NYDFS 23 NYCRR Part 500 Cybersecurity Readiness Assessment
Every NYDFS-licensed entity has been on the full amended 23 NYCRR Part 500 since 1 November 2025, when the last Second Amendment provisions took effect — multi-factor authentication for any individual accessing any information system (500.12) and written asset-inventory procedures (500.13) — and the certification of material compliance due each 15 April is signed by your highest-ranking executive and your CISO on the strength of evidence you must be able to produce. This is a fixed-price, three-week readiness assessment of one covered entity against the regulation as amended: governance (CISO designation and reporting, senior-governing-body oversight, the 500.3 policy set, the 500.9 risk assessment), the third-party service provider policy (500.11) read against NYDFS's October 2025 guidance, and every technical section mapped to the Microsoft 365 and Azure controls that actually implement it — access privileges and privileged access (500.7), MFA (500.12), asset inventory and data retention (500.13), monitoring and training (500.14), encryption (500.15), incident response and BCDR (500.16) and the 72-hour, 24-hour and 30-day notification procedures (500.17). You get a control-by-control gap register, an evidence index built for the April certification, and a prioritised remediation roadmap. $4,950 fixed for one Microsoft 365 tenant and one covered entity, quoted in writing before we start. Penetration testing, the Class A independent audit, acting as your CISO, remediation, non-Microsoft core systems, legal advice on your status and the filing itself sit outside the fee and are named as such below.
What this engagement is
Banks and trust companies, insurers, insurance agencies and producers, mortgage lenders and servicers, money transmitters and virtual-currency businesses licensed by the New York Department of Financial Services share one cybersecurity regulation — 23 NYCRR Part 500 — and, since the Second Amendment was finalised on 1 November 2023 and phased in through 1 November 2025, one version of it. There is no longer a 'coming into effect' to plan around. The MFA and asset-inventory provisions were the last to land; the April 2026 certification was the first to cover them; the April 2027 certification will cover a full calendar year on the complete rule. NYDFS has kept publishing around it — guidance on managing third-party service provider risk on 21 October 2025, a set of detailed MFA FAQs in December 2025 (two of them revised in early 2026), and two industry letters on 21 May 2026 on measures for a heightened threat environment and on frontier-AI risks — and it has enforced Part 500 through consent orders carrying monetary penalties. Many licensees are small: an agency with thirty staff, a mortgage lender with two hundred, a money transmitter with a dozen. They run the whole business on Microsoft 365, which means most of Part 500's technical sections are, in practice, questions about how Microsoft Entra ID, Intune, Defender, Purview and Azure are configured — and whether anyone can prove it. This assessment answers those questions section by section. We read your governance documents against 500.2 through 500.4, 500.9, 500.10 and 500.11: is a CISO designated — in-house, at an affiliate or at a third party, under the conditions 500.4 attaches — and does that CISO report in writing at least annually to the senior governing body; does the policy set cover the areas 500.3 lists and carry the approval it requires; is the risk assessment current, and does it visibly drive the program; does the third-party policy do what NYDFS said in October 2025 it expects. Then we go into the tenant with read-only roles and test each technical section against configuration rather than intentions: which identity paths still reach information systems without MFA, and whether the methods in use hold up against NYDFS's FAQs; how many privileged roles exist, whether they are activated just-in-time, when access was last reviewed and how leavers are removed; whether anything you hold qualifies as the written asset inventory 500.13 describes — owner, location, classification, support expiration date and recovery time objective per asset, with a defined update and validation frequency — and where Intune, Defender for Endpoint, Entra ID, Azure Resource Graph and Azure Arc can populate it; whether mail and web filtering, awareness training that covers social engineering, encryption in transit and at rest, audit-trail retention, backup protection and restore testing are in place and evidenced; and whether your incident response plan would actually start the 72-hour clock on the right day. Everything lands in three documents built for the people who sign. The gap register gives each section a finding — in place, partial, absent or not evidenced — with the setting or procedure behind it. The evidence index lists, per section, the artefact that demonstrates compliance, where it lives, who owns it and when it was last produced, so that the 15 April certification rests on data and documentation rather than recollection — and so that the alternative the rule provides, a written acknowledgment of non-compliance naming the sections and a remediation timeline, is a decision made in January with eyes open rather than in April under pressure. The roadmap ranks what to fix by exposure and effort, ties each item to a section and a setting, and marks what your own team can do from the report alone. Where the map from Part 500 to the NIST Cybersecurity Framework matters to your program, the register carries the CSF reference alongside. We are Microsoft 365 and Azure engineers who work in regulated tenants — not a law firm, an accountancy or a certification body of any kind. Whether you are a covered entity, a Class A company or entitled to the limited exemption in 500.19; whether a given event is a 'cybersecurity incident' as 500.1 defines it; and what your certification should say are determinations for your leadership and counsel. The assessment gives them the technical facts, mapped to the rule, in the form an examiner would recognise. It does not make you compliant, it does not certify anything, and no engagement from anyone can.
Success criteria
What you receive
How the work unfolds
Scope is agreed in writing: one tenant, one covered entity, whether Azure and on-premises servers are in, and which affiliates share systems. You declare your status — covered entity, Class A or not, limited exemption claimed or not — and we record it as the basis of the assessment. Documents are collected where they exist: policy set, risk assessment, prior certifications or acknowledgments, notices of exemption, CISO board reports, penetration-test and scan reports, training records, third-party inventory, incident response and BCDR plans with test records, asset inventory and its procedure, any written compensating-control approvals. Read-only roles are granted and interviews scheduled.
Entra ID: Conditional Access, authentication methods and registration, legacy authentication, privileged roles and PIM, access reviews, password protection, enterprise applications and consent, guest access. Intune and Defender: device inventory and compliance, Defender for Endpoint coverage and web-content filtering, disk encryption. Exchange Online and Defender for Office 365: mail filtering, Safe Links and Safe Attachments, message encryption. Purview: audit retention, retention and disposition policies, data loss prevention where nonpublic information is in scope. Azure where present: RBAC, Arc-enrolled servers, Backup and Site Recovery, diagnostic logging, storage and disk encryption. Backup posture for Microsoft 365 data. No configuration is changed and no nonpublic information is read.
Four to five conversations of about an hour with the CISO or acting CISO, the compliance officer, IT and operations: the policy set walked against 500.3, the risk assessment against 500.9, the third-party policy and inventory against 500.11 and the October 2025 guidance, the incident response and BCDR plans against 500.16 and the last test. One session is a notification walkthrough — who decides that a cybersecurity incident has occurred, when the 72-hour clock starts, who files, and what happens in the first 24 hours if an extortion payment is even being discussed.
Findings are drafted per section with the evidence reference and the setting or procedure behind each. The evidence index is assembled. A validation session with your stakeholders corrects factual errors and resolves open items; anything still unevidenced is recorded as such rather than assumed.
The roadmap is ranked and sequenced against the April calendar. The readout is delivered live to the executive who signs the certification, the CISO who co-signs it and the compliance officer who assembles it; the report and evidence index are handed over; our access is removed.
Prerequisites
Who does what
IT Partner
- Assess every applicable section against configuration and documents, and record the evidence behind each finding.
- Map each finding to its Part 500 section and, where a finding turns on it, to the NYDFS guidance or FAQ concerned.
- State MFA coverage path by path and privileged access role by role, from the tenant, not from a questionnaire.
- Build the evidence index and the ranked roadmap with named settings, procedures and owners.
- Deliver the readout in plain language for the executive who signs and the CISO who co-signs.
- State scope limits explicitly in the report, treat everything seen as confidential, and remove our access at the end.
Your team
- Provide access, documents and stakeholders on the agreed schedule.
- Own the determination of covered-entity, Class A and exemption status, and every other legal question.
- Validate draft findings for factual accuracy within the review window.
- Decide what the certification says, sign it and file it — and file any incident, extortion-payment or exemption notice.
- Decide remediation priorities and own risk acceptance for gaps left open, including any compensating-control approvals the CISO makes in writing.
- Execute the roadmap internally or scope follow-on work separately.
- Keep the evidence current after the readout — the rule's annual cycle does not pause.
What's not included
Limitations & technical notes
Frequently asked questions
Who has to comply with 23 NYCRR Part 500?
Any person or entity operating under, or required to operate under, a licence, registration, charter, certificate, permit, accreditation or similar authorisation under New York's Banking Law, Insurance Law or Financial Services Law — banks and trust companies, insurers, insurance agencies, brokers and individual producers, mortgage bankers, brokers and servicers, money transmitters and check cashers, virtual-currency businesses under the BitLicense, and more. Whether your organisation is a covered entity is a legal determination your counsel makes. What this assessment does is take that answer and test your Microsoft estate against the rule.
What changed on 1 November 2025, and are we already late?
Two things landed that day, the last of the Second Amendment's phased provisions. Section 500.12 now requires multi-factor authentication for any individual accessing any information system of the covered entity — not just remote access and privileged accounts, which was the older standard and remains the floor for entities with the limited exemption. Section 500.13(a) requires written policies and procedures that produce and maintain a complete, accurate and documented asset inventory, tracking owner, location, classification or sensitivity, support expiration date and recovery time objective per asset, with a defined update and validation frequency. If either is not in place, you are not 'about to be' out of compliance; you have been since November, and the April 2026 certification either covered it or should have been an acknowledgment. That is a reason to assess now, not a reason to wait.
When is the annual certification due, and who signs it?
By 15 April each year, for the prior calendar year, under 500.17(b). It is signed by the covered entity's highest-ranking executive and its CISO — or the senior officer responsible for the program where there is no CISO. There are two forms: a certification that the entity materially complied with Part 500 during the year, which must be based on data and documentation sufficient to determine and demonstrate that compliance, or a written acknowledgment that it did not, identifying every section not materially complied with, the nature and extent of the shortfall, and a remediation timeline or confirmation that remediation is complete. The supporting records are kept for five years. The evidence index this assessment produces is built to be the thing those two signatures rest on.
We are a small agency. Do we not have the limited exemption?
Possibly — and it is narrower than people assume. As we read the amended 500.19(a), the limited exemption is available to a covered entity with fewer than 20 employees and independent contractors (counting affiliates), or less than $7.5 million in gross annual revenue in each of the last three fiscal years from its own operations and its affiliates' New York operations, or less than $15 million in year-end total assets — and it requires a notice of exemption to be filed. What it excuses is a specific list: the CISO section, penetration testing, the audit trail, application security, cybersecurity personnel, the training and Class A monitoring parts of 500.14, encryption and the incident response section. What it leaves in place is most of what this assessment covers: the cybersecurity program and policy, the risk assessment, access privileges, MFA for remote access, for third-party applications holding nonpublic information and for privileged accounts, the asset inventory, the third-party policy, the notification obligations and the annual certification. And once an entity stops qualifying, the rule gives it 180 days to comply in full. If you crossed a threshold in 2025 — a merger, a growth year — that clock may already be running. Whether you qualify is a determination for your counsel; the assessment runs against whichever status you declare.
What counts as a 'cybersecurity incident', and what are the notification deadlines?
Under 500.1 a cybersecurity incident is a cybersecurity event at the covered entity, an affiliate or a third-party service provider that either requires you to notify any government body, self-regulatory agency or other supervisory body; has a reasonable likelihood of materially harming any material part of your normal operations; or results in the deployment of ransomware within a material part of your information systems. Under 500.17(a) the notice to the superintendent is due as promptly as possible and no later than 72 hours after you determine that such an incident has occurred, with a continuing duty to update. Under 500.17(c) an extortion payment made in connection with a cybersecurity event must be notified within 24 hours, followed within 30 days by a written description of why payment was necessary, the alternatives considered, the diligence done to find them and the diligence done to comply with applicable rules including sanctions requirements. The assessment does not decide whether an event is an incident — that is a legal judgment — but it does make sure your plan says who decides, how the determination is recorded, and who files.
Is Microsoft 365 NYDFS-compliant?
The question is malformed, and anyone who answers 'yes' without qualification is selling something. Microsoft publishes compliance documentation for 23 NYCRR Part 500 and its cloud services carry the platform-side controls and independent audits that cover Microsoft's half of shared responsibility. Your half — who can sign in and how, who holds privileged roles, whether audit logs are kept long enough, whether backups are protected and tested, whether nonpublic information is disposed of on schedule, whether your third-party policy covers your Microsoft partner — is configuration and procedure, and it ships in a collaboration-friendly default state rather than a Part 500 state. Measuring the distance between the two is what this assessment does.
What does 'MFA for any individual accessing any information system' mean for a Microsoft 365 shop?
In practice: Conditional Access requiring MFA for all users and all cloud applications, not just administrators or 'risky' sign-ins; legacy authentication blocked so nothing bypasses the policy; every third-party application from which nonpublic information is accessible either federated through Entra ID so the same policy applies or covered by its own MFA; VPN, remote desktop and Azure Virtual Desktop entry points behind MFA; privileged accounts on stronger methods than everyone else; service accounts that genuinely cannot log in interactively identified as such; and shared mailboxes and shared accounts dealt with rather than quietly excluded. NYDFS's December 2025 FAQs, two of which it revised in early 2026, are explicit that some methods are weaker than others — push notifications without number matching and SMS codes are the ones examiners ask about first — and 500.12(b) allows only one alternative to MFA: reasonably equivalent or more secure compensating controls approved in writing by the CISO and reviewed at least annually. The report lists every path, every method and every approval, so that 'we have MFA' becomes a statement you can defend.
Our asset inventory is Intune plus a spreadsheet. Is that enough for 500.13?
It is a start, and it is usually not enough as it stands. Intune, Defender for Endpoint device discovery, Entra ID device objects, Azure Resource Graph and Azure Arc between them can tell you what exists, where it is and who last used it — but none of them natively tracks the support expiration date or the recovery time objective the rule names, and 'classification' is a decision, not a discovery. What 500.13 actually requires is a written procedure: what the inventory contains, how each attribute is tracked, how often it is updated and validated. The assessment reviews the procedure against the rule, maps which attributes each Microsoft source can feed, and specifies the register — a SharePoint list or a Dataverse table is often enough — that fills the rest. It also reviews the other half of 500.13: the periodic, documented disposal of nonpublic information that is no longer needed, which in Microsoft 365 means Purview retention and disposition rather than good intentions.
What is a Class A company, and what extra does it owe?
As we read 500.1, a Class A company is a covered entity with at least $20 million in gross annual revenue in each of the last two fiscal years from its own and its affiliates' New York operations, plus either more than 2,000 employees averaged over those two years or more than $1 billion in gross annual revenue from all operations of the entity and its affiliates — counting affiliates that share information systems, cybersecurity resources or any part of the program. Class A companies owe three things on top of the rest: an independent audit of the cybersecurity program at least annually (500.2(c)); a privileged access management solution and an automated method of blocking commonly used passwords for all accounts (500.7(c)); and an endpoint detection and response solution plus a solution that centralises logging and security event alerting (500.14(b)), each unless the CISO has approved compensating controls in writing. The assessment tests all three against Entra ID Privileged Identity Management and password protection, Defender for Endpoint, and Microsoft Sentinel or Defender XDR — but it is not, and cannot be, the independent audit. Whether you are Class A is your counsel's determination.
Can you be our CISO?
Not by default, and not as part of this assessment. Section 500.4 does allow the CISO to be employed by an affiliate or a third-party service provider, provided the covered entity retains responsibility for compliance and designates a senior member of its own personnel to direct and oversee the arrangement. Where an entity wants that model, our Virtual CISO service can support it as a separately scoped, explicitly designated arrangement — with the annual written report to the senior governing body, the compensating-control approvals and the certification co-signature that the role carries. What we will never do is let an assessment engagement drift into an undocumented 'they handle security' relationship that leaves the rule's conditions unmet and you holding the certification.
Do you do the penetration test?
No. Section 500.5 requires annual penetration testing from inside and outside the network boundaries by a qualified party, plus automated vulnerability scanning and timely, risk-prioritised remediation. We check that the testing is happening, that the scope covers the systems that matter, that the findings are being closed — Defender Vulnerability Management data is good evidence here — and we point you to a testing provider. Keeping the test independent of the people who configure your controls is the whole point; an assessor who also sold you the pen test would be marking their own homework.
Our core system is not Microsoft. Does the assessment cover it?
No, and the report says so on every page where it matters. Core banking, policy administration, claims, loan origination and servicing, payment rails, trading and agency management systems have their own vendors, their own contracts and their own control questions — and they usually hold the transaction records that 500.6 requires you to be able to reconstruct. What we assess is the Microsoft estate around them: the identity that signs into them, the mail that carries their output, the file stores where their exports land, the devices that reach them. Where a core system integrates with the tenant, we note the touchpoint and its exposure and hand the rest to your third-party policy.
We already do NIST CSF, SOC 2 or the FTC Safeguards Rule. Does that count?
It helps, and the register is built to show how. Part 500 is prescriptive where those frameworks are descriptive — it names MFA, asset-inventory attributes, retention floors, notification clocks and signatories that NIST CSF leaves to your risk decisions and SOC 2 leaves to your control design — so an organisation with a mature CSF program can still have specific Part 500 gaps. The gap register carries the NIST CSF function next to each finding, so a program already organised around the framework can absorb it. Where you also run a cyber-insurance readiness or HIPAA exercise on the same tenant, the technical evidence overlaps substantially and we reuse it rather than re-collect it.
How disruptive is this to our staff?
Minimally. The technical review is read-only work in admin portals: no configuration changes, no agents, no downtime, and no reading of nonpublic information. The human load is four to five interviews of about an hour, a validation session, and the readout. The heaviest lift for most entities is finding the documents — which is itself the first finding.
Can you fix what you find, and can we take the report elsewhere?
Yes to both, and deliberately in that order. Remediation is separately scoped so the findings stay honest and you keep leverage on what to fix and with whom; the most common follow-ons are MFA and Conditional Access, Privileged Identity Management and access reviews, Defender for Endpoint and managed detection, audit retention through Sentinel, Purview retention and disposition, and backup with restore testing. Many entities execute the quick wins from the roadmap alone. The report, the register and the evidence index are yours, written so that your own team, another provider or your auditor can work from them. There is no minimum term and nothing tying you to us afterwards.
Why $4,950, and why fixed?
Because the scope is fixed: one Microsoft 365 tenant, one covered entity, the full section map, three weeks. The price is quoted in writing before work begins and you pay after you approve delivery. If your situation is genuinely larger — several licensees sharing one tenant, a Class A affiliate estate, a mid-migration merger — we say so in the scoping call and quote the difference before anything starts, not after.
Does Compliance Manager's 23 NYCRR Part 500 template do this already?
It is a useful scaffold and we will use it where your licensing includes it. Microsoft Purview Compliance Manager offers a premium assessment template for Part 500 that maps the regulation to improvement actions, some of which it can test automatically from tenant settings. What it does not do is read your policy set, interview your CISO, walk your notification procedure, assess your asset-inventory procedure against the five attributes, tell you which of its 'implemented' actions are backed by evidence an examiner would accept, or distinguish a configuration gap from a licensing gap. Premium templates are also separately licensed — Microsoft's charge, not ours. Treat it as one input to the register, not as the register.