Regulation · Financial services · New York
NYDFS 500 compliance means meeting 23 NYCRR Part 500, the New York Department of Financial Services cybersecurity regulation for banks, insurers and other licensed entities. The 2023 amendment phased in through 1 November 2025, adding universal MFA and asset inventories, and every covered entity certifies compliance by 15 April each year.
Entities licensed or chartered under New York banking, insurance or financial services law.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
NYDFS Part 500 requires a risk-based cybersecurity program with a CISO and board oversight, technical controls including universal MFA and an asset inventory, tested incident and continuity plans, fast incident reporting and an annual signed certification.
Program, policies, CISO, board oversight.
In QULDEX: Governance evidenceTesting, access, MFA, assets, encryption.
In QULDEX: Controls mapped to NIST CSFAssess and manage vendors.
In QULDEX: Vendor registerPlans tested yearly.
In QULDEX: Test results stored72 h, 24 h, 15 April.
In QULDEX: Timers and certification packThese 17 sections carry the obligations most covered entities work on. Select any section to see what it requires, typical evidence and the matching NIST CSF or ISO 27001 reference.
Showing up to 6 per group. Search, filter, or open a group to see all 17.
500.2Cybersecurity programMaintain a risk-based cybersecurity program; Class A companies also need independent audits of it.
In QULDEXQULDEX gives this section an owner, evidence requests and a review date, and maps it to NIST CSF and ISO 27001.
500.3Cybersecurity policyBoard-approved policies covering listed areas, reviewed at least yearly.
In QULDEXQULDEX gives this section an owner, evidence requests and a review date, and maps it to NIST CSF and ISO 27001.
500.4Cybersecurity governanceA CISO who reports to the board at least yearly; senior governing body oversight with sufficient expertise.
In QULDEXCISO reports and board minutes are evidence.
500.9Risk assessmentReview and update the risk assessment at least yearly and on material change.
In QULDEXThe risk register is versioned yearly.
500.5Vulnerability managementAnnual penetration tests and automated vulnerability scans, with timely remediation.
In QULDEXFindings become CAPA items with due dates.
500.7Access privileges and managementLimit privileged accounts, review access at least yearly, and control remote access.
In QULDEXAccess reviews run as recurring tasks.
500.12Multi-factor authenticationPhased in 2025MFA for any individual accessing any information system, from 1 November 2025, with limited CISO-approved exceptions.
In QULDEXMFA coverage is tracked per system.
500.13Asset management and data retentionPhased in 2025A complete, documented asset inventory with owner, location, classification, support end date and RTO, from 1 November 2025.
In QULDEXThe asset inventory holds the required fields.
500.14Monitoring and trainingMonitor user activity, protect against malicious code, and train staff annually including on social engineering.
In QULDEXQULDEX gives this section an owner, evidence requests and a review date, and maps it to NIST CSF and ISO 27001.
500.15EncryptionEncrypt nonpublic information in transit and at rest, or use CISO-approved compensating controls.
In QULDEXQULDEX gives this section an owner, evidence requests and a review date, and maps it to NIST CSF and ISO 27001.
500.11Third-party service provider securityPolicies to assess and manage third-party providers that hold or access nonpublic information.
In QULDEXEach provider is assessed and linked to its services.
500.16Incident response and business continuityWritten incident response, business continuity and disaster recovery plans, tested at least yearly, with backups protected.
In QULDEXPlan tests and results are stored per year.
500.17(a)Notice of cybersecurity incidentNotify NYDFS within 72 hours of determining that a reportable cybersecurity incident occurred.
In QULDEXIncidents start a 72-hour timer.
500.17(c)Notice of extortion paymentNotify NYDFS within 24 hours of an extortion payment, and give a written justification within 30 days.
In QULDEXExtortion payments start 24-hour and 30-day timers.
500.17(b)Annual certificationPhased in 2025Submit a certification of compliance, or an acknowledgment of noncompliance, by 15 April each year, signed by the CEO and CISO.
In QULDEXThe certification is prepared from live evidence.
500.20EnforcementA single act or failure, or failing to comply for 24 hours, can be a violation; NYDFS considers listed factors when setting penalties.
In QULDEXQULDEX gives this section an owner, evidence requests and a review date, and maps it to NIST CSF and ISO 27001.
500.1Class A companiesCompanies with at least $20 million in New York revenue and over 2,000 employees or $1 billion in revenue, with extra duties such as independent audits.
In QULDEXQULDEX gives this section an owner, evidence requests and a review date, and maps it to NIST CSF and ISO 27001.
Nothing matches that search.
Section numbers follow 23 NYCRR Part 500 as amended on 1 November 2023. Summaries are QULDEX paraphrases, not legal advice.
Keep the program and risk assessment current, prove the technical controls, test the plans, report incidents on time and certify by 15 April.
At least yearly and on material change.
Universal MFA and a complete inventory with the required fields.
Annual penetration test and regular vulnerability scans.
At least yearly, with results recorded.
At least yearly.
Dates follow the amended regulation. Durations are QULDEX planning ranges.
NYDFS examiners ask for these records, and the certification rests on them.
| Document | Section | Where it lives in QULDEX |
|---|---|---|
| Cybersecurity program and policies | 500.2–500.3 | Policy library |
| CISO annual report to the board | 500.4 | Policy library |
| Risk assessment | 500.9 | Risk register |
| Pen test and scan reports | 500.5 | CAPA automation |
| Access reviews | 500.7 | Evidence vault |
| MFA coverage evidence | 500.12 | Evidence vault |
| Asset inventory | 500.13 | Risk register |
| IR and BCDR plans and tests | 500.16 | Evidence vault |
| Incident and extortion notices | 500.17 | CAPA automation |
| Annual certification and supporting evidence | 500.17(b) | Audit workspace |
Section numbers follow 23 NYCRR Part 500 as amended.
Keeping compliant is an annual cycle. Universal MFA, the asset inventory and third-party management usually take the most work.
Bars compare relative effort across an annual cycle.
Check these eight things first. Nothing you enter leaves this page.
Part 500 lines up closely with NIST CSF and ISO 27001; access and change controls overlap with SOX ITGC testing at listed companies.
| NYDFS Part 500 | NIST CSF 2.0 | ISO 27001:2022 | SOX ITGC | Shared evidence |
|---|---|---|---|---|
| 500.4 Governance | GV.RR | 5.3 | — | CISO report |
| 500.7 Access | PR.AA | A.5.15–A.5.18 | Access reviews | Review sign-offs |
| 500.12 MFA | PR.AA-03 | A.8.5 | Authentication | MFA settings |
| 500.13 Assets | ID.AM | A.5.9 | Scoping | Inventory |
| 500.5 Testing | ID.RA | A.8.8 | — | Scan reports |
| 500.16 IR and BCDR | RS, RC | A.5.24–A.5.30 | Backup and recovery | Plan tests |
| 500.11 Vendors | GV.SC | A.5.19–A.5.22 | SOC 1 | Vendor register |
Indicative mapping for planning.
QULDEX is NYDFS 500 compliance and audit management software built from EGV Group's audit delivery, used by covered entities, their advisors and auditors. Pick your role to see who does what.
For NYDFS-licensed banks, insurers and financial firms.
For NYDFS consultants and internal audit.
For independent auditors, including Class A audits.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →Entities operating under a licence, registration or charter under New York banking, insurance or financial services law, with limited exemptions for small entities.
The amendment added Class A companies, stronger governance and board oversight, extortion payment notices, universal MFA and asset inventory requirements, phased in through 1 November 2025.
By 15 April each year, covering the previous calendar year. It is either a certification of compliance or an acknowledgment of noncompliance, signed by the CEO and CISO.
Reportable cybersecurity incidents within 72 hours of determining they occurred, and any extortion payment within 24 hours, with a written justification within 30 days.
A covered entity with at least $20 million in gross annual New York revenue and either over 2,000 employees or over $1 billion in gross annual revenue, including affiliates.
A file-naming scheme examiners can follow.
blog.quldex.comHow many samples auditors look at.
blog.quldex.comThe governance outcomes Part 500 now expects.
blog.quldex.comNIST CSF, 800-53 and CIS Controls articles.
Reviewed by
Answer a short readiness check and get a gap summary by section. No sales call needed to see the result.