Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Data Privacy

NYDFS Part 500 in 2026: What 27 Consent Orders and $144M in Fines Tell You About Examiner Priorities

All Part 500 amended requirements are now in effect. NYDFS has 27 consent orders and $144M in fines under its belt. Here's what examiners are finding — and what to do before they show up at your door.

By Rebecca Leung · July 15, 2026 ·
Table of Contents

Delta Dental Insurance Company and Delta Dental of New York thought they had cybersecurity under control. When the MOVEit vulnerability swept the industry in 2023, they were among the thousands of organizations affected. What cost them $2.25 million in April 2026 wasn’t being breached — it was what happened after. They failed to maintain sufficient incident response policies, failed to apply retention practices that protected nonpublic information, and failed to report the cybersecurity event on time.

That’s the pattern that defines NYDFS enforcement in 2026: not just having a breach, but failing to respond correctly under Part 500. By October 2025, NYDFS Superintendent Adrienne Harris had entered 27 consent orders and collected more than $144 million in fines. The 2026 examination cycle, which began with all amended requirements fully in effect for the first time, is on track to be the most consequential since the regulation launched in 2017.

TL;DR

  • All NYDFS Part 500 amended requirements are now in effect as of November 1, 2025 — there are no more phase-in periods to hide behind
  • 27 consent orders and $144M in fines through October 2025 gives NYDFS extensive enforcement precedent to draw from in 2026 examinations
  • Most common findings: incomplete MFA coverage, phishable MFA methods on privileged accounts, poor compliance documentation, and AI deployments without governance
  • Incident notification failures are a growing enforcement category — the Delta Dental settlement illustrates the consequences
  • Third-party risk oversight is the newest targeted examination domain
  • If your compliance documentation doesn’t match your actual control environment, 2026 is when that gap becomes expensive

Why 2026 Is Different From Every Year Before It

NYDFS Part 500 has been in effect since 2017. But for most of its history, there was always a next deadline to reference: the initial compliance date, the second phase, the third phase. When NYDFS amended the regulation in November 2023 with a series of enhanced requirements, it gave covered entities a phased implementation schedule running through November 2025.

That phase-in period ended. As of November 1, 2025, every amended requirement is live. There are no more “we’re implementing” responses that satisfy an examiner. The full scope includes:

  • MFA requirements: Enforced on all privileged accounts, remote access paths, cloud admin consoles, and email systems; phishing-resistant MFA required for highest-privilege accounts
  • Annual penetration testing: With documented remediation of findings within specific timeframes
  • CISO reporting: Annual written report to senior governing body on the cybersecurity program
  • Third-party risk oversight: Documented policies, periodic assessments, and contractual requirements for vendors with access to nonpublic information
  • Cybersecurity event notification: 72-hour notice to NYDFS for any cybersecurity event that has a reasonable likelihood of material harm, and 24-hour notice for ransomware payments

What examiners bring to a 2026 examination that they didn’t have in 2022: two years of enforcement data, precedent on how violations get categorized and priced, and FAQs on MFA implementation that take away the ambiguity firms used to rely on. NYDFS issued FAQs 18–23 specifically addressing MFA implementation just before the November 2025 deadline — explaining exactly what “phishing-resistant” means and which methods satisfy the enhanced requirement.


Twenty-seven consent orders is a curriculum. The patterns that emerge across those settlements tell you where NYDFS examiners focus and where covered entities consistently fail.

Access controls and MFA lead the findings. Incomplete MFA coverage is the most frequently cited violation. The enforcement record shows three distinct patterns: MFA not configured at all on certain account types (service accounts, backup admin consoles, legacy applications), MFA configured but using phishable methods (SMS-based authentication on accounts that now require hardware keys or FIDO2), and MFA documented as deployed but not enforced in practice (exceptions made and never reviewed, device enrollment gaps, and accounts provisioned outside the standard MFA deployment process).

The NYDFS FAQ guidance makes clear that SMS-based authentication is now insufficient for privileged accounts. Covered entities that passed prior examinations with SMS-based MFA documented as compliant need to assess whether that documentation still holds.

Incident notification timing. The Delta Dental settlement is instructive because the failure wasn’t obscure — it was one of the clearest requirements in the regulation: notify NYDFS within 72 hours of determining a cybersecurity event has occurred. Delta Dental’s notification failure on the MOVEit breach was a straightforward procedural gap. The settlement adds to enforcement precedent on what “reasonable likelihood of material harm” means as a notification trigger. If there’s any question about whether an event qualifies, the safe answer in 2026 is to notify and supplement later.

Documentation gaps. The third major pattern isn’t a specific control failure — it’s the inability to prove controls are working. Covered entities that have MFA deployed but no configuration export, no quarterly deployment report, and no documented exception log are finding that “trust us, it’s working” isn’t sufficient during examination. The same applies to penetration test remediation tracking, vendor assessment records, and the CISO annual report.


Six Control Domains Where Examiners Are Spending the Most Time

Based on NYDFS enforcement patterns and examination guidance, these six areas are receiving heightened scrutiny in 2026:

Control DomainWhat Examiners Look ForHigh-Frequency Finding
MFA coverageDeployment scope, method strength, exception documentationService accounts, backup systems, legacy apps outside MFA
Incident notification72-hour NYDFS notice; 24-hour ransomware payment noticeLate notification; unclear who owns the notification decision
Third-party riskVendor inventory, assessments, contractual security requirementsMissing contracts; no assessment cadence for vendors with NPI access
AI governanceDocumented AI deployment inventory; risk assessment for AI toolsAI deployments in production with no governance documentation
Penetration testingAnnual testing; remediation tracking and completion evidenceTesting completed but remediation open longer than required timeframes
CISO annual reportWritten report delivered to senior governing body; substantive contentNo written report; informal verbal briefing presented as compliance

The AI governance finding is worth calling out specifically because it represents a shift in what NYDFS is looking for. Examiners are now asking for AI deployment inventories and risk assessments for AI tools used in operations. This reflects NYDFS’s explicit guidance that Part 500’s cybersecurity program requirements apply to AI-powered systems — and that an AI tool used in operations without documented governance is a cybersecurity program gap.


The MFA Requirement in Detail

MFA is where most firms that get consent orders wish they’d spent more time before the examination. The requirement sounds simple — enforce MFA — but implementation gaps are pervasive.

What must have MFA in 2026:

  • All privileged accounts (admin, elevated, service accounts that can make system-level changes)
  • All remote access paths (VPN concentrators, remote desktop, SSH, jump hosts)
  • All email accounts for covered entity employees
  • All cloud admin consoles (Microsoft 365, Azure portal, AWS console, GCP console)
  • All backup admin interfaces
  • Any system that can access nonpublic information

What method is required:

  • Standard MFA (authenticator app) is sufficient for most accounts
  • Phishing-resistant MFA (FIDO2/WebAuthn or hardware security keys) is required for the highest-privilege accounts — specifically, those that can make changes to the covered entity’s cybersecurity program or access systems containing the most sensitive nonpublic information
  • SMS-based MFA is no longer considered sufficient for any privileged account under the November 2025 requirements

Where firms consistently have gaps:

  • Service accounts running automated processes — often granted elevated privileges, never configured for MFA, and rarely reviewed in access control audits
  • Backup software admin consoles — a favorite attack path for ransomware groups precisely because they’re often under-secured
  • Legacy on-premises applications — MFA integration isn’t supported natively; no compensating controls documented
  • Shared administrative accounts — MFA configured but the underlying account sharing undermines the control

Documented exceptions with compensating controls are explicitly permitted by Part 500 for situations where MFA can’t be technically implemented. But the exception must be documented, the compensating controls must be specific, and the exception must be reviewed on a defined schedule. “We couldn’t get MFA to work on the application” without documentation of the compensating control is a finding.


Third-Party Risk Oversight: The Newest Enforcement Focus

NYDFS’s November 2025 requirements significantly expanded third-party risk obligations. The regulation now requires covered entities to maintain written policies for third-party service providers that include:

  • Minimum cybersecurity standards for vendors with access to nonpublic information
  • Periodic assessment of vendors based on their risk profile (the regulation doesn’t specify a fixed frequency, but NYDFS FAQ guidance indicates annual assessment for critical vendors)
  • Contractual requirements ensuring vendor notification of cybersecurity events that may affect the covered entity

The enforcement record shows that the current gap for most covered entities isn’t a complete absence of third-party risk management — it’s coverage gaps. Critical vendors with access to nonpublic information who were onboarded before the third-party requirements took effect, operating under contracts that have no cybersecurity requirements. Vendors who received initial assessments at onboarding but haven’t been re-assessed. Cloud service providers listed in the vendor inventory but not included in the assessment cadence because someone classified them as “infrastructure” rather than “third-party service provider with NPI access.”

NYDFS issued specific guidance in the days before November 2025 on managing third-party risks — a signal that this was an anticipated problem area. For the 2026 examination cycle, examiners are asking for vendor inventories, assessment completion records, and contract language. Covered entities that can’t produce those for their critical vendors are getting findings.


Closing Your Gaps Before the Examination

If you’re a covered entity facing a 2026 NYDFS examination, the following areas need immediate documentation review — not control implementation, but verification that your documentation matches reality:

MFA gap analysis. Pull a configuration export from your IAM system showing every account with elevated privileges and every remote access path. Verify MFA is actively enforced (not just configured) for each. Document any exceptions with compensating controls. For accounts using SMS-based MFA, assess whether they qualify as requiring phishing-resistant methods under the FAQ guidance.

Third-party vendor inventory. Build a complete inventory of all third-party service providers with access to nonpublic information. For each, confirm: there’s a written contract with cybersecurity requirements, an assessment has been completed within the required timeframe, and the vendor’s risk tier is documented.

Incident response plan verification. The plan must include explicit procedures for the 72-hour NYDFS notification (including who owns the decision, what the threshold is for a notification event, and what documentation is required) and the 24-hour ransomware payment notice. Many firms have incident response plans that don’t address Part 500’s specific notification requirements — they cover the general response but leave the regulatory notification step vague.

CISO annual report. The report to the senior governing body must be written, substantive, and delivered to the board or board-equivalent. A verbal briefing to the risk committee is not a written report. The report should address the state of the cybersecurity program, material cybersecurity risks, and planned or necessary investments in cybersecurity.

AI deployment inventory. If you’re using AI tools in operations — and nearly every covered entity is, from fraud detection models to customer service tools to document processing — those deployments need to be inventoried and assessed under the cybersecurity program. This doesn’t require a separate AI governance framework, but it does require evidence that AI tools are included in the cybersecurity program’s scope.


So What?

The trajectory of NYDFS Part 500 enforcement is unambiguous. Superintendent Harris has used the regulation aggressively, with 27 consent orders building enforcement precedent that examiners use directly during examinations. The 2026 cycle, with all amended requirements now fully in effect, gives NYDFS’s examination team the tools to hold covered entities to the full scope of the regulation for the first time.

For firms that have been operating under the assumption that the phase-in period bought them continued flexibility: that assumption ended November 1, 2025. For firms that have controls in place but documentation gaps: 2026 examinations are finding that the documentation is the compliance, not the control. An MFA system that works perfectly but can’t be proven to work is a finding.

The Delta Dental settlement is a useful calibration. $2.25 million for incident response policy failures and a late notification is a significant penalty for what looks like a procedural lapse. NYDFS does not grade on effort — it grades on outcomes, documentation, and timeliness.

If your last documentation review of Part 500 compliance was more than six months ago, 2026 is the year to close that gap before an examiner does it for you.


Further Reading


For teams building or updating their cybersecurity and data privacy compliance program, the Data Privacy Compliance Kit includes multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA, along with data mapping tools, breach notification procedures, and consumer rights request workflows.

Related: FFIEC Cybersecurity Assessment Tool Retirement: What Replaces It | NYDFS Part 500 and FFIEC Cybersecurity KRI Metrics | Regulatory Exam Preparation Playbook

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Which organizations are subject to NYDFS Part 500?
23 NYCRR Part 500 covers every entity licensed, registered, or chartered by the New York Department of Financial Services — including banks, insurance companies, licensed lenders, mortgage servicers, money transmitters, premium finance agencies, and virtual currency licensees. Covered entities range from global financial institutions to smaller licensed lenders. There are limited exemptions for very small entities (fewer than 10 employees, less than $5M in gross revenue, or less than $10M in year-end total assets), but these are narrow and depend on meeting all three criteria.
What's the most common reason firms receive consent orders under Part 500 in 2026?
Multi-factor authentication failures are the most frequent trigger. This includes MFA that isn't enforced on all privileged accounts (service accounts, admin consoles, backup systems), SMS-based MFA on accounts requiring phishing-resistant methods, and exceptions that weren't properly documented or compensating-controlled. The April 2026 Delta Dental settlement also illustrated a second high-frequency category: failure to report a cybersecurity event on time. Incident notification failures are now specifically targeted in the 2026 examination cycle.
Does NYDFS Part 500 apply to us if we're headquartered outside New York?
If you hold any license from NYDFS — a money transmitter license, a mortgage banker license, a virtual currency license — you are a covered entity subject to Part 500, regardless of where your headquarters is. Many fintechs holding New York money transmitter licenses are surprised to find they're full covered entities. Only entities meeting all three elements of the limited exemption (under 10 employees, under $5M revenue, under $10M assets) may qualify for reduced requirements — and even exempt entities must notify NYDFS annually of their status.
What documentation do NYDFS examiners request during a Part 500 examination?
Examiners typically request: the current CISO annual report to senior leadership (now required under the 2023 amendments), the most recent penetration test results and remediation status, a configuration export or deployment report demonstrating MFA enforcement across all in-scope accounts, the most recent third-party vendor risk assessment results, documented exceptions to required controls with compensating controls, incident response plan (current version), and records of cybersecurity events reported to NYDFS. AI deployments without documented governance are now triggering specific requests for AI risk documentation.
What are the penalties for Part 500 non-compliance?
NYDFS can impose civil monetary penalties, require consent orders, and mandate specific remediation actions. The 2023 amendments strengthened NYDFS's enforcement toolkit and explicitly authorized penalties per violation — which NYDFS has interpreted to mean penalties can accrue per day or per occurrence. The $144M in fines collected through October 2025 across 27 consent orders averages roughly $5.3M per action — but individual settlements have ranged from $500K to FirstEnergy's $9M and Carnival Corporation's $5.5M settlement. The largest fines involve extended violations or inadequate breach response.
How does NYDFS Part 500 interact with the FFIEC Cybersecurity Assessment Tool?
NYDFS Part 500 and the FFIEC CAT are complementary but separate. The FFIEC CAT was retired in August 2025 and replaced by updated FFIEC examination procedures. Passing a FFIEC CAT-equivalent assessment doesn't satisfy Part 500, and Part 500 compliance doesn't automatically satisfy FFIEC examination standards — though there's significant overlap in control expectations around access management, incident response, and third-party risk. Covered entities subject to both (licensed by NYDFS and regulated by a federal banking regulator) need separate compliance programs that address each framework's specific requirements.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.