2 NAMES
Personal liability, signed
The annual Certification of Material Compliance is signed by both a senior officer and the CISO. It's a personal attestation to a regulator that pursues enforcement.
NYDFS Part 500 is the most prescriptive, aggressively enforced state cyber regulation in the country — and its annual certification is signed by both a senior officer and the CISO, personally. As of November 2025 the phase-in is over and every requirement is live. We build the program the signature can stand on.
Book a NYDFS 500 Strategy Call →// WHY PART 500, WHY NOW
2 NAMES
The annual Certification of Material Compliance is signed by both a senior officer and the CISO. It's a personal attestation to a regulator that pursues enforcement.
72 HRS
Report a covered cybersecurity incident within 72 hours of determining it occurred — plus a separate 24-hour notice for any extortion payment.
FULLY LIVE
The Second Amendment's multi-year rollout ended November 1, 2025. MFA, asset inventory, the lot — you're either compliant right now or you're not.
// "GOOD ENOUGH" ISN'T CERTIFIABLE
Part 500 doesn't ask whether your security feels solid — it asks two named people to personally certify material compliance with a long list of specific controls, and to retain the evidence for five years. Signing a certification that outruns reality is a personal attestation to a regulator known for enforcement. If you can't certify fully, the safer path is an Acknowledgment of Noncompliance with a remediation plan — not an inaccurate signature. Either way, the work that makes the certification defensible happens all year, not the week before April 15.
// THE PROGRAM, AND WHAT IT CERTIFIES TO
Part 500 spans a wide control set, but it all converges on one instrument. The dual-signature annual certification is where a senior officer and the CISO personally vouch that the program below is real.
Where it all comes due: the Certification of Material Compliance, signed by both a senior officer and the CISO, filed by April 15 for the prior calendar year, with supporting evidence retained five years. It's a personal attestation — or, if you can't certify fully, an Acknowledgment of Noncompliance with a remediation plan. The three program areas below are what the signature vouches for.
// CISO + GOVERNANCE
Program & Oversight
A named CISO, board-approved policy, written risk assessment, and an annual report to the senior governing body.
// TECHNICAL CONTROLS
Safeguards
MFA, encryption of NPI, asset inventory, access limits, vulnerability scans, pen testing, and logging.
// INCIDENT + VENDOR
Response & Third Parties
Incident response, the 72-hour and 24-hour notices, business continuity, and third-party risk management.
Class A Companies add independent audit, EDR, centralized logging, and password-blocking.
// THE PATH
From applicability to a defensible annual filing — then around again. The amber stages are the NYDFS-facing moments: the 72-hour incident notice and the dual-signature annual certification.
Scope
Applicability & Class A
WK 1–3
Govern
CISO & Risk Assessment
MO 1–2
Implement
Controls & Vendors
MO 2–6
Notify
72-Hour Readiness
IF TRIGGERED
Certify
Dual-Signature Filing
APRIL 15
Sustain
Evidence & Renewal
5-YR RETENTION
Amber stages are the NYDFS-facing moments — the 72-hour incident notice to the Superintendent, and the dual-signature Certification of Material Compliance filed by April 15. Between and around them, the program runs continuously, with five years of evidence retained.
// IS THIS YOU?
// 01 // NY LICENSED
Bank, insurer, broker, money transmitter, mortgage lender — if you operate under an NYDFS license, you're a Covered Entity unless a narrow exemption applies.
// 02 // CERT COMING DUE
The dual-signature certification is due and you can't yet say, with evidence, that you're in full material compliance. Signing blind is the real risk.
// 03 // MAYBE CLASS A
You're near the revenue and headcount thresholds but haven't confirmed status — and the heightened controls take real time to stand up before they certify.
// WHAT WE DO
// Phase 01 · Establish
We confirm applicability and Class A status, stand up or supplement the CISO function, and build the board-approved policy and written risk assessment the regulation is built around.
// Phase 02 · Implement
We implement and document the technical safeguards — MFA, encryption, asset inventory, access controls, testing — and build the third-party risk program the regulation now requires.
// Phase 03 · Certify
We build the 72-hour and 24-hour notification workflows into incident response, then assemble the evidence so the dual-signature certification is one your officers can sign with confidence.
// TWO NAMES ON THE LINE
// FREQUENTLY ASKED
Very likely, if you hold any New York financial license. Part 500 applies to Covered Entities — any organization operating under, or required to operate under, a license, registration, charter, permit, or similar authorization under New York's Banking Law, Insurance Law, or Financial Services Law. That sweeps in far more than banks: insurers, agents and brokers, money transmitters, mortgage lenders, trust companies, and credit unions.
If you're licensed by NYDFS, assume Part 500 applies unless you qualify for a narrow exemption — and even most exemptions still require core controls and a filed notice of exemption. Limited small-business exemptions exist based on size, revenue, and data thresholds, but they reduce rather than eliminate obligations. Because enforcement is aggressive and the certification carries personal liability, the safest first step is a clear applicability analysis, not an assumption you're out of scope.
Under the Second Amendment, the annual Certification of Material Compliance must be signed by both a senior officer and the CISO — a dual-signature requirement — and filed by April 15, covering the prior calendar year. This is what makes Part 500 different from most frameworks: it puts named individuals personally on the line. Signing a certification that doesn't reflect reality is a personal attestation to a regulator that pursues enforcement.
If your organization can't certify full material compliance, the regulation provides an alternative — an Acknowledgment of Noncompliance identifying the gaps with a remediation plan and timeline — which is far safer than an inaccurate certification. Covered Entities must also retain the supporting documentation for five years and produce it on request. The certification is only as defensible as the evidence behind it, which is why the work happens all year, not in April.
Part 500 has two fast reporting clocks, both commonly misunderstood. Under Section 500.17(a), you must notify the NYDFS Superintendent no later than 72 hours after determining that a reportable cybersecurity incident occurred — the clock starts at determination, not at the first indicator. A reportable incident includes one requiring notice to another government or supervisory body, one with a reasonable likelihood of materially harming normal operations, or one involving ransomware deployment.
Separately, if you make an extortion or ransomware payment, you must notify NYDFS within 24 hours of the payment and then provide a written explanation within 30 days of why payment was necessary and what alternatives were considered. Because these windows are short and the triggering events are stressful, the only reliable way to meet them is a tested incident response plan with the notification workflows built in and decision-makers rehearsed in advance.
Class A is a heightened tier for the largest Covered Entities. You're Class A if you have at least $20 million in gross annual revenue from New York operations including affiliates, and you also meet one of two thresholds: more than 2,000 employees on average over the last two fiscal years (counting affiliates), or more than $1 billion in gross annual revenue from all operations.
Class A Companies must meet all baseline requirements plus additional ones: independent audits of the program based on risk, an automated method to block commonly used passwords, endpoint detection and response, and a centralized logging or SIEM solution — unless the CISO approves reasonably equivalent or more secure compensating controls in writing, reviewed annually. If you might be Class A, confirming status early matters, because the heightened controls take real time to stand up and all certify on the same April 15 cycle.
// THE NEXT MOVE
Book a 30-minute NYDFS Part 500 strategy call with a WatchUr6 advisor. Bring your New York license type, whether you've designated a CISO, and whether you might be Class A. You'll walk away knowing your compliance gaps, your certification exposure, and a realistic path to a signature you can stand behind — whether you hire us or not.
Book a NYDFS 500 Strategy Call →SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED