Person at keyboard signing in securely to PC

Cybersecurity Requirements for Regulated Entities

Information about New York's Cybersecurity Regulation requirements.
Cybersecurity Requirements for Regulated Entities
SHARE

Overview

Which sections of the Cybersecurity Regulation apply to a Covered Entity depends on whether the Covered Entity qualifies for any exemption in Section 500.19 of the regulation or is a “Class A Company” as defined in Section 500.1(e). 

Select the appropriate section in the menu on the left learn more about which sections apply to each entity type.

Small Business Covered Entities (Section 500.19(a))

The following table outlines what sections of the regulation a Covered Entity is exempt from and must comply with if it qualifies for a Section 500.19(a) exemption.

Compliance Requirements:Exempt Requirements:
Cybersecurity program (500.2(a), (b), (d) and (e))Independent audits – for Class A Companies (500.2(c))
Cybersecurity policy (500.3)Cybersecurity governance (500.4)
Access privileges and management (500.7(a) and (b))Vulnerability management (500.5)
Risk Assessment (500.9)Audit trail (500.6)
Third-Party Service Provider security policy (500.11)Privileged access management and blocking commonly used passwords – for Class A Companies (500.7(c))
Multi-Factor Authentication (500.12)Application security (500.8)
Asset inventory and data retention requirements (500.13)Cybersecurity personnel and intelligence (500.10)
Provide cybersecurity awareness training (500.14(a)(3))Monitor user activity (500.14(a)(1))
Notices to superintendent (500.17)Implement risk-based controls to protect against malicious code (500.14(a)(2))
 Endpoint detection and response and centralized logging and security event alerting solutions – for Class A Companies (500.14(b))
 Encryption of Nonpublic Information (500.15)
 Incident response and business continuity management (500.16)

Other Limited Exempt Companies (Sections 500.19(c) and 500.19(d))

The table below outlines what sections of the regulation a Covered Entity is exempt from and must comply with if it qualifies for a Section 500.19(c) or (d) exemption.

Compliance Requirements:Exempt Requirements:
Risk Assessment (500.9)Cybersecurity program (500.2)
Third-Party Service Provider security policy (500.11)Cybersecurity policy (500.3)
Asset inventory and data retention requirements (500.13)

 
Cybersecurity governance (500.4)
Notices to superintendent (500.17)Vulnerability management (500.5)
 Audit trail (500.6)
 Access privileges and management (500.7)
 Application security (500.8)
 Cybersecurity personnel and intelligence (500.10)
 Multi-Factor Authentication (500.12)
 Monitoring and training (500.14)
 Encryption of Nonpublic Information (500.15)
 Incident response and business continuity management (500.16)

Standard Companies (not exempt or Class A)

The following table outlines what sections of the regulation a Covered Entity is exempt from and must comply with if it is a Standard Company (a company that does not qualify for any exemption or as a Class A Company).

Compliance Requirements:Exempt Requirements:
Cybersecurity program (500.2(a), (b), (d) and (e))Independent audits – for Class A Companies (500.2(c))
Cybersecurity policy (500.3)Privileged access management and blocking commonly used passwords – for Class A Companies (500.7(c))
Cybersecurity governance (500.4)Endpoint detection and response and centralized logging and security event alerting solutions – for Class A Companies (500.14(b))
Vulnerability management (500.5) 
Audit trail (500.6) 
Access privileges and management (500.7(a) and (b)) 
Application security (500.8) 
Risk Assessment (500.9) 
Cybersecurity personnel and intelligence (500.10) 
Third-Party Service Provider security policy (500.11) 
Multi-Factor Authentication (500.12)

 
 
Asset inventory and data retention requirements (500.13)

 
 
Monitoring and training (500.14(a)) 
Encryption of Nonpublic Information (500.15) 
Incident response and business continuity management (500.16) 
Notices to superintendent (500.17) 

Class A Companies (as defined in Section 500.1(e))

The following table outlines what sections of the regulation that apply to Class A Companies without exemptions.

Compliance Requirements:
Cybersecurity program (500.2, including 500.2(c) – Independent audits)
Cybersecurity policy (500.3)
Cybersecurity governance (500.4)
Vulnerability management (500.5)
Audit trail (500.6)
Access privileges and management (500.7 including 500.7(c) - Privileged access management and blocking commonly used passwords)
Application security (500.8)
Risk Assessment (500.9)
Cybersecurity personnel and intelligence (500.10)
Third-Party Service Provider security policy (500.11)
Multi-Factor Authentication (500.12) 
Asset inventory and data retention requirements (500.13)
Monitoring and training (500.14 including 500.14(b) - Endpoint detection and response and centralized logging and security event alerting solutions)
Encryption of Nonpublic Information (500.15)
Incident response and business continuity management (500.16)
Notices to superintendent (500.17)

Questions?

Visit our FAQs About the Cybersecurity Regulation and Compliance. If you still have questions or need help, email [email protected].