NY DFS Compliance Checklist
Interactive checklist to track your progress toward NY DFS 23 NYCRR 500 compliance. Check off items as you complete them.
Designate a CISO
500.04Limited ExemptAppoint a qualified Chief Information Security Officer responsible for overseeing the cybersecurity program.
Annual CISO Report
500.04Limited ExemptCISO reports in writing at least annually to the senior governing body on the cybersecurity program, including material risks and plans for remediating material inadequacies.
Senior Governing Body Oversight
500.04Limited ExemptSenior governing body oversees cybersecurity risk management, understands cybersecurity matters, receives regular reports and confirms resources are sufficient.
Written Cybersecurity Policy
500.03Implement and maintain written cybersecurity policies covering the 15 areas in 500.3, to the extent they apply to your operations.
Policy Approval
500.03Policies approved at least annually by a senior officer or the senior governing body.
Incident Response Plan
500.16Limited ExemptWritten incident response plan addressing required elements, including recovery from backups and root cause analysis.
Business Continuity & Disaster Recovery
500.16Limited ExemptWritten BCDR plan, with backups adequately protected from unauthorized alteration or destruction.
Access Privilege Management
500.07Limit user and privileged access to what each job needs, review all access at least annually, and promptly terminate access after departures.
Multi-Factor Authentication
500.12MFA for any individual accessing any information system (required since 1 Nov 2025). Limited-exemption entities: remote access to your systems, remote access to third-party applications holding nonpublic information, and privileged accounts.
Password Policy
500.07Where passwords are used, a written password policy that meets industry standards.
Conduct Risk Assessment
500.09Perform periodic risk assessments covering cybersecurity risks.
Update Risk Assessment
500.09Review and update the risk assessment at least annually and whenever a change materially affects your cyber risk.
Annual Penetration Testing
500.05Limited ExemptPenetration testing from inside and outside your system boundaries by a qualified party, at least annually.
Vulnerability Scanning
500.05Limited ExemptRun automated vulnerability scans, and manually review systems they miss, at the frequency your risk assessment sets.
Vulnerability Monitoring & Remediation
500.05Limited ExemptA monitoring process that promptly informs you of new vulnerabilities, and timely remediation prioritized by risk.
Audit Trail
500.06Limited ExemptMaintain audit trails to detect and respond to cybersecurity events.
User Activity Monitoring
500.14Limited ExemptRisk-based controls to monitor authorized users and detect unauthorized access to nonpublic information.
Malicious Code Protection
500.14Limited ExemptRisk-based controls against malicious code, including web and email filtering.
Encryption in Transit
500.15Limited ExemptWritten policy requiring industry-standard encryption of nonpublic information in transit over external networks.
Encryption at Rest
500.15Limited ExemptEncrypt nonpublic information at rest, or use CISO-approved compensating controls reviewed at least annually if infeasible.
Asset Inventory
500.13Documented inventory of information systems tracking owner, location, classification, support expiration date and recovery time objective (required since 1 Nov 2025).
Data Retention Policy
500.13Implement secure disposal of nonpublic information.
Security Awareness Training
500.14At least annual cybersecurity awareness training for all personnel, including social engineering.
Training Updates
500.14Update training to reflect risks identified in your risk assessment.
Third-Party Security Policy
500.11Written policies for third-party service provider security.
Vendor Due Diligence
500.11Assess third-party cybersecurity practices.
Vendor Contractual Requirements
500.11Guidelines covering vendor access controls and MFA, encryption, notice of cybersecurity events, and representations and warranties.
Incident Response Plan
500.16Limited ExemptDocumented plan for responding to cybersecurity events, including ransomware.
72-Hour Notification
500.17Notify DFS within 72 hours after determining that a cybersecurity incident occurred at your company, an affiliate or a third-party service provider, and keep DFS updated.
Extortion Payment Notice
500.17Notify DFS within 24 hours of any extortion payment and send a written explanation within 30 days.
Test Response Plans
500.16Limited ExemptTest incident response and BCDR plans, and your ability to restore from backups, at least annually.
File Certification or Acknowledgment
500.17By April 15 each year, file a certification of material compliance or an acknowledgment of noncompliance for the prior year, signed by your highest-ranking executive and your CISO.
Maintain Certification Records
500.17Keep the records supporting your certification or acknowledgment, including remediation plans, for 5 years.
Need Help With Your Compliance Program?
Buffalo Sentinel automates evidence collection, tracks your compliance status, and generates audit-ready reports.