NYDFS 23 NYCRR Part 500:
Cryptography for Regulated Financial Services Companies
| Region | New York State applies extraterritorially to any organization operating under a license, registration, charter, or similar authorization regardless of where it is headquartered |
| Applicability | Covered Entities: banks, insurers, licensed lenders, and virtual currency businesses regulated by the New York Department of Financial Services Class A Companies: the largest covered entities, subject to independent audits, privileged access management, and endpoint detection and response requirements Senior Governing Body and CISO: personally liable through the dual-signature annual certification |
| Relevant sections | Section 500.15: Encryption of nonpublic information Section 500.12: Multi-factor authentication Section 500.17: Notification and annual certification of material compliance |
Overview
The NYDFS Cybersecurity Regulation, first enacted in 2017, was substantially rewritten by the Second Amendment, effective November 1, 2023, and phased in through November 1, 2025. Every transition period has now passed, and the amended requirements are fully enforceable.
Section 500.15 requires encryption of nonpublic information both at rest and in transit. Where encryption is infeasible, the CISO must approve effective compensating controls in writing, and that approval must be reviewed at least annually. Section 500.12 now requires multi-factor authentication for any individual accessing any information system, regardless of role, location, or device, with NYDFS’s July 2025 guidance specifically flagging SMS and push-based authentication as weaker options that warrant careful risk-based justification.
Why it matters
NYDFS has levied fines up to $30 million for cybersecurity compliance failures, and the Second Amendment introduced personal liability: the annual Certification of Material Compliance must be signed by both the covered entity’s highest-ranking executive and its CISO, due April 15 each year and supported by documentation retained for five years.
Class A Companies, the largest regulated entities, face additional obligations, including independent audits, privileged access management, and endpoint detection and response, on top of the baseline encryption and authentication requirements that apply to every covered entity.
How this maps to cryptography
NYDFS 23 NYCRR Part 500 addresses cryptography through several interlocking control areas. The key areas with direct cryptographic implications are:
| Section | Function | What it says | Supporting Keyfactor Products |
| Section 500.15 | Encryption of Nonpublic Information | Encryption of nonpublic information at rest and in transit, with CISO-approved compensating controls documented and reviewed at least annually where encryption is infeasible. | EJBCA |
| Section 500.12 | MFA for All System Access | Certificate-based, phishing-resistant multi-factor authentication for every individual accessing any information system, addressing NYDFS’s guidance that SMS and push-based methods carry known weaknesses. | EJBCA |
| Section 500.7 | Privileged Access and Key Custody | Privileged access management tied to cryptographic credential issuance, enforcing least privilege for administrators of keys and certificates. | Keyfactor Command |
| Section 500.13 | Asset and Certificate Inventory | Asset inventory extended to certificates and cryptographic key material supporting systems that hold nonpublic information. | Keyfactor Command |
| Section 500.8 | Secure Application Development | Code-signing controls integrated into secure development practices for in-house applications processing nonpublic information. | SignServer |
| Section 500.17(b) | Annual Certification Evidence | A consolidated evidence package on cryptographic control status supporting the CEO and CISO dual-signature certification. | AgileSec |
Audit readiness
Assessments and examinations, whether self-conducted, performed by a regulator, or reviewed by an independent assessor, focus on demonstrated evidence rather than policy statements alone. Key areas that examiners and assessors commonly probe:
- Encryption Coverage and Compensating Controls: Is nonpublic information encrypted at rest and in transit, with any CISO-approved compensating controls documented and reviewed annually?
- Universal MFA Coverage: Since November 1, 2025, is MFA enforced for every individual accessing any information system, with weaker methods risk-justified in writing?
- Certificate and Key Inventory Tied to NPI Systems: Does the asset inventory required under Section 500.13 identify the certificates and keys protecting nonpublic information?
- CISO Written Approvals: Are compensating-control approvals and other CISO determinations documented and revisited at least annually?
- Class A Enhanced Controls: For Class A Companies, is there evidence of independent audits, privileged access management, and EDR coverage?
- Certification Package Retention: Is supporting documentation for the annual certification retained for the required five years?
TAKE THIS TO MANAGEMENT
Every transition period under the Second Amendment closed on November 1, 2025. There is no remaining grace period: encryption of nonpublic information, universal MFA, and the annual dual-signature certification are all fully enforceable now, and NYDFS has already levied fines up to $30 million against organizations that fell short.
The certification itself creates personal exposure for our CEO and CISO. Before either of them signs, we need documentation showing where nonpublic information is encrypted, where a CISO-approved compensating control stands in for encryption, and that our MFA coverage has no gaps, retained in a form we could hand a DFS examiner without notice.


