NAIC Insurance Data Security Model Law (MDL-668)
The National Association of Insurance Commissioners (NAIC) Insurance Data Security Model Law (Model 668) establishes data security standards for the insurance industry. Adopted by NAIC in 2017, it has been enacted by over 20 US states. It requires insurers and other licensed entities to develop comprehensive information security programs, conduct risk assessments, and notify regulators of cybersecurity events.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
Access Management
| Code | Title |
|---|---|
| MDL668.06 | Access Controls and Identity Management |
Affiliate Coordination
| Code | Title |
|---|---|
| MDL668.18 | Coordination with Producer and Affiliate Programs |
Application Security
| Code | Title |
|---|---|
| MDL668.08 | Secure Development and Change Management |
Board Oversight
| Code | Title |
|---|---|
| MDL668.04 | Board Oversight and Reporting |
Consumer Notification
| Code | Title |
|---|---|
| MDL668.13 | Consumer Notification of Breach |
Cryptographic Protection
| Code | Title |
|---|---|
| MDL668.07 | Encryption of Nonpublic Information |
Definitions and Scope
Sections 5-10: Key definitions and covered entities
| Code | Title |
|---|---|
| 7012(a) | Definitions |
| 7012(b)(1) | Covered Defence Information Identification |
| 7012(b)(2) | Scope of Protected Systems |
| 7012(b)(3) | COTS Exclusion |
| BIPA-SEC5-1 | Biometric Identifier Definition |
| BIPA-SEC5-2 | Biometric Information Definition |
| BIPA-SEC5-3 | Private Entity Definition |
| CTDPA-1 | Definitions |
| CTDPA-2 | Applicability Thresholds |
| MSA-5 | Definition of Modern Slavery |
| MSA-Commonwealth | Commonwealth Entities |
| MSA-Threshold | Revenue Threshold |
| NAIC-668-1 | Title and Purpose |
| NAIC-668-3 | Definitions |
| NAIC-668-9 | Exemptions |
Enforcement and Administration
Sections 7-8, 10: Commissioner powers, confidentiality, and penalties
| Code | Title |
|---|---|
| NAIC-668-10 | Penalties |
| NAIC-668-7 | Power of Commissioner |
| NAIC-668-8 | Confidentiality |
Governance and Accountability
| Code | Title |
|---|---|
| MDL668.03 | Designated Responsible Person |
Governance and Oversight
KISO governance and statutory framework
| Code | Title |
|---|---|
| Art. 17 | Quality Management System |
| Art. 18 | Documentation Keeping |
| Art. 19 | Automatically Generated Logs |
| Art. 20 | Corrective Actions and Duty of Information |
| DMF-1.1 | Data Governance Structure |
| DMF-1.2 | Roles and Responsibilities |
| DMF-1.3 | Executive Sponsorship |
Incident Response
| Code | Title |
|---|---|
| MDL668.11 | Cybersecurity Event Investigation |
Information Security Program
Security program requirements for licensees
| Code | Title |
|---|---|
| NAIC-668-4A | ISP Implementation |
| NAIC-668-4B | ISP Objectives |
| NAIC-668-4C | Risk Assessment |
| NAIC-668-4D1 | Access Controls |
| NAIC-668-4D2 | Physical Access Restrictions |
| NAIC-668-4D3 | Encryption |
| NAIC-668-4D4 | Secure Development |
| NAIC-668-4D5 | Audit Trails |
| NAIC-668-4D6 | Multi-Factor Authentication |
| NAIC-668-4D7 | Secure Disposal |
| NAIC-668-4D8 | Incident Detection and Response |
| NAIC-668-4D9 | Testing and Monitoring |
| NAIC-ISP-01 | Written Information Security Program |
| NAIC-ISP-02 | Risk Assessment |
| NAIC-ISP-03 | Security Measures |
| NAIC-ISP-04 | Board Oversight |
Investigation and Notification
Sections 5-6: Incident investigation and regulatory/consumer notification
| Code | Title |
|---|---|
| NAIC-668-5A | Investigation Requirement |
| NAIC-668-5B | Investigation Scope |
| NAIC-668-6A | Notification to Commissioner |
| NAIC-668-6B | Notification Content |
| NAIC-668-6C | Consumer Notification |
Monitoring
| Code | Title |
|---|---|
| MDL668.09 | Audit Trail and Monitoring |
People and Training
| Code | Title |
|---|---|
| MDL668.10 | Personnel Training and Awareness |
Program Governance
| Code | Title |
|---|---|
| MDL668.01 | Written Information Security Program |
Records Management
| Code | Title |
|---|---|
| MDL668.16 | Data Retention and Disposal |
Regulatory Attestation
| Code | Title |
|---|---|
| MDL668.14 | Annual Certification of Compliance |
Regulatory Notification
| Code | Title |
|---|---|
| MDL668.12 | Notification to the Commissioner |
Resilience
| Code | Title |
|---|---|
| MDL668.15 | Incident Response Plan Testing |
Risk Assessment
| Code | Title |
|---|---|
| MDL668.02 | Risk Assessment Process |
Third Party Risk
| Code | Title |
|---|---|
| MDL668.05 | Third Party Service Provider Oversight |
| MDL668.17 | Service Provider Notification Clauses |
Third-Party and Incident Management
Third-party oversight and cybersecurity event notification
| Code | Title |
|---|---|
| NAIC-TPM-01 | Third-Party Service Provider Oversight |
| NAIC-TPM-02 | Cybersecurity Event Investigation |
| NAIC-TPM-03 | Commissioner Notification |
Your Compliance Coverage
If you comply with NAIC Insurance Data Security Model Law (MDL-668), you already cover:
ISO 27001:2022
45%
30 controls mapped
Compare →CSA STAR (Security, Trust, Assurance, and Risk)
28%
19 controls mapped
Compare →FedRAMP Rev 5
28%
19 controls mapped
Compare →+ 660 more: TISAX — Trusted Information Security Assessment Exchange (28%), South Korea ISMS-P (27%)
See all 663 mapped frameworks ↓Maps to 663 other frameworks
Frequently Asked Questions
What is NAIC Insurance Data Security Model Law (MDL-668)?
NAIC Insurance Data Security Model Law (MDL-668) is a compliance framework from United States (NAIC) with 23 domains and 67 controls. The National Association of Insurance Commissioners (NAIC) Insurance Data Security Model Law (Model 668) establishes data security standards for the insurance industry. Adopted by NAIC in 2017, it has been enacted by over 20 US states. It requires insurers and other licensed entities to develop comprehensive information security programs, conduct risk assessments, and notify regulators of cybersecurity events. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NAIC Insurance Data Security Model Law (MDL-668) have?
NAIC Insurance Data Security Model Law (MDL-668) has 67 controls organised across 23 domains. The largest domains are Information Security Program (16 controls), Definitions and Scope (15 controls), Governance and Oversight (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NAIC Insurance Data Security Model Law (MDL-668) map to?
NAIC Insurance Data Security Model Law (MDL-668) maps to 663 other compliance frameworks. The top mapping partners are ISO 27001:2022 (45% coverage), CSA STAR (Security, Trust, Assurance, and Risk) (28% coverage), FedRAMP Rev 5 (28% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NAIC Insurance Data Security Model Law (MDL-668) compliance?
Start your NAIC Insurance Data Security Model Law (MDL-668) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NAIC Insurance Data Security Model Law (MDL-668) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 67 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required