Overview
Covered Entities must submit certain notices to the Department. There are four types of submissions required by the Cybersecurity Regulation:
- Annual Compliance Notification: Covered Entities must submit an annual notice by April 15th each year regarding their compliance (or non-compliance) with the Cybersecurity Regulation during the previous calendar year. See Section 500.17(b).
- Notice of Exemption: Covered Entities must submit a Notice of Exemption to DFS within 30 days of determining that they are exempt. See Section 500.19(f).
- Notice of a Cybersecurity Incident: Covered Entities must notify DFS of any Cybersecurity Incidents that occur at the Covered Entity, its Affiliates or a Third-Party Service Provider. See Section 500.17(a).
- Notice of Extortion Payment: Covered Entities must notify DFS if they make an extortion payment in connection with a Cybersecurity Event involving the Covered Entity. See Section 500.17(c).
DFS Portal and DFS ID
Cybersecurity submissions to DFS are made through the DFS Portal, which is accessed using DFS ID.
You will use multi-factor authentication (MFA) to log in, so be sure to have or download an authenticator app (e.g., Google Authenticator or Microsoft Authenticator) to an available mobile device before getting started. Visit our DFS ID page to learn more about DFS ID and MFA.
To get started, visit the DFS Portal and sign in using your DFS ID credentials and the MFA passcode from your phone's authenticator app.
For more information on DFS ID, including how to create a DFS ID account, visit the DFS ID page of our website. If you need assistance with DFS ID, submit a request through the DFS ID Help Form.
Submission Confirmation
Once a submission is complete, you will receive an email that includes a receipt number. The email receipt is the only confirmation of the submission that you will receive, and the receipt number is an important piece of information that should be kept. You may need the receipt number to renew your license.
If you do not receive an email from DFS after making a submission, email [email protected] with “Confirm My Submission” in the subject line. Include your name or your company’s name (as it appears on the DFS license) and one of the following for you or your company: DFS License number, NAIC number, NMLS Identification number, or DFS Institution number.
Submit an Annual Compliance Notification
All Covered Entities – other than those that qualify for a full exemption pursuant to Sections 500.19(b), (e), or (g) – must submit a notification each year by April 15 regarding their compliance with the Cybersecurity Regulation during the previous calendar year.
Covered Entities have the option of submitting either a Certification of Material Compliance or an Acknowledgment of Noncompliance. Covered Entities that qualify for a limited exemption pursuant to 500.19(a), (c), or (d) only have to certify material compliance or acknowledge noncompliance with sections of the Cybersecurity Regulation applicable to them during the previous calendar year.
Visit Cybersecurity Regulation Exemptions to see which sections are applicable to Covered Entities that qualify for limited exemptions.
Certifications of Material Compliance and Acknowledgments of Noncompliance must be signed by the Covered Entity’s highest-ranking executive and its Chief Information Security Officer (CISO). If the Covered Entity does not have a CISO, the Covered Entity’s highest-ranking executive and the Senior Officer responsible for the cybersecurity program of the Covered Entity must sign the Certification of Material Compliance and Acknowledgment of Noncompliance.
Section 500.17(b)(3) requires Covered Entities to keep all data and documentation supporting their annual compliance notifications for 5 years and provide that information to the Department upon request.
Submit a Certification of Material Compliance
Covered Entities that were materially compliant with all applicable sections of the Cybersecurity Regulation must submit a Certification of Material Compliance between January 1 and April 15 of the following calendar year.
Submit an Acknowledgment of Noncompliance
If a Covered Entity cannot certify that it was materially compliant with the Cybersecurity Regulation during the previous calendar year, it must submit an Acknowledgment of Noncompliance between January 1 and April 15, which;
- Acknowledges that, for the prior year, the Covered Entity did not materially comply with applicable sections;
- Identifies applicable sections of the Cybersecurity Regulation with which the Covered Entity did not materially comply;
- Describes the nature and extent of such noncompliance; and
- Provides a date when remediation is expected to be complete or confirmation that remediation has been completed.
Submit or Amend a Notice of Exemption
Covered Entities that determine they qualify for a full or limited exemption under Sections 500.19(a)-(e) of the Cybersecurity Regulation must submit a Notice of Exemption within 30 days of making such determination. Covered Entities that qualify for a full exemption under 500.19(g) do not need to submit a Notice of Exemption because this exemption is based on a status DFS is aware of.
Learn more about Exemptions from the Requirements of the Cybersecurity Regulation.
Submit a Notice of Exemption
Covered Entities that determine they qualify for exemptions under Sections 500.19(a)-(e) of the Cybersecurity Regulation must submit a Notice of Exemption within 30 days of making such determination. Some Covered Entities may qualify for more than one exemption. Covered Entities that qualify for more than one exemption should note all relevant exemptions on the Notice of Exemption.
Amend a Submitted Exemption
Covered Entities should amend a Notice of Exemption when their qualifications for an exemption change, but they still qualify for at least one exemption. Covered Entities must amend their Notices of Exemption through the DFS Portal.
Terminate a Filed Exemption
If Covered Entities no longer qualify for an exemption claimed on a previously submitted Notice of Exemption, they must update or terminate their Notice of Exemption through the DFS Portal as soon as reasonably possible.
Covered Entities have 180 days from the date they are no longer exempt to become fully compliant with the Cybersecurity Regulation, regardless of when the Notice of Termination is submitted with DFS.
Submitting Bulk Exemptions
Covered Entities that employ 50 or more individual Covered Entities that qualify for the same exemption may submit exemptions on behalf of those employees through the bulk submission process. Covered Entities using the bulk submission process must add and terminate exemptions when employment and exemption statuses changes.
Covered Entities that employ 50 or more individual Covered Entities and would like to request to use the bulk submission process should email the Department at [email protected] from the email address associated with their DFS ID account, and DFS will send further instructions.
Note: Covered Entities are ultimately responsible for ensuring their own compliance with the Cybersecurity Regulation. Therefore, individual Covered Entities should either (1) terminate the exemption through the DFS Portal or (2) confirm with its covering entity that changes to exemption or employment status were sent to DFS.
Confirmation and Receipt of Submissions and Terminations for Bulk Filing
The person who submits the bulk filing and the Covered Entities on whose behalf Notices of Exemption are submitted or terminated will receive an email confirmation from DFS. The email will include a receipt number and note the exemption(s) submitted or terminated. This email is the only confirmation of the submission that the submitter will receive. Retain a copy of the receipt number for future reference.
If you did not receive an email from DFS after making a submission or notice of termination, email [email protected] with “Confirm My Submission” in the subject line. Include your name or your company’s name (as it appears on the DFS license) and one of the following for you or your company: DFS License number, NAIC number, NMLS Identification number, or DFS Institution number.
Submit a Notice of a Cybersecurity Incident
Covered Entities must notify the Department as promptly as possible but in no event later than 72 hours after determining that a Cybersecurity Incident has occurred at the Covered Entity, an Affiliate, or a Third-Party Service Provider.
A Cybersecurity Incident, as defined in Section 500.1, is any act or attempt, whether successful or unsuccessful, to gain unauthorized access to, disrupt, or misuse an information system or information stored on such information system that:
- impacts the Covered Entity and requires the Covered Entity to notify any government body, self-regulatory agency, or any other supervisory body;
- has a reasonable likelihood of materially harming any material part of the normal operation(s) of the Covered Entity; or
- results in the deployment of ransomware within a material part of the Covered Entity’s Information Systems.
Submit a Notice of an Extortion Payment
Ransomware attacks continue to threaten financial services companies and their customers. DFS, like the FBI and other regulators, recommends against paying ransoms. While Covered Entities are not prohibited from making such payments, they must submit a Notice of Extortion Payment within 24 hours of making an extortion payment in connection with a Cybersecurity Event that occurred involving the Covered Entity.
In addition, within 30 days of the payment, Covered Entities must provide a written description of the reasons payment was necessary, a description of alternatives to payment considered, all diligence performed to find alternatives to payment, and all diligence performed to ensure compliance with applicable rules and regulations including those of the Office of Foreign Assets Control.
Print Detailed Instructions
-
Cybersecurity Instructions: How to Submit a Certification of Material Compliance for Entities
Detailed printable instructions for entities on how to submit a Certification of Material Compliance via the DFS Portal
Download
-
Cybersecurity Instructions: How to Submit a Certification of Material Compliance for Individual Licensees
Detailed printable instructions for individual licensees on how to submit a Certification of Material Compliance via the DFS Portal
Download
-
Cybersecurity Instructions: How to Submit an Acknowledgment of Noncompliance for Entities
Detailed printable instructions for Entities on how to submit an Acknowledgment of Noncompliance via the DFS Portal
Download
-
Cybersecurity Instructions: How to Submit an Acknowledgment of Noncompliance for Individual Licensees
Detailed printable instructions for individual licensees on how to submit an acknowledgement of noncompliance via the DFS portal.
Download
-
Cybersecurity Instructions: How to Submit or Amend a Notice of Exemption
Detailed printable instructions on how to submit or Amend a Notice of Exemption via the DFS Portal
Download
-
Cybersecurity Instructions: How to Terminate a Notice of Exemption
Detailed printable instructions on how to terminate a Notice of Exemption via the DFS Portal
Download
-
Cybersecurity Instructions: How to Report a Cybersecurity Incident
Detailed printable instructions for how to report a cybersecurity incident via the DFS Portal
Download
-
Cybersecurity Instructions: How to Report an Extortion Payment
Detailed printable instructions on how to report an Extortion Payment via the DFS Portal
Download
Questions?
Visit our FAQs About the Cybersecurity Regulation and Compliance. If you still have questions regarding the Cybersecurity Regulation or compliance with Part 500, email [email protected].
Visit the DFS ID page to learn more about using DFS ID and MFA to sign into the DFS Portal.