23 NYCRR Part 500 is the New York cybersecurity regulation that all of DFS's AI guidance hangs on. First effective March 1, 2017, it was substantially amended by a Second Amendment effective November 1, 2023, with the last provisions — universal multi-factor authentication (§500.12) and asset inventories (§500.13(a)) — mandatory from November 1, 2025. It requires a written cybersecurity program based on a documented risk assessment, a CISO, 72-hour incident notice, 24-hour notice of any extortion payment, and an annual certification signed by the CEO and CISO by April 15.
| Document | 23 NYCRR Part 500 — Cybersecurity Requirements for Financial Services Companies (Second Amendment) |
| Issued by | New York State Department of Financial Services |
| Type | Regulation |
| Status | In force |
| Published | Nov 1, 2023 |
| Effective | Nov 1, 2023 |
| Applies to | Every person or entity operating under a DFS license, registration, charter, certificate, permit, or accreditation under the Banking Law, Insurance Law, or Financial Services Law; heightened 'Class A' duties for large companies; limited exemptions for small entities |
| Official source | dfs.ny.gov ↗ |
| Use cases | Cybersecurity · Third-party & vendor AI · AI governance (general) · Data & privacy |
What are the key points of 23 NYCRR Part 500?
- Second Amendment effective Nov 1, 2023; §500.17 notice changes at 30 days; governance, incident response, BCDR at one year (Nov 1, 2024); vulnerability management, access privileges, and training at 18 months (May 1, 2025); MFA and asset inventory at two years (Nov 1, 2025).
- Creates 'Class A companies' (at least $20 million in NY gross annual revenue in each of the last two years plus either 2,000+ employees or $1 billion+ global gross revenue) with added duties: independent audits, privileged-access management, and endpoint detection and response.
- §500.17: notify the Superintendent within 72 hours of determining a cybersecurity incident at the entity, an affiliate, or a third-party service provider; notify within 24 hours of any extortion payment and explain it within 30 days.
- §500.9 risk assessment must be documented, updated at least annually and on material change, and drive the entire program — the hook DFS uses to require AI-specific threats to be assessed.
- §500.11 third-party service provider policy, §500.12 MFA, §500.13 data retention and asset inventory, §500.14 monitoring and annual training — the sections DFS's AI letters cite by number.
- §500.17(b) annual certification of material compliance (or acknowledgment of non-compliance with a remediation plan) signed by the highest-ranking executive and the CISO by April 15.
- §500.20 enforcement: DFS has imposed multi-million-dollar penalties, including a $2.25 million consent order against Delta Dental in April 2026, its first cyber enforcement of the year.
What did 23 NYCRR Part 500 change for banks?
Before the Second Amendment, Part 500 already required a risk-based program, but the 2023 rewrite added board-level oversight, Class A tiering, 24-hour ransom-payment notice, universal MFA, and CEO/CISO certification — turning it from a policy requirement into a control set DFS examines line by line. Because DFS regulates AI by reading these sections rather than writing new ones, Part 500 compliance is in practice the AI-cyber compliance standard for any bank with a New York charter, branch, or agency.
What are the key Part 500 compliance dates from the 2023 amendment?
Nov 1, 2023 effective; Dec 1, 2023 for new §500.17 notices; Nov 1, 2024 for governance, incident response, and business continuity; May 1, 2025 for vulnerability management, access privileges, malicious-code controls, and training; Nov 1, 2025 for universal MFA and asset inventory.
Who is a Class A company under Part 500?
A covered entity with at least $20 million in gross annual revenue in each of the last two fiscal years from New York operations (including affiliates' NY operations) and either more than 2,000 employees or over $1 billion in global gross annual revenue, averaged over the last two years.
| Date | Document | Status |
|---|---|---|
| May 21, 2026 | DFS Frontier AI Models Industry Letter (May 2026) — Heightened Cybersecurity Risks Associated with Frontier AI Models | In force |
| May 21, 2026 | DFS Heightened Threat Environment Guidance (May 2026) — Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment | In force |
| Dec 16, 2025 | Asrow Assembly Statement on AI in Insurance (Dec 2025) — Statement by DFS Acting Superintendent Kaitlin Asrow at the NYS Assembly Hearing on the Use of Artificial Intelligence Systems in Insurance Underwriting and Pricing | Final |
| Oct 16, 2024 | DFS AI Cybersecurity Industry Letter (Oct 2024) — Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks | In force |
| Jul 11, 2024 | Insurance Circular Letter No. 7 (2024) — Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing | In force |
| May 30, 2024 | DFS Virtual Currency Customer Service Guidance (May 2024) — Guidance Regarding Customer Service Requests and Complaints (Virtual Currency Entities) | In force |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →