First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Blog/NYDFS Part 500: the 15 April 2027 certification,…

NYDFS Part 500: the 15 April 2027 certification, and the Microsoft 365 evidence you should be collecting now

2026-09-06·IT PartnerNewComplianceSecurityNYDFSMicrosoft 365Financial Services

The signature goes on the page in April. The evidence behind it is created between now and 31 December 2026, and there is no way to go back and collect it later. The certification due on 15 April 2027 is the first to cover a full calendar year under the complete amended rule, which makes the next sixteen weeks the part that matters.

What is actually due on 15 April 2027

Section 500.17(b) is short and it does not move. By 15 April each year, every covered entity files with the New York Department of Financial Services one of two things for the prior calendar year: a certification that it materially complied with 23 NYCRR Part 500, or a written acknowledgment that it did not, naming each section it fell short on and a remediation timeline.

Two people sign it: the covered entity's highest-ranking executive and its chief information security officer, or the senior officer responsible for the program where there is no CISO. As we read the rule, the certification must rest on data and documentation sufficient to determine and demonstrate that compliance, and the supporting records are kept for five years.

The filing due on 15 April 2027 covers 1 January to 31 December 2026 — the first certification period in which every provision of the Second Amendment was in force for the whole twelve months. The signature is about thirty-one weeks away; the evidence window closes in about sixteen. Other dates worth putting on the same calendar are on our Microsoft deadlines page.

What follows is our engineering reading of the public text of Part 500 as of September 2026, not legal advice.

Who has to file, and who only thinks they are exempt

Part 500 reaches anyone operating under, or required to operate under, a licence, registration, charter, certificate or permit under New York's Banking Law, Insurance Law or Financial Services Law. In practice: banks and trust companies, insurers, agencies, brokers and individual producers, mortgage bankers and servicers, money transmitters, check cashers and BitLicense virtual-currency businesses.

Small does not mean exempt. The limited exemption in 500.19(a) is available, as we read it, to an entity with fewer than 20 employees and independent contractors including affiliates, or under $7.5 million in gross annual revenue in each of the last three fiscal years from New York operations, or under $15 million in year-end total assets, and it requires a notice of exemption to be filed. It excuses a specific list of sections, but leaves in place the cybersecurity program and policy, the risk assessment, access privileges, an MFA floor, the asset inventory, the third-party provider policy, notification and the annual certification. Once an entity stops qualifying it has 180 days to comply in full, so a merger or a strong 2026 may already have started a clock.

Section 500.4 allows the CISO to sit at an affiliate or a third-party provider, provided the entity keeps responsibility and designates a senior member of its own staff to oversee it. That is the model our Virtual CISO service supports. Which box you are in is a determination for your counsel rather than for an engineer.

What landed on 1 November 2025, and why 2026 is the year that gets certified

The Second Amendment was finalised on 1 November 2023 and phased in over two years. The last two provisions landed on 1 November 2025.

Section 500.12 now requires multi-factor authentication for any individual accessing any information system of the covered entity. That is broader than the older standard, which covered remote access, remote access to third-party applications from which nonpublic information is accessible, and privileged accounts other than service accounts that cannot log in interactively. Those three remain the floor for entities with the limited exemption.

Section 500.13(a) requires written policies and procedures designed to produce and maintain a complete, accurate and documented asset inventory, tracking per asset the owner, location, classification or sensitivity, support expiration date and recovery time objective, plus the frequency required to update and validate it.

The certification filed in April 2026 touched both, but covered only the last two months of 2025. The one filed in April 2027 covers all twelve months of 2026. If universal MFA was finished in February, or the inventory procedure written in June, that is a fact about the certification period, and the filing has to be accurate about it.

"MFA for any individual accessing any information system", in a Microsoft 365 tenant

In a Microsoft 365 tenant that phrase comes down to a few concrete questions, answered by configuration rather than intention. A Conditional Access policy requiring multi-factor authentication for all users and all cloud applications, not only for administrators or for sign-ins scored as risky. Legacy authentication blocked, so nothing quietly bypasses the policy. Every third-party application from which nonpublic information is reachable either federated through Entra ID or carrying its own MFA. VPN, remote desktop and Azure Virtual Desktop behind the same requirement. Privileged accounts on stronger methods than everyone else. Service accounts that genuinely cannot sign in interactively identified as such, rather than used as a general excuse. Shared mailboxes and shared accounts dealt with rather than excluded.

NYDFS published MFA FAQs in December 2025 and revised two of them in early 2026; they are explicit that methods are not interchangeable. Section 500.12(b) allows exactly one alternative: reasonably equivalent or more secure compensating controls, approved in writing by the CISO and reviewed at least annually. An undocumented exclusion is not a compensating control.

The evidence to hold by December is narrow: the exported policy, a dated report of who is in scope, the exclusion list with a reason against each entry, and the CISO's written approval with its last review date. Where the gap is configuration rather than paperwork, the fixes are ordinary work: MFA for all users and a reviewed Conditional Access policy set.

The asset inventory your tenant does not already have

Most tenants can tell you what exists. Intune, Defender for Endpoint device discovery, Entra ID device objects, Azure Resource Graph and Azure Arc between them cover existence, location and recent use. Two of the five attributes 500.13 names are in none of them: support expiration date is a fact about a vendor's lifecycle, not about a device, and recovery time objective is a business decision. Classification is a decision too, even where Purview labels help apply it.

So the inventory is usually a join: the discovery sources for what they know, plus a register carrying the rest, and a SharePoint list or Dataverse table is often enough. What the rule asks for is the written procedure around it, and a spreadsheet with no procedure behind it is the common finding.

The other half of 500.13 gets missed: periodic, documented disposal of nonpublic information no longer needed for business operations. In Microsoft 365 that means retention and disposition policies that actually run, which is what Purview data lifecycle management is for. Disposition review records are evidence; an intention to tidy up is not. Evidence to hold by December: the procedure with an approval date, a dated export of the inventory, and the record of the last validation.

Evidence with a shelf life: audit trails, backups and the notification clocks

Some evidence has a shelf life, and Microsoft's defaults are shorter than the rule's floors. As we read 500.6, records needed to reconstruct material financial transactions are kept at least five years, and audit trail records for detecting and responding to cybersecurity events at least three. Microsoft Purview Audit Standard retains most audit records for 180 days by default. Audit Premium raises that to one year for the core workloads, and ten years needs the separate retention add-on, which is Microsoft's per-user charge and yours. So a January 2026 sign-in record can be gone before anyone asks for it: retention policies or an export to Sentinel have to exist before the data ages out.

Section 500.16 asks for continuity and disaster recovery plans and for backups maintained and tested. Native Microsoft 365 Backup covers Exchange Online, SharePoint and OneDrive; Microsoft's consumption charge for protected data is separate and is the customer's. What counts for the certification is the dated restore test, because a backup nobody has restored from is a plan, not a control.

Section 500.17 sets the clocks: notice to the superintendent no later than 72 hours after determining a cybersecurity incident occurred at the entity, an affiliate or a third-party provider, and an extortion payment notified within 24 hours with a written description due within 30 days. Whether an event is an incident is a legal judgment; what the plan must say is who makes it and who files. The only way to know is to walk it, with incident response on the shelf beforehand.

The order of work between now and 31 December

Sixteen weeks is enough if the work runs in the right order.

First, close live gaps, because a gap open in November is a gap in the certification period. Universal MFA and audit retention are the two that get worse with delay: one is a compliance state, the other destroys evidence while you think about it.

Second, find out where you stand rather than where the last project left you. A read-only Microsoft 365 security audit shows which identity paths still reach information systems without MFA, who holds privileged roles, what audit retention is really set to, and whether anything in the tenant resembles an asset inventory.

Third, build the evidence index while the year is still running: per section, the artefact that demonstrates it, where it lives, who owns it, when it was last produced. That is the difference between a certification supported by data and one supported by memory. Keeping it current is what a compliance evidence and audit readiness retainer does for an agreed framework.

Fourth, decide in January, not April. If a section will not be materially complied with for 2026, the rule provides the acknowledgment route — a decision that deserves runway and a complete gap register.

Where you are today What the 15 April 2027 filing has to say What to do before 31 December 2026
MFA required for all users and all cloud apps, legacy auth blocked, exclusions documented Materially compliant with 500.12 for the period Export the policy, the in-scope user report and the exclusion list, and date them
MFA on admins and remote access only A gap under 500.12 unless the limited exemption applies Extend Conditional Access to all users and all cloud applications now, so the gap has an end date inside 2026
Users excluded from MFA with no written approval An undocumented exclusion, not a compensating control Either bring them into policy or get the CISO's written 500.12(b) approval, with a review date
Device list in Intune plus a spreadsheet Partial under 500.13 Write the procedure, add owner, classification, support expiration date and recovery time objective, and set an update and validation frequency
No documented disposal of nonpublic information A gap under the second half of 500.13 Turn on retention and disposition in Purview and keep the disposition records
Purview Audit at the 180-day default Cannot evidence the 500.6 three-year audit-trail floor Set retention policies or export to Sentinel or Log Analytics before the early-2026 data ages out
Backups configured, never restore-tested Weak under 500.16 Run a restore test and keep the dated result
Incident response plan does not name who determines an incident The 72-hour clock has no defined start Walk the plan, assign the determination, record how it is documented and who files
No CISO designated, or a third-party arrangement with nothing in writing 500.4 conditions unmet, and one of the two signatures is unassigned Designate the CISO, or formalise the third-party arrangement with an internal senior overseer
Assuming the limited exemption without filing a notice The exemption is claimed but not evidenced Confirm the position with counsel, file the notice, and check whether a 2025 or 2026 threshold crossing started the 180-day clock
Possibly a Class A company (broadly, $20M+ New York revenue in each of the last two fiscal years plus 2,000+ employees or $1B+ total revenue) Also owes an independent audit of the program, privileged access management with blocked common passwords, and EDR plus centralised logging Confirm the status with counsel, then test those three against Entra ID Privileged Identity Management, Defender for Endpoint and Sentinel

Key takeaways

  • The certification under 500.17(b) is due 15 April every year for the prior calendar year, signed by the highest-ranking executive and the CISO, with supporting records kept five years.
  • The 15 April 2027 filing covers 1 January to 31 December 2026 — the first full calendar year with every Second Amendment provision in force, which makes the evidence window close on 31 December 2026, not in April.
  • Since 1 November 2025, 500.12 requires MFA for any individual accessing any information system, and 500.13 requires a written asset-inventory procedure tracking owner, location, classification, support expiration date and recovery time objective.
  • Microsoft 365 defaults are shorter than the rule's floors: Purview Audit Standard keeps most records 180 days against a three-year audit-trail floor in 500.6, so retention has to be extended before the data ages out.
  • The rule provides a written acknowledgment of non-compliance as an alternative to certifying — a decision worth making in January with a complete gap register, not on 14 April.
  • Covered-entity status, Class A status and limited-exemption eligibility are legal determinations for your counsel; what an engineering assessment supplies is the configuration evidence behind whichever position you take.

If your Microsoft 365 tenant is where most of Part 500's technical sections actually live, the useful next step is knowing what evidence exists today and what has to be created before the year closes. Our Compliance Evidence and Audit Readiness Retainer keeps that index current month by month from Entra ID, Purview, Defender and Intune, in an audit binder that lives in your own SharePoint. If you would rather start with the map than the retainer, a Microsoft 365 security audit will show you where the gaps are. Either way, bring the question to a free 30-minute session first — we will tell you which of the two you need, and we are engineers rather than your lawyers, so the status questions still go to counsel.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.