AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

NYDFS Part 500 for the Small Covered Entity: MFA Everywhere, an Asset List, and an April Signature

NYDFS Part 500 requirements for a small agency or broker: universal MFA since 1 November 2025, an asset inventory, and the April certification the owner signs.

Sam KhanSam Khan The Cyber ExpertFounder and CEOSeptember 2, 2026 · 6 min read

What "limited exemption" turned out to mean

The owner of an eight-person independent insurance agency in Buffalo has filed the same DFS exemption notice every year since 2018. She reads "limited exemption" the way most people would: exempt, with limits. The agency's IT is a local firm that comes when called. Two producers work from home through a remote desktop connection the IT firm set up in 2020. The password has not changed since.

In November a broker partner's compliance officer sends a courtesy email. The final phase of the amended regulation is in effect, she writes, and it applies to limited-exempt entities too: multifactor authentication for anyone accessing the agency's systems, a written asset inventory, and the annual certification, due 15 April, signed by the owner personally. She attaches the regulation section and highlights the line.

The owner asks the IT firm to check the remote desktop logs before she replies. The firm calls back the next afternoon. The connection accepted a successful login at 2:14 on a Sunday morning, from an address in a country where no one at the agency has ever been. It stayed connected for eleven minutes. Nothing appears to have been taken. The firm cannot say that with confidence, because the logs only go back thirty days.

She has four months to sign a document that says the agency materially complied. She now knows two things it did not do and one thing she cannot prove.

What the heck does this mean

Part 500 is 23 NYCRR 500, the New York Department of Financial Services cybersecurity regulation. It applies to anyone DFS licenses: banks and insurers, and also the independent agency, the mortgage broker, the money transmitter and the small lender.

A covered entity is any of those licensees. The limited exemption, under section 500.19, lets small entities skip some requirements based on headcount, revenue and assets. It does not skip MFA, the asset inventory, access controls, the risk assessment, vendor oversight, training or the certification.

The Second Amendment is the 2023 rewrite of the regulation. Its requirements arrived in phases, and the last phase, universal MFA and asset inventory procedures, took effect on 1 November 2025.

Universal MFA means every person who accesses your information systems uses a second factor, not just remote users and administrators. For an agency it means the agency management system, email, carrier portals and that remote desktop connection.

The certification of compliance is the annual filing, due 15 April, in which the senior executive and the person responsible for cybersecurity state that the entity complied for the prior year, or admit that it did not and say what they are fixing. Signing one you cannot support is a regulatory problem of its own.

The numbers that matter

Universal multifactor authentication and asset inventory procedures took effect for covered entities on 1 November 2025, under the New York Department of Financial Services' Second Amendment to Part 500. The phase-in is finished; there is no later date to wait for.

The first annual certification covering those provisions was due on 15 April 2026, per DFS's 2026 filing cycle. The next one arrives on the same date next year, and the owner signs it.

Credential abuse appeared in 39% of breaches across the full attack chain, according to the Verizon 2026 Data Breach Investigations Report. The 2:14 a.m. login is what that statistic looks like from inside an eight-person agency.

What to do this week

  1. Write the asset inventory: every laptop, phone, server, network device and cloud application, with an owner, a location, the software version and the date it was last updated. A spreadsheet is fine. A spreadsheet that exists is the requirement. (CIS 1 Inventory and Control of Enterprise Assets)
  2. Turn on MFA for the agency management system, email, every carrier portal and the remote desktop connection, for every person, this week. Then change the remote desktop password, or better, put the connection behind the MFA and close it to the open internet. (CIS 6 Access Control Management)
  3. List the accounts with administrator rights, including the IT firm's, and cut the list to the people who use them. Give the IT firm its own named accounts with MFA rather than a shared one. (CIS 5 Account Management)
  4. Set log retention to a year on the remote access system, email and the agency management system, so the next 2:14 a.m. login can be traced back further than thirty days. (CIS 6 Access Control Management)
  5. Write a one-page incident plan with names: who decides an incident has occurred, who files the DFS notice within 72 hours, who calls the carriers and the broker partners. Walk through the Sunday login as the first exercise. (CIS 17 Incident Response Management)
  6. Open an evidence folder labeled with next April's date and put this week's inventory, MFA screenshots, admin list and incident plan in it. The certification is easy to sign when the folder is full. (CIS 17 Incident Response Management)

Where AccuSights fits

Our assessment reads Part 500 for a small covered entity and tells you which sections apply under your exemption, which ones you already meet, and which ones the April signature cannot yet support. Our team implements the controls at a reasonable rate, from MFA and the asset inventory to data loss prevention, scanning and protection of the systems the producers use from home, and we keep the evidence folder filling up between filings. Take the three-minute Cyber Hygiene Test, or book 15 minutes with an engineer before you sign.

Questions people ask

Who qualifies for the Part 500 limited exemption? Small covered entities that fall under DFS's headcount, revenue and asset thresholds, and certain entities that hold a license but do not operate under it. The exemption has to be claimed by filing a notice with DFS, and it trims the list of requirements rather than removing it. A limited-exempt agency still needs a risk assessment, access controls, MFA, an asset inventory, a vendor policy, training and the annual certification.

Does Part 500 require 72-hour reporting? Yes. A covered entity must notify DFS within 72 hours of determining that a cybersecurity incident has occurred, including incidents at a vendor that affect you, and the notice is filed through the DFS portal. A separate notice applies if you make an extortion payment. The 72 hours run from the determination, which is why the incident plan needs a named person who decides, and a clock that starts when they do.

What must the annual certification include? Either a certification that the entity materially complied with Part 500 for the prior calendar year, or an acknowledgment that it did not, with the sections missed and a remediation plan with dates. It is signed by the highest-ranking executive and the person responsible for cybersecurity, filed by 15 April, and DFS expects the records behind it to be kept for five years. For an eight-person agency, the owner signs both lines.

An exemption tells you which pages of the regulation you may skip. It has never once told an attacker which door to leave alone.

Controls this post maps to

CIS 6 Access Control ManagementCIS 1 Inventory and Control of Enterprise AssetsCIS 17 Incident Response Management

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.