NYDFS 23 NYCRR 500
23 NYCRR 500 is a New York State regulation issued by the New York Department of Financial Services (NYDFS) that requires banks and financial services companies to put in place a cybersecurity program to better protect consumer and institution data. Covered organizations are generally expected to assess their cybersecurity risk, implement protective controls, and report certain cybersecurity events. It applies to entities that are regulated by NYDFS, rather than to all businesses generally.
23 NYCRR 500 is a New York Department of Financial Services (NYDFS) cybersecurity regulation that mandates covered financial institutions establish and maintain a documented cybersecurity program and related controls to protect consumer and institutional data. In many implementations this includes conducting cybersecurity risk assessments, deploying protective measures, and reporting qualifying cybersecurity events or breaches to the regulator. Scope note: the regulation is jurisdiction-specific to entities subject to NYDFS supervision and centers on cybersecurity/information security; it is not, in itself, a general financial, operational, geopolitical, or ESG risk framework, and the evidence provided here does not enumerate specific control requirements, thresholds, timelines, or version details. Practitioners should consult the regulation's actual text and current NYDFS guidance for precise obligations, as those details are not established in this evidence.
Why it matters
23 NYCRR 500 matters because it establishes cybersecurity as a regulatory obligation, not merely a best practice, for financial institutions supervised by NYDFS. For third-party and supply chain risk professionals, the regulation is significant because covered organizations must protect consumer and institutional data, and much of that data is handled by external service providers, vendors, and business partners. When a regulated entity relies on third parties, the cybersecurity risk introduced by those relationships becomes part of the entity's own compliance exposure, which raises the stakes for how vendors are assessed, onboarded, and monitored.
Because the regulation requires covered institutions to assess cybersecurity risk, implement protective controls, and report qualifying cybersecurity events, it creates downstream expectations that flow into vendor relationships. A cybersecurity event at a supplier can become a reportable matter for the regulated institution, meaning that gaps in third-party visibility can translate directly into regulatory and reputational consequences. This is why organizations subject to NYDFS supervision often extend their internal cybersecurity requirements to the contracts and assessments they conduct with external parties.
It is important to keep the regulation's scope in perspective. 23 NYCRR 500 is jurisdiction-specific to entities subject to NYDFS supervision and centers on cybersecurity and information security; it is not, in itself, a general financial, operational, geopolitical, or ESG risk framework. The evidence available here does not enumerate specific control requirements, thresholds, or reporting timelines, so practitioners should treat the regulation's actual text and current NYDFS guidance as the authoritative source for precise obligations rather than relying on summaries.
Who it's relevant to
Inside NYDFS 23 NYCRR 500
Common questions
Answers to the questions practitioners most commonly ask about NYDFS 23 NYCRR 500.
