NYDFS Cybersecurity Regulation 2026: The April 15 Certification Deadline and Your Records Obligations
Arhivix is celebrating 2 years: one system for over 500 companies. Register and try free for 14 days

NYDFS Cybersecurity Regulation 2026: The April 15 Certification Deadline and Your Records Obligations

New York-regulated financial firms face an April 15, 2026 certification deadline under 23 NYCRR 500, and the underlying recordkeeping rules are catching companies off guard.

August 17, 2026 Arhivix Team 6 min
NYDFS Cybersecurity Regulation 2026: The April 15 Certification Deadline and Your Records Obligations

A compliance officer's April surprise

In February 2026, the compliance lead at a mid-sized New York-licensed money transmitter pulled up the DFS portal to file the firm's Annual Certification of Compliance and found a problem. The certification, due April 15, now requires the Chief Information Security Officer and a senior officer to jointly attest that the company met every requirement of 23 NYCRR 500, the New York Department of Financial Services Cybersecurity Regulation, including provisions that only became fully enforceable a few months earlier. Pulling together five years of audit trail records, a current asset inventory, and evidence of incident response testing across departments that had never been asked for this level of documentation before turned a routine filing into a six-week scramble. That scenario is playing out at hundreds of firms across the state this year, and it points to a document management problem that predates the deadline itself.

What 23 NYCRR 500 actually requires

23 NYCRR 500 has applied to DFS-licensed institutions since 2017, but the Second Amendment, adopted in November 2023, added a much heavier documentation burden and phased it in through November 1, 2025. Covered entities, which include state-chartered banks, insurance companies and agents, mortgage lenders and servicers, money transmitters, virtual currency businesses, and investment advisers licensed or registered with DFS, must now maintain a written asset inventory covering all information systems, enforce multi-factor authentication across nearly all access points, and keep an incident response plan that is actually tested, not just drafted and filed away.

The Annual Certification of Compliance, filed by April 15 each year for the prior calendar year, now has to reflect all of that. A covered entity files either a Certification of Material Compliance or, if it cannot honestly make that claim, an Acknowledgment of Noncompliance identifying the specific gaps and a remediation timeline. Both documents must be signed personally by the CISO and a senior officer, which means neither party can sign without underlying records to back up the attestation.

The retention rules hiding inside the regulation

Section 500.6 of the regulation is where the document management burden really sits. It requires covered entities to maintain audit trail systems capable of reconstructing material financial transactions, with those transaction records kept for not fewer than five years, and separately requires records that log and alert on cybersecurity events to be retained for not fewer than three years. Section 500.13 adds a parallel obligation: entities must have documented policies for the secure disposal of nonpublic information that is no longer needed for business purposes, which means a defensible destruction schedule, not just deletion whenever someone gets around to it.

In practice, this means three separate retention clocks running at once inside the same organization: five years for transaction-level audit records, three years for security event logs, and whatever statutory period applies to the underlying customer or transaction data itself under other state and federal rules. Firms that store these records in scattered systems, personal drives, or vendor tools with no unified retention policy typically cannot answer basic questions during an exam, such as producing a complete audit trail for a transaction from three years ago within a reasonable timeframe.

Enforcement has real teeth

DFS is not treating this as a paperwork exercise. Since 2021, the department has entered consent orders with 27 entities over cybersecurity regulation violations, resulting in more than $144 million in penalties, with $63.3 million of that total coming in 2024 and 2025 alone. The largest 2025 action against Block, Inc. resulted in a $40 million penalty tied in part to failures in maintaining board-reviewed third-party risk and business continuity controls, and Healthplex, Inc., a licensed insurance agent, paid a $2 million penalty in August 2025 for cybersecurity regulation violations. Consent orders in this space consistently cite gaps in documentation, not just technical failures: missing risk assessments, incomplete asset inventories, and an inability to produce audit trail records on request.

What this means for document practices before the next filing

Firms preparing for the April 2026 certification, and every certification after it, need four things organized and retrievable in one place: a current, dated asset inventory; incident response plan documentation with evidence of testing; audit trail records segmented by the five-year and three-year retention clocks under Section 500.6; and a written, followed data disposal policy under Section 500.13. Treating these as a scattered collection of spreadsheets and email attachments makes the annual certification harder every single year, since the CISO and senior officer signing the form are personally attesting to records they may not be able to locate on short notice. Building a centralized, auditable record of these documents before the next certification cycle is the difference between a routine filing and another six-week scramble.