NYDFS 23 NYCRR 500 Compliance Checklist
Practical control checklist for financial services and insurance entities
This checklist covers the core cybersecurity controls required under 23 NYCRR 500. Use it to assess your current compliance posture and identify gaps before a NYDFS examination.
Section 1: Cybersecurity Program
☐ Written Cybersecurity Policy
Board-approved policy addressing all required domains (risk assessment, access controls, data protection, incident response, vendor management, etc.)
Reference: 23 NYCRR 500.03
☐ Chief Information Security Officer (CISO) Designated
Qualified individual (internal or external) responsible for cybersecurity program oversight and reporting
Reference: 23 NYCRR 500.04
☐ Annual Risk Assessment
Documented assessment identifying material cybersecurity risks, evaluating controls, and establishing remediation priorities
Reference: 23 NYCRR 500.09
Section 2: Access Controls & Identity Management
☐ Multi-Factor Authentication (MFA)
MFA required for all external access to internal networks and privileged accounts
Reference: 23 NYCRR 500.12
☐ Access Control Policies
Documented policies limiting user access privileges based on role and need
Reference: 23 NYCRR 500.07
☐ Access Review Process
Regular review and prompt termination of access rights upon role change or separation
Reference: 23 NYCRR 500.07
☐ Password Management
Strong password policies, periodic changes, and secure storage mechanisms
Reference: 23 NYCRR 500.07
Section 3: Data Protection & Encryption
☐ Encryption at Rest
Nonpublic information encrypted when stored on internal networks and systems
Reference: 23 NYCRR 500.15
☐ Encryption in Transit
Nonpublic information encrypted during transmission over external networks
Reference: 23 NYCRR 500.15
☐ Data Inventory & Classification
Documented inventory of nonpublic information and classification scheme
Reference: 23 NYCRR 500.03(b)(2)
☐ Secure Disposal Procedures
Documented procedures for secure disposal of nonpublic information
Reference: 23 NYCRR 500.13
Section 4: Monitoring & Detection
☐ Audit Trails & Logging
Systems maintain audit trails tracking user activity, exceptions, security events
Reference: 23 NYCRR 500.06
☐ Security Event Monitoring
Systems monitor and detect cybersecurity events
Reference: 23 NYCRR 500.05
☐ Penetration Testing
Annual penetration testing or equivalent continuous monitoring
Reference: 23 NYCRR 500.05
☐ Vulnerability Assessment
Regular vulnerability assessments including timely patching and remediation
Reference: 23 NYCRR 500.05
Section 5: Incident Response & Business Continuity
☐ Written Incident Response Plan
Documented plan for responding to cybersecurity events, including roles, escalation, and notification procedures
Reference: 23 NYCRR 500.16
☐ Incident Notification Procedures
Process for notifying NYDFS within 72 hours of ransomware attacks or other material cybersecurity events
Reference: 23 NYCRR 500.17
☐ Business Continuity and Disaster Recovery Plan
Written plan addressing data backup, system recovery, critical operations continuity
Reference: 23 NYCRR 500.16
☐ Plan Testing
Annual testing of incident response and business continuity plans
Reference: 23 NYCRR 500.16
Section 6: Third-Party Service Providers
☐ Third-Party Risk Policy
Written policy for identification, assessment, and oversight of third-party service providers
Reference: 23 NYCRR 500.11
☐ Due Diligence Procedures
Risk-based evaluation process before engaging vendors with access to nonpublic information
Reference: 23 NYCRR 500.11
☐ Contractual Protections
Written agreements requiring vendors to implement appropriate security controls
Reference: 23 NYCRR 500.11
☐ Ongoing Monitoring
Periodic assessment of third-party security practices and compliance with contract terms
Reference: 23 NYCRR 500.11
Section 7: Training & Awareness
☐ Security Awareness Training
Annual training for all personnel on cybersecurity risks and safe practices
Reference: 23 NYCRR 500.14(a)
☐ Specialized Training
Enhanced training for personnel with cybersecurity responsibilities
Reference: 23 NYCRR 500.14(b)
☐ Training Documentation
Records of training completion, attendance, and curriculum updates
Reference: 23 NYCRR 500.14
Section 8: Reporting & Certification
☐ Annual Certification
Board-approved certification of compliance filed with NYDFS by February 15 annually
Reference: 23 NYCRR 500.17(a)
☐ Board Reporting
CISO provides regular reports to board or senior officer on cybersecurity program status
Reference: 23 NYCRR 500.04(b)
☐ Exemption Documentation (if applicable)
Limited exemptions available for small entities; must be documented and filed
Reference: 23 NYCRR 500.19
Next Steps
If you identified multiple gaps or are uncertain about your compliance status, we can conduct a comprehensive assessment and provide a prioritized remediation roadmap.
Important: This checklist is for guidance only and does not constitute legal advice. NYDFS requirements are subject to change and interpretation. Consult with legal counsel and compliance professionals for your specific obligations.
Last updated: September 2026