Overview
Covered Entities may qualify to be exempt from some or all of the requirements of the Cybersecurity Regulation.
- Entities that qualify for a full exemption do not need to comply with any requirements of the Cybersecurity Regulation.
- Entities that qualify for a limited exemption need to comply with some requirements of the Cybersecurity Regulation.
This section of the Cybersecurity Resource Center addresses the types of exemptions available, when Covered Entities qualify for an exemption, and the requirements with which exempt Covered Entities must comply.
For help determining whether you qualify for an exemption, use the “Am I Exempt from DFS's Cybersecurity Regulation?” Flowchart (PDF).
Full Exemptions
Covered Entities that qualify for an exemption under to Section 500.19(b), Section 500.19(e), or Section 500.19(g) do not need to comply with any sections of the Cybersecurity Regulation.
Covered Entities that qualify for an exemption under Sections 500.19(b) or (e) must submit a Notice of Exemption to the Department.
- Section 500.19(b) Exemption: To qualify for a Section 500.19(b) exemption, a Covered Entity must be an employee, agent, wholly owned subsidiary, representative, or designee of another DFS-regulated business, and all aspects of the Covered Entity’s business must be fully covered by the cybersecurity program of the other DFS-regulated business.
- Section 500.19(e) Exemption: To qualify for a Section 500.19(e) exemption, a Covered Entity must be an individual insurance broker subject to Insurance Law Section 2104 who (1) does not operate, maintain, use or control any Information Systems, and that does not, and is not required to control, own, access, generate, receive, or possess Nonpublic Information; (2) has not, for anything of value, acted or aided in any manner in soliciting, negotiating, or selling any policy or contract or in placing risks or taking out insurance on behalf of another person for at least one year; and (3) does not otherwise qualify as a Covered Entity (for example, does not hold another type of license).
- Section 500.19(g) Exemption: To qualify for a Section 500.19(g) exemption, a Covered Entity must be:
- a charitable annuity society,
- a risk retention group not chartered in NY,
- an accredited reinsurer, certified reinsurer, or recognized reciprocal jurisdiction reinsurer pursuant to 11 NYCRR Part 125
- an individual insurance agent placed in inactive status under Insurance Law Section 2103, or
- an individual mortgage loan originator placed in inactive status under Banking Law Section 599-i.
Note: A Covered Entity that meets one or more of these requirements is not exempt if it maintains another DFS license. Unlike other exemptions, Covered Entities that qualify for an exemption under Section 500.19(g) do not need to submit a Notice of Exemption.
Limited Exemptions
Covered Entities that qualify for a limited exemption pursuant to Section 500.19(a), Section 500.19(c), or Section 500.19(d) need to comply with some of the Cybersecurity Regulation’s requirements.
- Section 500.19(a) Limited Exemption: A Covered Entity qualifies for a Section 500.19(a) limited exemption if any one of the following is true:
- A Covered Entity and its Affiliates combined have less than 20 employees and independent contractors; or
- A Covered Entity has less than $7,500,000 in gross annual revenue in each of the last 3 fiscal years from all of its business operations, wherever located, and its Affiliates’ New York business operations; or
- A Covered Entity and its Affiliates combined have less than $15,000,000 in year-end total assets.
“Affiliate” is defined broadly in Section 500.1(a) of the Cybersecurity Regulation as any Person that controls, is controlled by, or is under common control with another Person. “Control” in this context means the possession, direct or indirect, of the power to direct or cause the direction of the management and policies of a Person, whether through the ownership of stock of such Person or otherwise.
- Section 500.19(c) Limited Exemption: To qualify for a Section 500.19(c) limited exemption, a Covered Entity must not directly or indirectly operate, maintain, utilize, or control any Information Systems, and must not be required to directly or indirectly control own, access, generate, receive, or possess Nonpublic Information.
- Section 500.19(d) Limited Exemption: To qualify for a Section 500.19(d) limited exemption, a Covered Entity must be a captive insurance company that does not and is not required to directly or indirectly control, own, access, generate, receive, or possess Nonpublic Information other than information relating to its corporate parent company or Affiliates.
Requirements for Exempt Covered Entities
Covered Entities that qualify for either a 500.19(b) or 500.19(e) full exemption must submit a Notice of Exemption. The Notice of Exemption remains valid for as long as the Covered Entity qualifies for the exemption (i.e., Covered Entities do not need to re-submit a Notice of Exemption every year).
Covered Entities that no longer qualify for a full exemption must terminate their exemption as soon as reasonably possible. Section 500.19(h) requires Covered Entities to comply with all applicable requirements of the Cybersecurity Regulation within 180 days from the date they no longer qualify for an exemption.
Covered Entities that qualify for a limited exemption under Sections 500.19(a), (c), or (d) must:
- Submit a Notice of Exemption;
- Comply with applicable sections of the Cybersecurity Regulation; and
- Submit an annual compliance notification each year regarding compliance with the Cybersecurity Regulation during the previous calendar year.
Section 500.19(a) Sections
The table below lists the sections of the regulation with which Covered Entities qualifying for an exemption pursuant to Section 500.19(a) have to comply, and those with which they do not have to comply.
| Must comply with: | Do not have to comply with: |
|---|---|
| Cybersecurity program (500.2(a), (b), (d) and (e)) | Independent audits - for Class A Companies (500.2(c)) |
| Cybersecurity policy (500.3) | Cybersecurity governance (500.4) |
| Access privileges and management (500.7(a) and (b)) | Vulnerability management (500.5) |
| Risk assessment (500.9) | Audit trail (500.6) |
| Third-party service provider security policy (500.11) | Privileged access management and blocking commonly used passwords – for Class A Companies (500.7(c)) |
| Multi-factor authentication (500.12) | Application security (500.8) |
| Asset management and data retention requirements (500.13) | Cybersecurity personnel and intelligence (500.10) |
| Provide cybersecurity awareness training (500.14(a)(3)) | Monitor user activity (500.14(a)(1)) |
| Submit Notices to superintendent (500.17) | Implement risk-based controls to protect against malicious code (500.14(a)(2)) |
| Monitoring and training – for Class A Companies (500.14(b)) | |
| Encryption of nonpublic information (500.15) | |
| Incident response and business continuity management (500.16) |
Section 500.19(c) or Section 500.19(d) Exemptions
The table below lists the sections of the regulation with which Covered Entities qualifying for an exemption pursuant to Section 500.19(c) or Section 500.19(d) must comply, and those with which they do have to comply.
| Must comply with: | Do not have to comply with: |
|---|---|
| Risk assessment (500.9) | Cybersecurity program (500.2) |
| Third-party service provider security policy (500.11) | Cybersecurity policy (500.3) |
| Access management and data retention requirements (500.13) | Cybersecurity governance (500.4) |
| Notices to superintendent (500.17) | Vulnerability management (500.5) |
| Audit trail (500.6) | |
| Access privileges and management (500.7) | |
| Application security (500.8) | |
| Cybersecurity personnel and intelligence (500.10) | |
| Multi-factor authentication (500.12) | |
| Monitoring and training (500.14) | |
| Encryption of nonpublic information (500.15) | |
| Incident response and business continuity management(500.16) |
Notice of Exemption
Covered Entities that qualify for exemptions under Section 500.19(a)-(e) must submit a Notice of Exemption. The Notice of Exemption remains valid for as long as the Covered Entity qualifies for the exemption (i.e., Covered Entities do not need to re-submit a Notice of Exemption every year).
Covered Entities that qualify for a full exemption pursuant to Section 500.19(g) do not need to submit a Notice of Exemption because this exemption is based on a status for which DFS is already aware, such as the Covered Entities’ license type or appointment status.
Visit Cybersecurity Submissions to learn how and get started.
Termination of Exemption
Covered Entities that no longer qualify for an exemption must terminate any previously filed Notices of Exemption as soon as reasonably possible and must come into compliance with all applicable requirements of the Cybersecurity Regulation within 180 days from the date they cease to qualify for the exemption.
Visit Cybersecurity Submissions to learn how and get started.
Questions?
Visit our FAQs About the Cybersecurity Regulation and Compliance. If you still have questions regarding the Cybersecurity Regulation or compliance with Part 500, email [email protected].
Visit the DFS ID page to learn more about using DFS ID and MFA to sign into the DFS Portal.