annual security awareness training

    November

  • CISO annual board report

    December

  • Begin filing prep for next year

    December

Incident Notification Timeline

When a cybersecurity incident occurs, you must notify NY DFS according to this timeline. The 72-hour clock starts when you determine that an incident occurred, not when you first notice something unusual.

!

Immediately

Activate your incident response plan, begin containment, and investigate promptly to determine whether a cybersecurity incident (500.1(g)) has occurred.

72h

Within 72 Hours of Determination

CRITICAL: Notify the DFS Superintendent electronically through the DFS portal (500.17(a)(1)). This includes incidents at your affiliates and third-party service providers.

24h

Extortion Payment: 24 Hours and 30 Days

If you make an extortion payment, notify DFS within 24 hours of paying, and within 30 days send a written explanation of why payment was necessary, the alternatives and diligence considered, and your sanctions compliance checks (500.17(c)).

+

Ongoing

Promptly give DFS any information it requests about the incident, and keep DFS updated with material changes or new information (500.17(a)(2)).

Never Miss a Compliance Deadline

Buffalo Sentinel tracks your compliance deadlines and sends reminders, and its incident tracker runs the 72-hour clock from your determination.