Keyfactor Tech Days 2027 – Be Part of The Trust Security Conference in San Diego Register now!

NYDFS 23 NYCRR Part 500:

Cryptography for Regulated Financial Services Companies

Updated: August 24, 2026
RegionNew York State applies extraterritorially to any organization operating under a license, registration, charter, or similar authorization regardless of where it is headquartered
ApplicabilityCovered Entities: banks, insurers, licensed lenders, and virtual currency businesses regulated by the New York Department of Financial Services Class A Companies: the largest covered entities, subject to independent audits, privileged access management, and endpoint detection and response requirements Senior Governing Body and CISO: personally liable through the dual-signature annual certification
Relevant sectionsSection 500.15: Encryption of nonpublic information Section 500.12: Multi-factor authentication Section 500.17: Notification and annual certification of material compliance

Overview

The NYDFS Cybersecurity Regulation, first enacted in 2017, was substantially rewritten by the Second Amendment, effective November 1, 2023, and phased in through November 1, 2025. Every transition period has now passed, and the amended requirements are fully enforceable.

Section 500.15 requires encryption of nonpublic information both at rest and in transit. Where encryption is infeasible, the CISO must approve effective compensating controls in writing, and that approval must be reviewed at least annually. Section 500.12 now requires multi-factor authentication for any individual accessing any information system, regardless of role, location, or device, with NYDFS’s July 2025 guidance specifically flagging SMS and push-based authentication as weaker options that warrant careful risk-based justification.

Why it matters 

NYDFS has levied fines up to $30 million for cybersecurity compliance failures, and the Second Amendment introduced personal liability: the annual Certification of Material Compliance must be signed by both the covered entity’s highest-ranking executive and its CISO, due April 15 each year and supported by documentation retained for five years.

Class A Companies, the largest regulated entities, face additional obligations, including independent audits, privileged access management, and endpoint detection and response, on top of the baseline encryption and authentication requirements that apply to every covered entity.

How this maps to cryptography 

NYDFS 23 NYCRR Part 500 addresses cryptography through several interlocking control areas. The key areas with direct cryptographic implications are:

SectionFunctionWhat it saysSupporting Keyfactor Products
Section 500.15Encryption of Nonpublic InformationEncryption of nonpublic information at rest and in transit, with CISO-approved compensating controls documented and reviewed at least annually where encryption is infeasible.EJBCA
Section 500.12MFA for All System AccessCertificate-based, phishing-resistant multi-factor authentication for every individual accessing any information system, addressing NYDFS’s guidance that SMS and push-based methods carry known weaknesses.EJBCA
Section 500.7Privileged Access and Key CustodyPrivileged access management tied to cryptographic credential issuance, enforcing least privilege for administrators of keys and certificates.Keyfactor Command
Section 500.13Asset and Certificate InventoryAsset inventory extended to certificates and cryptographic key material supporting systems that hold nonpublic information.Keyfactor Command
Section 500.8Secure Application DevelopmentCode-signing controls integrated into secure development practices for in-house applications processing nonpublic information.SignServer
Section 500.17(b)Annual Certification EvidenceA consolidated evidence package on cryptographic control status supporting the CEO and CISO dual-signature certification.AgileSec

Audit readiness

Assessments and examinations, whether self-conducted, performed by a regulator, or reviewed by an independent assessor, focus on demonstrated evidence rather than policy statements alone. Key areas that examiners and assessors commonly probe:

  • Encryption Coverage and Compensating Controls:  Is nonpublic information encrypted at rest and in transit, with any CISO-approved compensating controls documented and reviewed annually?
  • Universal MFA Coverage:  Since November 1, 2025, is MFA enforced for every individual accessing any information system, with weaker methods risk-justified in writing?
  • Certificate and Key Inventory Tied to NPI Systems:  Does the asset inventory required under Section 500.13 identify the certificates and keys protecting nonpublic information?
  • CISO Written Approvals:  Are compensating-control approvals and other CISO determinations documented and revisited at least annually?
  • Class A Enhanced Controls:  For Class A Companies, is there evidence of independent audits, privileged access management, and EDR coverage?
  • Certification Package Retention:  Is supporting documentation for the annual certification retained for the required five years?