Does the NYDFS Cybersecurity Rule Apply to Your Business?
If your business holds a license, registration, or charter under New York's Banking Law, Insurance Law, or Financial Services Law, you are almost certainly a "covered entity" under 23 NYCRR Part 500, New York's cybersecurity regulation. That covers a lot more than banks. Insurance agencies, mortgage brokers, check cashers, money transmitters, and title companies all fall under it. The rule has been fully phased in since November 2025, and the first annual certification covering the new requirements was due this past April.
A lot of businesses that technically qualify have no idea. They assume the rule is for Wall Street. It isn't.
Who Actually Has to Comply
The regulation, formally 23 NYCRR Part 500, applies to any individual or organization "operating under or required to operate under a license, registration, charter, certificate, permit, accreditation or similar authorization" under New York's Banking Law, Insurance Law, or Financial Services Law. That includes:
- Insurance agencies and brokers licensed in New York
- Mortgage brokers and loan originators
- Check cashers and money transmitters
- Title insurance companies
- Any state-chartered bank or credit union doing business in New York
It doesn't matter if your headquarters is in New Jersey. If you hold a New York license to sell insurance or originate mortgages, the rule reaches you. This is the part that catches growing businesses off guard. A 60-person insurance brokerage in Hoboken with a New York producer's license is a covered entity whether anyone there has read the regulation or not.
What Changed in the 2025 Amendments
New York's Department of Financial Services adopted a second round of amendments to Part 500 back in November 2023, and rolled them out in phases through November 2025. The last phase is the one most businesses are still catching up on. Two pieces matter most.
First, multifactor authentication is now required for anyone accessing any information system tied to the business, not just remote access or privileged accounts. That includes third-party contractors, on-premises staff, and even service accounts that used to be excluded. Single sign-on by itself doesn't satisfy the requirement unless the sign-on itself is MFA-protected.
Second, covered entities now need a written, maintained asset inventory covering every system in the environment, not just the ones that touch sensitive data. DFS was explicit about this in its rulemaking commentary: it rejected requests to limit the inventory to systems containing nonpublic information. The inventory has to track ownership, location, classification, support expiration, and recovery time objectives for each asset, and the policy has to say how often it gets reviewed.
Beyond those two, the amendments also added risk assessments at least annually (and after any material change to the business), automated vulnerability scanning, stricter access control reviews, and a 72-hour reporting window to DFS for covered cybersecurity events.
The Small Business Exemption, and Why Your Business Might Not Qualify
Part 500 does include a limited exemption under Section 500.19(a). A business qualifies if it has fewer than 20 employees and independent contractors across the entity and its affiliates, or less than $7.5 million in gross annual revenue from all operations in each of the last three years, or less than $15 million in year-end total assets.
Here's the catch for our audience specifically. A business with 25 to 250 employees is, almost by definition, past the headcount threshold. Even a firm well under the revenue and asset thresholds can lose the exemption on headcount alone. Growing past 20 people is a milestone most businesses celebrate. Under Part 500, it's also the point where the compliance clock starts running if you're a covered entity.
What a Real Compliance Program Requires
If you're a covered entity without a qualifying exemption, the program has to include a written cybersecurity policy approved annually, a risk assessment reviewed at least once a year, MFA across the board, an asset inventory with a documented review cadence, access control limits based on need to know, annual cybersecurity awareness training that covers social engineering, and an incident response plan.
Each year by April 15, a covered entity's CISO or senior cybersecurity officer has to certify compliance to DFS, or file a written acknowledgement of noncompliance that names every section the business is short on and lays out a remediation timeline. DFS has said plainly that false certifications carry personal liability for the person who signs them. This isn't a check-the-box form.
What Happens if You're Out of Compliance
DFS examinations in 2026 are focused on whether certifications hold up against actual documented practice, not just whether the paperwork got filed. Early filings from this year's April deadline showed a pattern: larger institutions mostly filed clean certifications, while a meaningful share of mid-sized firms filed acknowledgements of noncompliance, usually citing gaps in MFA coverage for contractors and service accounts, or an asset inventory that was more aspiration than reality.
None of this is a one-person job on top of running an insurance agency or a mortgage shop. Between the asset inventory, the MFA rollout across every access point, the annual risk assessment, and the documentation trail DFS expects behind all of it, this is the kind of ongoing program a managed IT partner builds and maintains, not something bolted on before an April deadline.
Frequently Asked Questions
Does my business have to comply with 23 NYCRR 500 if we're based outside New York?
Yes, if you hold a license, registration, or similar authorization under New York's Banking, Insurance, or Financial Services Law. Physical headquarters location doesn't matter. A New Jersey firm with a New York insurance producer's license is a covered entity.
What is the small business exemption threshold?
Section 500.19(a) exempts businesses with fewer than 20 employees and contractors, or under $7.5 million in gross annual revenue for each of the last three years, or under $15 million in year-end total assets. Meeting any one of the three preserves the exemption; most businesses in the 25-250 employee range will not qualify on headcount alone.
Is single sign-on enough to satisfy the MFA requirement?
No. Single sign-on only counts if the initial sign-on itself requires multifactor authentication. DFS has also recommended token-based MFA over push notifications or biometrics, citing MFA fatigue attacks and deepfake risk with the latter two.
What's the deadline for the annual compliance certification?
April 15 each year, covering the prior calendar year. Covered entities file either a certification of material compliance or a written acknowledgement of noncompliance with a remediation plan.
What happens if we file an acknowledgement of noncompliance?
You avoid a false certification, which carries its own liability risk, but you're on record with DFS with a remediation timeline. DFS examinations are expected to scrutinize whether that timeline was followed.
Figuring out whether your business is a covered entity under 23 NYCRR 500, and building the documentation to prove compliance, is easier with an IT partner who has done it before. Get in touch to talk through where your business stands.