Feature Data Privacy
SEC Regulation S-P's June 2026 Deadline Has Passed: What Smaller Investment Advisers Still Need to Fix in Their Incident Response Programs
The SEC's Reg S-P amendments required smaller investment advisers and broker-dealers to have written incident response programs and 30-day customer notification procedures by June 3, 2026. Here's what the rule actually requires and where examination is already finding gaps.
Table of Contents
TL;DR
- The SEC’s Regulation S-P amendments required smaller investment advisers and broker-dealers to have written incident response programs and 30-day customer notification procedures by June 3, 2026. That deadline has passed.
- The 30-day clock runs from when your firm “becomes aware” an incident has occurred or is reasonably likely to have occurred — not when the investigation concludes.
- The written incident response program must be a policy document, not an informal practice. Annual review is required.
- Service provider oversight under Reg S-P requires you to extend your incident response and safeguard requirements to the vendors handling your customer data — with contractual provisions.
June 3, 2026 was the deadline. If you run a registered investment advisory firm below the $1.5 billion AUM threshold, or a smaller broker-dealer, that date marks when you were required to have a written incident response program in place, a customer notification procedure capable of meeting a 30-day clock, and a service provider oversight framework that extends your safeguards to the vendors who hold your clients’ data.
Most of the industry conversation about the SEC’s Regulation S-P amendments focused on the larger entities — the December 2025 deadline. Smaller firms got a six-month extension. And for many of them, that extension became a reason to delay rather than a runway to build.
The examination cycle that follows a compliance deadline is where the gaps get documented.
What the 2024 Amendments Actually Changed
The original Regulation S-P — the SEC’s privacy rule for broker-dealers, investment advisers, investment companies, and transfer agents — dates to 2000. Its core requirement is the Annual Privacy Notice to customers explaining how you use and share their nonpublic personal information. That requirement still exists.
What the 2024 amendments added is a separate, operationally distinct set of obligations focused on incident response:
- A written incident response program designed to detect, respond to, and recover from unauthorized access to or use of customer information
- 30-day customer notification when sensitive customer information has been or is reasonably likely to have been accessed without authorization
- Service provider oversight — covered institutions must extend their Reg S-P safeguard requirements to the service providers that access, maintain, or process customer information
- Annual review of the written incident response program
These are not policy enhancements to the existing annual notice framework. They are a new, operational compliance layer that requires written documentation, a functioning notification procedure, and a vendor management component.
Who Is Covered by the June 2026 Deadline
The phased rollout sorted covered institutions by size. If you had not reached the threshold for a “large entity” classification by the December 2025 date, your deadline was June 3, 2026:
| Entity type | Smaller entity threshold |
|---|---|
| Registered investment advisers | Less than $1.5 billion in regulatory AUM |
| Broker-dealers | Below the threshold for larger broker-dealer classification |
| Investment companies | Smaller closed-end, open-end companies |
| Funding portals | All funding portals |
| Transfer agents | Smaller transfer agents |
If you are a state-registered investment adviser — exempt from SEC registration — you are not directly subject to Regulation S-P. Your obligations may run under the FTC Safeguards Rule if you are a non-banking financial institution, or under state privacy and cybersecurity requirements. The two frameworks are independent.
The distinction matters because many smaller RIAs that are SEC-registered assumed they were too small to be subject to meaningful federal cybersecurity obligations. The 2024 amendments explicitly closed that assumption: the amended Reg S-P’s incident response requirements apply to all covered institutions, scaled only by compliance deadline, not by scope.
The Written Incident Response Program: What “Written” Means
The amendment requires written policies and procedures — not a document reference in your compliance manual that points to a vendor’s terms of service, not an informal understanding among principals, not a checklist you have on a shared drive.
A defensible written incident response program under Reg S-P needs to address:
Detection: How does your firm identify that an unauthorized access to customer information has occurred or is reasonably likely to have occurred? This should reference your security monitoring, vendor notification procedures, and alert thresholds. Detection is the input to the 30-day clock — and the documentation trail starts here.
Scope assessment: Written procedures for determining the nature, scope, and affected customer population of an incident. You need to know which customer information was accessed and how many customers are affected before you can make a defensible notification decision.
Containment and response: Steps to contain and control the incident, prevent further access, and preserve evidence. NIST SP 800-61 Rev. 2 — the industry standard IR framework — organizes these into preparation, detection, containment, eradication, recovery, and post-incident phases. Your written program does not need to replicate it, but it should address each phase.
Notification determination: A written decision process for determining whether the incident triggers the customer notification duty. The threshold under Reg S-P is not a specific number of affected consumers — it is whether the incident involves “sensitive customer information” that has or is reasonably likely to have been accessed without authorization. A written notification decision document — capturing the facts known, the determination made, the date, and the individuals who made it — is the evidence that your 30-day clock was measured from the right start point. This is the kind of contemporaneous record that incident response documentation frameworks are designed to capture.
Customer notification: The procedures for drafting, approving, and sending customer notifications within 30 days of the awareness trigger. The program should specify who owns this step, what the notification must include (nature of the incident, data involved, steps the firm is taking, contact information for follow-up), and the approval chain.
Annual review: A documented annual review of the program, including whether any incidents occurred during the year, whether the program’s procedures performed as designed, and what changes are needed.
The 30-Day Clock: “Becomes Aware” Is Broader Than “Discovers”
The customer notification deadline runs from the date you “become aware” that an incident involving sensitive customer information has occurred or is reasonably likely to have occurred — including the latter.
The “reasonably likely” language is the part that catches firms. It means you cannot defer the start of the clock until you have confirmed, with forensic certainty, that data was accessed. If your system logs show suspicious access patterns that a reasonable firm would recognize as unauthorized, that is awareness for Reg S-P purposes even if the investigation is still underway.
The SEC built a pressure valve into this: the amendments explicitly permit covered institutions to engage in a reasonable investigation during the 30-day window before sending customer notification. You are not required to notify on Day 1 based on preliminary information. But the investigation happens inside the 30-day window, not before the clock starts.
This has a direct implication for incident response decision documentation: the date your firm first identified the suspicious activity, and the date your incident response team formally assessed it, need to be documented separately from the date the notification was sent. Examiners will ask when awareness occurred — and “when the investigation concluded” is not a legally defensible answer if awareness preceded that date.
Service Provider Oversight: Where Most Programs Have the Biggest Gap
The amendments require covered institutions to extend their Reg S-P safeguard requirements to the service providers that access, maintain, or process customer information on their behalf. This includes:
- Contractual provisions requiring service providers to implement appropriate safeguards
- Procedures for monitoring service provider compliance
- Notification requirements from service providers to the covered institution when an incident occurs that involves customer information
This is not a new concept — the original Safeguards Rule included vendor oversight provisions. But for smaller RIAs and broker-dealers, the operational gap is often severe: custodians, portfolio management platforms, CRM systems, and document management tools all hold client data. If your service agreements do not require those vendors to notify you of incidents involving your customer data within a timeframe that preserves your 30-day window, you cannot meet your Reg S-P notification obligation for incidents that originate at a vendor.
Consider the timing math: if your custodian discovers a breach on Day 0 and notifies you on Day 20, you have 10 days to assess, determine notification is required, draft the notice, approve it, and send it to affected clients. A vendor agreement that requires notification within 72 hours of the vendor’s discovery gives you a working window. A vendor agreement that says nothing about notification timing leaves you exposed.
For firms managing their vendor oversight under FINRA’s exam guidance, the 2024 Reg S-P amendments extend these obligations — they don’t replace existing FINRA cybersecurity expectations.
What SEC Examination Is Finding
The June 2026 deadline for smaller entities falls inside the SEC’s active 2026 examination cycle, which has identified cybersecurity and data protection as top examination priorities. Based on what regulators have signaled and what examination patterns typically show after a major compliance deadline:
Missing written programs: Smaller firms that intended to “get to it” during the six-month extension often arrive at the examination with general policies but no written incident response program specifically satisfying Reg S-P’s requirements. A general privacy policy does not satisfy the incident response program requirement.
Clock documentation gaps: Firms that experienced security incidents since the rule took effect often lack documentation of when awareness occurred, making it impossible to confirm the 30-day clock was met. The determination date is a required element of defensible compliance.
Vendor agreements without notification provisions: Service provider contracts that predate the amendments frequently lack requirements for the vendor to notify the covered institution when an incident affects its customer data. Smaller firms may not have renegotiated those terms.
No annual review record: The annual review requirement produces a document. Firms that have not reviewed the program cannot produce a review record for the most recent year.
For broker-dealers, the FINRA 2026 Regulatory Oversight Report identified cybersecurity governance as a continuing examination focus, and the Reg S-P compliance deadline adds specificity to what examiners are looking for in the member firm examination cycle.
The SEC’s 8-K Disclosure Obligation Is Separate
If your firm is a public reporting company — or if your firm is an investment adviser to a public company fund — the SEC’s cybersecurity disclosure rules under Item 1.05 of Form 8-K add a parallel obligation. A material cybersecurity incident at a reporting company requires a Form 8-K within four business days of the materiality determination.
The Reg S-P customer notification and the 8-K disclosure run on different tracks and serve different audiences. Reg S-P notification is to affected customers; 8-K disclosure is to public investors. Both can be triggered by the same incident, and both run on their own clocks from different trigger points.
State breach notification obligations add a third layer, with 30-to-90-day windows that vary by jurisdiction. The same breach can require: SEC 8-K disclosure within four business days (if material and you’re a reporting company); Reg S-P customer notification within 30 days of awareness; and state consumer notification within whatever the applicable state requires.
So What?
If you are a smaller investment adviser or broker-dealer that has not completed a written incident response program meeting the SEC’s Reg S-P requirements, here is the short-form remediation path:
-
Document your detection framework. What monitoring and alerting tells you that a potential unauthorized access has occurred? Who receives that alert and within what timeframe?
-
Write the incident response program. It needs to address detection, scope assessment, containment, notification determination, customer notification, and annual review. “Reasonably designed to detect, respond to, and recover” is the standard.
-
Add notification decision documentation. Every incident should produce a contemporaneous record of the date awareness was established, the determination made, and when the 30-day clock began.
-
Review your service provider agreements. Add vendor notification requirements that give you enough of your 30-day window to act. 72-hour notification from vendor to you is a reasonable starting point.
-
Schedule and document the annual review. Mark the calendar now. The review record is an examinable document.
The SEC’s Reg S-P amendments are not aspirational guidance — they are final rules with examination and enforcement backing. The deadline has passed. The examination cycle is underway.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Who is a 'smaller entity' under the SEC's Regulation S-P amendments?
Does Regulation S-P's 30-day notice requirement apply to all security incidents?
When does the 30-day clock start under Regulation S-P?
What must a written incident response program include under Regulation S-P?
How does Regulation S-P notification interact with SEC cybersecurity disclosure obligations?
What are the penalties for failing to comply with Regulation S-P?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
Global Privacy Control for Financial Services: A State-by-State Scope Test
A practical Global Privacy Control guide for financial services: state scope, GLBA exemptions, signal handling, testing, and evidence.
Aug 17, 2026
Data Privacy
California Just Fined a Data Broker $116K for Making Opt-Out Too Hard. Your Fintech's Data Practices Are Next.
CalPrivacy ordered LocateSmarter to pay $116,490 over registration and opt-out violations, then fined Cybba $52,400 two days later.
Aug 14, 2026
Data Privacy
Washington MHMDA for Fintech: The GLBA Data Exemption and CPA Enforcement
Washington's My Health My Data Act has a data-level GLBA exemption and uses the Consumer Protection Act for public and private enforcement.
Aug 12, 2026