NYDFS Cybersecurity Regulation (23 NYCRR Part 500)
New York Department of Financial Services Cybersecurity Requirements for Financial Services Companies. 23 NYCRR Part 500 requires DFS-regulated entities to establish and maintain a cybersecurity program, implement and maintain a cybersecurity policy, and designate a CISO. Second Amendment (November 2023) introduced Class A company requirements, enhanced governance, and expanded incident reporting.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
Application Security
| Code | Title |
|---|---|
| NYDFS-500.08 | Application Security |
Asset Management
| Code | Title |
|---|---|
| NYDFS-500.13 | Asset Management and Data Retention |
Attestation
| Code | Title |
|---|---|
| NYDFS-500.17(b) | Annual Certification or Acknowledgement of Compliance |
Class A Company Enhanced Requirements
Sections 500.2(c), 500.5, 500.14: Enhanced requirements for large covered entities (Second Amendment)
| Code | Title |
|---|---|
| NYDFS-500-CLA-1 | Class A Designation Criteria |
| NYDFS-500-CLA-2 | Independent Audit Requirement |
| NYDFS-500-CLA-3 | Endpoint Detection and Response |
| NYDFS-500-CLA-4 | Privileged Access Management |
Data Protection
| Code | Title |
|---|---|
| NYDFS-500.15 | Encryption of Nonpublic Information |
Enhanced Requirements
| Code | Title |
|---|---|
| NYDFS-500.23 | Class A Companies Additional Requirements |
Governance
| Code | Title |
|---|---|
| NYDFS-500.04 | Chief Information Security Officer |
Governance and Program Structure
Sections 500.1-500.4: Definitions, program, policy, and CISO requirements
| Code | Title |
|---|---|
| NYDFS-500.2a | Cybersecurity Program |
| NYDFS-500.2b | Program Core Functions |
| NYDFS-500.3 | Cybersecurity Policy |
| NYDFS-500.4a | Chief Information Security Officer |
| NYDFS-500.4b | CISO Reporting to Board |
| NYDFS-500.4c | Senior Governing Body Oversight |
Identity and Access Management
| Code | Title |
|---|---|
| NYDFS-500.07 | Access Privileges and Management |
| NYDFS-500.12 | Multi Factor Authentication |
Incident Response
| Code | Title |
|---|---|
| NYDFS-500.16 | Incident Response Plan |
Incident Response and Notification
Sections 500.16-500.17: Incident response plan and regulatory notification
| Code | Title |
|---|---|
| NYDFS-500.16 | Incident Response Plan |
| NYDFS-500.17a | Notification to Superintendent - Incidents |
| NYDFS-500.17b | Notification - Ransomware |
| NYDFS-500.17c | Annual Certification of Compliance |
Logging
| Code | Title |
|---|---|
| NYDFS-500.06 | Audit Trail |
Notification
| Code | Title |
|---|---|
| NYDFS-500.17 | Notice of Cybersecurity Event |
Policy
| Code | Title |
|---|---|
| NYDFS-500.03 | Cybersecurity Policy |
Programme Governance
| Code | Title |
|---|---|
| NYDFS-500.02 | Cybersecurity Programme |
Programme Management
| Code | Title |
|---|---|
| NYDFS-500.22 | Transitional Periods and Implementation |
Risk Assessment and Security Controls
Sections 500.5, 500.7, 500.9: Risk assessment, access privileges, and security testing
| Code | Title |
|---|---|
| NYDFS-500.5 | Penetration Testing and Vulnerability Assessments |
| NYDFS-500.7 | Access Privileges and Management |
| NYDFS-500.9a | Risk Assessment Requirement |
| NYDFS-500.9b | Risk Assessment Content |
Risk Management
| Code | Title |
|---|---|
| NYDFS-500.09 | Risk Assessment |
Scope and Exemptions
| Code | Title |
|---|---|
| NYDFS-500.19 | Exemptions |
Technical Safeguards
Sections 500.10-500.15: Encryption, monitoring, MFA, and data handling
| Code | Title |
|---|---|
| 314.4(c)(1) | Access controls |
| 314.4(c)(3) | Encryption requirements |
| 314.4(c)(5) | Multi-factor authentication |
| 314.4(c)(8) | Monitoring and logging |
| HIPAA-164.312(a)(1) | Access control |
| HIPAA-164.312(b) | Audit controls |
| HIPAA-164.312(c)(1) | Integrity |
| HIPAA-164.312(d) | Person or entity authentication |
| HIPAA-164.312(e)(1) | Transmission security |
| NYDFS-500.10 | Cybersecurity Personnel and Intelligence |
| NYDFS-500.11 | Third Party Service Provider Security Policy |
| NYDFS-500.12 | Multi Factor Authentication |
| NYDFS-500.13 | Asset Management and Data Retention |
| NYDFS-500.14 | Training and Monitoring |
| NYDFS-500.15 | Encryption of Nonpublic Information |
Training and Awareness
Sections 500.10, 500.14: Training requirements for personnel
| Code | Title |
|---|---|
| NYDFS-500.10b | Cybersecurity Personnel Training |
| NYDFS-500.14c | Cybersecurity Awareness Training |
Vendor Risk
| Code | Title |
|---|---|
| NYDFS-500.11 | Third Party Service Provider Security Policy |
Vulnerability Management
| Code | Title |
|---|---|
| NYDFS-500.05 | Vulnerability Management |
Workforce
| Code | Title |
|---|---|
| NYDFS-500.10 | Cybersecurity Personnel and Intelligence |
| NYDFS-500.14 | Training and Monitoring |
Your Compliance Coverage
If you comply with NYDFS Cybersecurity Regulation (23 NYCRR Part 500), you already cover:
CSA CCM v4
46%
22 controls mapped
Compare →TISAX — Trusted Information Security Assessment Exchange
46%
22 controls mapped
Compare →NIST SP 800-82 Rev 3 — Guide to OT Security
44%
21 controls mapped
Compare →+ 610 more: NAIC Insurance Data Security Model Law (MDL-668) (44%), ISO 27001:2022 (42%)
See all 613 mapped frameworks ↓Maps to 613 other frameworks
Frequently Asked Questions
What is NYDFS Cybersecurity Regulation (23 NYCRR Part 500)?
NYDFS Cybersecurity Regulation (23 NYCRR Part 500) is a compliance framework from United States with 24 domains and 55 controls. New York Department of Financial Services Cybersecurity Requirements for Financial Services Companies. 23 NYCRR Part 500 requires DFS-regulated entities to establish and maintain a cybersecurity program, implement and maintain a cybersecurity policy, and designate a CISO. Second Amendment (November 2023) introduced Class A company requirements, enhanced governance, and expanded incident reporting. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NYDFS Cybersecurity Regulation (23 NYCRR Part 500) have?
NYDFS Cybersecurity Regulation (23 NYCRR Part 500) has 55 controls organised across 24 domains. The largest domains are Technical Safeguards (15 controls), Governance and Program Structure (6 controls), Class A Company Enhanced Requirements (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NYDFS Cybersecurity Regulation (23 NYCRR Part 500) map to?
NYDFS Cybersecurity Regulation (23 NYCRR Part 500) maps to 613 other compliance frameworks. The top mapping partners are CSA CCM v4 (46% coverage), TISAX — Trusted Information Security Assessment Exchange (46% coverage), NIST SP 800-82 Rev 3 — Guide to OT Security (44% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NYDFS Cybersecurity Regulation (23 NYCRR Part 500) compliance?
Start your NYDFS Cybersecurity Regulation (23 NYCRR Part 500) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NYDFS Cybersecurity Regulation (23 NYCRR Part 500) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 55 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required