New York's Part 500 was the first substantial state cybersecurity regulation with genuine specificity, and it remains among the strictest. The amendments finalized in 2023, phased in through 2025, raised the requirements again.
For a covered entity, this is not a framework to align with. It is a regulation with defined obligations, personal certification by named officers, and an enforcement history.
Who Is Covered
Part 500 applies to entities operating under a license, registration, charter or similar authorization under New York banking, insurance or financial services law. That reaches banks, insurers, mortgage brokers and servicers, money transmitters, virtual currency businesses and a broad range of financial services firms.
Coverage follows licensure rather than geography. An organization headquartered in Texas with a New York license is covered, which is a point some firms discover late.
Limited exemptions exist for smaller entities based on employee count, revenue and asset thresholds, and they are partial rather than complete. Exempt entities still carry a substantial subset of obligations, and the exemption must be filed rather than assumed.
The Testing Requirements
Section 500.5 sets out two distinct obligations, and conflating them is the most common error.
Penetration testing, annually, of information systems, based on relevant identified risks, conducted from both inside and outside the information systems' boundaries by a qualified internal or external party.
Vulnerability assessment, comprising automated scans or manual review of systems at a frequency determined by the risk assessment, and at minimum bi-annually. The amendments also require a monitoring process to promptly inform the entity of new security vulnerabilities, and timely remediation with documentation.
Both are required. Neither substitutes for the other. The internal-and-external framing in the penetration testing requirement is explicit and rules out an external-only engagement.
The phrase "based on relevant identified risks" ties scope to your risk assessment, which means your risk assessment needs to be current and defensible, since it is what justifies your scope.
What the Amendments Added
The amendments were substantial and several affect testing scope indirectly.
Multifactor authentication was broadened significantly, now required for remote access to information systems, remote access to third-party applications from which nonpublic information is accessible, and all privileged accounts. This is one of the most testable requirements in the regulation, and an assessment that finds privileged accounts without MFA has found a compliance failure rather than merely a weakness.
Asset inventory became explicit, requiring a documented and maintained inventory with tracking of key information for each asset. This matters for testing because scope arguments usually collapse into inventory arguments.
Governance and oversight expectations rose. The CISO must report to the board at least annually, and that report must address material cybersecurity risks, the effectiveness of the program and remediation plans. Testing results are a natural and expected input.
Class A companies, a category defined by size thresholds, carry additional requirements including independent audit of the cybersecurity program, more extensive monitoring, and password controls.
Incident notification was tightened, including a 24-hour requirement to notify the Superintendent of an extortion payment, with a written explanation of the reasoning within 30 days.
Certification Is Personal
The annual certification must be signed by the highest-ranking executive and the CISO. The amendments changed the model so an entity may either certify material compliance or submit an acknowledgment of non-compliance with an identified remediation plan and timeline.
That second option is a genuine improvement, and firms should use it rather than certify optimistically. Certifying compliance while knowing of gaps is a materially worse position than acknowledging them with a plan, and the officers signing carry that exposure personally.
The practical implication is that testing findings need to reach the people who sign. A CISO certifying compliance without having read the penetration test report is in an uncomfortable position.
Scoping It Well
Three areas repay attention in a Part 500 engagement.
Privileged access and MFA coverage, because the requirement is explicit and the failure mode, service accounts and legacy systems excluded from MFA, is extremely common.
Third-party service provider connectivity. Section 500.11 requires policies for third-party security, and the practical question is what each provider could reach. Vendor-connected systems inside the network are consistently among the weakest points found.
Internal segmentation and blast radius, because the internal testing requirement is explicit and because the risk that concerns a financial regulator is an attacker reaching systems that move money.
The Broader Trend
Part 500 has been influential well beyond New York. Other state regulators and the NAIC model law have drawn on it, and firms operating in multiple states increasingly find that satisfying Part 500 substantially satisfies the rest.
For a multi-state financial services firm, building the program to Part 500 and mapping outward is usually more efficient than assembling requirements state by state.
To discuss a Part 500 penetration test covering internal and external boundaries, get in touch.
Frequently asked questions
Who does NYDFS Part 500 apply to?
Entities operating under a license, registration or charter from the New York State Department of Financial Services. That covers banks, insurers, mortgage servicers, money transmitters and a wide range of financial services businesses. It applies based on New York licensure rather than physical location, so an organization headquartered elsewhere can be fully covered.
What does Part 500 require for penetration testing?
Annual penetration testing of information systems, based on relevant identified risks and conducted from both inside and outside the boundaries. Separately it requires automated scanning or manual review of systems at a frequency determined by risk, and at minimum bi-annual vulnerability assessments. These are distinct obligations.
What did the amendments change?
Several things: multifactor authentication requirements were broadened substantially, asset inventory obligations were made explicit, incident reporting was tightened including notification of ransomware payments, governance and board oversight expectations were raised, and a class of larger covered entities was made subject to additional requirements including independent audit.
Who has to certify compliance?
Annual certification must be submitted by the highest-ranking executive and the chief information security officer, and it now allows for either full certification or acknowledgment of non-compliance with a remediation plan. Personal certification by named officers is what gives Part 500 more practical force than frameworks with no equivalent.
What are the incident reporting timelines?
Cybersecurity events must be reported to the Superintendent within 72 hours where they meet the notification criteria, which include events requiring notice to another regulator and events with a reasonable likelihood of materially harming normal operations. Extortion payments carry their own notification requirement within 24 hours, with a written explanation following within 30 days.
