← Back to Resources

NY DFS Compliance Checklist

Interactive checklist to track your progress toward NY DFS 23 NYCRR 500 compliance. Check off items as you complete them.

0 of 33 items completed
0%

Designate a CISO

500.04Limited Exempt

Appoint a qualified Chief Information Security Officer responsible for overseeing the cybersecurity program.

Annual CISO Report

500.04Limited Exempt

CISO reports in writing at least annually to the senior governing body on the cybersecurity program, including material risks and plans for remediating material inadequacies.

Senior Governing Body Oversight

500.04Limited Exempt

Senior governing body oversees cybersecurity risk management, understands cybersecurity matters, receives regular reports and confirms resources are sufficient.

Written Cybersecurity Policy

500.03

Implement and maintain written cybersecurity policies covering the 15 areas in 500.3, to the extent they apply to your operations.

Policy Approval

500.03

Policies approved at least annually by a senior officer or the senior governing body.

Incident Response Plan

500.16Limited Exempt

Written incident response plan addressing required elements, including recovery from backups and root cause analysis.

Business Continuity & Disaster Recovery

500.16Limited Exempt

Written BCDR plan, with backups adequately protected from unauthorized alteration or destruction.

Access Privilege Management

500.07

Limit user and privileged access to what each job needs, review all access at least annually, and promptly terminate access after departures.

Multi-Factor Authentication

500.12

MFA for any individual accessing any information system (required since 1 Nov 2025). Limited-exemption entities: remote access to your systems, remote access to third-party applications holding nonpublic information, and privileged accounts.

Password Policy

500.07

Where passwords are used, a written password policy that meets industry standards.

Conduct Risk Assessment

500.09

Perform periodic risk assessments covering cybersecurity risks.

Update Risk Assessment

500.09

Review and update the risk assessment at least annually and whenever a change materially affects your cyber risk.

Annual Penetration Testing

500.05Limited Exempt

Penetration testing from inside and outside your system boundaries by a qualified party, at least annually.

Vulnerability Scanning

500.05Limited Exempt

Run automated vulnerability scans, and manually review systems they miss, at the frequency your risk assessment sets.

Vulnerability Monitoring & Remediation

500.05Limited Exempt

A monitoring process that promptly informs you of new vulnerabilities, and timely remediation prioritized by risk.

Audit Trail

500.06Limited Exempt

Maintain audit trails to detect and respond to cybersecurity events.

User Activity Monitoring

500.14Limited Exempt

Risk-based controls to monitor authorized users and detect unauthorized access to nonpublic information.

Malicious Code Protection

500.14Limited Exempt

Risk-based controls against malicious code, including web and email filtering.

Encryption in Transit

500.15Limited Exempt

Written policy requiring industry-standard encryption of nonpublic information in transit over external networks.

Encryption at Rest

500.15Limited Exempt

Encrypt nonpublic information at rest, or use CISO-approved compensating controls reviewed at least annually if infeasible.

Asset Inventory

500.13

Documented inventory of information systems tracking owner, location, classification, support expiration date and recovery time objective (required since 1 Nov 2025).

Data Retention Policy

500.13

Implement secure disposal of nonpublic information.

Security Awareness Training

500.14

At least annual cybersecurity awareness training for all personnel, including social engineering.

Training Updates

500.14

Update training to reflect risks identified in your risk assessment.

Third-Party Security Policy

500.11

Written policies for third-party service provider security.

Vendor Due Diligence

500.11

Assess third-party cybersecurity practices.

Vendor Contractual Requirements

500.11

Guidelines covering vendor access controls and MFA, encryption, notice of cybersecurity events, and representations and warranties.

Incident Response Plan

500.16Limited Exempt

Documented plan for responding to cybersecurity events, including ransomware.

72-Hour Notification

500.17

Notify DFS within 72 hours after determining that a cybersecurity incident occurred at your company, an affiliate or a third-party service provider, and keep DFS updated.

Extortion Payment Notice

500.17

Notify DFS within 24 hours of any extortion payment and send a written explanation within 30 days.

Test Response Plans

500.16Limited Exempt

Test incident response and BCDR plans, and your ability to restore from backups, at least annually.

File Certification or Acknowledgment

500.17

By April 15 each year, file a certification of material compliance or an acknowledgment of noncompliance for the prior year, signed by your highest-ranking executive and your CISO.

Maintain Certification Records

500.17

Keep the records supporting your certification or acknowledgment, including remediation plans, for 5 years.

Need Help With Your Compliance Program?

Buffalo Sentinel automates evidence collection, tracks your compliance status, and generates audit-ready reports.