Blog / US compliance
US compliance
The NYDFS Annual Certification: What to Have Ready in March So the 15 April Filing Takes an Afternoon
The NYDFS annual certification is due 15 April. The evidence a covered entity should collect in March for Part 500, from asset inventory to MFA and logs.
The folder she opens on 22 February
The compliance officer at a thirty-four person mortgage lender in White Plains opens last year's certification folder on a Monday morning in late February. She has done this filing before, twice, and is not worried, exactly. Curious is closer. What she wants is to see what is in there before anyone asks her.
The asset inventory is a spreadsheet. Its file properties say it was last modified in October 2024. It lists forty-one laptops; the firm bought nine more in the spring and retired six.
Multi-factor authentication: on for everyone, according to an email from the IT provider dated last March. She reads the email again. It says "all users." It does not say service accounts, and it does not say the loan origination vendor, whose support team logs in remotely to fix things twice a month using a shared account created in 2021.
Log retention on the file server holding borrower documents: thirty days, because that is the default and nobody changed it.
None of these are catastrophes. Each one is a sentence she would have to write carefully, or a thing she would have to fix, and it is 22 February. She has seven weeks. Had she opened this folder on 10 April, she would have had five days and a choice she did not want to make.
That is the entire argument of this post. The date on the calendar is 15 April. The work is in March.
What the heck does this mean
23 NYCRR Part 500 is the New York State Department of Financial Services cybersecurity regulation. If you hold a DFS licence, and that includes plenty of small mortgage lenders, insurance agencies, money transmitters and advisers who never think of themselves as banks, you are a covered entity.
The regulation's final phase has been in force since 1 November 2025. Two of the additions matter most to a firm your size: universal multi-factor authentication, and a maintained asset inventory. The annual filing is due 15 April.
Jargon translated. Covered entity: you, if DFS gave you a licence. Asset inventory: a current list of the hardware, software and cloud services your business runs on, each with an owner. Universal multi-factor authentication: a second factor for everyone who signs in, which includes the vendor logging in from another state. And the 72-hour incident notice: if a reportable cybersecurity event happens, DFS hears about it within 72 hours, which is a deadline you cannot meet if nobody knows who makes the call.
Confirm with your counsel exactly which filing your firm makes and who signs it. The rule text sets that out, and it is not identical for every covered entity. What follows is about the evidence underneath the signature, which is the same for everyone. Our Part 500 page goes through the requirement list itself.
The numbers that matter
Credential abuse was the initial access route in 13% of breaches in the Verizon 2026 Data Breach Investigations Report. That is the exact gap universal multi-factor authentication is aimed at, and the shared vendor account above is the version of it that certifications miss.
The median time to patch an internet-facing vulnerability was 43 days in the Verizon 2026 report. Six weeks of a known, published, fixable hole, on the systems most visible from outside.
The average cost of a data breach reached USD 4.99 million in IBM's 2026 Cost of a Data Breach report. A thirty-four person lender will not see that figure. It will see the version scaled to its size, plus a regulator asking what the certification was based on.
What to do this week
- Rebuild the asset inventory from the systems themselves, not from last year's spreadsheet. Export the device list from your management tool, the user and application list from your cloud tenant, and the subscription list from accounts payable. Reconcile the three. Accounts payable finds the software nobody told IT about. (CIS 1 Inventory and Control of Enterprise Assets)
- Produce the full list of every account that can reach your systems, split into staff, service accounts and third-party accounts. Confirm multi-factor authentication on each, and kill the shared vendor logins by giving each vendor engineer a named account. Save the export with the date on it. (CIS 6 Access Control Management)
- Check log retention on every system holding customer data this week, not in April. If the answer is thirty days by default, change it now so that by the filing date you have a period of real coverage rather than a promise. (CIS 8 Audit Log Management)
- Build the evidence folder in March, one file per requirement, named so a stranger could find it: inventory export, MFA report, retention settings, training records, vendor list, risk assessment date. Next year this folder is the filing. (CIS 1 Inventory and Control of Enterprise Assets)
- For anything not yet done, write the one-line remediation with a month attached before April arrives. "Vendor named accounts: in progress, complete by 31 May." A dated plan is a document. An intention is not. (CIS 6 Access Control Management)
- Rehearse the 72-hour notice for thirty minutes with whoever answers the phone at 6pm. Who decides it is reportable, who drafts the notice, who calls counsel, and where the numbers live if email is the thing that is down. (CIS 17 Incident Response Management)
Where AccuSights fits
We run the assessment against Part 500 as a covered entity's examiner would read it, and hand back the evidence folder rather than a findings dump: what is true today, what is not, and a dated plan for the rest. Firms across the New York metro use the Cyber Hygiene Test in February to decide how much March work is coming, and it takes three minutes. Our team implements the controls at a reasonable rate, from access reviews and logging to data loss prevention and scanning. A 15-minute call with an engineer usually settles the two questions counsel will ask.
Questions people ask
When is the NYDFS annual certification due? 15 April. The final phase of the amended 23 NYCRR Part 500 has been in force since 1 November 2025, so this is the filing where the full set of requirements, including universal multi-factor authentication and a maintained asset inventory, is in scope for the year being certified. Start the evidence work in March. Firms that begin in April end up certifying from memory, which is the worst possible basis for a signature.
What counts as an asset inventory under Part 500? A maintained record of the systems in your environment rather than a one-time spreadsheet. In practice that means hardware, software and the cloud services holding your data, each with an owner, a location and an end-of-support date, kept current as things change. The test to apply is simple: if a new laptop or a new software subscription appeared last month, does it show up in the list without anyone remembering to add it manually?
Does Part 500 really require multi-factor authentication for everyone? The amended rule moved to universal multi-factor authentication, which is a meaningful change from the older, narrower requirement. The place small firms get caught is not staff logins, which are usually covered. It is the service accounts, the vendor remote-access accounts and the legacy sign-in protocols that quietly skip it. Pull the full list of accounts that can reach your systems, including the ones that belong to other companies, and check each one.
A certification is a sentence about the past twelve months, and March is the only month left in which you can still change what that sentence says.
Controls this post maps to
CIS Controls v8.1. These are the same controls our assessment scores and the console watches.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
NYDFS Part 500 for the Small Covered Entity: MFA Everywhere, an Asset List, and an April Signature
NYDFS Part 500 requirements for a small agency or broker: universal MFA since 1 November 2025, an asset inventory, and the April certification the owner signs.
US complianceThe WISP a CPA Firm Can Write in a Week, Before the January Rush Starts
A CPA WISP for tax season: what the FTC Safeguards Rule and IRS Publication 4557 expect, the Security Six, and the PTIN attestation you already signed.
US complianceRegulation S-P Six Months In: The 30-Day Clock Runs While You Wait for the Mailbox Export
Regulation S-P six months in: where the 30-day customer notice actually goes wrong for smaller advisers, and the four records that shorten the clock.
