CiberLATAMbywhalemate

NYDFS tightens its cybersecurity framework

NYDFS keeps its cybersecurity resource center and 23 NYCRR Part 500 active, while guidance also tracks GLBA and PCI DSS changes.

Whalemate Labs · AI-assisted researchAug 1, 20263 min read

The official NYDFS notice keeps a cybersecurity resource center available for regulated entities and confirms an active compliance framework under 23 NYCRR Part 500. Independent technical guidance consulted for this report adds that the Second Amendment to that rule, adopted in November 2023, moved through phased obligations through November 2025 and is now fully in effect in 2026.

NYDFS and the state of compliance

The New York State Department of Financial Services’ official notice maintains a cybersecurity resource center for regulated entities and reflects an active compliance framework under 23 NYCRR Part 500. Independent technical guidance reviewed for this note adds that the Second Amendment to that regulation, adopted in November 2023, introduced staggered obligations through November 2025 and that, in 2026, those requirements are now fully in force.

That New York framework remains a direct reference point for financial institutions with a US footprint, including because of the reach its cited sources assign to third-party service providers. Petronella Technology Group says the rule applies to outside providers and requires CISO leadership, periodic testing, and encryption of nonpublic information both in transit and at rest. Wiz likewise says NYDFS imposes obligations on third-party providers for licensed institutions.

Other rules shaping the landscape

DPO Consulting’s guide summarizes GLBA as including the Privacy Rule and the Safeguards Rule for the handling and protection of consumers’ financial information. The same source says 23 NYCRR 500 requires a cybersecurity program, risk assessment, and annual compliance certification, along with a 72-hour deadline for cybersecurity incident notification.

Petronella adds that, for public issuers, the SEC requires disclosure of material incidents on Form 8-K within four business days after materiality is determined. In payments, HYPR’s technical guidance places PCI DSS v4.0.1 under mandatory compliance as of March 31, 2025.

HYPR also reports that the FFIEC Cybersecurity Assessment Tool was officially retired on August 31, 2025, and that financial institutions should use the NIST Cybersecurity Framework 2.0 and CISA Cybersecurity Performance Goals as primary self-assessment tools. Atlas Systems, meanwhile, offers a broader view of the set of rules that often overlap in this sector, although the specific facts in this report are defined by the technical sources consulted.

For institutions in Argentina and Mexico that operate with correspondents or subsidiaries in the US financial system, the practical takeaway is that privacy, data safeguards, risk management, incident reporting, and third-party standards now coexist across multiple regulatory frameworks that are already in effect.

Sources

View all