Skip to content
    Back to Regulatory Radar
    ImportantFramework UpdateNovember 1, 2025

    NYDFS Part 500 Second Amendment Final Phase: Universal MFA and Asset Inventory in Effect

    On November 1, 2025, the final transitional period of the Second Amendment to the New York Department of Financial Services cybersecurity regulation (23 NYCRR Part 500) expired under section 500.22(d)(4). Covered entities must now use multi-factor authentication for any individual accessing any of their information systems under section 500.12, with a narrower scope only for entities qualifying for the limited exemption. Section 500.13(a) simultaneously took effect, requiring written policies and procedures that produce and maintain a complete, accurate, and documented asset inventory tracking owner, location, classification, support expiration date, and recovery time objectives.

    NYDFS 500NIST CSFFinTechSaaS

    Key Analytics

    November 1, 2025
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    2
    Frameworks Affected

    Impact Analysis

    With this phase, every requirement of the amended regulation is fully enforceable for DFS-licensed banks, insurers, money transmitters, and virtual currency businesses; there are no remaining grace periods. The annual certification filed by April 15, 2026 under section 500.17(b) was the first to cover a compliance period that included these requirements, and each certification must be backed by data and documentation sufficient to demonstrate material compliance. Entities relying on compensating controls in place of MFA need written CISO approval and at least annual reviews of those controls. Vendors serving DFS-regulated clients should expect MFA coverage and asset inventory practices to surface in due diligence questionnaires.

    Recommended Actions

    • Verify MFA is enforced for every individual accessing any information system, including remote access, cloud and third-party applications holding nonpublic information, and privileged accounts
    • Obtain written CISO approval for any compensating controls used in place of MFA and schedule reviews at least annually per section 500.12(b)
    • Implement written asset inventory policies that track owner, location, classification or sensitivity, support expiration date, and recovery time objectives per section 500.13(a)
    • Define and document the frequency for updating and validating the asset inventory, and assign ownership for keeping it current
    • Confirm the data and documentation behind your April 15 annual filing under section 500.17(b) actually demonstrates material compliance with the fully phased-in regulation

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Moderate70-150 hours
    Key Workstreams
    • Close MFA coverage gaps on cloud and third-party applications holding nonpublic information
    • Extend the asset inventory to the full 500.13(a) attribute set and update cadence
    • Compensating control approvals and annual review scheduling per 500.12(b)

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 70-150 hours
    Start cold under pressureSignificant · 160-340 hours

    Roughly 90 to 190 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events