Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Regulatory Compliance

NYDFS Part 500 Phase 3: The MFA and Asset Inventory Gaps Covered Entities Are Still Getting Wrong in 2026

The November 2025 Phase 3 requirements under 23 NYCRR Part 500 are now in effect — and the April 2026 certification must reflect full compliance. Here's what most covered entities are still getting wrong on universal MFA, asset inventory, and third-party service provider oversight.

Table of Contents

If your IT team handed you a “we’re compliant” on the November 2025 NYDFS Part 500 deadline, ask three questions before you sign the April 2026 certification.

Does your MFA policy cover every user accessing every information system — including employees logging into internal corporate apps on the internal network, not just VPN users or external-facing portals?

Does your asset inventory include data flows and access points, with a recovery time objective and support expiration date for each asset, based on written procedures?

Does every third-party service provider contract include a requirement that the TPSP use MFA to access your systems and provide immediate notification of any cybersecurity event affecting your data?

If the answer to any of those is “we need to check,” you have compliance work to do before April 15.

TL;DR

  • November 1, 2025 Phase 3 requirements are now in effect: universal MFA covering all users on all information systems, plus written asset inventory procedures with specific required fields
  • April 15, 2026 annual certification covers calendar year 2025 — the first full compliance certification; repeated noncompliance acknowledgments signal an enforcement risk
  • MFA scope is the most common gap: the prior standard covered remote/external access; Phase 3 requires MFA for all users on all systems with no location or sensitivity carve-outs
  • Asset inventories need specific fields (owner, location, classification, support expiration date, RTO) and must include data flows and access points — a hardware-only IT list isn’t sufficient
  • NYDFS October 2025 industry letter flagged covered entities delegating cybersecurity compliance to TPSPs without oversight as an increasing violation pattern; TPSP contract gaps are now an active examination focus
  • $144M+ in fines, 27 consent orders since 2021; Healthplex’s $2M August 2025 action specifically cited missing MFA

The Four Phases — Where You Should Be Now

The 2023 Second Amendment to 23 NYCRR Part 500 rolled out in phases to give covered entities time to implement. That runway is closed. Here’s the timeline:

Compliance DeadlineRequirement
December 1, 2023Incident notification to NYDFS under §500.17(a): report cybersecurity events reported to other authorities + ransomware
April 29, 2024General Phase 2 provisions: penetration testing, vulnerability assessments, access privilege reviews, CISO designation, training, third-party policy
April 15, 2024First annual certification (covering 2023)
November 1, 2025Phase 3: universal MFA (§500.12) + asset inventory procedures (§500.13)
April 15, 2026Annual certification covering calendar year 2025 — first full certification

If you filed an Acknowledgment of Noncompliance in April 2024 for Phase 2 gaps, NYDFS has that on file. Filing another one for Phase 3 in April 2026 — nearly two and a half years after the Second Amendment took effect — is a different conversation with your examiner than the first acknowledgment was.

Phase 3 in Detail: The MFA Requirement

Section 500.12 under the amended regulation requires that covered entities use multi-factor authentication “for any individual accessing any information system of a covered entity.”

Three phrases matter here.

“Any individual.” Not just employees. Not just full-time staff. Contractors, consultants, temporary workers, and third-party service provider users who access your systems all fall within scope. If your MFA rollout covered employees and left contractor accounts on password-only access, you have a gap.

“Any information system.” Not just remote access. Not just external-facing systems. Not just systems containing sensitive data. The amended regulation covers all information systems — including internal corporate applications, on-premise systems, network shares, and cloud platforms accessed from the corporate network. The old standard that many covered entities implemented — MFA for VPN/remote access, password-only for internal systems — is no longer compliant.

NYDFS recommended approach: Token-based MFA over push-based or text-based MFA. Push-based MFA is vulnerable to fatigue attacks (where users approve malicious pushes under bombardment). Text-based MFA is vulnerable to SIM-swapping. NYDFS flagged these vulnerabilities in its guidance. This is a recommendation, not a hard requirement — but it’s the standard examiners will reference when evaluating whether your MFA controls are adequate.

Common MFA Scope Errors

The most frequent compliance gap is scope misinterpretation. Covered entities that implemented MFA for their VPN, their email platform, and their customer-facing systems — and then stopped — are typically covering maybe 40–60% of the systems that Phase 3 requires.

Specific systems that routinely fall outside MFA coverage:

  • Internal finance systems (AP/AR, payroll, general ledger)
  • HR systems and employee records platforms
  • Internal document management and SharePoint-equivalent systems
  • Backup and recovery systems
  • Network management tools
  • On-premise server access (RDP or direct)
  • Legacy systems where MFA integration requires middleware

For each of these, the question is the same: can any user — employee or external — access this system with only a password? If yes, that’s a Phase 3 gap.

Phase 3 in Detail: The Asset Inventory Requirement

Section 500.13 requires covered entities to implement written policies and procedures for the creation and maintenance of a comprehensive information system asset inventory.

Two pieces to this: the written procedures and the inventory itself.

The Written Procedures

The procedures must define:

  • How the inventory is created initially
  • The frequency of updates and validation
  • How assets are classified
  • Who is responsible for maintaining the inventory

A spreadsheet your IT team updates when they remember isn’t compliant. You need documented procedures specifying who owns the inventory process, how often it’s updated, what triggers an update (new systems, vendor changes, architecture changes), and how the inventory is validated against the actual environment.

The Inventory Itself — Required Fields

NYDFS is explicit about what the inventory must track for each asset. Many covered entities have IT asset inventories that meet generic IT management standards but are missing Part 500-specific fields. The regulation requires:

FieldWhat It MeansCommon Gap
OwnerThe person or team accountable for the assetGeneric “IT” ownership rather than named individual or function
LocationPhysical or logical locationCloud assets often lack location documentation
ClassificationSensitivity/criticality tierAsset classifications done for IT but not mapped to data sensitivity
Support expiration dateWhen vendor support ends (patching, updates)Not tracked at asset level; missed for end-of-life systems
Recovery time objective (RTO)How quickly this asset must be restored in a disruptionRTOs often exist at system level but not reflected in the asset inventory

Beyond those fields, the inventory must cover hardware, software, data flows, and access points — not just devices and endpoints.

Data flows and access points are where most inventories fall short. An asset inventory that lists your servers, laptops, and cloud accounts but doesn’t document how data moves between them — or the access points where external users connect — is incomplete under Phase 3.

The TPSP Problem NYDFS Explicitly Called Out

On October 21, 2025, NYDFS issued an industry letter to executives and information security personnel titled “Guidance on Managing Risks Related to Third-Party Service Providers.” The letter didn’t create new requirements — it clarified what covered entities are already required to do, and it was issued because NYDFS had identified a pattern of noncompliance.

The pattern: covered entities increasingly outsourcing cybersecurity functions to TPSPs and treating the TPSP’s compliance assertions as the covered entity’s own compliance. That’s not how it works.

The letter was direct: “Covered entities cannot delegate their compliance obligations under Part 500 to a third party. The covered entity remains ultimately responsible for managing cybersecurity risks, including those posed by TPSPs.”

What Covered Entities Must Do for TPSPs

Due diligence before onboarding:

  • Does the TPSP have a cybersecurity program that meets Part 500 standards?
  • What access controls does the TPSP implement for their own systems and for accessing yours?
  • Can the TPSP demonstrate compliance with Part 500 or an equivalent framework (SOC 2, ISO/IEC 27001, HITRUST)?
  • A vendor questionnaire alone doesn’t satisfy this. NYDFS expects qualified personnel to validate responses and assess residual risk.

Contract requirements: At minimum, TPSP contracts need:

  1. Cybersecurity event notification: Immediate or timely notice when a cybersecurity event affects the covered entity’s systems or the NPI the TPSP holds
  2. Data location and transfer restrictions: Disclosure of where data is stored, processed, or accessed; prior approval for cross-border transfers
  3. MFA requirements: Contractual obligation that TPSP users accessing your systems use MFA at the same level Part 500 requires
  4. Compliance representations: Attestation that the TPSP maintains cybersecurity controls consistent with Part 500 obligations

See also the existing vendor due diligence techniques post for how to validate TPSP questionnaire responses beyond checkbox collection.

Ongoing monitoring: NYDFS also called out the failure to monitor residual access. Access points that become unnecessary during the course of a TPSP relationship should be revoked — not left open until the contract terminates. Monitoring TPSP access on an ongoing basis, with access reviews at least annually for critical providers, is the standard NYDFS expects to see.

Class A Companies: Are You One and Do You Know It?

The Second Amendment created a new threshold category — Class A companies — with enhanced requirements beyond the baseline.

Class A threshold: At least $20 million in gross annual revenue from New York operations, AND either 2,000+ employees OR $1 billion+ in gross annual revenue globally.

Additional Class A requirements:

  • Annual independent cybersecurity audit
  • Privileged access management (PAM) solution for privileged accounts
  • Endpoint detection and response (EDR) system
  • Enhanced requirements for compensating controls

Growing organizations frequently cross the Class A threshold without realizing it — and without implementing the additional required controls. If your organization has been expanding New York operations, growing headcount, or approaching the revenue thresholds, it’s worth checking whether you’ve crossed into Class A territory.

The April 15, 2026 Certification

The annual certification covering calendar year 2025 is due April 15, 2026. This is the first certification that must reflect compliance with the November 2025 Phase 3 requirements.

Two options: Certification of Material Compliance (certifying you met all applicable requirements in 2025) or Acknowledgment of Noncompliance (identifying specific areas of noncompliance and providing a remediation plan).

If you’re filing an Acknowledgment, NYDFS wants to see: which specific provisions were not in compliance, a description of the remediation steps in progress, and a target compliance date. An acknowledgment without a credible remediation plan is a signal to examiners.

For covered entities that filed Acknowledgments in prior years and are still working through compliance, the enforcement math is getting harder: NYDFS has demonstrated willingness to impose multi-million dollar fines (27 consent orders, $144M+ since 2021), and Healthplex’s $2 million August 2025 settlement specifically named missing MFA as a core violation.

What to Audit Before April 15

MFA:

  • Map all information systems; for each, confirm whether MFA is enforced for all users
  • Verify contractor and TPSP user access is covered, not just employee access
  • Check whether SMS/push-based MFA is deployed and whether token-based alternatives are feasible for high-risk systems
  • Document what systems remain on single-factor and your timeline for remediation

Asset inventory:

  • Confirm written procedures exist specifying update frequency, ownership, and validation process
  • Check whether the inventory includes all required fields: owner, location, classification, support expiration date, RTO
  • Verify data flows and access points are documented, not just devices
  • Validate that the inventory reflects current architecture, including recent cloud migrations

TPSP:

  • Review existing contracts for cybersecurity event notification, MFA, and data location provisions
  • Identify TPSPs with access to your systems or NPI that lack updated contract language
  • Document due diligence on TPSP cybersecurity programs — questionnaire responses, SOC reports, or attestations

The NYDFS enforcement patterns post details what past consent orders cited as violations — useful calibration for where your gaps carry the most risk.

For covered entities managing multiple simultaneous compliance obligations, a structured incident response and notification framework also matters here: the FFIEC 36-hour incident notification rule and your NYDFS cybersecurity event reporting obligations (§500.17) run simultaneously in a real incident.

So What?

Phase 3 is no longer upcoming. The April 2026 certification is the evidence artifact.

If your MFA rollout stopped at remote access and VPN users, you have a scope gap. If your asset inventory is a hardware list without RTOs or data flows, you have a field gap. If your TPSP contracts don’t include cybersecurity event notification or MFA requirements, you have a TPSP gap. All three are active NYDFS examination priorities based on the October 2025 guidance letter and recent enforcement patterns.

The remediation path for each is defined in the regulation. What’s changed is that the runway for self-identified noncompliance is getting shorter with each certification cycle — and NYDFS’s appetite for continued acknowledgments without corresponding remediation progress is limited.

If you’re managing the full compliance workload and need a structured framework for tracking what’s open, where evidence exists, and what’s overdue, the Incident Response & Breach Notification Kit includes notification obligation tracking and a compliance status log that covers multi-regulatory frameworks. Or you can get the kit directly to get everything in one place.


External sources: NYDFS Cybersecurity Resource Center · NYDFS October 2025 TPSP Industry Letter · Second Amendment Full Text · Hogan Lovells Phase 3 Analysis · Greenberg Traurig MFA and Asset Inventory Guidance

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does the universal MFA requirement mean employees logging into internal office applications need MFA too?
Yes. Section 500.12 of the amended regulation requires MFA for any user accessing any information system of a covered entity — regardless of location (internal or remote), type of user (employee, contractor, or TPSP), or the sensitivity of the information on the system. Internal corporate apps, intranet portals, and on-premise systems are all in scope. The prior standard covered remote access and certain external-facing systems; Phase 3 eliminates those carve-outs.
What specific fields must the asset inventory include to satisfy §500.13?
The regulation requires covered entities to maintain written procedures for creating and maintaining an asset inventory, and the inventory itself must track, at minimum: the asset owner, the asset location, the classification (sensitivity level), the support expiration date, and the recovery time objective (RTO) for each asset. The inventory must also account for hardware, software, data flows, and access points — not just devices. A standard IT inventory that lists hardware without RTOs, data flows, or support expiration dates is not sufficient.
If we filed an Acknowledgment of Noncompliance in prior certifications, do we need to do anything special for the April 2026 submission?
Prior Acknowledgments of Noncompliance are noted by NYDFS. The April 15, 2026 certification covers calendar year 2025 — which includes the November 1, 2025 Phase 3 compliance deadline. If you weren't compliant with Phase 3 MFA or asset inventory requirements by November 1, 2025, you need to either achieve compliance before submitting the certification or file another noncompliance acknowledgment. Filing repeated noncompliance acknowledgments signals to NYDFS that the institution is not progressing — and increases examination risk.
What are the Class A company thresholds and what additional requirements apply?
Class A status is triggered when a covered entity has at least $20 million in gross annual revenue from New York operations AND either over 2,000 employees or over $1 billion in gross annual revenue globally. Class A entities must comply with additional requirements including annual independent cybersecurity audits, privileged access management (PAM) solutions for privileged accounts, and endpoint detection and response (EDR) systems. Growing institutions should monitor whether they cross these thresholds — becoming Class A without implementing the required controls is an enforcement risk.
What should covered entity TPSP contracts include to satisfy NYDFS's October 2025 guidance?
NYDFS's October 21, 2025 industry letter identified specific contract provisions that covered entities should require from TPSPs: (1) cybersecurity event notification — immediate or timely notice when a cybersecurity event directly impacts the covered entity's systems or NPI; (2) data location and transfer restrictions — where data is stored, processed, or accessed, and prior written approval for cross-border transfers; (3) MFA requirements for TPSP access to covered entity systems; and (4) compliance representations that the TPSP maintains cybersecurity controls aligned with Part 500 requirements.
What enforcement actions has NYDFS taken related to Phase 3 or TPSP requirements specifically?
NYDFS's August 2025 consent order against Healthplex ($2 million) cited absence of MFA as a primary violation — providing a preview of how Phase 3 gaps will be enforced. The department has entered into 27 consent orders since 2021 resulting in over $144 million in total fines. Going into 2026, NYDFS has explicitly flagged intensifying scrutiny on covered entities' cybersecurity examination readiness, particularly on access controls, MFA coverage, and third-party oversight.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.