NY DFS Compliance Resources

Free guides, templates, tools, and articles to help your business achieve and maintain NY DFS 23 NYCRR 500 compliance.

Policy & Document Templates

Download our free compliance templates to jumpstart your NY DFS program. All templates are designed to meet 23 NYCRR 500 requirements.

Pro Tip

These templates are a starting point. Customize them to reflect your organization's specific risks, systems, and processes.

Download All Templates

Available Templates

Information Security Policy
500.03
Incident Response Plan
500.16
Business Continuity Plan
500.03
Access Control Policy
500.07
Data Retention Policy
500.13
Encryption Policy
500.15
Vendor Management Policy
500.11
Asset Inventory Template
500.03
Training Acknowledgment Form
500.14
Annual Certification Checklist
500.17
Risk Assessment Template
500.09
Penetration Test Scope Document
500.05

Key Compliance Dates & Deadlines

Important dates to keep on your calendar for NY DFS compliance.

April 15

Annual Certification Filing Deadline

Submit certification for prior calendar year

Within 72 hours

Cybersecurity Event Notification

Report qualifying cybersecurity events to DFS

Annually

Penetration Testing

Complete annual penetration test (full compliance entities)

Annually

Risk Assessment Update

Review and update risk assessment

Annually

Security Awareness Training

Complete training for all personnel

As needed

Policy Reviews

Update policies when material changes occur

Frequently Asked Questions

Common questions about NY DFS 23 NYCRR 500 compliance.

Who needs to comply with NY DFS 23 NYCRR 500?

All entities operating under a license, registration, or authorization under New York Banking Law, Insurance Law, or Financial Services Law. This includes banks, insurance companies, mortgage brokers, money transmitters, and other financial services companies.

What is the limited exemption and who qualifies?

The limited exemption (Section 500.19) is available to businesses with fewer than 10 employees (including independent contractors), less than $5 million in gross annual revenue from NY operations for the last 3 years, AND less than $10 million in year-end total assets. All three criteria must be met.

When is the annual certification due?

The annual certification of compliance (or acknowledgment of noncompliance) must be filed by April 15th each year, covering the prior calendar year. The filing is submitted through the DFS portal.

Do I need a CISO if I qualify for limited exemption?

No. Entities that qualify for limited exemption are exempt from the CISO requirement under Section 500.04. However, someone must still be responsible for overseeing your cybersecurity program.

How often do I need penetration testing?

Section 500.05 requires annual penetration testing from a qualified internal or external party. Limited exemption entities are exempt from this requirement, but vulnerability scanning is still recommended.

What are the penalties for non-compliance?

NY DFS can impose penalties up to $250,000 per violation or $75,000 per day for ongoing violations. Additionally, non-compliance can result in license revocation, public enforcement actions, and reputational damage.

Can I use a virtual CISO instead of hiring one?

Yes. Section 500.04 allows for a third-party CISO arrangement. The CISO can be employed by an affiliate or a third-party service provider, as long as they are qualified and have access to your board/senior management.

What training is required for employees?

Section 500.14 requires regular cybersecurity awareness training for all personnel. Training should cover risks, policies, and procedures. The frequency isn't specified, but annual training with phishing simulations is industry standard.

Have more questions?

Contact Our Team

Ready to Simplify Your Compliance?

Buffalo Sentinel automates evidence collection, tracks your compliance status, and keeps you audit-ready year-round.