<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "Who needs to comply with NYDFS cybersecurity regulation?"
title: "Who Needs to Comply With the NYDFS Cybersecurity Regulation"
seoTitle: "NYDFS 23 NYCRR 500: Who Must Comply"
summary: "The NYDFS Cybersecurity Regulation (23 NYCRR Part 500) applies to covered entities: organizations operating under a license, charter, or registration under New York Banking, Insurance, or Financial Services law. That means banks and trust companies, insurance companies and licensed agents, mortgage lenders and servicers, money transmitters, virtual currency firms, and other licensed lenders doing business in New York. It does not directly apply to ordinary software companies. Small covered entities, generally those with fewer than 20 employees or below revenue and asset thresholds, get limited exemptions from some requirements, while the largest, designated Class A companies, carry extra obligations. SaaS vendors feel the regulation indirectly through section 500.11, which requires covered entities to impose security requirements on their third-party service providers."
publishedAt: "2026-08-22"
keywords:
  - "NYDFS cybersecurity regulation"
  - "23 NYCRR Part 500"
  - "who must comply with NYDFS"
  - "NYDFS covered entity"
  - "NYDFS third party service provider"
pillar: "Beyond SOC 2"
faqs:
  - question: "does nydfs apply to vendors?"
    answer: "Not directly, but effectively yes. Section 500.11 requires every covered entity to maintain a third-party service provider security policy, including due diligence and minimum security expectations for vendors that access its systems or nonpublic information. So if you sell software to a NY-licensed bank or insurer, you are not regulated by NYDFS, but your customer is required to vet you, which arrives as security questionnaires, contract clauses, and requests for evidence such as a SOC 2 report."
  - question: "what is a class a company under nydfs?"
    answer: "Class A companies are the largest covered entities, defined in the 2023 amendment by revenue and headcount thresholds, generally at least $20 million in annual revenue from New York operations combined with either very large total revenue or a workforce over 2,000 employees, counting affiliates. They carry obligations beyond the baseline, including independent audits of their cybersecurity program and stronger monitoring and access controls. Most covered entities are not Class A."
  - question: "is soc 2 enough for nydfs?"
    answer: "No. NYDFS compliance is a regulatory obligation with its own specific requirements, including an annual certification to the superintendent, a CISO role, incident reporting within 72 hours, and prescribed technical controls, none of which a SOC 2 report satisfies by itself. For vendors, though, the dynamic differs: a covered entity vetting you under its 500.11 program is looking for evidence of your security posture, and a SOC 2 report is the most common artifact that answers that request."
  - question: "does nydfs apply to out-of-state companies?"
    answer: "Yes. Coverage turns on licensure, not location: any entity operating under a license, registration, or charter under New York Banking, Insurance, or Financial Services law is a covered entity wherever it is headquartered. An insurer based in Ohio or a lender based in California that holds a New York license is fully in scope. Companies with no New York license are outside the regulation regardless of whether they have New York customers."
  - question: "how often is the nydfs certification of compliance filed?"
    answer: "Annually. Each covered entity submits a certification of material compliance, or an acknowledgment of non-compliance with a remediation plan, to the department for the prior calendar year, filed early in the following year. Since the 2023 amendment the filing must be signed by the highest-ranking executive and the CISO or their equivalents. Limited-exemption entities still file; claiming an exemption is itself a notice submitted to NYDFS."
---

## Who needs to comply with NYDFS cybersecurity regulation?

The NYDFS Cybersecurity Regulation, formally 23 NYCRR Part 500, applies to "covered entities": any organization operating under, or required to operate under, a license, registration, or charter under New York's Banking Law, Insurance Law, or Financial Services Law. In practice that means banks, trust companies, insurance companies and licensed insurance agents and brokers, mortgage lenders and servicers, money transmitters, check cashers, virtual currency businesses licensed under the BitLicense regime, and other licensed lenders doing business in New York. If NYDFS licenses you, Part 500 covers you, regardless of where you are headquartered.

Disambiguation up front: "NYDFS compliance" in a search almost always means this cybersecurity regulation, first effective in 2017 and substantially amended in November 2023, and not the department's other supervisory rules. And the regulation is entity-based, not data-based: unlike GDPR or state privacy laws, it attaches to holding a New York financial license, not to processing New Yorkers' data.

## The four positions you can be in

| Position | Who falls here | What applies |
|---|---|---|
| Standard covered entity | NY-licensed banks, insurers, mortgage firms, money transmitters, licensed lenders | Full Part 500: cybersecurity program and policy, CISO, risk assessments, MFA, encryption, incident reporting to NYDFS within 72 hours, annual certification |
| Limited-exemption entity | Small covered entities, generally fewer than 20 employees (counting affiliates) or below revenue and asset thresholds set in section 500.19 | Still covered and still must file, but exempt from several requirements such as the CISO designation and some technical mandates |
| Class A company | The largest covered entities, defined by NY revenue combined with total revenue or headcount over 2,000, counting affiliates | Everything above plus more: independent audits, enhanced monitoring, stronger access and password controls |
| Third-party service provider | Vendors, including SaaS companies, with access to a covered entity's systems or nonpublic information | Not directly regulated, but contractually held to the covered entity's 500.11 vendor security requirements |

Three points worth stressing. First, exempt does not mean out of scope: limited-exemption entities must still run a cybersecurity program and file with NYDFS, they just skip parts of the rule, and they must file a notice claiming the exemption. Second, the thresholds moved in the 2023 amendment (the employee cutoff rose from 10 to 20, and Class A was newly created), so guidance written before 2023 understates who is exempt and omits Class A entirely. Third, the amendment's requirements phased in over roughly two years, with the final tranche, including expanded MFA coverage, landing in late 2025, which is why enforcement attention is high right now.

## How the regulation reaches companies that are not covered

Most startups asking this question are not covered entities. They are vendors to one. Section 500.11 requires every covered entity to maintain a third-party service provider security policy: due diligence before onboarding a vendor, minimum cybersecurity practices the vendor must meet, and periodic reassessment. The covered entity is on the hook to NYDFS for doing this, so it pushes the obligation downstream through security questionnaires, contract security addenda, and requests for audit reports.

That is the practical answer for a SaaS company: NYDFS will never examine you, but your bank and insurance customers must examine you, on a recurring basis, and their questionnaires track Part 500's themes: access controls and MFA, encryption of nonpublic information, incident response and notification commitments, and personnel security.

## Where Screenata fits

Screenata does not sell an NYDFS compliance program, and a covered entity's own Part 500 obligations, certifications, and filings sit with its compliance and legal teams. What Screenata covers is the vendor side of the equation: a [SOC 2](/solutions/soc-2), ISO 27001, or HIPAA program that produces the evidence a covered entity's 500.11 review asks for, with about 70% of evidence collected automatically and delivered as cryptographically signed evidence packs. If your first NYDFS-flavored questionnaire just arrived from a bank or insurer prospect, that questionnaire, not Part 500 itself, is the requirement you actually have to satisfy.
