First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/NYDFS 23 NYCRR Part 500 Cybersecurity Readiness Assessment
AssessmentCompliance

NYDFS 23 NYCRR Part 500 Cybersecurity Readiness Assessment

Every NYDFS-licensed entity has been on the full amended 23 NYCRR Part 500 since 1 November 2025, when the last Second Amendment provisions took effect — multi-factor authentication for any individual accessing any information system (500.12) and written asset-inventory procedures (500.13) — and the certification of material compliance due each 15 April is signed by your highest-ranking executive and your CISO on the strength of evidence you must be able to produce. This is a fixed-price, three-week readiness assessment of one covered entity against the regulation as amended: governance (CISO designation and reporting, senior-governing-body oversight, the 500.3 policy set, the 500.9 risk assessment), the third-party service provider policy (500.11) read against NYDFS's October 2025 guidance, and every technical section mapped to the Microsoft 365 and Azure controls that actually implement it — access privileges and privileged access (500.7), MFA (500.12), asset inventory and data retention (500.13), monitoring and training (500.14), encryption (500.15), incident response and BCDR (500.16) and the 72-hour, 24-hour and 30-day notification procedures (500.17). You get a control-by-control gap register, an evidence index built for the April certification, and a prioritised remediation roadmap. $4,950 fixed for one Microsoft 365 tenant and one covered entity, quoted in writing before we start. Penetration testing, the Class A independent audit, acting as your CISO, remediation, non-Microsoft core systems, legal advice on your status and the filing itself sit outside the fee and are named as such below.

Timeline 3 weeksService owner Dan ApplebyMicrosoft 365Microsoft Entra IDMicrosoft Purview

What this engagement is

Banks and trust companies, insurers, insurance agencies and producers, mortgage lenders and servicers, money transmitters and virtual-currency businesses licensed by the New York Department of Financial Services share one cybersecurity regulation — 23 NYCRR Part 500 — and, since the Second Amendment was finalised on 1 November 2023 and phased in through 1 November 2025, one version of it. There is no longer a 'coming into effect' to plan around. The MFA and asset-inventory provisions were the last to land; the April 2026 certification was the first to cover them; the April 2027 certification will cover a full calendar year on the complete rule. NYDFS has kept publishing around it — guidance on managing third-party service provider risk on 21 October 2025, a set of detailed MFA FAQs in December 2025 (two of them revised in early 2026), and two industry letters on 21 May 2026 on measures for a heightened threat environment and on frontier-AI risks — and it has enforced Part 500 through consent orders carrying monetary penalties. Many licensees are small: an agency with thirty staff, a mortgage lender with two hundred, a money transmitter with a dozen. They run the whole business on Microsoft 365, which means most of Part 500's technical sections are, in practice, questions about how Microsoft Entra ID, Intune, Defender, Purview and Azure are configured — and whether anyone can prove it. This assessment answers those questions section by section. We read your governance documents against 500.2 through 500.4, 500.9, 500.10 and 500.11: is a CISO designated — in-house, at an affiliate or at a third party, under the conditions 500.4 attaches — and does that CISO report in writing at least annually to the senior governing body; does the policy set cover the areas 500.3 lists and carry the approval it requires; is the risk assessment current, and does it visibly drive the program; does the third-party policy do what NYDFS said in October 2025 it expects. Then we go into the tenant with read-only roles and test each technical section against configuration rather than intentions: which identity paths still reach information systems without MFA, and whether the methods in use hold up against NYDFS's FAQs; how many privileged roles exist, whether they are activated just-in-time, when access was last reviewed and how leavers are removed; whether anything you hold qualifies as the written asset inventory 500.13 describes — owner, location, classification, support expiration date and recovery time objective per asset, with a defined update and validation frequency — and where Intune, Defender for Endpoint, Entra ID, Azure Resource Graph and Azure Arc can populate it; whether mail and web filtering, awareness training that covers social engineering, encryption in transit and at rest, audit-trail retention, backup protection and restore testing are in place and evidenced; and whether your incident response plan would actually start the 72-hour clock on the right day. Everything lands in three documents built for the people who sign. The gap register gives each section a finding — in place, partial, absent or not evidenced — with the setting or procedure behind it. The evidence index lists, per section, the artefact that demonstrates compliance, where it lives, who owns it and when it was last produced, so that the 15 April certification rests on data and documentation rather than recollection — and so that the alternative the rule provides, a written acknowledgment of non-compliance naming the sections and a remediation timeline, is a decision made in January with eyes open rather than in April under pressure. The roadmap ranks what to fix by exposure and effort, ties each item to a section and a setting, and marks what your own team can do from the report alone. Where the map from Part 500 to the NIST Cybersecurity Framework matters to your program, the register carries the CSF reference alongside. We are Microsoft 365 and Azure engineers who work in regulated tenants — not a law firm, an accountancy or a certification body of any kind. Whether you are a covered entity, a Class A company or entitled to the limited exemption in 500.19; whether a given event is a 'cybersecurity incident' as 500.1 defines it; and what your certification should say are determinations for your leadership and counsel. The assessment gives them the technical facts, mapped to the rule, in the form an examiner would recognise. It does not make you compliant, it does not certify anything, and no engagement from anyone can.

Success criteria

01The entity profile is documented as you declare it — licence type, covered-entity status, Class A or limited-exemption position, affiliates that share information systems or the cybersecurity program, and what was filed last April — with every assumption written down.
02Every applicable section of 23 NYCRR Part 500 (500.2 through 500.17, and 500.19 where an exemption is claimed) has a written finding — in place, partial, absent or not evidenced — tied to the configuration or document behind it.
03MFA coverage under 500.12 is stated path by path: cloud sign-in, on-premises and VPN or remote-desktop access, third-party applications from which nonpublic information is accessible, privileged accounts, service and shared accounts, legacy authentication — with every gap and every CISO-approved compensating control listed.
04The asset-inventory procedure is assessed against 500.13(a) — owner, location, classification or sensitivity, support expiration date, recovery time objective, update and validation frequency — and the disposal procedure against 500.13(b), with the Microsoft data sources that can feed each attribute named.
05Privileged access, annual access review, leaver removal, remote-control protocols and password policy are assessed against 500.7, including the privileged-access-management and commonly-used-password blocking that 500.7(c) requires of Class A companies where that applies.
06Incident response, BCDR and notification procedures are assessed against 500.16 and 500.17: plan contents, annual test evidence, backup protection and restore testing, and a documented decision path for the 72-hour incident notice, the 24-hour extortion-payment notice and the 30-day written explanation.
07The evidence index covers every section with an artefact, a location, an owner and a date — or an explicit 'no evidence exists' — so the highest-ranking executive and the CISO can see what the April certification would rest on.
08Leadership, the CISO and the compliance officer have received the readout, the ranked roadmap names a setting or procedure and an owner per item, and no deliverable claims or implies certification or an assured compliance outcome.

What you receive

Entity and scope profile memo — the status you declare (covered entity, Class A, limited exemption), the affiliates and systems in scope, the Microsoft estate boundary, and the assumptions the rest of the report rests on.
Governance and policy gap review — CISO designation and the 500.4 conditions where the role sits at an affiliate or third party, the CISO's annual written report and the senior governing body's oversight, coverage of the 500.3 policy areas and their approval, currency of the 500.9 risk assessment and how it drives the program, 500.10 personnel and training, and the 500.11 third-party service provider policy and inventory read against NYDFS's 21 October 2025 guidance — including the fact that we, as your Microsoft partner, are one of the providers your policy has to cover.
Control-by-control gap register — every applicable section mapped to a finding, the evidence reference, the Microsoft 365 or Azure setting or written procedure at issue, and the NIST CSF function it corresponds to.
MFA and identity coverage report (500.12 and 500.7) — Conditional Access policy set, authentication-method strength and registration state against NYDFS's December 2025 FAQs, legacy authentication, service and shared accounts, third-party SaaS federated through Entra ID and the paths that are not, VPN, remote desktop and Azure Virtual Desktop entry points; privileged role inventory, Privileged Identity Management and just-in-time activation, break-glass accounts, access-review evidence, leaver removal timing, remote-control protocols on servers and endpoints, and Entra password protection against the 500.7(c) banned-password requirement; the register of any compensating controls the CISO has approved in writing and when each was last reviewed.
Asset inventory and data retention review (500.13) — the written procedure against the five tracked attributes and the update and validation frequency, the Intune, Defender for Endpoint, Entra ID device, Azure Resource Graph and Azure Arc data that can populate it, the attributes no Microsoft source tracks natively and the register that fills them, and the nonpublic-information disposal procedure against Purview retention and disposition.
Monitoring, training, encryption and audit-trail review (500.14, 500.15, 500.6) — Defender for Office 365 and Defender for Endpoint web-content filtering as the 'monitor and filter web traffic and electronic mail' control, awareness-training records including the social-engineering component, endpoint detection and centralised logging and alerting where 500.14(b) applies, encryption in transit and at rest with the CISO's annual review of it, and audit retention across Purview Audit, Entra ID sign-in logs and Microsoft Sentinel against the retention floors 500.6 sets.
Incident response, BCDR and notification review (500.16 and 500.17) — plan contents against the rule, the last annual test with critical staff, backup protection against unauthorised alteration or destruction and the last restore test, the decision path from 'something happened' to 'we have determined a cybersecurity incident occurred', who files on the DFS portal, the 24-hour and 30-day extortion-payment obligations, and how Microsoft Defender XDR incident evidence feeds the notice.
Evidence index for the 15 April certification — per section: the artefact that demonstrates material compliance, where it lives, who owns it, when it was last produced, and the gaps that would force a written acknowledgment of non-compliance instead of a certification.
Prioritised remediation roadmap — ranked by exposure and effort, each item tied to a section and a named setting or procedure, marked client-executable versus engagement-scale, and sequenced against the certification calendar.
Executive readout — delivered live to the highest-ranking executive, the CISO and the compliance officer, with a board-level summary on request.

How the work unfolds

Week 1 — Kickoff, entity profile and document intake

Scope is agreed in writing: one tenant, one covered entity, whether Azure and on-premises servers are in, and which affiliates share systems. You declare your status — covered entity, Class A or not, limited exemption claimed or not — and we record it as the basis of the assessment. Documents are collected where they exist: policy set, risk assessment, prior certifications or acknowledgments, notices of exemption, CISO board reports, penetration-test and scan reports, training records, third-party inventory, incident response and BCDR plans with test records, asset inventory and its procedure, any written compensating-control approvals. Read-only roles are granted and interviews scheduled.

Weeks 1–2 — Technical review of the Microsoft estate

Entra ID: Conditional Access, authentication methods and registration, legacy authentication, privileged roles and PIM, access reviews, password protection, enterprise applications and consent, guest access. Intune and Defender: device inventory and compliance, Defender for Endpoint coverage and web-content filtering, disk encryption. Exchange Online and Defender for Office 365: mail filtering, Safe Links and Safe Attachments, message encryption. Purview: audit retention, retention and disposition policies, data loss prevention where nonpublic information is in scope. Azure where present: RBAC, Arc-enrolled servers, Backup and Site Recovery, diagnostic logging, storage and disk encryption. Backup posture for Microsoft 365 data. No configuration is changed and no nonpublic information is read.

Week 2 — Governance, procedure and notification interviews

Four to five conversations of about an hour with the CISO or acting CISO, the compliance officer, IT and operations: the policy set walked against 500.3, the risk assessment against 500.9, the third-party policy and inventory against 500.11 and the October 2025 guidance, the incident response and BCDR plans against 500.16 and the last test. One session is a notification walkthrough — who decides that a cybersecurity incident has occurred, when the 72-hour clock starts, who files, and what happens in the first 24 hours if an extortion payment is even being discussed.

Weeks 2–3 — Gap register, evidence index and validation

Findings are drafted per section with the evidence reference and the setting or procedure behind each. The evidence index is assembled. A validation session with your stakeholders corrects factual errors and resolves open items; anything still unevidenced is recorded as such rather than assumed.

Week 3 — Roadmap and executive readout

The roadmap is ranked and sequenced against the April calendar. The readout is delivered live to the executive who signs the certification, the CISO who co-signs it and the compliance officer who assembles it; the report and evidence index are handed over; our access is removed.

Prerequisites

A NYDFS-licensed entity — or one that believes it is a covered entity — of roughly 20 to 2,000 people, running Microsoft 365 (commercial or GCC), with or without Azure and on-premises servers.
Your own declaration of status: covered entity; Class A or not; limited exemption claimed or not, and the notice of exemption filed if so; the affiliates that share information systems, cybersecurity resources or any part of the cybersecurity program. We assess against the status you declare; we do not determine it.
A named executive sponsor, the CISO or the person acting in that role, and a compliance or IT contact who can reach system owners and answer questions in days rather than weeks — three weeks holds only if they do.
Read-only access for the engagement window: Global Reader and Security Reader in Entra ID, the Purview reader roles for audit and retention, and Reader on in-scope Azure subscriptions. We make no configuration changes.
Documents where they exist: the cybersecurity policy set, the risk assessment, prior certifications or acknowledgments, CISO reports to the senior governing body, penetration-test and vulnerability-scan reports, training records, the third-party service provider inventory and policy, incident response and BCDR plans and test records, the asset inventory and its procedure, and any written compensating-control approvals. Absence is a finding, not a blocker.
Availability for four to five interviews of about an hour in weeks 1–2, a validation session in week 3, and the readout.
An agreed secure channel for exchanging assessment evidence; nonpublic information is not copied out of the tenant for this engagement.
The fixed fee covers one Microsoft 365 tenant, one Azure environment where present, and one covered entity. Multiple licensees or affiliates sharing a tenant, or a Class A company's affiliate estate, are scoped and quoted in writing before work starts.

Who does what

IT Partner

  • Assess every applicable section against configuration and documents, and record the evidence behind each finding.
  • Map each finding to its Part 500 section and, where a finding turns on it, to the NYDFS guidance or FAQ concerned.
  • State MFA coverage path by path and privileged access role by role, from the tenant, not from a questionnaire.
  • Build the evidence index and the ranked roadmap with named settings, procedures and owners.
  • Deliver the readout in plain language for the executive who signs and the CISO who co-signs.
  • State scope limits explicitly in the report, treat everything seen as confidential, and remove our access at the end.

Your team

  • Provide access, documents and stakeholders on the agreed schedule.
  • Own the determination of covered-entity, Class A and exemption status, and every other legal question.
  • Validate draft findings for factual accuracy within the review window.
  • Decide what the certification says, sign it and file it — and file any incident, extortion-payment or exemption notice.
  • Decide remediation priorities and own risk acceptance for gaps left open, including any compensating-control approvals the CISO makes in writing.
  • Execute the roadmap internally or scope follow-on work separately.
  • Keep the evidence current after the readout — the rule's annual cycle does not pause.

What's not included

Penetration testing and vulnerability scanning — 500.5 requires annual penetration testing from inside and outside the network and automated vulnerability scanning with risk-prioritised remediation. We check that both happen and that findings are being closed (Defender Vulnerability Management data counts as evidence) and point you to a testing provider; the Web Application Security Assessment covers one public application, not the annual network test, and remediation at scale is Managed Vulnerability Remediation.
The Class A independent audit under 500.2(c) — an audit must be independent of the people who build and run the controls, and an assessment is not an audit.
Acting as your CISO — 500.4 allows the CISO to sit at an affiliate or a third-party service provider, on condition that you retain responsibility for compliance and designate a senior member of your own personnel to direct and oversee the arrangement. The Virtual CISO service can support such a designated arrangement, scoped separately; this assessment does not make us your CISO, and we will not describe it that way.
Non-Microsoft core systems — core banking, policy administration, claims, loan origination and servicing, payment and transmission rails, trading, agency management systems and custom applications. Their touchpoints with the tenant (single sign-on, mail flow, data exports) are noted; the systems themselves are not assessed.
Legal advice of any kind — covered-entity, Class A and exemption determinations; whether an event is a cybersecurity incident; sanctions diligence on an extortion payment; examiner correspondence; enforcement defence.
Filing anything with NYDFS — the certification or acknowledgment, notices of exemption, incident notices, extortion-payment notices. We prepare the evidence and the walkthrough; your officers file.
Authoring the policy set or the risk assessment — we review both against 500.3 and 500.9; drafting them is CISO work, available through the vCISO service or quoted separately.
Awareness-training delivery and phishing simulation — Managed Security Awareness Training.
Ongoing evidence maintenance and the annual re-assessment — the Compliance Evidence and Audit Readiness Retainer keeps the Part 500 evidence index current between certifications.
Microsoft licensing purchases and Microsoft's metered charges — Entra ID P2 or Entra ID Governance, Defender plans, Purview Audit Premium or the 10-year audit retention add-on, Compliance Manager premium templates, Sentinel and Log Analytics ingestion, Azure Backup storage — are Microsoft's charges to you wherever the roadmap identifies them as genuinely required.
Attestation or certification of any kind — we are not a law firm, a CPA, a QSA, a C3PAO or a certification body, and 'NYDFS certified' is not something anyone can sell you.

Limitations & technical notes

!This page and the engagement contain no legal advice. The regulatory summaries are our engineering reading of the public text of 23 NYCRR Part 500 as amended — the Second Amendment was finalised on 1 November 2023 and all of its provisions have been in force since 1 November 2025 — together with NYDFS's published guidance, industry letters and FAQs as of September 2026. NYDFS's own interpretation and its examiners control; your counsel decides what applies to you.
!No certification, and no promise of a compliance outcome. The certification of material compliance is your highest-ranking executive's and CISO's statement, made on data and documentation they must retain for five years; the evidence index is our way of making sure that documentation exists. Nothing here makes the statement for them.
!This is a point-in-time assessment. Configuration drift, new applications, staffing changes and licensing changes age the findings; the report is dated and says so.
!Findings depend on the access and disclosure provided. Systems, affiliates and providers not disclosed, and shadow IT outside the tenant, are outside what the assessment can see.
!Status determinations are yours. We assess against the covered-entity, Class A or limited-exemption position you declare, and we note where the facts we can see — headcount in Entra ID, for instance — look inconsistent with it, without deciding the question.
!Available controls depend on licensing. Privileged Identity Management and access reviews need Entra ID P2 or Entra ID Governance; Safe Links, Safe Attachments and Attack Simulation Training need Defender for Office 365 plans; endpoint detection and response needs Defender for Endpoint; audit retention beyond the default needs Audit Premium or the 10-year add-on. The report separates configuration gaps from licensing gaps and will not recommend an upgrade that a configuration change can cover.
!Audit-trail floors are the rule's, and they are long: as we read 500.6, records for reconstructing material financial transactions must be kept for at least five years and records for detecting and responding to cybersecurity events for at least three. Microsoft's defaults are shorter — 180 days for Purview Audit Standard, one year for the core workloads under Audit Premium, longer only with the add-on or an export to Sentinel or Log Analytics — and the transaction records usually live in core systems outside this scope. The report states what your retention actually is.
!Microsoft's own evidence — its audit reports and the 23 NYCRR Part 500 offering documentation it publishes, and the Compliance Manager premium template for Part 500 where your licensing includes it — covers Microsoft's side of shared responsibility. It is not evidence of your configuration and does not replace the register.
!NYDFS revises its FAQs and issues guidance between amendments. The May 2026 industry letters are guidance, not rule text; we are not aware of a further amendment to Part 500 at the time of writing, and the readout flags anything proposed by the delivery date.
!The assessment reviews configuration and documents; it does not read, search or export nonpublic information, and customer data stays in the tenant.
!$4,950 covers one Microsoft 365 tenant, one Azure environment where present and one covered entity. Larger or shared estates receive a fixed written quote before work starts, not a surprise after.

Frequently asked questions

Who has to comply with 23 NYCRR Part 500?

Any person or entity operating under, or required to operate under, a licence, registration, charter, certificate, permit, accreditation or similar authorisation under New York's Banking Law, Insurance Law or Financial Services Law — banks and trust companies, insurers, insurance agencies, brokers and individual producers, mortgage bankers, brokers and servicers, money transmitters and check cashers, virtual-currency businesses under the BitLicense, and more. Whether your organisation is a covered entity is a legal determination your counsel makes. What this assessment does is take that answer and test your Microsoft estate against the rule.

What changed on 1 November 2025, and are we already late?

Two things landed that day, the last of the Second Amendment's phased provisions. Section 500.12 now requires multi-factor authentication for any individual accessing any information system of the covered entity — not just remote access and privileged accounts, which was the older standard and remains the floor for entities with the limited exemption. Section 500.13(a) requires written policies and procedures that produce and maintain a complete, accurate and documented asset inventory, tracking owner, location, classification or sensitivity, support expiration date and recovery time objective per asset, with a defined update and validation frequency. If either is not in place, you are not 'about to be' out of compliance; you have been since November, and the April 2026 certification either covered it or should have been an acknowledgment. That is a reason to assess now, not a reason to wait.

When is the annual certification due, and who signs it?

By 15 April each year, for the prior calendar year, under 500.17(b). It is signed by the covered entity's highest-ranking executive and its CISO — or the senior officer responsible for the program where there is no CISO. There are two forms: a certification that the entity materially complied with Part 500 during the year, which must be based on data and documentation sufficient to determine and demonstrate that compliance, or a written acknowledgment that it did not, identifying every section not materially complied with, the nature and extent of the shortfall, and a remediation timeline or confirmation that remediation is complete. The supporting records are kept for five years. The evidence index this assessment produces is built to be the thing those two signatures rest on.

We are a small agency. Do we not have the limited exemption?

Possibly — and it is narrower than people assume. As we read the amended 500.19(a), the limited exemption is available to a covered entity with fewer than 20 employees and independent contractors (counting affiliates), or less than $7.5 million in gross annual revenue in each of the last three fiscal years from its own operations and its affiliates' New York operations, or less than $15 million in year-end total assets — and it requires a notice of exemption to be filed. What it excuses is a specific list: the CISO section, penetration testing, the audit trail, application security, cybersecurity personnel, the training and Class A monitoring parts of 500.14, encryption and the incident response section. What it leaves in place is most of what this assessment covers: the cybersecurity program and policy, the risk assessment, access privileges, MFA for remote access, for third-party applications holding nonpublic information and for privileged accounts, the asset inventory, the third-party policy, the notification obligations and the annual certification. And once an entity stops qualifying, the rule gives it 180 days to comply in full. If you crossed a threshold in 2025 — a merger, a growth year — that clock may already be running. Whether you qualify is a determination for your counsel; the assessment runs against whichever status you declare.

What counts as a 'cybersecurity incident', and what are the notification deadlines?

Under 500.1 a cybersecurity incident is a cybersecurity event at the covered entity, an affiliate or a third-party service provider that either requires you to notify any government body, self-regulatory agency or other supervisory body; has a reasonable likelihood of materially harming any material part of your normal operations; or results in the deployment of ransomware within a material part of your information systems. Under 500.17(a) the notice to the superintendent is due as promptly as possible and no later than 72 hours after you determine that such an incident has occurred, with a continuing duty to update. Under 500.17(c) an extortion payment made in connection with a cybersecurity event must be notified within 24 hours, followed within 30 days by a written description of why payment was necessary, the alternatives considered, the diligence done to find them and the diligence done to comply with applicable rules including sanctions requirements. The assessment does not decide whether an event is an incident — that is a legal judgment — but it does make sure your plan says who decides, how the determination is recorded, and who files.

Is Microsoft 365 NYDFS-compliant?

The question is malformed, and anyone who answers 'yes' without qualification is selling something. Microsoft publishes compliance documentation for 23 NYCRR Part 500 and its cloud services carry the platform-side controls and independent audits that cover Microsoft's half of shared responsibility. Your half — who can sign in and how, who holds privileged roles, whether audit logs are kept long enough, whether backups are protected and tested, whether nonpublic information is disposed of on schedule, whether your third-party policy covers your Microsoft partner — is configuration and procedure, and it ships in a collaboration-friendly default state rather than a Part 500 state. Measuring the distance between the two is what this assessment does.

What does 'MFA for any individual accessing any information system' mean for a Microsoft 365 shop?

In practice: Conditional Access requiring MFA for all users and all cloud applications, not just administrators or 'risky' sign-ins; legacy authentication blocked so nothing bypasses the policy; every third-party application from which nonpublic information is accessible either federated through Entra ID so the same policy applies or covered by its own MFA; VPN, remote desktop and Azure Virtual Desktop entry points behind MFA; privileged accounts on stronger methods than everyone else; service accounts that genuinely cannot log in interactively identified as such; and shared mailboxes and shared accounts dealt with rather than quietly excluded. NYDFS's December 2025 FAQs, two of which it revised in early 2026, are explicit that some methods are weaker than others — push notifications without number matching and SMS codes are the ones examiners ask about first — and 500.12(b) allows only one alternative to MFA: reasonably equivalent or more secure compensating controls approved in writing by the CISO and reviewed at least annually. The report lists every path, every method and every approval, so that 'we have MFA' becomes a statement you can defend.

Our asset inventory is Intune plus a spreadsheet. Is that enough for 500.13?

It is a start, and it is usually not enough as it stands. Intune, Defender for Endpoint device discovery, Entra ID device objects, Azure Resource Graph and Azure Arc between them can tell you what exists, where it is and who last used it — but none of them natively tracks the support expiration date or the recovery time objective the rule names, and 'classification' is a decision, not a discovery. What 500.13 actually requires is a written procedure: what the inventory contains, how each attribute is tracked, how often it is updated and validated. The assessment reviews the procedure against the rule, maps which attributes each Microsoft source can feed, and specifies the register — a SharePoint list or a Dataverse table is often enough — that fills the rest. It also reviews the other half of 500.13: the periodic, documented disposal of nonpublic information that is no longer needed, which in Microsoft 365 means Purview retention and disposition rather than good intentions.

What is a Class A company, and what extra does it owe?

As we read 500.1, a Class A company is a covered entity with at least $20 million in gross annual revenue in each of the last two fiscal years from its own and its affiliates' New York operations, plus either more than 2,000 employees averaged over those two years or more than $1 billion in gross annual revenue from all operations of the entity and its affiliates — counting affiliates that share information systems, cybersecurity resources or any part of the program. Class A companies owe three things on top of the rest: an independent audit of the cybersecurity program at least annually (500.2(c)); a privileged access management solution and an automated method of blocking commonly used passwords for all accounts (500.7(c)); and an endpoint detection and response solution plus a solution that centralises logging and security event alerting (500.14(b)), each unless the CISO has approved compensating controls in writing. The assessment tests all three against Entra ID Privileged Identity Management and password protection, Defender for Endpoint, and Microsoft Sentinel or Defender XDR — but it is not, and cannot be, the independent audit. Whether you are Class A is your counsel's determination.

Can you be our CISO?

Not by default, and not as part of this assessment. Section 500.4 does allow the CISO to be employed by an affiliate or a third-party service provider, provided the covered entity retains responsibility for compliance and designates a senior member of its own personnel to direct and oversee the arrangement. Where an entity wants that model, our Virtual CISO service can support it as a separately scoped, explicitly designated arrangement — with the annual written report to the senior governing body, the compensating-control approvals and the certification co-signature that the role carries. What we will never do is let an assessment engagement drift into an undocumented 'they handle security' relationship that leaves the rule's conditions unmet and you holding the certification.

Do you do the penetration test?

No. Section 500.5 requires annual penetration testing from inside and outside the network boundaries by a qualified party, plus automated vulnerability scanning and timely, risk-prioritised remediation. We check that the testing is happening, that the scope covers the systems that matter, that the findings are being closed — Defender Vulnerability Management data is good evidence here — and we point you to a testing provider. Keeping the test independent of the people who configure your controls is the whole point; an assessor who also sold you the pen test would be marking their own homework.

Our core system is not Microsoft. Does the assessment cover it?

No, and the report says so on every page where it matters. Core banking, policy administration, claims, loan origination and servicing, payment rails, trading and agency management systems have their own vendors, their own contracts and their own control questions — and they usually hold the transaction records that 500.6 requires you to be able to reconstruct. What we assess is the Microsoft estate around them: the identity that signs into them, the mail that carries their output, the file stores where their exports land, the devices that reach them. Where a core system integrates with the tenant, we note the touchpoint and its exposure and hand the rest to your third-party policy.

We already do NIST CSF, SOC 2 or the FTC Safeguards Rule. Does that count?

It helps, and the register is built to show how. Part 500 is prescriptive where those frameworks are descriptive — it names MFA, asset-inventory attributes, retention floors, notification clocks and signatories that NIST CSF leaves to your risk decisions and SOC 2 leaves to your control design — so an organisation with a mature CSF program can still have specific Part 500 gaps. The gap register carries the NIST CSF function next to each finding, so a program already organised around the framework can absorb it. Where you also run a cyber-insurance readiness or HIPAA exercise on the same tenant, the technical evidence overlaps substantially and we reuse it rather than re-collect it.

How disruptive is this to our staff?

Minimally. The technical review is read-only work in admin portals: no configuration changes, no agents, no downtime, and no reading of nonpublic information. The human load is four to five interviews of about an hour, a validation session, and the readout. The heaviest lift for most entities is finding the documents — which is itself the first finding.

Can you fix what you find, and can we take the report elsewhere?

Yes to both, and deliberately in that order. Remediation is separately scoped so the findings stay honest and you keep leverage on what to fix and with whom; the most common follow-ons are MFA and Conditional Access, Privileged Identity Management and access reviews, Defender for Endpoint and managed detection, audit retention through Sentinel, Purview retention and disposition, and backup with restore testing. Many entities execute the quick wins from the roadmap alone. The report, the register and the evidence index are yours, written so that your own team, another provider or your auditor can work from them. There is no minimum term and nothing tying you to us afterwards.

Why $4,950, and why fixed?

Because the scope is fixed: one Microsoft 365 tenant, one covered entity, the full section map, three weeks. The price is quoted in writing before work begins and you pay after you approve delivery. If your situation is genuinely larger — several licensees sharing one tenant, a Class A affiliate estate, a mid-migration merger — we say so in the scoping call and quote the difference before anything starts, not after.

Does Compliance Manager's 23 NYCRR Part 500 template do this already?

It is a useful scaffold and we will use it where your licensing includes it. Microsoft Purview Compliance Manager offers a premium assessment template for Part 500 that maps the regulation to improvement actions, some of which it can test automatically from tenant settings. What it does not do is read your policy set, interview your CISO, walk your notification procedure, assess your asset-inventory procedure against the five attributes, tell you which of its 'implemented' actions are backed by evidence an examiner would accept, or distinguish a configuration gap from a licensing gap. Premium templates are also separately licensed — Microsoft's charge, not ours. Treat it as one input to the register, not as the register.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$4,950 per project
3 weeks
Book the Part 500 assessment