Skip to main content
Category: Regulatory Frameworks

NYDFS 23 NYCRR 500

Also known as: 23 NYCRR 500, 23 NYCRR Part 500, NYDFS Cybersecurity Regulation, NYDFS Part 500
Simply put

23 NYCRR 500 is a New York State regulation issued by the New York Department of Financial Services (NYDFS) that requires banks and financial services companies to put in place a cybersecurity program to better protect consumer and institution data. Covered organizations are generally expected to assess their cybersecurity risk, implement protective controls, and report certain cybersecurity events. It applies to entities that are regulated by NYDFS, rather than to all businesses generally.

Formal definition

23 NYCRR 500 is a New York Department of Financial Services (NYDFS) cybersecurity regulation that mandates covered financial institutions establish and maintain a documented cybersecurity program and related controls to protect consumer and institutional data. In many implementations this includes conducting cybersecurity risk assessments, deploying protective measures, and reporting qualifying cybersecurity events or breaches to the regulator. Scope note: the regulation is jurisdiction-specific to entities subject to NYDFS supervision and centers on cybersecurity/information security; it is not, in itself, a general financial, operational, geopolitical, or ESG risk framework, and the evidence provided here does not enumerate specific control requirements, thresholds, timelines, or version details. Practitioners should consult the regulation's actual text and current NYDFS guidance for precise obligations, as those details are not established in this evidence.

Why it matters

23 NYCRR 500 matters because it establishes cybersecurity as a regulatory obligation, not merely a best practice, for financial institutions supervised by NYDFS. For third-party and supply chain risk professionals, the regulation is significant because covered organizations must protect consumer and institutional data, and much of that data is handled by external service providers, vendors, and business partners. When a regulated entity relies on third parties, the cybersecurity risk introduced by those relationships becomes part of the entity's own compliance exposure, which raises the stakes for how vendors are assessed, onboarded, and monitored.

Because the regulation requires covered institutions to assess cybersecurity risk, implement protective controls, and report qualifying cybersecurity events, it creates downstream expectations that flow into vendor relationships. A cybersecurity event at a supplier can become a reportable matter for the regulated institution, meaning that gaps in third-party visibility can translate directly into regulatory and reputational consequences. This is why organizations subject to NYDFS supervision often extend their internal cybersecurity requirements to the contracts and assessments they conduct with external parties.

It is important to keep the regulation's scope in perspective. 23 NYCRR 500 is jurisdiction-specific to entities subject to NYDFS supervision and centers on cybersecurity and information security; it is not, in itself, a general financial, operational, geopolitical, or ESG risk framework. The evidence available here does not enumerate specific control requirements, thresholds, or reporting timelines, so practitioners should treat the regulation's actual text and current NYDFS guidance as the authoritative source for precise obligations rather than relying on summaries.

Who it's relevant to

Compliance and regulatory affairs teams
Teams responsible for regulatory adherence at NYDFS-supervised banks and financial services companies need to interpret and operationalize the regulation's cybersecurity program requirements. Because the regulation is jurisdiction-specific to NYDFS-regulated entities, these teams must determine whether their organization falls within scope and consult the regulation's actual text for precise obligations rather than relying on summaries.
Third-party and vendor risk managers
Professionals who assess and monitor external suppliers and service providers are relevant because covered institutions must protect consumer and institutional data that is often handled by third parties. A cybersecurity event at a vendor may carry consequences for the regulated entity's own compliance posture, so vendor due diligence and ongoing monitoring often need to reflect the regulation's cybersecurity expectations.
Information security and cybersecurity leaders
Security leaders at covered financial institutions are typically accountable for implementing the protective controls and risk assessment activities the regulation contemplates. Their focus is squarely on cybersecurity and information security; the regulation does not, in itself, address financial, operational, geopolitical, or ESG risk, so those domains require separate treatment.
Incident response and breach reporting functions
Because the regulation requires reporting of qualifying cybersecurity events to the regulator, functions responsible for detecting and escalating incidents need clarity on what triggers a reporting obligation. The specific thresholds and timelines are not established in this evidence and should be confirmed against current NYDFS guidance and the regulation's text.

Inside NYDFS 23 NYCRR 500

Third-Party Service Provider Security Policy
A required written policy governing the security practices of third-party service providers that access or hold a covered entity's nonpublic information or information systems. It typically addresses identification and risk assessment of such providers, minimum cybersecurity practices they must meet, due diligence processes, and periodic reassessment. It focuses on information security aspects of the relationship and does not by itself address financial, operational, or broader supply chain risks.
Scope of Covered Entities
The regulation applies to entities operating under a license, registration, charter, or similar authorization under New York banking, insurance, or financial services law. It is a New York State financial-sector regulation and does not have direct authority over entities outside that jurisdiction or sector, though such entities may be affected as third parties to covered entities.
Access Controls and Encryption Expectations
Provisions addressing controls over access to nonpublic information, including expectations relating to multi-factor authentication and encryption of data in transit and at rest, applied both internally and, where relevant, in the context of third-party access. These are information-security controls and do not extend to non-cyber dimensions of third-party risk.
Risk Assessment Basis
The regulation contemplates that a covered entity's cybersecurity program and its treatment of third-party providers be informed by a periodic risk assessment. This ties third-party requirements to the entity's assessed risk rather than imposing identical controls on all relationships.
Certification and Notification Obligations
Requirements for covered entities to periodically certify compliance and to notify the regulator of certain cybersecurity events. These obligations rest with the covered entity; they do not transfer to third parties, though a third party's incident may trigger a covered entity's notification duty depending on the circumstances.

Common questions

Answers to the questions practitioners most commonly ask about NYDFS 23 NYCRR 500.

Does NYDFS 23 NYCRR 500 apply only to banks headquartered in New York?
No. The regulation applies to entities operating under a license, registration, charter, certificate, permit, accreditation, or similar authorization under New York's Banking, Insurance, or Financial Services Laws, regardless of where the entity is headquartered. This can include insurers, mortgage companies, and other covered financial institutions, not only banks, and the trigger is the New York authorization rather than the location of the corporate headquarters. Certain covered entities may qualify for limited exemptions based on factors such as size, though such exemptions are typically partial rather than complete and depend on the specific criteria in the rule.
Is compliance with 23 NYCRR 500 the same as being certified secure or free of third-party risk?
No. The regulation establishes cybersecurity program requirements for covered entities; it does not confer a certification, and meeting its obligations does not eliminate cyber, third-party, or supply chain risk. Compliance is generally demonstrated through required program elements and periodic certifications or acknowledgments submitted to the regulator, which are attestations by the covered entity rather than independent guarantees of security. Residual risk typically remains, and satisfying the rule addresses defined regulatory expectations rather than assuring that any particular vendor or system is secure.
How does 23 NYCRR 500 shape a covered entity's third-party service provider requirements?
The regulation typically requires covered entities to maintain written policies and procedures governing the security of information systems and nonpublic information that are accessible to, or held by, third-party service providers. In many programs this includes conducting risk-based due diligence, setting minimum security practices for providers, and defining periodic assessment expectations. The rule generally frames these as risk-based obligations rather than a single prescribed control set, so the depth of assessment often varies by the sensitivity of data and access involved. It centers on the covered entity's direct third-party relationships and does not by itself extend prescriptive requirements across lower supply chain tiers.
What role does the covered entity's leadership play under the regulation?
The regulation typically assigns accountability at senior levels, including designation of a qualified individual responsible for overseeing and enforcing the cybersecurity program, often referred to in program terms as a CISO function, and periodic reporting to the governing body such as the board or senior officer. Covered entities generally submit periodic certifications or acknowledgments regarding the program to the regulator. These are governance and attestation mechanisms; they document senior oversight but do not substitute for independent verification of the underlying controls.
Does the regulation require incident notification, and how quickly?
The regulation includes obligations to notify the regulator of certain cybersecurity events within a defined reporting window after determination that a reportable event has occurred. Because reporting triggers and timeframes are specified in the rule and have been subject to amendment, covered entities should confirm the current text and applicable thresholds rather than relying on a remembered figure. Notification to the regulator is a distinct obligation from any breach notification duties owed to affected individuals or other authorities, which may arise under separate laws depending on the circumstances.
How does 23 NYCRR 500 interact with other cybersecurity frameworks and jurisdictions a firm may already follow?
The regulation sets baseline program requirements for New York-authorized entities and can coexist with frameworks and standards a firm uses for its broader program, such as those addressing information security management or supplier relationships. Alignment with such frameworks may support but does not automatically satisfy the specific obligations in the rule, and the rule's requirements are distinct from those of other state, federal, or non-U.S. regimes an entity may also be subject to. Firms operating across multiple jurisdictions typically need to reconcile overlapping expectations rather than treating any single regime as globally sufficient.

Common misconceptions

23 NYCRR 500 imposes its cybersecurity requirements directly on a covered entity's third-party service providers.
The regulation binds the covered entity, not its providers. It requires the covered entity to establish policies and due diligence governing those providers, but the compliance and certification obligations remain with the covered entity. Any provider obligations arise through contract and the covered entity's own program rather than by direct regulatory mandate.
The regulation is a general third-party risk framework applicable to any organization.
It is a New York State financial-services regulation with a defined set of covered entities. It centers on cybersecurity and the protection of nonpublic information, and does not address financial, operational, geopolitical, or ESG dimensions of third-party or supply chain risk.
Completing initial due diligence on a service provider satisfies the regulation's third-party expectations.
The third-party security policy is expected to address both onboarding due diligence and periodic reassessment. A point-in-time onboarding review does not, on its own, meet the expectation for ongoing evaluation informed by the covered entity's risk assessment.

Best practices

Maintain a written third-party service provider security policy that explicitly covers identification, risk-based due diligence, minimum security practices, and periodic reassessment, rather than treating onboarding as a one-time control.
Tie third-party requirements to the entity's periodic risk assessment so that controls applied to each provider reflect its assessed risk rather than a uniform standard.
Use contractual terms to translate the covered entity's cybersecurity expectations to providers, recognizing that the regulation binds the covered entity and does not directly obligate the provider.
Address information-security controls such as access management, multi-factor authentication, and encryption in third-party arrangements, while separately managing financial, operational, and other risks the regulation does not cover.
Establish processes to detect and evaluate provider-related cybersecurity events, since such events may trigger the covered entity's own notification obligations.
Coordinate compliance across jurisdictions and sectors, noting that entities outside New York's financial sector may be affected as third parties even though the regulation does not directly govern them.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps