NYDFS Part 500

23 NYCRR Part 500 — Cybersecurity Requirements for Financial Services Companies · New York State Department of Financial Services (DFS) · Official site

New York State regulation binding DFS-licensed banks, insurers, and other financial services companies to a documented cybersecurity program — risk assessment, access controls, a designated CISO reporting to the board, and notification to the Department after a cybersecurity event. Promulgated in March 2017 as the first such state regulation in the US; the Second Amendment phases further obligations in on staged transition dates.

Timeline

No changes recorded yet — we are watching, and nothing has been published.

Monitoring

Watched by 1 official source. Watching since 10 September 2026. Last checked 1 hour, 42 minutes ago.