NYDFS Cybersecurity Regulation (23 NYCRR Part 500)
New York Department of Financial Services Cybersecurity Requirements for Financial Services Companies. 23 NYCRR Part 500 requires DFS-regulated entities to establish and maintain a cybersecurity program, implement and maintain a cybersecurity policy, and designate a CISO. Second Amendment (November 2023) introduced Class A company requirements, enhanced governance, and expanded incident reporting.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Class A Company Enhanced Requirements
Sections 500.2(c), 500.5, 500.14: Enhanced requirements for large covered entities (Second Amendment)
| Code | Title |
|---|---|
| NYDFS-500-CLA-1 | Class A Designation Criteria |
| NYDFS-500-CLA-2 | Independent Audit Requirement |
| NYDFS-500-CLA-3 | Endpoint Detection and Response |
| NYDFS-500-CLA-4 | Privileged Access Management |
Governance and Program Structure
Sections 500.1-500.4: Definitions, program, policy, and CISO requirements
| Code | Title |
|---|---|
| NYDFS-500.2a | Cybersecurity Program |
| NYDFS-500.2b | Program Core Functions |
| NYDFS-500.3 | Cybersecurity Policy |
| NYDFS-500.4a | Chief Information Security Officer |
| NYDFS-500.4b | CISO Reporting to Board |
| NYDFS-500.4c | Senior Governing Body Oversight |
Incident Response and Notification
Sections 500.16-500.17: Incident response plan and regulatory notification
| Code | Title |
|---|---|
| NYDFS-500.16 | Incident Response and Business Continuity |
| NYDFS-500.17a | Notification to Superintendent - Incidents |
| NYDFS-500.17b | Notification - Ransomware |
| NYDFS-500.17c | Annual Certification of Compliance |
Risk Assessment and Security Controls
Sections 500.5, 500.7, 500.9: Risk assessment, access privileges, and security testing
| Code | Title |
|---|---|
| NYDFS-500.5 | Penetration Testing and Vulnerability Assessments |
| NYDFS-500.7 | Access Privileges and Management |
| NYDFS-500.9a | Risk Assessment Requirement |
| NYDFS-500.9b | Risk Assessment Content |
Technical Safeguards
Sections 500.10-500.15: Encryption, monitoring, MFA, and data handling
| Code | Title |
|---|---|
| 314.4(c)(1) | Access controls |
| 314.4(c)(3) | Encryption requirements |
| 314.4(c)(5) | Multi-factor authentication |
| 314.4(c)(8) | Monitoring and logging |
| HIPAA-164.312(a)(1) | Access control |
| HIPAA-164.312(b) | Audit controls |
| HIPAA-164.312(c)(1) | Integrity |
| HIPAA-164.312(d) | Person or entity authentication |
| HIPAA-164.312(e)(1) | Transmission security |
| NYDFS-500.10 | Cybersecurity Personnel and Intelligence |
| NYDFS-500.11 | Third-Party Service Provider Security Policy |
| NYDFS-500.12 | Multi-Factor Authentication |
| NYDFS-500.13 | Asset Management and Data Governance |
| NYDFS-500.14 | Monitoring and Logging |
| NYDFS-500.15 | Encryption of Nonpublic Information |
Training and Awareness
Sections 500.10, 500.14: Training requirements for personnel
| Code | Title |
|---|---|
| NYDFS-500.10b | Cybersecurity Personnel Training |
| NYDFS-500.14c | Cybersecurity Awareness Training |
Maps to 595 other frameworks
Frequently Asked Questions
What is NYDFS Cybersecurity Regulation (23 NYCRR Part 500)?
NYDFS Cybersecurity Regulation (23 NYCRR Part 500) is a compliance framework from United States with 6 domains and 35 controls. New York Department of Financial Services Cybersecurity Requirements for Financial Services Companies. 23 NYCRR Part 500 requires DFS-regulated entities to establish and maintain a cybersecurity program, implement and maintain a cybersecurity policy, and designate a CISO. Second Amendment (November 2023) introduced Class A company requirements, enhanced governance, and expanded incident reporting. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NYDFS Cybersecurity Regulation (23 NYCRR Part 500) have?
NYDFS Cybersecurity Regulation (23 NYCRR Part 500) has 35 controls organised across 6 domains. The largest domains are Technical Safeguards (15 controls), Governance and Program Structure (6 controls), Class A Company Enhanced Requirements (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NYDFS Cybersecurity Regulation (23 NYCRR Part 500) map to?
NYDFS Cybersecurity Regulation (23 NYCRR Part 500) maps to 595 other compliance frameworks. The top mapping partners are CSA CCM v4 (63% coverage), TISAX — Trusted Information Security Assessment Exchange (63% coverage), NAIC Insurance Data Security Model Law (MDL-668) (60% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NYDFS Cybersecurity Regulation (23 NYCRR Part 500) compliance?
Start your NYDFS Cybersecurity Regulation (23 NYCRR Part 500) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NYDFS Cybersecurity Regulation (23 NYCRR Part 500) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required