Feature Data Privacy
NYDFS Part 500 in 2026: What 27 Consent Orders and $144M in Fines Tell You About Examiner Priorities
All Part 500 amended requirements are now in effect. NYDFS has 27 consent orders and $144M in fines under its belt. Here's what examiners are finding — and what to do before they show up at your door.
Table of Contents
Delta Dental Insurance Company and Delta Dental of New York thought they had cybersecurity under control. When the MOVEit vulnerability swept the industry in 2023, they were among the thousands of organizations affected. What cost them $2.25 million in April 2026 wasn’t being breached — it was what happened after. They failed to maintain sufficient incident response policies, failed to apply retention practices that protected nonpublic information, and failed to report the cybersecurity event on time.
That’s the pattern that defines NYDFS enforcement in 2026: not just having a breach, but failing to respond correctly under Part 500. By October 2025, NYDFS Superintendent Adrienne Harris had entered 27 consent orders and collected more than $144 million in fines. The 2026 examination cycle, which began with all amended requirements fully in effect for the first time, is on track to be the most consequential since the regulation launched in 2017.
TL;DR
- All NYDFS Part 500 amended requirements are now in effect as of November 1, 2025 — there are no more phase-in periods to hide behind
- 27 consent orders and $144M in fines through October 2025 gives NYDFS extensive enforcement precedent to draw from in 2026 examinations
- Most common findings: incomplete MFA coverage, phishable MFA methods on privileged accounts, poor compliance documentation, and AI deployments without governance
- Incident notification failures are a growing enforcement category — the Delta Dental settlement illustrates the consequences
- Third-party risk oversight is the newest targeted examination domain
- If your compliance documentation doesn’t match your actual control environment, 2026 is when that gap becomes expensive
Why 2026 Is Different From Every Year Before It
NYDFS Part 500 has been in effect since 2017. But for most of its history, there was always a next deadline to reference: the initial compliance date, the second phase, the third phase. When NYDFS amended the regulation in November 2023 with a series of enhanced requirements, it gave covered entities a phased implementation schedule running through November 2025.
That phase-in period ended. As of November 1, 2025, every amended requirement is live. There are no more “we’re implementing” responses that satisfy an examiner. The full scope includes:
- MFA requirements: Enforced on all privileged accounts, remote access paths, cloud admin consoles, and email systems; phishing-resistant MFA required for highest-privilege accounts
- Annual penetration testing: With documented remediation of findings within specific timeframes
- CISO reporting: Annual written report to senior governing body on the cybersecurity program
- Third-party risk oversight: Documented policies, periodic assessments, and contractual requirements for vendors with access to nonpublic information
- Cybersecurity event notification: 72-hour notice to NYDFS for any cybersecurity event that has a reasonable likelihood of material harm, and 24-hour notice for ransomware payments
What examiners bring to a 2026 examination that they didn’t have in 2022: two years of enforcement data, precedent on how violations get categorized and priced, and FAQs on MFA implementation that take away the ambiguity firms used to rely on. NYDFS issued FAQs 18–23 specifically addressing MFA implementation just before the November 2025 deadline — explaining exactly what “phishing-resistant” means and which methods satisfy the enhanced requirement.
What 27 Consent Orders Teach You
Twenty-seven consent orders is a curriculum. The patterns that emerge across those settlements tell you where NYDFS examiners focus and where covered entities consistently fail.
Access controls and MFA lead the findings. Incomplete MFA coverage is the most frequently cited violation. The enforcement record shows three distinct patterns: MFA not configured at all on certain account types (service accounts, backup admin consoles, legacy applications), MFA configured but using phishable methods (SMS-based authentication on accounts that now require hardware keys or FIDO2), and MFA documented as deployed but not enforced in practice (exceptions made and never reviewed, device enrollment gaps, and accounts provisioned outside the standard MFA deployment process).
The NYDFS FAQ guidance makes clear that SMS-based authentication is now insufficient for privileged accounts. Covered entities that passed prior examinations with SMS-based MFA documented as compliant need to assess whether that documentation still holds.
Incident notification timing. The Delta Dental settlement is instructive because the failure wasn’t obscure — it was one of the clearest requirements in the regulation: notify NYDFS within 72 hours of determining a cybersecurity event has occurred. Delta Dental’s notification failure on the MOVEit breach was a straightforward procedural gap. The settlement adds to enforcement precedent on what “reasonable likelihood of material harm” means as a notification trigger. If there’s any question about whether an event qualifies, the safe answer in 2026 is to notify and supplement later.
Documentation gaps. The third major pattern isn’t a specific control failure — it’s the inability to prove controls are working. Covered entities that have MFA deployed but no configuration export, no quarterly deployment report, and no documented exception log are finding that “trust us, it’s working” isn’t sufficient during examination. The same applies to penetration test remediation tracking, vendor assessment records, and the CISO annual report.
Six Control Domains Where Examiners Are Spending the Most Time
Based on NYDFS enforcement patterns and examination guidance, these six areas are receiving heightened scrutiny in 2026:
| Control Domain | What Examiners Look For | High-Frequency Finding |
|---|---|---|
| MFA coverage | Deployment scope, method strength, exception documentation | Service accounts, backup systems, legacy apps outside MFA |
| Incident notification | 72-hour NYDFS notice; 24-hour ransomware payment notice | Late notification; unclear who owns the notification decision |
| Third-party risk | Vendor inventory, assessments, contractual security requirements | Missing contracts; no assessment cadence for vendors with NPI access |
| AI governance | Documented AI deployment inventory; risk assessment for AI tools | AI deployments in production with no governance documentation |
| Penetration testing | Annual testing; remediation tracking and completion evidence | Testing completed but remediation open longer than required timeframes |
| CISO annual report | Written report delivered to senior governing body; substantive content | No written report; informal verbal briefing presented as compliance |
The AI governance finding is worth calling out specifically because it represents a shift in what NYDFS is looking for. Examiners are now asking for AI deployment inventories and risk assessments for AI tools used in operations. This reflects NYDFS’s explicit guidance that Part 500’s cybersecurity program requirements apply to AI-powered systems — and that an AI tool used in operations without documented governance is a cybersecurity program gap.
The MFA Requirement in Detail
MFA is where most firms that get consent orders wish they’d spent more time before the examination. The requirement sounds simple — enforce MFA — but implementation gaps are pervasive.
What must have MFA in 2026:
- All privileged accounts (admin, elevated, service accounts that can make system-level changes)
- All remote access paths (VPN concentrators, remote desktop, SSH, jump hosts)
- All email accounts for covered entity employees
- All cloud admin consoles (Microsoft 365, Azure portal, AWS console, GCP console)
- All backup admin interfaces
- Any system that can access nonpublic information
What method is required:
- Standard MFA (authenticator app) is sufficient for most accounts
- Phishing-resistant MFA (FIDO2/WebAuthn or hardware security keys) is required for the highest-privilege accounts — specifically, those that can make changes to the covered entity’s cybersecurity program or access systems containing the most sensitive nonpublic information
- SMS-based MFA is no longer considered sufficient for any privileged account under the November 2025 requirements
Where firms consistently have gaps:
- Service accounts running automated processes — often granted elevated privileges, never configured for MFA, and rarely reviewed in access control audits
- Backup software admin consoles — a favorite attack path for ransomware groups precisely because they’re often under-secured
- Legacy on-premises applications — MFA integration isn’t supported natively; no compensating controls documented
- Shared administrative accounts — MFA configured but the underlying account sharing undermines the control
Documented exceptions with compensating controls are explicitly permitted by Part 500 for situations where MFA can’t be technically implemented. But the exception must be documented, the compensating controls must be specific, and the exception must be reviewed on a defined schedule. “We couldn’t get MFA to work on the application” without documentation of the compensating control is a finding.
Third-Party Risk Oversight: The Newest Enforcement Focus
NYDFS’s November 2025 requirements significantly expanded third-party risk obligations. The regulation now requires covered entities to maintain written policies for third-party service providers that include:
- Minimum cybersecurity standards for vendors with access to nonpublic information
- Periodic assessment of vendors based on their risk profile (the regulation doesn’t specify a fixed frequency, but NYDFS FAQ guidance indicates annual assessment for critical vendors)
- Contractual requirements ensuring vendor notification of cybersecurity events that may affect the covered entity
The enforcement record shows that the current gap for most covered entities isn’t a complete absence of third-party risk management — it’s coverage gaps. Critical vendors with access to nonpublic information who were onboarded before the third-party requirements took effect, operating under contracts that have no cybersecurity requirements. Vendors who received initial assessments at onboarding but haven’t been re-assessed. Cloud service providers listed in the vendor inventory but not included in the assessment cadence because someone classified them as “infrastructure” rather than “third-party service provider with NPI access.”
NYDFS issued specific guidance in the days before November 2025 on managing third-party risks — a signal that this was an anticipated problem area. For the 2026 examination cycle, examiners are asking for vendor inventories, assessment completion records, and contract language. Covered entities that can’t produce those for their critical vendors are getting findings.
Closing Your Gaps Before the Examination
If you’re a covered entity facing a 2026 NYDFS examination, the following areas need immediate documentation review — not control implementation, but verification that your documentation matches reality:
MFA gap analysis. Pull a configuration export from your IAM system showing every account with elevated privileges and every remote access path. Verify MFA is actively enforced (not just configured) for each. Document any exceptions with compensating controls. For accounts using SMS-based MFA, assess whether they qualify as requiring phishing-resistant methods under the FAQ guidance.
Third-party vendor inventory. Build a complete inventory of all third-party service providers with access to nonpublic information. For each, confirm: there’s a written contract with cybersecurity requirements, an assessment has been completed within the required timeframe, and the vendor’s risk tier is documented.
Incident response plan verification. The plan must include explicit procedures for the 72-hour NYDFS notification (including who owns the decision, what the threshold is for a notification event, and what documentation is required) and the 24-hour ransomware payment notice. Many firms have incident response plans that don’t address Part 500’s specific notification requirements — they cover the general response but leave the regulatory notification step vague.
CISO annual report. The report to the senior governing body must be written, substantive, and delivered to the board or board-equivalent. A verbal briefing to the risk committee is not a written report. The report should address the state of the cybersecurity program, material cybersecurity risks, and planned or necessary investments in cybersecurity.
AI deployment inventory. If you’re using AI tools in operations — and nearly every covered entity is, from fraud detection models to customer service tools to document processing — those deployments need to be inventoried and assessed under the cybersecurity program. This doesn’t require a separate AI governance framework, but it does require evidence that AI tools are included in the cybersecurity program’s scope.
So What?
The trajectory of NYDFS Part 500 enforcement is unambiguous. Superintendent Harris has used the regulation aggressively, with 27 consent orders building enforcement precedent that examiners use directly during examinations. The 2026 cycle, with all amended requirements now fully in effect, gives NYDFS’s examination team the tools to hold covered entities to the full scope of the regulation for the first time.
For firms that have been operating under the assumption that the phase-in period bought them continued flexibility: that assumption ended November 1, 2025. For firms that have controls in place but documentation gaps: 2026 examinations are finding that the documentation is the compliance, not the control. An MFA system that works perfectly but can’t be proven to work is a finding.
The Delta Dental settlement is a useful calibration. $2.25 million for incident response policy failures and a late notification is a significant penalty for what looks like a procedural lapse. NYDFS does not grade on effort — it grades on outcomes, documentation, and timeliness.
If your last documentation review of Part 500 compliance was more than six months ago, 2026 is the year to close that gap before an examiner does it for you.
Further Reading
- NYDFS Cybersecurity Resource Center — primary source for FAQs, guidance, and examination procedures
- Ropes & Gray: NYDFS Regulated Entities Face Stronger Cybersecurity Regulations (2026)
- Reversec: NYDFS Part 500 Cybersecurity Enforcement Whitepaper
- NYDFS Part 500 Compliance Roadmap for Financial Services
- Beyond Identity: NYDFS Part 500 Compliance Strategies
For teams building or updating their cybersecurity and data privacy compliance program, the Data Privacy Compliance Kit includes multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA, along with data mapping tools, breach notification procedures, and consumer rights request workflows.
Related: FFIEC Cybersecurity Assessment Tool Retirement: What Replaces It | NYDFS Part 500 and FFIEC Cybersecurity KRI Metrics | Regulatory Exam Preparation Playbook
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Which organizations are subject to NYDFS Part 500?
What's the most common reason firms receive consent orders under Part 500 in 2026?
Does NYDFS Part 500 apply to us if we're headquartered outside New York?
What documentation do NYDFS examiners request during a Part 500 examination?
What are the penalties for Part 500 non-compliance?
How does NYDFS Part 500 interact with the FFIEC Cybersecurity Assessment Tool?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
Oregon's Privacy Law Has a Feature No Other State Has — and Financial Services Companies Are Probably in Scope
The Oregon Consumer Privacy Act's 30-day cure period ended January 1, 2026. The AG can now sue without notice. More importantly for financial services: the GLBA exemption is narrower than most assume, fintechs have significant exposure on non-NPI data, and Oregon requires something no other state does — a list of the specific named third parties that received consumer data.
Jul 17, 2026
Data Privacy
Connecticut's CTDPA Just Got a Lot Bigger — And Fintechs May Not Know They're Covered
Connecticut's CTDPA expanded on July 1, 2026 — lower thresholds, narrowed GLBA exemption, eliminated cure period, new profiling impact assessments. Here's what fintechs and nonbank lenders need to do now.
Jul 16, 2026
Data Privacy
California's ADMT Rules Are Live: What Banks and Fintechs Get Wrong About the GLBA Exemption
The CPPA finalized ADMT regulations effective January 1, 2026 — and California's GLBA exemption is narrower than you think. Here's what financial institutions and fintechs actually need to do about automated decision-making, opt-out rights, and risk assessments.
Jul 13, 2026