Regulation · Financial services · New York

NYDFS 500 compliance: the amended Part 500 requirements explained

NYDFS 500 compliance means meeting 23 NYCRR Part 500, the New York Department of Financial Services cybersecurity regulation for banks, insurers and other licensed entities. The 2023 amendment phased in through 1 November 2025, adding universal MFA and asset inventories, and every covered entity certifies compliance by 15 April each year.

Key takeaways

What you need to know about NYDFS 500

Fully phased inThe last amended requirements, MFA and asset inventory, applied from 1 November 2025.
CEO and CISO signThe annual certification is signed by both.
Fast reporting72 hours for incidents, 24 hours for extortion payments.
Class A tierLarger companies face independent audits and more.
Board oversightThe governing body must oversee cyber risk.

Who must comply with NYDFS 500?

Entities licensed or chartered under New York banking, insurance or financial services law.

BanksState-chartered banks and branches.
InsurersLicensed insurance companies and producers.
Money transmitters and virtual currency firmsLicensed by NYDFS.
Mortgage companiesLicensed lenders and servicers.
Third-party providersThrough contract requirements in 500.11.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the regulation requires

What does NYDFS Part 500 require?

NYDFS Part 500 requires a risk-based cybersecurity program with a CISO and board oversight, technical controls including universal MFA and an asset inventory, tested incident and continuity plans, fast incident reporting and an annual signed certification.

500.2–500.4 Govern

Program and governance

Program, policies, CISO, board oversight.

In QULDEX: Governance evidence
500.5–500.15 Protect

Technical controls

Testing, access, MFA, assets, encryption.

In QULDEX: Controls mapped to NIST CSF
500.11 Vendors

Third-party providers

Assess and manage vendors.

In QULDEX: Vendor register
500.16 Recover

IR and continuity

Plans tested yearly.

In QULDEX: Test results stored
500.17 Report

Notices and certification

72 h, 24 h, 15 April.

In QULDEX: Timers and certification pack
Section explorer

Which Part 500 sections matter most?

These 17 sections carry the obligations most covered entities work on. Select any section to see what it requires, typical evidence and the matching NIST CSF or ISO 27001 reference.

2017Part 500 in force
Nov 2023amended
Nov 2025fully phased in
15 Apryearly certification

Showing up to 6 per group. Search, filter, or open a group to see all 17.

Governance 4

  1. 500.2Cybersecurity program

    Maintain a risk-based cybersecurity program; Class A companies also need independent audits of it.

    In QULDEXQULDEX gives this section an owner, evidence requests and a review date, and maps it to NIST CSF and ISO 27001.

    Typical evidence
    Program documentation
    Maps to
    NIST CSF GV

  2. 500.3Cybersecurity policy

    Board-approved policies covering listed areas, reviewed at least yearly.

    In QULDEXQULDEX gives this section an owner, evidence requests and a review date, and maps it to NIST CSF and ISO 27001.

    Typical evidence
    Approved policies
    Maps to
    ISO 27001 A.5.1

  3. 500.4Cybersecurity governance

    A CISO who reports to the board at least yearly; senior governing body oversight with sufficient expertise.

    In QULDEXCISO reports and board minutes are evidence.

    Typical evidence
    CISO report, minutes
    Maps to
    NIST CSF GV.RR

  4. 500.9Risk assessment

    Review and update the risk assessment at least yearly and on material change.

    In QULDEXThe risk register is versioned yearly.

    Typical evidence
    Risk assessment
    Maps to
    ISO 27001 6.1

Technical controls 7

  1. 500.5Vulnerability management

    Annual penetration tests and automated vulnerability scans, with timely remediation.

    In QULDEXFindings become CAPA items with due dates.

    Typical evidence
    Pen test, scan reports
    Maps to
    ISO 27001 A.8.8

  2. 500.7Access privileges and management

    Limit privileged accounts, review access at least yearly, and control remote access.

    In QULDEXAccess reviews run as recurring tasks.

    Typical evidence
    Access reviews
    Maps to
    ISO 27001 A.5.15–A.5.18

  3. 500.12Multi-factor authenticationPhased in 2025

    MFA for any individual accessing any information system, from 1 November 2025, with limited CISO-approved exceptions.

    In QULDEXMFA coverage is tracked per system.

    Typical evidence
    MFA settings
    Maps to
    ISO 27001 A.8.5

  4. 500.13Asset management and data retentionPhased in 2025

    A complete, documented asset inventory with owner, location, classification, support end date and RTO, from 1 November 2025.

    In QULDEXThe asset inventory holds the required fields.

    Typical evidence
    Asset inventory
    Maps to
    ISO 27001 A.5.9

  5. 500.14Monitoring and training

    Monitor user activity, protect against malicious code, and train staff annually including on social engineering.

    In QULDEXQULDEX gives this section an owner, evidence requests and a review date, and maps it to NIST CSF and ISO 27001.

    Typical evidence
    Training records
    Maps to
    ISO 27001 A.6.3

  6. 500.15Encryption

    Encrypt nonpublic information in transit and at rest, or use CISO-approved compensating controls.

    In QULDEXQULDEX gives this section an owner, evidence requests and a review date, and maps it to NIST CSF and ISO 27001.

    Typical evidence
    Encryption evidence
    Maps to
    ISO 27001 A.8.24

  7. 500.11Third-party service provider security

    Policies to assess and manage third-party providers that hold or access nonpublic information.

    In QULDEXEach provider is assessed and linked to its services.

    Typical evidence
    Vendor assessments
    Maps to
    ISO 27001 A.5.19–A.5.22

Response and reporting 4

  1. 500.16Incident response and business continuity

    Written incident response, business continuity and disaster recovery plans, tested at least yearly, with backups protected.

    In QULDEXPlan tests and results are stored per year.

    Typical evidence
    IR and BCDR plans, test results
    Maps to
    ISO 22301

  2. 500.17(a)Notice of cybersecurity incident

    Notify NYDFS within 72 hours of determining that a reportable cybersecurity incident occurred.

    In QULDEXIncidents start a 72-hour timer.

    Typical evidence
    Incident notices
    Maps to
    NIS2 Art. 23

  3. 500.17(c)Notice of extortion payment

    Notify NYDFS within 24 hours of an extortion payment, and give a written justification within 30 days.

    In QULDEXExtortion payments start 24-hour and 30-day timers.

    Typical evidence
    Payment notice, justification

  4. 500.17(b)Annual certificationPhased in 2025

    Submit a certification of compliance, or an acknowledgment of noncompliance, by 15 April each year, signed by the CEO and CISO.

    In QULDEXThe certification is prepared from live evidence.

    Typical evidence
    Annual certification

Scope and enforcement 2

  1. 500.20Enforcement

    A single act or failure, or failing to comply for 24 hours, can be a violation; NYDFS considers listed factors when setting penalties.

    In QULDEXQULDEX gives this section an owner, evidence requests and a review date, and maps it to NIST CSF and ISO 27001.

  2. 500.1Class A companies

    Companies with at least $20 million in New York revenue and over 2,000 employees or $1 billion in revenue, with extra duties such as independent audits.

    In QULDEXQULDEX gives this section an owner, evidence requests and a review date, and maps it to NIST CSF and ISO 27001.

Section numbers follow 23 NYCRR Part 500 as amended on 1 November 2023. Summaries are QULDEX paraphrases, not legal advice.

Annual cycle

How do you comply with NYDFS 500 each year?

Keep the program and risk assessment current, prove the technical controls, test the plans, report incidents on time and certify by 15 April.

  1. Update the risk assessment

    At least yearly and on material change.

  2. Confirm MFA and asset inventory

    Universal MFA and a complete inventory with the required fields.

  3. Test and scan

    Annual penetration test and regular vulnerability scans.

  4. Test IR and BCDR plans

    At least yearly, with results recorded.

  5. CISO report to the board

    At least yearly.

  6. Certify by 15 April

    Every incidentNotify within 72 hours
    Any extortion paymentNotify within 24 hours
    15 AprilCertification or acknowledgment

Dates follow the amended regulation. Durations are QULDEX planning ranges.

Records to keep

Which documents does NYDFS 500 need?

NYDFS examiners ask for these records, and the certification rests on them.

DocumentSectionWhere it lives in QULDEX
Cybersecurity program and policies500.2–500.3Policy library
CISO annual report to the board500.4Policy library
Risk assessment500.9Risk register
Pen test and scan reports500.5CAPA automation
Access reviews500.7Evidence vault
MFA coverage evidence500.12Evidence vault
Asset inventory500.13Risk register
IR and BCDR plans and tests500.16Evidence vault
Incident and extortion notices500.17CAPA automation
Annual certification and supporting evidence500.17(b)Audit workspace

Section numbers follow 23 NYCRR Part 500 as amended.

Time and cost

How much effort does NYDFS 500 take?

Keeping compliant is an annual cycle. Universal MFA, the asset inventory and third-party management usually take the most work.

Where the time goes

Risk assessment3–6 wk
MFA and inventory1–3 mo
TestingYearly
Plans and testsYearly
Certification2–4 wk

Bars compare relative effort across an annual cycle.

What changes the effort

  • Class A status: adds independent audits
  • Legacy systems: MFA exceptions need CISO approval
  • Vendors: third-party assessments
  • Existing NIST CSF or ISO 27001: covers much of the program
  • Prior findings: examiners revisit them
Readiness check · 2 minutes

How ready are you for NYDFS 500?

Check these eight things first. Nothing you enter leaves this page.

500.4Does the CISO report to the board at least yearly?
500.9Is the risk assessment updated this year?
500.12Is MFA in place for every user on every information system?
500.13Does the asset inventory include owner, location, classification, support end and RTO?
500.5Have you done this year's penetration test?
500.16Were IR and BCDR plans tested this year?
500.17(a)Can you notify NYDFS within 72 hours?
500.17(b)Is evidence ready for the 15 April certification?
Crosswalk

How NYDFS 500 maps to NIST CSF, ISO 27001 and SOX ITGC

Part 500 lines up closely with NIST CSF and ISO 27001; access and change controls overlap with SOX ITGC testing at listed companies.

NYDFS crosswalk

NYDFS Part 500NIST CSF 2.0ISO 27001:2022SOX ITGCShared evidence
500.4 GovernanceGV.RR5.3—CISO report
500.7 AccessPR.AAA.5.15–A.5.18Access reviewsReview sign-offs
500.12 MFAPR.AA-03A.8.5AuthenticationMFA settings
500.13 AssetsID.AMA.5.9ScopingInventory
500.5 TestingID.RAA.8.8—Scan reports
500.16 IR and BCDRRS, RCA.5.24–A.5.30Backup and recoveryPlan tests
500.11 VendorsGV.SCA.5.19–A.5.22SOC 1Vendor register

Indicative mapping for planning.

Where QULDEX fits

How QULDEX runs NYDFS 500 from risk assessment to certification

QULDEX is NYDFS 500 compliance and audit management software built from EGV Group's audit delivery, used by covered entities, their advisors and auditors. Pick your role to see who does what.

For NYDFS-licensed banks, insurers and financial firms.

  1. RiskUpdate the risk assessmentVersioned risk register
  2. ControlsProve MFA and inventoryCoverage tracked per system
  3. TestRun testsPen test and scan findings into CAPA
  4. ReportNotify NYDFS72 h and 24 h timers
  5. BoardReport to the boardCISO report from live data
  6. CertifyCertify by 15 AprilCertification pack from evidence
Without one systemWith QULDEX
Certification signed on trustCertification backed by live evidence
Asset inventory missing required fieldsInventory with owner, location and RTO
MFA exceptions undocumentedCISO-approved exceptions on record
Deadlines tracked by hand72 h, 24 h and 15 April timers
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

NYDFS 500 questions people ask

Who must comply with NYDFS Part 500?

Entities operating under a licence, registration or charter under New York banking, insurance or financial services law, with limited exemptions for small entities.

What changed in the 2023 amendment?

The amendment added Class A companies, stronger governance and board oversight, extortion payment notices, universal MFA and asset inventory requirements, phased in through 1 November 2025.

When is the NYDFS annual certification due?

By 15 April each year, covering the previous calendar year. It is either a certification of compliance or an acknowledgment of noncompliance, signed by the CEO and CISO.

What must be reported to NYDFS and how fast?

Reportable cybersecurity incidents within 72 hours of determining they occurred, and any extortion payment within 24 hours, with a written justification within 30 days.

What is a Class A company under Part 500?

A covered entity with at least $20 million in gross annual New York revenue and either over 2,000 employees or over $1 billion in gross annual revenue, including affiliates.

Sources

References

  1. 23 NYCRR Part 500, as amended 1 Nov 2023. dfs.ny.gov
  2. NYDFS guidance on requirements effective 1 Nov 2025. dfs.ny.gov
  3. Hogan Lovells, final Part 500 requirements effective 1 Nov 2025. hoganlovells.com
  4. NIST CSF 2.0. nist.gov

Reviewed by

Manisha Dubey

Framework reviewer · QULDEX

Reviewed this page against 23 NYCRR Part 500 as amended in 2023.

Page history
  • : Page first built on the amended regulation: section explorer, annual cycle and readiness check

Certify on 15 April with evidence behind it

Answer a short readiness check and get a gap summary by section. No sales call needed to see the result.

Schedule
Book a Demo