Skip to main content
—
Framework library
Framework module · nydfs-500

NYDFS 23 NYCRR 500

New York's cybersecurity regulation for banks, insurers, and other DFS-licensed entities — with a named CISO, board reporting, and 72-hour incident notice.

23 NYCRR 500 (2023 amendments) · NYDFS Cybersecurity Resource Center · published 2023-11-01

Standing today
Directory entry

00Answer

from the registry record
What is NYDFS 23 NYCRR 500?
New York's cybersecurity regulation for banks, insurers, and other DFS-licensed entities — with a named CISO, board reporting, and 72-hour incident notice.
Who does NYDFS 23 NYCRR 500 apply to?
NYDFS 23 NYCRR 500 applies to financial services, insurance, US-NY, per NYDFS Cybersecurity Resource Center.
What is the current version of NYDFS 23 NYCRR 500?
The current edition is 23 NYCRR 500 (2023 amendments), issued by NYDFS Cybersecurity Resource Center and published 2023-11-01. Source: https://www.dfs.ny.gov/industry_guidance/cybersecurity.
What does an assessment under NYDFS 23 NYCRR 500 require?
No control catalog has been ingested for NYDFS 23 NYCRR 500 yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

NYDFS 23 NYCRR 500 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Metadata only; the amended regulation, phased obligations, and reporting workflows are not ingested or modeled.

02Registry record

checked 2026-08-30
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Governance · Access control · Incident response · Regulator reporting
Applies to
financial services · insurance · US-NY
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30

03Version ledger

2 editions
23 NYCRR 500 (2017)Supersededdate not published
23 NYCRR 500 (2023 amendments)Current edition · supersedes 23 NYCRR 500 (2017)2023-11-01

05Change history

06Related frameworks

scored from registry facts
  1. APRA CPS 2302026 determination (effective 2026-07-01)

    Also applies to insurance · Australia's cross-industry prudential standard for operational risk, continuity of critical operations, and material service-provider risk at APRA-regulated entities. It is a binding supervisory standard, not a certification.

  2. Digital Operational Resilience ActRegulation (EU) 2022/2554

    Also applies to financial services · The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.

  3. Also applies to financial services · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

  4. Also applies to financial services · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.

NYDFS 23 NYCRR 500 | ControlFrame