NYDFS 23 NYCRR 500 Compliance Checklist

Practical control checklist for financial services and insurance entities

This checklist covers the core cybersecurity controls required under 23 NYCRR 500. Use it to assess your current compliance posture and identify gaps before a NYDFS examination.

Section 1: Cybersecurity Program

☐ Written Cybersecurity Policy

Board-approved policy addressing all required domains (risk assessment, access controls, data protection, incident response, vendor management, etc.)

Reference: 23 NYCRR 500.03

☐ Chief Information Security Officer (CISO) Designated

Qualified individual (internal or external) responsible for cybersecurity program oversight and reporting

Reference: 23 NYCRR 500.04

☐ Annual Risk Assessment

Documented assessment identifying material cybersecurity risks, evaluating controls, and establishing remediation priorities

Reference: 23 NYCRR 500.09

Section 2: Access Controls & Identity Management

☐ Multi-Factor Authentication (MFA)

MFA required for all external access to internal networks and privileged accounts

Reference: 23 NYCRR 500.12

☐ Access Control Policies

Documented policies limiting user access privileges based on role and need

Reference: 23 NYCRR 500.07

☐ Access Review Process

Regular review and prompt termination of access rights upon role change or separation

Reference: 23 NYCRR 500.07

☐ Password Management

Strong password policies, periodic changes, and secure storage mechanisms

Reference: 23 NYCRR 500.07

Section 3: Data Protection & Encryption

☐ Encryption at Rest

Nonpublic information encrypted when stored on internal networks and systems

Reference: 23 NYCRR 500.15

☐ Encryption in Transit

Nonpublic information encrypted during transmission over external networks

Reference: 23 NYCRR 500.15

☐ Data Inventory & Classification

Documented inventory of nonpublic information and classification scheme

Reference: 23 NYCRR 500.03(b)(2)

☐ Secure Disposal Procedures

Documented procedures for secure disposal of nonpublic information

Reference: 23 NYCRR 500.13

Section 4: Monitoring & Detection

☐ Audit Trails & Logging

Systems maintain audit trails tracking user activity, exceptions, security events

Reference: 23 NYCRR 500.06

☐ Security Event Monitoring

Systems monitor and detect cybersecurity events

Reference: 23 NYCRR 500.05

☐ Penetration Testing

Annual penetration testing or equivalent continuous monitoring

Reference: 23 NYCRR 500.05

☐ Vulnerability Assessment

Regular vulnerability assessments including timely patching and remediation

Reference: 23 NYCRR 500.05

Section 5: Incident Response & Business Continuity

☐ Written Incident Response Plan

Documented plan for responding to cybersecurity events, including roles, escalation, and notification procedures

Reference: 23 NYCRR 500.16

☐ Incident Notification Procedures

Process for notifying NYDFS within 72 hours of ransomware attacks or other material cybersecurity events

Reference: 23 NYCRR 500.17

☐ Business Continuity and Disaster Recovery Plan

Written plan addressing data backup, system recovery, critical operations continuity

Reference: 23 NYCRR 500.16

☐ Plan Testing

Annual testing of incident response and business continuity plans

Reference: 23 NYCRR 500.16

Section 6: Third-Party Service Providers

☐ Third-Party Risk Policy

Written policy for identification, assessment, and oversight of third-party service providers

Reference: 23 NYCRR 500.11

☐ Due Diligence Procedures

Risk-based evaluation process before engaging vendors with access to nonpublic information

Reference: 23 NYCRR 500.11

☐ Contractual Protections

Written agreements requiring vendors to implement appropriate security controls

Reference: 23 NYCRR 500.11

☐ Ongoing Monitoring

Periodic assessment of third-party security practices and compliance with contract terms

Reference: 23 NYCRR 500.11

Section 7: Training & Awareness

☐ Security Awareness Training

Annual training for all personnel on cybersecurity risks and safe practices

Reference: 23 NYCRR 500.14(a)

☐ Specialized Training

Enhanced training for personnel with cybersecurity responsibilities

Reference: 23 NYCRR 500.14(b)

☐ Training Documentation

Records of training completion, attendance, and curriculum updates

Reference: 23 NYCRR 500.14

Section 8: Reporting & Certification

☐ Annual Certification

Board-approved certification of compliance filed with NYDFS by February 15 annually

Reference: 23 NYCRR 500.17(a)

☐ Board Reporting

CISO provides regular reports to board or senior officer on cybersecurity program status

Reference: 23 NYCRR 500.04(b)

☐ Exemption Documentation (if applicable)

Limited exemptions available for small entities; must be documented and filed

Reference: 23 NYCRR 500.19

Next Steps

If you identified multiple gaps or are uncertain about your compliance status, we can conduct a comprehensive assessment and provide a prioritized remediation roadmap.

Important: This checklist is for guidance only and does not constitute legal advice. NYDFS requirements are subject to change and interpretation. Consult with legal counsel and compliance professionals for your specific obligations.

Last updated: September 2026