Financial · US Securities and Exchange Commission
SEC Regulation S-P (2024 amendments)
Written incident response program and 30-day customer notice. Smaller RIAs became subject June 3, 2026.
Who it applies to
The businesses that carry SEC Reg S-P, and the pages written for them.
Each industry page names the regulation, the obligation and the clock, tells the story of an owner in that trade, and shows what we protect for them.
Which packages satisfy it
What it asks for
In plain English, what SEC Reg S-P expects you to have in place.
- A written information security programScoped to the customer and cardholder data you hold, owned by a named individual.
- Risk assessmentDocumented, repeated on a schedule, and driving what you actually implement.
- Core controlsMFA, encryption in transit and at rest, access reviews, secure configurations, patching and logging.
- Third-party oversightService providers assessed, contracted and monitored for how they protect the data you give them.
- Incident response and noticeA written plan, rehearsed, that meets the notification windows your regulator sets.
- Testing and reportingPeriodic testing of the controls and a report to leadership or the board.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.
Questions we get about SEC Reg S-P
Do you certify SEC Reg S-P compliance?
Where do we start with SEC Reg S-P?
We also need other frameworks. Do we do SEC Reg S-P separately?
Also in financial: PCI DSS · FTC Safeguards · NYDFS 500 · FINRA · every framework by industry
Next step
Thirty minutes, an engineer, a written scope for SEC Reg S-P.
Book the demo and see how one control set carries SEC Reg S-P and everything else you owe. Or leave your details and an engineer replies within one business day.