NYDFS Part 500, formally 23 NYCRR 500, is the New York Department of Financial Services cybersecurity regulation. Unlike most US cybersecurity guidance it is an enforceable rule rather than examination guidance, it applies to any entity licensed by NYDFS, and it requires an annual compliance certification signed by senior leadership.
Every transitional deadline has now passed
The Second Amendment took effect on 1 November 2023 with phased implementation, and a great deal of published commentary still describes parts of it as upcoming. As of September 2026 that is wrong. The final transitional period expired on 1 November 2025, carrying multi-factor authentication under section 500.12 and the asset inventory requirement under section 500.13(a). Part 500 as amended is in force in all respects, and no third amendment has been adopted.
A related trap: sections 500.22(a) and (b) set the original 2017 transitional periods and are long expired. Only 500.22(c) and (d) govern Second Amendment timing. Any analysis citing 500.22(b) for these dates is reading the wrong subsection.
What the Second Amendment added
Governance moved upward. Section 500.4 puts oversight with the "senior governing body," which must understand cybersecurity well enough to exercise it, require management to implement the program, receive regular reporting and confirm adequate resourcing. The CISO reports annually in writing on program effectiveness, material risks and remediation, and must report material issues on a timely basis rather than waiting for the cycle.
Multi-factor authentication became near-universal: MFA for any individual accessing any information system. The asset inventory must be complete, documented and track owner, location, classification, support expiration and recovery time objectives. Incident notification runs to 72 hours; an extortion payment triggers notice within 24 hours and a written explanation of why it was necessary within 30 days. The annual compliance certification is due 15 April. A new Class A tier faces independent program audit plus endpoint detection and centralized logging.
How NYDFS treats AI
NYDFS has issued two AI letters, and the consistent pattern in both is worth understanding before anyone claims Part 500 has AI requirements.
The first, 16 October 2024, addressed cybersecurity risks arising from artificial intelligence — AI-enabled social engineering and deepfakes, AI-enhanced attacks, exposure of large volumes of nonpublic information including biometrics, and supply-chain vulnerabilities. The second, 21 May 2026, addressed heightened risks associated with frontier AI models, recommending refreshed risk assessments, expedited vulnerability management, third-party dependency mapping and human oversight of AI-generated code.
Both state explicitly that they impose no new requirements. NYDFS frames AI as something the existing Part 500 framework must be applied to, not as a new regime. In practice that means the obligations that bite are the ones already there: the asset inventory has to include AI systems, MFA has to cover access to them, the 72-hour clock runs on an AI-related incident, and the CISO's report has to address them. Which makes runtime governance an inventory and evidence problem as much as a security one — see examination readiness, tamper-evident audit logs and the financial services page.
Related terms
GLBA · FFIEC · FINRA Rule 3110 · Tamper-evident audit log · Full glossary
Verified against the adopted amendment text and NYDFS industry letters in September 2026. Regulations change. If something here is out of date, tell us and we will correct it.
Put this in the path of your own agents.
Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.
Request a Demo Read the docs