Skip to content
Sunday, August 23, 2026
Daily Detective NewsCrime & Policing / Legal Affairs
Software

What NYDFS Part 500 Requires After the 2023 Amendments: 72-Hour Reporting and the 2025 Deadlines

New York's amended cybersecurity regulation 23 NYCRR 500 imposes a 72-hour ransomware reporting duty and phase-in obligations that conclude in November 2025.

Document folders and a closed laptop on a marble surface beside a wall clock

New York's amended cybersecurity regulation, 23 NYCRR Part 500, requires covered entities licensed by the New York State Department of Financial Services to report cybersecurity incidents within 72 hours, file an annual certification signed by both the chief information security officer and the highest-ranking executive, and complete a phased schedule of controls obligations that largely concludes on November 1, 2025. The amendments took effect November 1, 2023, with transition periods of 18 to 24 months attached to specific provisions. 3G Times publishes information, not legal advice; entities should direct fact-specific questions to qualified counsel.

The regulation applies to any entity operating under a DFS license, charter, or registration — banks, insurers, mortgage servicers, and money transmitters among them — plus licensed virtual-currency businesses, which the amendments folded explicitly into the definition of covered entity. The 2023 rewrite replaced the original 2017 regulation's risk-based flexibility with prescriptive minimums; where the 2017 text asked whether a program was broadly adequate, the amended text names the controls. That shift from principles to prescriptions is the single most consequential change for compliance planning.

What are the new reporting deadlines?

The amended rule sets three distinct clocks. A covered entity must notify DFS within 72 hours of determining that a cybersecurity incident has occurred, including ransomware deployments in which an unauthorized person gains access to privileged accounts, per the notification section of the amended regulation published on dfs.ny.gov. Extraordinary emergencies — events that disable reporting ability entirely — carry a 24-hour notice obligation once the entity first pays or intends to pay. Separately, the annual certification of material compliance is due each year by April 15, and it must now be signed by the CISO and the highest-ranking executive jointly, a change from the 2017 regime's single officer attestation.

The 72-hour clock starts at determination, not at discovery of the underlying intrusion. Incident-response runbooks that key legal review to the end of forensic investigation will miss the window; the amended rule expects notification while facts are still forming.

Which phase-in deadlines arrive in 2025?

The amendments staggered the heavier obligations, and the November 1, 2025 date closes out most of the calendar:

ObligationCompliance date
72-hour incident notification, 24-hour extraordinary-emergency noticeNovember 1, 2023
Annual certification signed by CISO and highest-ranking executive (due April 15, 2025, for 2024)April 15, 2024 onward
Access privilege review, password and MFA requirementsNovember 1, 2024
Asset inventory, EDR deployment, testing of incident responseNovember 1, 2025
Encryption of data in transit and at rest, audit trail retention (five years)November 1, 2025

Dates in the table are drawn from the transition schedule in the amended regulation as published by DFS. Class B companies — smaller institutions as defined in the rule — hold modified obligations on several of these items, and the exemption list is worth reading before budgeting.

What changed on governance and the CISO report?

The amendments added a board-level reporting duty: the CISO must report to the board at least semi-annually on material cybersecurity matters, covering program status, material risks, and compliance posture. The annual certification also changed character — it certifies material compliance, not perfect compliance, and requires the entity to identify any areas of non-compliance with remediation plans and dates. Regulators have treated a certification that hides known gaps as a separate violation from the underlying gap itself, so the document deserves more legal attention than the underlying controls sometimes get.

Multi-factor authentication became the default rather than a scale-based option. The amended rule requires MFA for remote access to information systems and for privileged accounts, with limited exemptions that must be documented and risk-justified.

What should compliance teams prioritize now?

Read against the text, the operational sequence is concrete:

  1. Rebuild incident-notification triggers around the 72-hour determination standard, with legal review embedded rather than sequential.
  2. Inventory privileged accounts against the access-review requirements that took effect November 1, 2024, since ransomware reporting turns on privileged-account compromise.
  3. Prepare the joint CISO-and-executive certification with documented remediation plans for any disclosed gaps.
  4. Schedule the 2025 items — encryption, audit trails, asset inventory — against the November 1, 2025 close of the transition calendar.

What the record establishes is a prescriptive regime with fixed dates and an attestation regime that exposes senior management personally. What remains open is how DFS will exercise its examination discretion over first-cycle certifications; that will be settled in enforcement and examination practice rather than in the regulation's text.

Sources

  1. New York State Department of Financial Services, amended 23 NYCRR Part 500 (effective November 1, 2023)
  2. New York State Department of Financial Services, amended 23 NYCRR Part 500 (effective November 1, 2023)
  3. New York State Department of Financial Services, amended 23 NYCRR Part 500 (effective November 1, 2023)