Beyond the April Deadline: What NYSDFS Part 500 Compliance Looks Like in Practice
If you filed your NYSDFS Part 500 annual certification in April and are relieved it was over, you’re not alone. But here’s the thing nobody puts on the checklist: the certification covers last year. The compliance work it represents? That has to keep going.
If you’re a covered entity under 23 NYCRR Part 500 (an investment adviser, community bank, insurance company, licensed lender, or any other financial services firm operating in New York), mid-year is the right moment to take stock. Not because an examiner is knocking. Because that’s how the regulation actually works.
Here’s what ongoing compliance looks like in practice, and what most smaller covered entities miss in the months after the April deadline.
What the April certification actually covered
The annual certification you filed was a statement about your compliance posture during the prior calendar year. It affirmed that you had, or were working toward, the controls Part 500 requires.
What it didn’t do was lock anything in. NYSDFS’s cybersecurity regulation is continuous by design; controls need to be maintained, not just demonstrated once. New vendors get added, employees turn over, and the asset inventory you built for the certification isn’t automatically accurate six months later.
Think of the certification as a snapshot, not a seal of approval. The regulators know it, and so do their examiners. If NYSDFS ever comes knocking, what they’ll look for is evidence of an ongoing program, not a certification filed nine months ago.
For a fuller picture of what Part 500 requires now that it’s fully in effect, see our earlier piece: NYSDFS Part 500: What “Fully in Effect” Means for Smaller Regulated Organizations.
The five areas most likely to surface gaps in a mid-year review
These are the controls that come up most often in NYSDFS examinations, and the ones most likely to drift between certification cycles.
If you’ve filed a Limited Exemption Notice with NYSDFS, some of what follows may not apply to you in full — the exemption reduces requirements, it doesn’t eliminate them. We’re Happy to Help you work through which of these still apply to your situation.
1. Multi-factor authentication
MFA on email accounts, remote access, and privileged systems isn’t a suggestion under Part 500: it’s required. It’s also the control most likely to have gaps in practice. New accounts get created without it, exceptions get made for executives, and remote access tools get added with MFA scheduled for “later.”
Mid-year is a good time to verify that MFA is actually deployed everywhere it’s supposed to be, not just on the accounts that were easy.
2. Third Party Risk Management
Part 500 requires covered entities to implement a Third Party Risk Management program that includes written policies and procedures, due diligence before onboarding, and periodic reassessment of your most critical vendors. The standard question examiners ask isn’t “do you have a vendor list?” It’s “show me your due diligence process, and show me that you applied it.”
Since your last certification: have you added any vendors that touch your systems or your customers’ nonpublic information? If yes: did they go through your Third Party Risk Management process? If the answer is “we did an email exchange and checked a box,” that may not hold up. A questionnaire, a documented review, and a record of the outcome is what a mature program looks like.
3. Vulnerability management
Part 500 requires both vulnerability assessments and penetration testing, and they’re different things. Vulnerability scanning identifies known weaknesses in your systems on a scheduled basis. Penetration testing involves someone actively trying to exploit those weaknesses to see how far they get.
For standard covered entities, the regulation requires penetration testing at least annually and vulnerability assessments at least twice per year.
Running the scans is the easy part. The gap we see most often isn’t skipping the test — it’s doing the test and never actioning the results. A vulnerability assessment with no documented remediation plan isn’t compliance; it’s a liability you didn’t know you had. What regulators want to see is Vulnerability Management as a continuous process: the assessment, the remediation tracking, and the documentation together. If examiners ask for your last penetration test report, the follow-up question is always: what did you do about it?
4. Asset inventory
Your asset inventory is the foundation of your cybersecurity program; you can’t protect what you don’t know you have. Part 500 requires covered entities to maintain a current inventory of information systems, and to keep it accurate, not just build it for the certification.
The mid-year question: does your inventory reflect what you’re actually running today? Cloud applications added since January, devices issued to new hires, a SaaS tool the marketing team signed up for without going through IT. These create scope gaps that show up in examinations.
5. Incident response plan
You need one, and “tested” means something more than an executive reading the document and nodding.
Tabletop exercises — structured walkthroughs of what your team would do in a ransomware scenario, a wire fraud attempt, or a third-party breach — are how you find out whether your plan works before it matters. Part 500 requires that your incident response plan be reviewed and tested annually. If you haven’t tested yours since last year’s certification, mid-year is the right time.
The documentation gap most smaller covered entities underestimate
Here is what NYSDFS examinations are built on: documents. Not intention, not verbal explanations of what you’ve been doing. Documents.
Part 500 requires that a qualified individual oversee and implement your cybersecurity program and report annually to your board. That role can be filled by an internal CISO or an external firm — OrbitalFire fills this role for a number of covered entities. What can’t be delegated is the certification itself: a senior officer of your organization puts their name on the annual compliance statement, and with it comes accountability for everything that certification represents. The report, the process behind it, and the evidence supporting its conclusions are exactly what examiners ask for first.
“If it isn’t documented, it wasn’t done” is how New York state examiners approach this. A vulnerability assessment report buried in someone’s inbox with no documented action is a documentation gap. So is a new vendor onboarded with an empty Third Party Risk Management file. Examiners can only evaluate what you put in front of them. Work that happened but wasn’t written down doesn’t count.
A mid-year compliance checklist
Use this as a quick self-audit. These are the questions a NYSDFS examiner is likely to ask first.
- Is your asset inventory current as of today, not just the certification-date snapshot?
- Have any new vendors been added since January? If yes, did they go through your Third Party Risk Management process?
- When was your last vulnerability assessment? Is there a documented remediation plan with status?
- Is annual penetration testing scheduled? Is there a report from the last one, with follow-up documented?
- Is MFA enabled on all external-facing accounts, remote access, and privileged accounts? (Not just the ones that were easy.)
- When was your incident response plan last tested? Is there documentation of the test?
- Is your Qualified Individual / CISO in place, and have they reported to your board this year?
If you can answer “yes” and produce documentation for each of these, you’re in solid shape. If any answer is “no” or “I think so, but I’m not sure,” that’s your mid-year work.
What happens if NYSDFS comes calling
Most covered entities will face an examination before they face an enforcement action. Examinations typically begin with a document request: your risk assessment, your cybersecurity policy, your Third Party Risk Management documentation, evidence of control implementation. Examiners work from what you give them.
The organizations that come through examinations cleanly built their compliance program for their business, not for the annual certification. That means the documentation was there before the examiner asked, because the work had been getting done all along.
Demonstrating that you’ve identified gaps and are actively working through them is a very different conversation with an examiner than appearing to have done nothing. Part 500 gives covered entities room to work through remediation, but not room to discover the gaps for the first time during an exam.
If NYSDFS comes calling, give us a call. We’ve been through this with customers and know what examiners look for. The earlier in the process we’re involved, the better.
The bottom line
The April certification was the accountability moment. What happens in the months between certifications is what the regulation is actually measuring.
Mid-year is a reasonable time to check the five areas above and make sure the program you certified is the program you’re actually running. Nothing dramatic has to be happening. The organizations that find gaps before an examiner does are the ones who looked.
Want to understand if you’re staying on track with NYSDFS? We’re Happy to Help.
Frequently asked questions
Does NYSDFS Part 500 apply to my small firm?
Part 500 covers entities licensed, registered, or chartered under New York banking, insurance, or financial services law. A limited exemption applies to firms with fewer than 10 employees, less than $5 million in gross annual revenue, and less than $10 million in year-end total assets. Firms that qualify can apply for the limited exemption and are subject to reduced requirements — but not zero requirements.
I filed the April certification. Am I done for the year?
No. The certification covers prior-year compliance. The controls it references — MFA, Third Party Risk Management, vulnerability assessments, incident response testing — are ongoing requirements. They need to be maintained, documented, and practiced throughout the year.
What is the most common finding in a NYSDFS examination?
Incomplete Third Party Risk Management documentation and gaps in vulnerability assessment remediation tracking come up frequently. The issue is usually not that organizations skipped the control — it’s that they didn’t document what they did. Examiners can only evaluate what’s in front of them.
Do I need a Chief Information Security Officer?
Part 500 requires a qualified individual responsible for your cybersecurity program. That person can be internal or external. Smaller covered entities that don’t have a dedicated internal CISO often work with an external cybersecurity firm to fill that role. What the regulation doesn’t allow is leaving the position vacant.
What does a NYSDFS examination actually look like?
Typically, it starts with a document request: your risk assessment, policies, evidence of control implementation, and Third Party Risk Management records. This is usually followed by a virtual or in-person meeting. Examiners are thorough but reasonable. Organizations that come prepared with organized documentation — and that can explain what they’ve done and why — generally have straightforward examinations.



