Screenata

Beyond SOC 2

Who needs to comply with NYDFS cybersecurity regulation?

August 22, 20264 min read

Who needs to comply with NYDFS cybersecurity regulation?

The NYDFS Cybersecurity Regulation, formally 23 NYCRR Part 500, applies to "covered entities": any organization operating under, or required to operate under, a license, registration, or charter under New York's Banking Law, Insurance Law, or Financial Services Law. In practice that means banks, trust companies, insurance companies and licensed insurance agents and brokers, mortgage lenders and servicers, money transmitters, check cashers, virtual currency businesses licensed under the BitLicense regime, and other licensed lenders doing business in New York. If NYDFS licenses you, Part 500 covers you, regardless of where you are headquartered.

Disambiguation up front: "NYDFS compliance" in a search almost always means this cybersecurity regulation, first effective in 2017 and substantially amended in November 2023, and not the department's other supervisory rules. And the regulation is entity-based, not data-based: unlike GDPR or state privacy laws, it attaches to holding a New York financial license, not to processing New Yorkers' data.

The four positions you can be in

PositionWho falls hereWhat applies
Standard covered entityNY-licensed banks, insurers, mortgage firms, money transmitters, licensed lendersFull Part 500: cybersecurity program and policy, CISO, risk assessments, MFA, encryption, incident reporting to NYDFS within 72 hours, annual certification
Limited-exemption entitySmall covered entities, generally fewer than 20 employees (counting affiliates) or below revenue and asset thresholds set in section 500.19Still covered and still must file, but exempt from several requirements such as the CISO designation and some technical mandates
Class A companyThe largest covered entities, defined by NY revenue combined with total revenue or headcount over 2,000, counting affiliatesEverything above plus more: independent audits, enhanced monitoring, stronger access and password controls
Third-party service providerVendors, including SaaS companies, with access to a covered entity's systems or nonpublic informationNot directly regulated, but contractually held to the covered entity's 500.11 vendor security requirements

Three points worth stressing. First, exempt does not mean out of scope: limited-exemption entities must still run a cybersecurity program and file with NYDFS, they just skip parts of the rule, and they must file a notice claiming the exemption. Second, the thresholds moved in the 2023 amendment (the employee cutoff rose from 10 to 20, and Class A was newly created), so guidance written before 2023 understates who is exempt and omits Class A entirely. Third, the amendment's requirements phased in over roughly two years, with the final tranche, including expanded MFA coverage, landing in late 2025, which is why enforcement attention is high right now.

How the regulation reaches companies that are not covered

Most startups asking this question are not covered entities. They are vendors to one. Section 500.11 requires every covered entity to maintain a third-party service provider security policy: due diligence before onboarding a vendor, minimum cybersecurity practices the vendor must meet, and periodic reassessment. The covered entity is on the hook to NYDFS for doing this, so it pushes the obligation downstream through security questionnaires, contract security addenda, and requests for audit reports.

That is the practical answer for a SaaS company: NYDFS will never examine you, but your bank and insurance customers must examine you, on a recurring basis, and their questionnaires track Part 500's themes: access controls and MFA, encryption of nonpublic information, incident response and notification commitments, and personnel security.

Where Screenata fits

Screenata does not sell an NYDFS compliance program, and a covered entity's own Part 500 obligations, certifications, and filings sit with its compliance and legal teams. What Screenata covers is the vendor side of the equation: a SOC 2, ISO 27001, or HIPAA program that produces the evidence a covered entity's 500.11 review asks for, with about 70% of evidence collected automatically and delivered as cryptographically signed evidence packs. If your first NYDFS-flavored questionnaire just arrived from a bank or insurer prospect, that questionnaire, not Part 500 itself, is the requirement you actually have to satisfy.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.