Feature Regulatory Compliance
NYDFS Part 500 Phase 3: The MFA and Asset Inventory Gaps Covered Entities Are Still Getting Wrong in 2026
The November 2025 Phase 3 requirements under 23 NYCRR Part 500 are now in effect — and the April 2026 certification must reflect full compliance. Here's what most covered entities are still getting wrong on universal MFA, asset inventory, and third-party service provider oversight.
Table of Contents
If your IT team handed you a “we’re compliant” on the November 2025 NYDFS Part 500 deadline, ask three questions before you sign the April 2026 certification.
Does your MFA policy cover every user accessing every information system — including employees logging into internal corporate apps on the internal network, not just VPN users or external-facing portals?
Does your asset inventory include data flows and access points, with a recovery time objective and support expiration date for each asset, based on written procedures?
Does every third-party service provider contract include a requirement that the TPSP use MFA to access your systems and provide immediate notification of any cybersecurity event affecting your data?
If the answer to any of those is “we need to check,” you have compliance work to do before April 15.
TL;DR
- November 1, 2025 Phase 3 requirements are now in effect: universal MFA covering all users on all information systems, plus written asset inventory procedures with specific required fields
- April 15, 2026 annual certification covers calendar year 2025 — the first full compliance certification; repeated noncompliance acknowledgments signal an enforcement risk
- MFA scope is the most common gap: the prior standard covered remote/external access; Phase 3 requires MFA for all users on all systems with no location or sensitivity carve-outs
- Asset inventories need specific fields (owner, location, classification, support expiration date, RTO) and must include data flows and access points — a hardware-only IT list isn’t sufficient
- NYDFS October 2025 industry letter flagged covered entities delegating cybersecurity compliance to TPSPs without oversight as an increasing violation pattern; TPSP contract gaps are now an active examination focus
- $144M+ in fines, 27 consent orders since 2021; Healthplex’s $2M August 2025 action specifically cited missing MFA
The Four Phases — Where You Should Be Now
The 2023 Second Amendment to 23 NYCRR Part 500 rolled out in phases to give covered entities time to implement. That runway is closed. Here’s the timeline:
| Compliance Deadline | Requirement |
|---|---|
| December 1, 2023 | Incident notification to NYDFS under §500.17(a): report cybersecurity events reported to other authorities + ransomware |
| April 29, 2024 | General Phase 2 provisions: penetration testing, vulnerability assessments, access privilege reviews, CISO designation, training, third-party policy |
| April 15, 2024 | First annual certification (covering 2023) |
| November 1, 2025 | Phase 3: universal MFA (§500.12) + asset inventory procedures (§500.13) |
| April 15, 2026 | Annual certification covering calendar year 2025 — first full certification |
If you filed an Acknowledgment of Noncompliance in April 2024 for Phase 2 gaps, NYDFS has that on file. Filing another one for Phase 3 in April 2026 — nearly two and a half years after the Second Amendment took effect — is a different conversation with your examiner than the first acknowledgment was.
Phase 3 in Detail: The MFA Requirement
Section 500.12 under the amended regulation requires that covered entities use multi-factor authentication “for any individual accessing any information system of a covered entity.”
Three phrases matter here.
“Any individual.” Not just employees. Not just full-time staff. Contractors, consultants, temporary workers, and third-party service provider users who access your systems all fall within scope. If your MFA rollout covered employees and left contractor accounts on password-only access, you have a gap.
“Any information system.” Not just remote access. Not just external-facing systems. Not just systems containing sensitive data. The amended regulation covers all information systems — including internal corporate applications, on-premise systems, network shares, and cloud platforms accessed from the corporate network. The old standard that many covered entities implemented — MFA for VPN/remote access, password-only for internal systems — is no longer compliant.
NYDFS recommended approach: Token-based MFA over push-based or text-based MFA. Push-based MFA is vulnerable to fatigue attacks (where users approve malicious pushes under bombardment). Text-based MFA is vulnerable to SIM-swapping. NYDFS flagged these vulnerabilities in its guidance. This is a recommendation, not a hard requirement — but it’s the standard examiners will reference when evaluating whether your MFA controls are adequate.
Common MFA Scope Errors
The most frequent compliance gap is scope misinterpretation. Covered entities that implemented MFA for their VPN, their email platform, and their customer-facing systems — and then stopped — are typically covering maybe 40–60% of the systems that Phase 3 requires.
Specific systems that routinely fall outside MFA coverage:
- Internal finance systems (AP/AR, payroll, general ledger)
- HR systems and employee records platforms
- Internal document management and SharePoint-equivalent systems
- Backup and recovery systems
- Network management tools
- On-premise server access (RDP or direct)
- Legacy systems where MFA integration requires middleware
For each of these, the question is the same: can any user — employee or external — access this system with only a password? If yes, that’s a Phase 3 gap.
Phase 3 in Detail: The Asset Inventory Requirement
Section 500.13 requires covered entities to implement written policies and procedures for the creation and maintenance of a comprehensive information system asset inventory.
Two pieces to this: the written procedures and the inventory itself.
The Written Procedures
The procedures must define:
- How the inventory is created initially
- The frequency of updates and validation
- How assets are classified
- Who is responsible for maintaining the inventory
A spreadsheet your IT team updates when they remember isn’t compliant. You need documented procedures specifying who owns the inventory process, how often it’s updated, what triggers an update (new systems, vendor changes, architecture changes), and how the inventory is validated against the actual environment.
The Inventory Itself — Required Fields
NYDFS is explicit about what the inventory must track for each asset. Many covered entities have IT asset inventories that meet generic IT management standards but are missing Part 500-specific fields. The regulation requires:
| Field | What It Means | Common Gap |
|---|---|---|
| Owner | The person or team accountable for the asset | Generic “IT” ownership rather than named individual or function |
| Location | Physical or logical location | Cloud assets often lack location documentation |
| Classification | Sensitivity/criticality tier | Asset classifications done for IT but not mapped to data sensitivity |
| Support expiration date | When vendor support ends (patching, updates) | Not tracked at asset level; missed for end-of-life systems |
| Recovery time objective (RTO) | How quickly this asset must be restored in a disruption | RTOs often exist at system level but not reflected in the asset inventory |
Beyond those fields, the inventory must cover hardware, software, data flows, and access points — not just devices and endpoints.
Data flows and access points are where most inventories fall short. An asset inventory that lists your servers, laptops, and cloud accounts but doesn’t document how data moves between them — or the access points where external users connect — is incomplete under Phase 3.
The TPSP Problem NYDFS Explicitly Called Out
On October 21, 2025, NYDFS issued an industry letter to executives and information security personnel titled “Guidance on Managing Risks Related to Third-Party Service Providers.” The letter didn’t create new requirements — it clarified what covered entities are already required to do, and it was issued because NYDFS had identified a pattern of noncompliance.
The pattern: covered entities increasingly outsourcing cybersecurity functions to TPSPs and treating the TPSP’s compliance assertions as the covered entity’s own compliance. That’s not how it works.
The letter was direct: “Covered entities cannot delegate their compliance obligations under Part 500 to a third party. The covered entity remains ultimately responsible for managing cybersecurity risks, including those posed by TPSPs.”
What Covered Entities Must Do for TPSPs
Due diligence before onboarding:
- Does the TPSP have a cybersecurity program that meets Part 500 standards?
- What access controls does the TPSP implement for their own systems and for accessing yours?
- Can the TPSP demonstrate compliance with Part 500 or an equivalent framework (SOC 2, ISO/IEC 27001, HITRUST)?
- A vendor questionnaire alone doesn’t satisfy this. NYDFS expects qualified personnel to validate responses and assess residual risk.
Contract requirements: At minimum, TPSP contracts need:
- Cybersecurity event notification: Immediate or timely notice when a cybersecurity event affects the covered entity’s systems or the NPI the TPSP holds
- Data location and transfer restrictions: Disclosure of where data is stored, processed, or accessed; prior approval for cross-border transfers
- MFA requirements: Contractual obligation that TPSP users accessing your systems use MFA at the same level Part 500 requires
- Compliance representations: Attestation that the TPSP maintains cybersecurity controls consistent with Part 500 obligations
See also the existing vendor due diligence techniques post for how to validate TPSP questionnaire responses beyond checkbox collection.
Ongoing monitoring: NYDFS also called out the failure to monitor residual access. Access points that become unnecessary during the course of a TPSP relationship should be revoked — not left open until the contract terminates. Monitoring TPSP access on an ongoing basis, with access reviews at least annually for critical providers, is the standard NYDFS expects to see.
Class A Companies: Are You One and Do You Know It?
The Second Amendment created a new threshold category — Class A companies — with enhanced requirements beyond the baseline.
Class A threshold: At least $20 million in gross annual revenue from New York operations, AND either 2,000+ employees OR $1 billion+ in gross annual revenue globally.
Additional Class A requirements:
- Annual independent cybersecurity audit
- Privileged access management (PAM) solution for privileged accounts
- Endpoint detection and response (EDR) system
- Enhanced requirements for compensating controls
Growing organizations frequently cross the Class A threshold without realizing it — and without implementing the additional required controls. If your organization has been expanding New York operations, growing headcount, or approaching the revenue thresholds, it’s worth checking whether you’ve crossed into Class A territory.
The April 15, 2026 Certification
The annual certification covering calendar year 2025 is due April 15, 2026. This is the first certification that must reflect compliance with the November 2025 Phase 3 requirements.
Two options: Certification of Material Compliance (certifying you met all applicable requirements in 2025) or Acknowledgment of Noncompliance (identifying specific areas of noncompliance and providing a remediation plan).
If you’re filing an Acknowledgment, NYDFS wants to see: which specific provisions were not in compliance, a description of the remediation steps in progress, and a target compliance date. An acknowledgment without a credible remediation plan is a signal to examiners.
For covered entities that filed Acknowledgments in prior years and are still working through compliance, the enforcement math is getting harder: NYDFS has demonstrated willingness to impose multi-million dollar fines (27 consent orders, $144M+ since 2021), and Healthplex’s $2 million August 2025 settlement specifically named missing MFA as a core violation.
What to Audit Before April 15
MFA:
- Map all information systems; for each, confirm whether MFA is enforced for all users
- Verify contractor and TPSP user access is covered, not just employee access
- Check whether SMS/push-based MFA is deployed and whether token-based alternatives are feasible for high-risk systems
- Document what systems remain on single-factor and your timeline for remediation
Asset inventory:
- Confirm written procedures exist specifying update frequency, ownership, and validation process
- Check whether the inventory includes all required fields: owner, location, classification, support expiration date, RTO
- Verify data flows and access points are documented, not just devices
- Validate that the inventory reflects current architecture, including recent cloud migrations
TPSP:
- Review existing contracts for cybersecurity event notification, MFA, and data location provisions
- Identify TPSPs with access to your systems or NPI that lack updated contract language
- Document due diligence on TPSP cybersecurity programs — questionnaire responses, SOC reports, or attestations
The NYDFS enforcement patterns post details what past consent orders cited as violations — useful calibration for where your gaps carry the most risk.
For covered entities managing multiple simultaneous compliance obligations, a structured incident response and notification framework also matters here: the FFIEC 36-hour incident notification rule and your NYDFS cybersecurity event reporting obligations (§500.17) run simultaneously in a real incident.
So What?
Phase 3 is no longer upcoming. The April 2026 certification is the evidence artifact.
If your MFA rollout stopped at remote access and VPN users, you have a scope gap. If your asset inventory is a hardware list without RTOs or data flows, you have a field gap. If your TPSP contracts don’t include cybersecurity event notification or MFA requirements, you have a TPSP gap. All three are active NYDFS examination priorities based on the October 2025 guidance letter and recent enforcement patterns.
The remediation path for each is defined in the regulation. What’s changed is that the runway for self-identified noncompliance is getting shorter with each certification cycle — and NYDFS’s appetite for continued acknowledgments without corresponding remediation progress is limited.
If you’re managing the full compliance workload and need a structured framework for tracking what’s open, where evidence exists, and what’s overdue, the Incident Response & Breach Notification Kit includes notification obligation tracking and a compliance status log that covers multi-regulatory frameworks. Or you can get the kit directly to get everything in one place.
External sources: NYDFS Cybersecurity Resource Center · NYDFS October 2025 TPSP Industry Letter · Second Amendment Full Text · Hogan Lovells Phase 3 Analysis · Greenberg Traurig MFA and Asset Inventory Guidance
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does the universal MFA requirement mean employees logging into internal office applications need MFA too?
What specific fields must the asset inventory include to satisfy §500.13?
If we filed an Acknowledgment of Noncompliance in prior certifications, do we need to do anything special for the April 2026 submission?
What are the Class A company thresholds and what additional requirements apply?
What should covered entity TPSP contracts include to satisfy NYDFS's October 2025 guidance?
What enforcement actions has NYDFS taken related to Phase 3 or TPSP requirements specifically?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Keep reading
Related posts.
Regulatory Compliance
Effective Challenge in Model Risk Management: Document the Disagreement
Model risk management effective challenge needs a decision trail. Build a challenge memo that preserves evidence, responses, conditions, and escalation.
Jul 24, 2026
Regulatory Compliance
FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now
FinCEN's student aid fraud alert gives banks nine red flags, a SAR keyword, and a clear transaction-monitoring task for ACH refunds.
Jul 23, 2026
Regulatory Compliance
Magnolia Diagnostics False Claims Act Settlement: Why Investors Paid Part of the $24 Million
The Magnolia Diagnostics False Claims Act settlement reached investors, requisition controls, and $24M in payments. Here is what to fix.
Jul 23, 2026