Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

All US rules

NYDFS Cybersecurity Regulation

23 NYCRR Part 500 · Read 2026-08-15

In force since 2017. The second amendment took effect on 1 November 2023, with transitional dates running to November 2025.

Identifier

Identifier
23 NYCRR Part 500
Level
State NY
Status
Phased
Adopted
2017-03-01
Applies from
2023-11-01
Supervisory bodies
NYDFS

Named requirements

  • Cybersecurity program and policy

    23 NYCRR 500.2 and 500.3

    A documented programme and a policy approved by the board or a senior officer.

  • Chief Information Security Officer

    23 NYCRR 500.4

    A named officer and an annual written report to the governing body.

  • Multi-factor authentication

    23 NYCRR 500.12

    Multi-factor authentication for remote and privileged access.

  • Notice of a cybersecurity event

    23 NYCRR 500.17

    Notice to the supervisor within 72 hours, and an annual certification.

Official source

EU acts on the same ground

  • CELEX 32022L2555

    Both texts name a responsible function, require reporting to the governing body and set an early notice for significant incidents. The EU text covers essential entities, the state rule covers licensed financial firms.

United States case law

10 decisions · Read from CourtListener, Free Law Project on 2026-08-22.

Change monitoring

The row is re-read against the publisher's own publication on a fixed interval. The dates below can be checked on the spot and travel with the API response.

Change monitoring
FieldValue
RegisterNYDFS — 23 NYCRR Part 500
PublisherNew York State Department of Financial Services
Last read2026-08-15
IntervalEvery 30 days
Next re-read2026-09-14
StatusChecked against the publisher
Open the register at the publisher

Row history

Dated events concerning this exact row, newest first. No event appears here without a date in a primary source.

Row history
DateEventSource
2026-08-15Row read against the official publicationNew York State Department of Financial Services
2023-11-01Date of application according to the publisherNew York State Department of Financial Services
2017-03-01Adopted under 23 NYCRR Part 500New York State Department of Financial Services

Monitoring states when the row was checked, not how the legal position should be assessed.

The string below travels with a memo, a case file or an agent chain. The same string sits in the citation field of the API response.

23 NYCRR Part 500, NYDFS Cybersecurity Regulation. ExploreWorld Legal, https://legal.exploreworldai.com/us/regler/nydfs-cybersecurity (hämtad 2026-08-25, bevis sha256:8b861579db165d25, bygge legal-2026-08-25).

sha256:
8b861579db165d25e1a1ad8cd5bbd30696ed23e5ee633885737fb735d945341e
hämtad:
2026-08-25
source_confidence:
derived
bygge:
legal-2026-08-25
officiell källa:
https://www.dfs.ny.gov/

Derived path to the publisher. The address is built from the identifier and lands in the publisher's own register. dfs.ny.gov.

The row is a source reference with an official identifier. No legal advice and no compliance decision.

Verifiable trust signals

  • Six fixed blocks, one source per line
  • No sentence written by a language model
  • Engine version and read date on every answer
  • No customer data, no documents, no advice
  • Model card and audit published under the EU AI Act

Model cardAudit