CiberLATAMbywhalemate

NYDFS tightens its cybersecurity framework

NYDFS keeps its cybersecurity resource center and 23 NYCRR Part 500 active, while guidance also tracks GLBA and PCI DSS changes.

Whalemate Labs · AI-assisted researchPublished:Updated 3 min read

The official NYDFS notice keeps a cybersecurity resource center available for regulated entities and confirms an active compliance framework under 23 NYCRR Part 500. Independent technical guidance consulted for this report adds that the Second Amendment to that rule, adopted in November 2023, moved through phased obligations through November 2025 and is now fully in effect in 2026.

The New York State Department of Financial Services is keeping its cybersecurity resource center active for regulated entities and maintaining the 23 NYCRR Part 500 framework, according to the official notice. Technical guidance reviewed for this report adds that the Second Amendment, adopted in November 2023, introduced phased obligations through November 2025, and that those requirements are now fully in force in 2026.

What does the NYDFS framework cover?

New York’s framework remains a direct reference point for financial institutions with a presence in the United States, including the scope its consulted sources attribute to third-party service providers. Petronella Technology Group says the regulation applies to external providers and requires CISO leadership, periodic testing, and encryption of nonpublic information both in transit and at rest.

Wiz also says the NYDFS imposes obligations on third-party providers of licensed institutions.

What other rules are part of the regulatory map?

DPO Consulting’s guide says the GLBA includes the Privacy Rule and the Safeguards Rule for the handling and protection of consumer financial information. The same source says 23 NYCRR 500 requires a cybersecurity program, risk assessment, and annual compliance certification, along with a 72-hour deadline for cybersecurity incident reporting.

Petronella adds that for public issuers, the SEC requires disclosure of material incidents in Form 8-K within four business days after materiality is determined. In the payments sector, HYPR’s technical guidance places PCI DSS v4.0.1 under mandatory compliance as of March 31, 2025.

What changed for self-assessment tools?

HYPR also says the FFIEC Cybersecurity Assessment Tool was officially withdrawn on August 31, 2025, and that financial institutions should now use NIST Cybersecurity Framework 2.0 and CISA Cybersecurity Performance Goals as their primary self-assessment tools.

Element Date/requirement Source/agency
Second Amendment to 23 NYCRR Part 500 Adopted in November 2023; phased obligations through November 2025; fully in force in 2026 Technical guidance reviewed / NYDFS
Incident notification under 23 NYCRR 500 72 hours DPO Consulting
SEC Form 8-K Within four business days after materiality is determined Petronella
PCI DSS v4.0.1 Mandatory compliance since March 31, 2025 HYPR
FFIEC Cybersecurity Assessment Tool Officially withdrawn on August 31, 2025 HYPR

Atlas Systems offers a broader view of the set of rules that often overlap in this sector, although the specific facts in this note are defined by the technical sources reviewed.

What does this mean for institutions in Argentina and Mexico?

For institutions in Argentina and Mexico that work with correspondent banks or subsidiaries in the U.S. financial system, the practical point is that privacy, data protection, risk management, incident reporting, and third-party standards all apply under different regulatory frameworks that are already in force.

Sources

View all