Feature Regulatory Compliance
NYDFS Part 500 Class A Requirements: What the 2023 Amendments Added and Where 2026 Exams Are Finding Gaps
NYDFS's Second Amendment to Part 500 created a new Class A tier for larger covered entities. The final compliance deadline passed November 1, 2024 — and 2026 is the first full examination cycle with all amended requirements in scope. Here's what examiners are finding and what covered entities are still getting wrong.
Table of Contents
TL;DR
- NYDFS’s 2023 Second Amendment created a new Class A tier with four additional requirements: independent cybersecurity audit, PAM solution, EDR tools, and automatic common-password blocking
- The final phase-in deadline was November 1, 2024 — 2026 is the first full examination cycle with all amended requirements in scope
- CEO and CISO must now both sign the annual certification, creating personal liability for security executives
- Common 2026 exam gaps: MFA holes in vendor-managed systems, 72-hour notification runbooks not updated, third-party contracts missing required cybersecurity provisions
The $11.3 Million Lesson About Auto Insurance Quoting Tools
In November 2024, NYDFS and the New York Attorney General announced settlements with GEICO and Travelers totaling $11.3 million — GEICO for $9.75 million and Travelers for $1.55 million. The underlying facts were straightforward: hackers exploited auto insurance quoting tools to steal driver’s license numbers. GEICO’s publicly-facing quoting website failed to protect the data. Travelers’ agent portal was password-protected but had no multifactor authentication — despite the company receiving industry alerts in early 2021 warning that hackers were specifically targeting those systems.
This is what NYDFS enforcement looks like: a known threat vector, an industry alert, and a covered entity that didn’t implement MFA on the system in scope. The violations cited included failure to implement adequate data security controls and noncompliance with the cybersecurity regulation’s access management requirements.
Nine months later, in August 2025, NYDFS fined Healthplex — a licensed insurance agent — $2 million for a breach notification that arrived four months after discovery instead of within the required 72 hours.
Since 2021, NYDFS has entered into 27 consent orders under the cybersecurity regulation, resulting in over $144 million in total fines. The enforcement program isn’t slowing down. And 2026 is the first year examiners have the full scope of the 2023 amendments to test against.
What the Second Amendment Actually Changed
The original Part 500 regulation went into effect in 2017. NYDFS finalized the Second Amendment on November 1, 2023 — the most significant expansion of the regulation since its adoption. Requirements phased in through multiple compliance deadlines, with the final tranche effective November 1, 2024.
The amendments added, among other things:
- A new Class A company tier with heightened requirements
- CEO and CISO dual-signature on the annual certification (creating personal liability for security executives)
- Updated 72-hour breach notification requirements
- New third-party cybersecurity contract provisions required for covered entities’ vendor agreements
- Enhanced governance requirements including board-level cybersecurity expertise documentation
- Strengthened asset management and data classification obligations
The Debevoise analysis of the November 2024 requirements summarizes what the final phase-in added: governance and risk assessment formalization, encryption scope expansion, and incident response/BCP integration — requirements that build on the Class A structure established a year earlier.
The Class A Tier: Who It Applies To
The Second Amendment introduced a formal tiering structure. Class A companies are covered entities — including all affiliates — that meet either of these thresholds:
- More than 2,000 employees (total, including all affiliates)
- More than $1 billion in gross annual revenue (total, including all affiliates)
The affiliate aggregation matters. A covered entity with 800 employees that is part of a parent with 2,500 total employees is a Class A company. The calculation doesn’t stop at the regulated entity.
Separate from Class A, the regulation maintains a limited exemption for smaller covered entities: those with fewer than 10 employees, less than $5 million in gross annual revenue, and less than $10 million in year-end total assets. For covered entities that don’t qualify for the exemption but don’t meet Class A thresholds, the standard Part 500 requirements apply.
The Four Class A Requirements
Class A companies face four requirements that don’t apply to other covered entities:
1. Annual independent audit of the cybersecurity program. This goes beyond a self-assessment. The audit must be conducted by an independent auditor — internal audit qualifies if it’s structured with adequate separation from the CISO function. External auditors provide a stronger independence argument if your examination posture is at risk.
2. Privileged access management (PAM) solution. Class A companies must implement a formal PAM system to control, monitor, and audit access by privileged users — system administrators, database admins, service accounts. The requirement reflects NYDFS’s enforcement history: access control failures, particularly admin and privileged access without adequate controls, appear repeatedly in enforcement actions.
3. Endpoint detection and response (EDR) tools. EDR goes beyond traditional antivirus — it provides real-time monitoring, behavioral analysis, and automated response capability for endpoint threats. NYDFS isn’t prescribing specific vendors, but the requirement is substantive: tools that log and detect endpoint activity, not passive signature-based tools.
4. Automatic blocking of commonly used passwords. Covered entities must implement technical controls that check passwords at creation or reset against lists of commonly used or compromised passwords and block them automatically. NIST SP 800-63B has provided the standard for this for years; NYDFS is now mandating it for Class A companies.
The CEO/CISO Dual Signature
The personal liability angle is the most significant governance change in the amendments for security executives. The annual certification submitted to NYDFS — confirming that the covered entity complied with Part 500 requirements during the prior calendar year — must now be signed by both the CEO and the CISO (or equivalent).
This is a material change from the original regulation, which required board-level or senior officer sign-off but didn’t specifically require the CISO’s personal signature. Ropes & Gray flagged in January 2026 that covered entities need to ensure their CISOs understand what they’re certifying and that the underlying evidence supports the certification.
The April 15, 2026 deadline for the 2025 annual certification has passed. If your organization missed it or filed without the dual-signature requirement, that’s an examination finding waiting to happen.
Where 2026 Exams Are Finding Gaps
The 2026 examination cycle is the first with the full scope of amended requirements in play. The gaps showing up most consistently:
MFA Gaps in Vendor-Managed Systems
Part 500 requires MFA for any access to the covered entity’s information systems from external networks, and for privileged access internally. The problem: many covered entities rely on vendor-managed platforms — core banking systems, insurance platforms, third-party portals — where MFA is controlled by the vendor, not the covered entity.
Examiners are asking covered entities to demonstrate either that MFA is in place on those systems or that they have contractual provisions requiring the vendor to maintain MFA and evidence confirming compliance. Neither is easy to produce if the vendor relationship was established before the amendments.
The Travelers case is instructive: the agent portal that hackers accessed after an industry alert about credential-stuffing attacks had no MFA. The covered entity knew about the threat vector. The control wasn’t in place.
72-Hour Notification Runbooks Not Updated
The Healthplex consent order is the clearest enforcement precedent for this gap. The 72-hour clock for notifying NYDFS of a cybersecurity event runs from when the covered entity first becomes aware — not from when the investigation concludes. A four-month delay resulted in a $2 million penalty.
Examiners are reviewing incident response plans and asking specifically: does the runbook identify the 72-hour notification requirement? Is there a defined escalation path that gets the NYDFS notification decision to the right person within that window? Many covered entities updated their plans after the Second Amendment but haven’t validated that the actual notification process — the human workflow, not the document — has been tested.
The incident response decision log is the documentation artifact that demonstrates you have a process, not just a policy. Examiners want to see the record of how notification decisions get made, not just the policy that says you’ll make them.
Third-Party Vendor Contracts Missing Required Provisions
The Second Amendment expanded third-party risk requirements. Covered entities must now include specific cybersecurity provisions in contracts with third-party service providers: requirements for the provider’s cybersecurity program, notification obligations in the event of a breach, and provisions for the covered entity to audit or assess the vendor’s cybersecurity controls.
Existing vendor contracts, often negotiated before 2023, typically don’t include these provisions. Covered entities that haven’t done a contract review and remediation cycle are carrying a gap that shows up in every examination.
The vendor risk questionnaire and contract conditions review covers what the amended requirements mean operationally for vendor management programs — which contracts need to be renegotiated and what provisions are required. Examiners want to see both updated contract language and evidence that the covered entity assessed which contracts needed remediation.
Asset Inventory Gaps
The amendments strengthened asset inventory requirements. Covered entities must maintain an accurate, current inventory of information systems and data assets. For most covered entities, the gap is cloud infrastructure and SaaS: environments added quickly, often by engineering teams, that aren’t reflected in the security team’s asset tracking.
Examiners are asking for documentation of how the covered entity maintains the inventory, how frequently it’s updated, and how new assets get added. A spreadsheet last updated eight months ago covering on-premise systems but not cloud workloads is an examination finding.
What the Penalty Structure Looks Like
Willful violations of Part 500 carry civil penalties up to $75,000 per day. In practice, consent order penalties have ranged from $2 million for smaller covered entities with specific notification violations to $30 million for larger entities with more systemic failures.
The aggregate figure since enforcement began in 2021: 27 consent orders, over $144 million in total fines. The HYPR analysis of noncompliance costs notes that remediation costs after an enforcement action typically exceed the penalty itself, particularly when systemic access control failures require enterprise-wide remediation.
Getting Examination-Ready Before You’re Examined
The gap between a “we’re working on it” posture and an examination-ready posture is primarily documentation. NYDFS examiners expect to see:
- Class A status determination: A documented assessment of whether you qualify, including the employee and revenue calculation across affiliates
- PAM implementation evidence: Not just a vendor contract, but logs showing privileged access is being monitored and audited
- EDR deployment scope: Documentation of which endpoints are covered and which, if any, are excluded — with rationale
- MFA coverage map: For every system accessible from external networks, evidence that MFA is in place or a documented compensating control
- 2026 annual certification: Signed by both CEO and CISO, with underlying evidence file
- 72-hour notification runbook: A tested, documented workflow — not just a policy section
The SOC 2 compliance discipline — maintaining an evidence library, mapping controls to requirements, tracking gaps against a remediation timeline — translates directly to Part 500 examination preparation. The SOC 2 Compliance Checklist covers the security and access control requirements that overlap significantly with Part 500’s hardened access management, encryption, and monitoring requirements.
So What?
NYDFS Part 500 enforcement isn’t theoretical — it’s produced 27 consent orders and over $144 million in penalties in five years. The Second Amendment added substantive requirements, Class A companies face additional obligations on top of those, and 2026 exams are the first to test the full amended scope.
The covered entities that emerge from 2026 examinations with findings are primarily the ones that updated policy documents but didn’t validate the operational workflows underneath them. MFA on the paper is different from MFA on the actual vendor portal. A 72-hour notification requirement in the IR plan is different from a tested escalation workflow that gets the decision to the right person in time.
Update the contracts. Test the notification runbook. Map the MFA coverage. Document the Class A status determination. These are bounded, completable tasks — and they’re what separates a clean examination from a consent order.
The SOC 2 Compliance Checklist includes 151 readiness checks across all five Trust Services Criteria with evidence collection guidance — the security and access control coverage maps closely to NYDFS Part 500’s MFA, encryption, monitoring, and access management requirements, giving covered entities a structured evidence-gathering framework for both audits simultaneously.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
SOC 2 Compliance Checklist
151 readiness checks cross-referenced to the AICPA Trust Services Criteria, with evidence collection guidance.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What qualifies a company as a Class A company under NYDFS Part 500?
What additional requirements apply specifically to Class A companies?
When did the NYDFS Part 500 amendments take effect?
Who must sign the NYDFS annual certification now?
What are the most common exam gaps NYDFS is finding in 2026?
What are the civil penalty ranges for Part 500 violations?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
SOC 2 Compliance Checklist
151 readiness checks cross-referenced to the AICPA Trust Services Criteria, with evidence collection guidance.
◆ Keep reading
Related posts.
Regulatory Compliance
The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs
OFAC's December 2025 settlement with Exodus Movement — $3.1 million for 254 apparent violations of the Iranian Transactions and Sanctions Regulations — is the clearest statement yet that non-custodial crypto wallets are in scope for sanctions obligations. The finding that staff advised Iranian users to use VPNs is the detail that turns a compliance failure into an egregious one.
Jul 30, 2026
Regulatory Compliance
Iuka State Bank Written Agreement: The Fed's 30-Day Credit Risk and BSA/AML Remediation List
The Iuka State Bank written agreement maps Fed findings to 30- and 60-day fixes across credit, capital, liquidity, and BSA/AML.
Jul 30, 2026
Regulatory Compliance
OCC-FDIC CRA Proposal: The 2026 Changes Banks Need to Map Now
The OCC-FDIC CRA proposal changes bank thresholds, lending tests, grant eligibility, and reporting. Here is the control impact.
Jul 30, 2026