NYDFS Cybersecurity Regulation
NYDFS Cybersecurity Regulation is a state rule (NY) published as 23 NYCRR Part 500. Adopted 2017-03-01, applies from 2023-11-01. In force with later dates still to come: In force since 2017. The second amendment took effect on 1 November 2023, with transitional dates running to November 2025.
- NYDFS Cybersecurity Regulation covers cybersecurity program and policy, chief information security officer, multi-factor authentication and notice of a cybersecurity event.
- NYDFS Cybersecurity Regulation does not settle whether a single company meets it. That is read in the company's own text and its filings.
- Supervised by New York State Department of Financial Services. The text is published by New York State Department of Financial Services.
- The text names financial services and insurance.
- nis2-2022-2555: Both texts name a responsible function, require reporting to the governing body and set an early notice for significant incidents. The EU text covers essential entities, the state rule covers licensed financial firms.
- US regulatory register
- Financial services
- Insurance
- New York State Department of Financial Services
- NIS2 — Directive (EU) 2022/2555
Identity
| Identifier | 23 NYCRR Part 500 |
|---|---|
| Adopted | 2017-03-01 |
| Applies from | 2023-11-01 |
| Status | In force since 2017. The second amendment took effect on 1 November 2023, with transitional dates running to November 2025. |
| Supervision | New York State Department of Financial Services |
| Sectors named | Financial services, Insurance |
| Risk areas | Information security, Recordkeeping |
Requirements in the text
- Cybersecurity program and policy, Reference: 23 NYCRR 500.2 and 500.3. A documented programme and a policy approved by the board or a senior officer.
- Chief Information Security Officer, Reference: 23 NYCRR 500.4. A named officer and an annual written report to the governing body.
- Multi-factor authentication, Reference: 23 NYCRR 500.12. Multi-factor authentication for remote and privileged access.
- Notice of a cybersecurity event, Reference: 23 NYCRR 500.17. Notice to the supervisor within 72 hours, and an annual certification.
Official sources
- 23 NYCRR Part 500, Cybersecurity Requirements for Financial Services Companies, New York State Department of Financial Services
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.