Quick answer
23 NYCRR Part 500 is the New York Department of Financial Services (NYDFS) cybersecurity regulation, covering entities licensed under New York banking, insurance, or financial services law: banks, insurers, mortgage companies, money transmitters, and crypto businesses with a BitLicense. It mandates a risk-based cybersecurity program with named requirements (a CISO, MFA, encryption, penetration testing, access reviews, vendor security policies), 72-hour incident notification to NYDFS, and an annual compliance certification signed by senior leadership. Amendments have steadily tightened it, and NYDFS enforces with real penalties.
The named requirements
Part 500 is unusually specific for a US regulation:
- Governance: a designated CISO reporting to the board, a written cybersecurity policy, and board-level oversight, the management accountability pattern again.
- Risk assessment driving the program's design, updated as the business changes.
- Technical controls: MFA (with narrowing exceptions), encryption of nonpublic information in transit and at rest, audit trails, application security, and vulnerability management including penetration testing and scanning cadences.
- Access privileges: periodic reviews, least privilege, and prompt termination discipline.
- Third-party service provider policy: due diligence and contractual security requirements for vendors, the flow-down that reaches technology providers.
- Incident response and 72-hour reporting of cybersecurity events to NYDFS, plus ransomware-payment notifications.
- The annual certification: senior officers certify material compliance, with personal accountability that concentrates minds.
Who feels it beyond the licensees
The third-party provisions convert into vendor diligence: if your customers hold NYDFS licenses, expect their Part 500-driven questionnaires, contract clauses, and incident notification requirements. And because the regulation influenced other US state and federal financial rules, its shape (CISO, MFA, 72 hours, annual certification) recurs across the financial compliance landscape; see running it on OptiTech.

Get a personalized walkthrough of automated compliance for your team. No commitment required.