WATCHUR6 // NYDFS PART 500 // AUDIT READINESS

The certification is signed
by name. Yours.

NYDFS Part 500 is the most prescriptive, aggressively enforced state cyber regulation in the country — and its annual certification is signed by both a senior officer and the CISO, personally. As of November 2025 the phase-in is over and every requirement is live. We build the program the signature can stand on.

Book a NYDFS 500 Strategy Call
23 NYCRR PART 500 DUAL-SIGNATURE CERT 72-HOUR NOTICE VETERAN-LED

// WHY PART 500, WHY NOW

The phase-in is over. Every requirement is live now.

2 NAMES

Personal liability, signed

The annual Certification of Material Compliance is signed by both a senior officer and the CISO. It's a personal attestation to a regulator that pursues enforcement.

72 HRS

To notify the Superintendent

Report a covered cybersecurity incident within 72 hours of determining it occurred — plus a separate 24-hour notice for any extortion payment.

FULLY LIVE

No deadlines left to hide behind

The Second Amendment's multi-year rollout ended November 1, 2025. MFA, asset inventory, the lot — you're either compliant right now or you're not.

// "GOOD ENOUGH" ISN'T CERTIFIABLE

Our security is solid, we'll just sign the certification.
The signature is only as defensible as the evidence behind it.

Part 500 doesn't ask whether your security feels solid — it asks two named people to personally certify material compliance with a long list of specific controls, and to retain the evidence for five years. Signing a certification that outruns reality is a personal attestation to a regulator known for enforcement. If you can't certify fully, the safer path is an Acknowledgment of Noncompliance with a remediation plan — not an inaccurate signature. Either way, the work that makes the certification defensible happens all year, not the week before April 15.

// THE PROGRAM, AND WHAT IT CERTIFIES TO

A whole program. One signature that vouches for all of it.

Part 500 spans a wide control set, but it all converges on one instrument. The dual-signature annual certification is where a senior officer and the CISO personally vouch that the program below is real.

The Annual Certification Dual-signature · due April 15 · the accountability instrument

Where it all comes due: the Certification of Material Compliance, signed by both a senior officer and the CISO, filed by April 15 for the prior calendar year, with supporting evidence retained five years. It's a personal attestation — or, if you can't certify fully, an Acknowledgment of Noncompliance with a remediation plan. The three program areas below are what the signature vouches for.

// CISO + GOVERNANCE

Program & Oversight

A named CISO, board-approved policy, written risk assessment, and an annual report to the senior governing body.

// TECHNICAL CONTROLS

Safeguards

MFA, encryption of NPI, asset inventory, access limits, vulnerability scans, pen testing, and logging.

// INCIDENT + VENDOR

Response & Third Parties

Incident response, the 72-hour and 24-hour notices, business continuity, and third-party risk management.

Class A Companies add independent audit, EDR, centralized logging, and password-blocking.

23 NYCRR 500 · FIRST STATE CYBER REG, 2017 Second Amendment · FULLY IN EFFECT NOV 2025 Dual-Signature Cert · DUE APRIL 15

// THE PATH

Six stages, then certify it every year.

From applicability to a defensible annual filing — then around again. The amber stages are the NYDFS-facing moments: the 72-hour incident notice and the dual-signature annual certification.

Scope

Applicability & Class A

WK 1–3

Govern

CISO & Risk Assessment

MO 1–2

Implement

Controls & Vendors

MO 2–6

Notify

72-Hour Readiness

IF TRIGGERED

Certify

Dual-Signature Filing

APRIL 15

Sustain

Evidence & Renewal

5-YR RETENTION

Amber stages are the NYDFS-facing moments — the 72-hour incident notice to the Superintendent, and the dual-signature Certification of Material Compliance filed by April 15. Between and around them, the program runs continuously, with five years of evidence retained.

// IS THIS YOU?

Three signs Part 500 is your obligation.

// 01 // NY LICENSED

You hold a New York financial license

Bank, insurer, broker, money transmitter, mortgage lender — if you operate under an NYDFS license, you're a Covered Entity unless a narrow exemption applies.

// 02 // CERT COMING DUE

April 15 is approaching and you're unsure

The dual-signature certification is due and you can't yet say, with evidence, that you're in full material compliance. Signing blind is the real risk.

// 03 // MAYBE CLASS A

You might be a Class A Company

You're near the revenue and headcount thresholds but haven't confirmed status — and the heightened controls take real time to stand up before they certify.

// WHAT WE DO

The program, the controls, and a certification you can sign.

// Phase 01 · Establish

Scope, CISO & Governance

We confirm applicability and Class A status, stand up or supplement the CISO function, and build the board-approved policy and written risk assessment the regulation is built around.

  • Applicability, exemption, and Class A analysis
  • CISO designation or fractional (vCISO) support
  • Risk assessment and board-approved policy

// Phase 02 · Implement

Controls & Third-Party Risk

We implement and document the technical safeguards — MFA, encryption, asset inventory, access controls, testing — and build the third-party risk program the regulation now requires.

  • MFA, encryption, asset inventory, access controls
  • Penetration testing and vulnerability management
  • Third-party / vendor risk management

// Phase 03 · Certify

Notification & Certification

We build the 72-hour and 24-hour notification workflows into incident response, then assemble the evidence so the dual-signature certification is one your officers can sign with confidence.

  • Incident response with 72-hour / 24-hour workflows
  • Certification evidence package and 5-year retention
  • Annual certification readiness review

// TWO NAMES ON THE LINE

When the certification is signed personally, "we think we're compliant" isn't good enough.

Book a NYDFS 500 Strategy Call

// FREQUENTLY ASKED

The Part 500 questions teams keep asking.

Does NYDFS Part 500 apply to us if we're not a bank?

Very likely, if you hold any New York financial license. Part 500 applies to Covered Entities — any organization operating under, or required to operate under, a license, registration, charter, permit, or similar authorization under New York's Banking Law, Insurance Law, or Financial Services Law. That sweeps in far more than banks: insurers, agents and brokers, money transmitters, mortgage lenders, trust companies, and credit unions.

If you're licensed by NYDFS, assume Part 500 applies unless you qualify for a narrow exemption — and even most exemptions still require core controls and a filed notice of exemption. Limited small-business exemptions exist based on size, revenue, and data thresholds, but they reduce rather than eliminate obligations. Because enforcement is aggressive and the certification carries personal liability, the safest first step is a clear applicability analysis, not an assumption you're out of scope.

Who actually signs the annual certification, and why does that matter?

Under the Second Amendment, the annual Certification of Material Compliance must be signed by both a senior officer and the CISO — a dual-signature requirement — and filed by April 15, covering the prior calendar year. This is what makes Part 500 different from most frameworks: it puts named individuals personally on the line. Signing a certification that doesn't reflect reality is a personal attestation to a regulator that pursues enforcement.

If your organization can't certify full material compliance, the regulation provides an alternative — an Acknowledgment of Noncompliance identifying the gaps with a remediation plan and timeline — which is far safer than an inaccurate certification. Covered Entities must also retain the supporting documentation for five years and produce it on request. The certification is only as defensible as the evidence behind it, which is why the work happens all year, not in April.

What are the 72-hour and 24-hour notification requirements?

Part 500 has two fast reporting clocks, both commonly misunderstood. Under Section 500.17(a), you must notify the NYDFS Superintendent no later than 72 hours after determining that a reportable cybersecurity incident occurred — the clock starts at determination, not at the first indicator. A reportable incident includes one requiring notice to another government or supervisory body, one with a reasonable likelihood of materially harming normal operations, or one involving ransomware deployment.

Separately, if you make an extortion or ransomware payment, you must notify NYDFS within 24 hours of the payment and then provide a written explanation within 30 days of why payment was necessary and what alternatives were considered. Because these windows are short and the triggering events are stressful, the only reliable way to meet them is a tested incident response plan with the notification workflows built in and decision-makers rehearsed in advance.

What's different for a Class A Company?

Class A is a heightened tier for the largest Covered Entities. You're Class A if you have at least $20 million in gross annual revenue from New York operations including affiliates, and you also meet one of two thresholds: more than 2,000 employees on average over the last two fiscal years (counting affiliates), or more than $1 billion in gross annual revenue from all operations.

Class A Companies must meet all baseline requirements plus additional ones: independent audits of the program based on risk, an automated method to block commonly used passwords, endpoint detection and response, and a centralized logging or SIEM solution — unless the CISO approves reasonably equivalent or more secure compensating controls in writing, reviewed annually. If you might be Class A, confirming status early matters, because the heightened controls take real time to stand up and all certify on the same April 15 cycle.

// THE NEXT MOVE

Build the program before you put your name on it.

Book a 30-minute NYDFS Part 500 strategy call with a WatchUr6 advisor. Bring your New York license type, whether you've designated a CISO, and whether you might be Class A. You'll walk away knowing your compliance gaps, your certification exposure, and a realistic path to a signature you can stand behind — whether you hire us or not.

Book a NYDFS 500 Strategy Call

SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED