Skip to content
RiskTemplates · The Daily Brief Sunday, September 27, 2026
Wire OFAC Just Codified Its Penalty Playbook. What 31 CFR Part 505 Means for Your Sanctions Compliance Program. SEP 26

Feature Incident Response

Both Reg S-P Deadlines Have Passed. Here's What SEC Examiners Are Now Checking When They Walk Into Your Firm.

Regulation S-P compliance deadlines passed for larger entities in December 2025 and for smaller entities in June 2026. The SEC named it an examination priority for FY 2026. Here is what examiners are actually testing, and where the most common deficiencies appear.

By Rebecca Leung · September 26, 2026 ·
Table of Contents

TL;DR

  • Both Regulation S-P compliance deadlines have passed: larger entities since December 3, 2025, smaller entities since June 3, 2026 — no grace period remains for any covered firm
  • The SEC named Reg S-P an examination priority for FY 2026: examiners are testing whether firms have operational incident response programs, not just filed a policy document
  • Three core requirements: a written IRP covering detection, response, and remediation; 30-day customer notification for breaches; and vendor contracts with a 72-hour notification obligation on service providers
  • Most common gaps: IRP drafted but never tested, ambiguous triggering criteria for the 30-day clock, and vendor agreements that predate the amendment and don’t include the 72-hour clause
  • The deficiency-to-enforcement pipeline is moving: deficiency letters today become enforcement referrals for firms that don’t remediate

There is a specific moment in an SEC examination when a firm realizes its Regulation S-P compliance was a paperwork exercise, not a program.

An examiner asks to see the firm’s incident response program. The compliance officer pulls up a policy document. The examiner asks when it was last tested. Pause. Asks to see the vendor contracts verifying the 72-hour notification obligation. Another pause. Asks for documentation showing how the firm would determine — for a specific hypothetical breach — when the 30-day customer notification clock starts running.

A firm that can answer all three with documentation is exam-ready. Most cannot.

Both Regulation S-P compliance deadlines have now passed. Larger entities — broker-dealers, investment companies, and RIAs with $1.5 billion or more in AUM — have been subject to the rule since December 3, 2025. Smaller entities reached their compliance deadline on June 3, 2026. The SEC named Regulation S-P an examination priority for fiscal year 2026, examiners are actively testing compliance, and the deficiency pipeline is accumulating.

Who the Rule Covers — and Why “Smaller Entity” Matters

The amended rule applies to five categories of SEC-regulated institutions: broker-dealers, registered investment advisers, investment companies, funding portals, and SEC-regulated transfer agents.

The “smaller entity” designation matters because it describes where compliance gaps are concentrated. Smaller entities include RIAs with less than $1.5 billion in AUM and smaller broker-dealers — a large share of the SEC-registered universe, particularly the independent RIA community. These firms had until June 3, 2026 to comply. That deadline has now passed.

One important boundary: amended Regulation S-P covers SEC-registered entities. State-registered RIAs — typically those below $100 million in AUM — are not subject to the SEC’s amended rule, though state-level data security requirements apply. Any firm uncertain about which framework governs it should clarify that threshold question before assuming compliance posture.

The Three Core Requirements

The amended rule adds three substantive requirements to the existing Safeguards Rule framework:

1. The Written Incident Response Program

Every covered firm must have a written incident response program (IRP) addressing unauthorized access to or use of customer information. The SEC’s examination guidance specifies that the IRP must cover detection, response, and remediation — three distinct phases with different operational content.

Detection is where many firms underinvest. A written IRP that covers response and notification but lacks detection procedures — specifically, how does the firm identify that a breach occurred, and how does it document the moment of “awareness” — is incomplete. Detection is also where the 30-day notification clock starts, which makes it the most legally consequential phase to have documented.

Response includes containment (stopping ongoing unauthorized access), evidence preservation, internal escalation, and coordination with outside counsel and forensic resources. The IRP needs enough procedural specificity that it could be executed by someone other than the person who drafted it.

Remediation covers root cause analysis, control improvements, and documentation of the completed response. Examiners ask to see evidence that closed incidents were actually remediated — not just marked closed in a log.

2. The 30-Day Notification Clock

When a covered firm becomes aware of unauthorized access to or use of customer information, it must notify affected individuals as soon as possible but no later than 30 days after becoming aware.

The triggering standard is awareness, not confirmation. A firm that detects a potential breach, opens an investigation, and delays notification pending investigation conclusion is not complying if the investigation runs past 30 days. The clock starts when the firm becomes aware of unauthorized access — a lower threshold than confirmed breach.

This has direct implications for IRP design. The moment of “awareness” needs to be defined and documented. Who at the firm has authority to determine that awareness has occurred? What documentation captures that determination? What happens if the 30-day deadline approaches before the investigation concludes?

Firms also need clarity on what “customer information” triggers the obligation. The rule covers information collected in connection with a product or service — financial account data, transaction records, personal information from account opening. The scope is broad; a firm relying on a narrow reading runs the risk of missing notifications it was required to send.

3. Vendor Oversight — The 72-Hour Clause

The amended rule includes a vendor oversight obligation that is frequently underimplemented: service providers must notify the covered firm within 72 hours of becoming aware of a qualifying breach involving the firm’s customer data.

The obligation runs to the service provider, but enforcing it requires action by the covered firm. Examiners are asking to see vendor contracts that include the 72-hour notification clause. If your service agreements were negotiated before the rule amendments took effect, there is a reasonable likelihood the 72-hour obligation is not in them.

The fix is a targeted vendor contract review — identifying which service providers handle customer information and confirming the 72-hour clause is present. For service providers that handle significant customer data but won’t agree to the clause, that’s a vendor risk issue that belongs in your TPRM program. As covered separately in today’s post on the September 2026 TPRM guidance proposal, regulators are increasingly focused on whether vendor oversight actually reflects the risk each relationship presents — and a service provider that won’t commit to 72-hour breach notification is a risk that warrants documented response.

What the SEC Examination Actually Looks Like

The SEC’s examination of Reg S-P compliance focuses on operational reality, not policy documents. Examiners are testing whether the program functions, not whether a policy binder exists.

Typical examination requests include:

  • Produce the written incident response program — and expect follow-up on its completeness across all three phases
  • Demonstrate testing — when was the IRP last tested or exercised? Produce evidence: tabletop exercise records, simulation documentation, or table-of-contents from a post-incident review
  • Walk through the awareness determination — for a hypothetical breach scenario, explain how the firm would identify and document the moment “awareness” occurred
  • Show vendor contracts — covering the firm’s top data-handling service providers, with the 72-hour notification clause identified
  • Confirm incident history — has the firm had any incidents or potential incidents since the compliance effective date? If so, what was the documented response?
  • Describe the notification process — how would the firm send 30-day notifications? What template, what distribution list, what documentation that notices were sent?

Firms that can answer with documentation are exam-ready. Firms with a written policy but no operational evidence are likely to receive a deficiency letter. The SEC’s stated position is that beyond deficiency letters, referral to the Division of Enforcement remains a possibility where examiners identify significant or repeated gaps.

The Most Common Deficiencies

Based on examiner staff guidance and practitioner-reported patterns, the deficiencies appearing most frequently fall into five categories:

No written IRP at all. Firms that treated Reg S-P compliance as a matter for their existing privacy policy or a policy addendum — rather than a standalone documented program covering detection, response, and remediation — are non-compliant on the most basic requirement.

IRP drafted but never tested. A policy document that has never been through a tabletop exercise, simulation, or post-incident review doesn’t demonstrate operational readiness. The rule’s intent is a functioning program; an untested document doesn’t satisfy that intent.

Ambiguous awareness triggers. IRPs that describe response procedures without defining how awareness is determined — and who has authority to make that call — leave firms exposed when an examiner walks through a hypothetical. A well-drafted IRP defines awareness criteria, documents who makes the determination, and creates a paper trail from detection to awareness declaration.

Vendor contracts without the 72-hour clause. This is the most operationally fixable gap but requires active remediation: reviewing contracts for the clause and negotiating its inclusion where absent. Examiners are checking this.

No detection-to-awareness documentation. For past incidents, firms need to be able to show the timeline from initial detection to the awareness determination that started the 30-day clock. If that documentation doesn’t exist for historical incidents, it’s worth creating a retrospective record.

What the Breach Data Shows

The regulatory urgency isn’t theoretical. According to 2026 financial services cybersecurity data, Q1 2026 recorded 65 finance-sector incidents — a 76% increase over Q1 2025. The average cost of a financial sector data breach reached $5.56 million in 2025, second only to healthcare.

The SEC named Reg S-P as an exam priority before that Q1 data was available. The trend reinforces the regulatory logic: the volume and cost of breaches in the financial sector means the question of whether firms’ notification and response programs actually function is consequential, not procedural.

For firms that have experienced incidents since December 2025 without triggering formal notifications, now is the time to document the basis for that determination. If customer information was accessed without authorization and no notification was sent, there needs to be a documented rationale — not a gap an examiner fills in with the worst-case interpretation.

The NYDFS Overlap

For New York-regulated firms, Reg S-P operates alongside NYDFS’s heightened cybersecurity examination standards, which include their own incident response plan requirements under Part 500. The two frameworks are complementary but not identical: NYDFS Part 500 applies to NYDFS-licensed entities, while Reg S-P covers SEC-registered ones. An SEC-registered investment adviser that also holds a New York license faces both.

The practical implication: a unified IRP that addresses both frameworks’ requirements is more defensible than two documents that may be inconsistent. If your firm is subject to both, a gap analysis identifying where the frameworks diverge is a worthwhile project before the next examination cycle.

So What?

Both deadlines have passed. There is no forthcoming grace period, and no amendment pending that extends the compliance window. The SEC has told you it considers Regulation S-P an examination priority, which means it will appear on the examination checklist.

The deficiency-to-enforcement timeline works like this: deficiency letter, remediation deadline, follow-up examination. Firms that receive a deficiency letter today have a window to remediate. Firms that receive a second deficiency letter for the same gap are looking at enforcement referral territory.

The good news: Regulation S-P compliance is achievable for firms of any size. A written IRP covering detection, response, and remediation. Documented testing evidence. Vendor contracts with the 72-hour clause. A defined process for starting the 30-day notification clock. None of these require a GRC platform or a large compliance team — they require documented procedures and evidence of actually running them.

The SEC’s broader compliance examination posture — noted in the risk alert on annual compliance reviews — is consistent: examiners are evaluating whether your compliance program is functional, not whether your policy binder is current. Reg S-P is one piece of that interest.

The policy binder is not the program. The program is what happens when the breach occurs at 11pm on a Friday and someone at your firm needs to determine whether the 30-day clock just started.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

When did amended Regulation S-P take effect?
The amendments became effective December 3, 2025 for larger entities — broker-dealers, investment companies, and registered investment advisers with $1.5 billion or more in assets under management. The compliance deadline for smaller entities passed June 3, 2026. As of September 2026, there is no grace period remaining for any covered institution.
Who is covered by amended Regulation S-P?
The amended rule covers broker-dealers, registered investment advisers (RIAs), investment companies, funding portals, and transfer agents regulated by the SEC. Smaller entities — primarily RIAs with less than $1.5 billion in AUM and smaller broker-dealers — had an additional six months to comply, with their deadline passing June 3, 2026. State-registered RIAs (typically under $100 million in AUM) are not covered by the SEC's amended rule.
What does the 30-day notification requirement actually require?
Covered firms must notify affected individuals as soon as possible but no later than 30 days after the firm becomes aware of unauthorized access to or use of customer information. The clock starts at awareness — not at investigation conclusion or confirmed breach. Separately, service providers must notify the covered firm within 72 hours of becoming aware of a qualifying breach involving the firm's customer data.
What does an incident response program under Reg S-P need to include?
The rule requires a written incident response program that addresses detection of unauthorized access, response procedures (containment and remediation), notification processes meeting the 30-day timeline, and documentation of the program and past incidents. The SEC's examination focus is on whether the program is operational — not whether the policy document exists — so testing evidence, tabletop exercise records, and vendor contract verification are all part of what examiners evaluate.
What are the most common Reg S-P deficiencies examiners are finding?
Based on exam staff guidance and practitioner reporting, the most common gaps are: no written IRP at all; IRP drafted but never tested; ambiguous criteria for when the 30-day notification clock starts; vendor contracts that lack the 72-hour notification obligation; and insufficient documentation of the awareness timeline. Vendor oversight — specifically whether firms have verified that service providers know and can meet their notification obligations — is a consistent examination focus.
Does Reg S-P apply to state-registered investment advisers?
No. Amended Regulation S-P applies to SEC-registered entities. State-registered RIAs — typically those with less than $100 million in AUM — are subject to state-level data security requirements, which vary by state. NYDFS Part 500 and similar state frameworks apply to state-licensed entities; the SEC's amended Reg S-P does not.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

◆ Keep reading

Related posts.

Incident Response

NYDFS's May Guidance on Heightened Cybersecurity Threats Is Now an Exam Reference. Here's What Your IR Program Needs to Show.

On May 21, 2026, NYDFS published explicit guidance on what regulated entities should do when cybersecurity risks spike — and told examiners to treat it as a reference point. Here's what the guidance actually requires, why 'voluntary' understates the stakes, and what your incident response program needs to fix before a NYDFS exam.

Sep 20, 2026

Incident Response

NYDFS Fined Delta Dental $2.25M for an IR Plan That Couldn't Answer the Right Questions. Can Yours?

NYDFS's first cyber enforcement action of 2026 — a $2.25 million penalty against Delta Dental — wasn't about missing firewalls or unpatched servers. It was about an incident response plan that didn't address regulatory reporting obligations clearly. Here are the five gaps regulators consistently find in incident response programs at financial services firms, and how to close them before an examiner does.

Sep 14, 2026

Incident Response

CISA's CIRCIA Is Finalizing This Month. Here's What the New 72-Hour Reporting Clock Means for Your Financial Services Incident Response Program.

CISA's CIRCIA final rule — requiring 72-hour cyber incident reporting to CISA and 24-hour ransomware payment disclosure — is expected to publish in September 2026. For financial services firms, it creates a fifth notification obligation running parallel to OCC/FDIC, SEC, NYDFS, and state breach notification clocks. Here's what your IR program needs to add before the effective date.

Sep 8, 2026

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.