Scrutineer · By framework
NAIC Insurance Data Security Model Law software
The NAIC Insurance Data Security Model Law, Model 668, is enacted in about half the states. Licensees need a written security program, vendor oversight, an incident response plan and a commissioner notice within 72 hours. Domestic insurers also certify compliance every February 15.
Scrutineer maps each obligation to controls you already evidence for SOC 2, ISO 27001 or NYDFS Part 500. Compliance software, not legal advice.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with NAIC model 668
The small-licensee exemption covers Section 4 only. The 72-hour clock still applies
The most common misreading of Model 668 at small agencies is that fewer than ten employees means the law does not apply. Section 9A(1) exempts a licensee with fewer than ten employees, counting independent contractors, from Section 4 of the Act, which is the information security program. It does not exempt that licensee from Section 5, the duty to investigate a cybersecurity event, or from Section 6, the duty to notify the commissioner within 72 hours. So a nine-person agency can skip the written program under the model text and still owes a prompt investigation, five years of event records and a notice containing up to thirteen named data elements. Losing the exemption is not instant either: under Section 9B a licensee that stops qualifying has 180 days to comply. Adopting states have changed details like this, so read your own state's enacted text, but the structure of the exemption is the part most summaries get wrong.
Nonpublic Information is wider than a breach law, and the clock starts at determination
Most state breach notification laws turn on consumer identifiers. Model 668 defines Nonpublic Information to include business related information of the licensee whose tampering, unauthorized disclosure, access or use would cause a material adverse impact to the business, operations or security of the licensee. A ransomware event that encrypts your rating models or claims system, with no consumer record touched, can therefore still be a cybersecurity event you investigate and, where it is reasonably likely to materially harm a material part of your normal operations, report. The 72 hours in Section 6A run from a determination that a cybersecurity event has occurred, not from first alert, which is why the investigation record matters: it shows when you knew. The notice then carries a continuing obligation to update and supplement, so the same record keeps growing after the first filing.
One control library can carry several states, NYDFS and HIPAA at once
The model was written to sit alongside frameworks insurers already run. Its drafting note says a licensee in compliance with NYDFS Part 500 is also in compliance with the Act, and Section 9A(2) treats a HIPAA covered licensee with a maintained information security program as meeting Section 4, provided it submits a written statement certifying that compliance. The controls overlap heavily with SOC 2 and ISO 27001: access control, encryption of Nonpublic Information in transit over external networks and on portable devices, secure development, monitoring, audit trails and secure disposal. Where they diverge, the model is often the softer text. Multi-factor authentication appears as a control that "may include" MFA, while amended Part 500 requires MFA for anyone accessing your information systems. Build to the strictest version once, then evidence each state from the same controls instead of running one program per regulator.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps each Section 4 obligation, from the risk assessment in 4C to the incident response plan in 4H, onto the controls you already evidence for SOC 2, ISO 27001 or NYDFS Part 500, and flags which are net new
- Schedules the annual assessment of key controls that Section 4C(5) requires, so the effectiveness test happens every year whether or not an outside auditor is booked
- Drafts the written annual board report Section 4E asks for from live data: program status, risk decisions, third-party service provider arrangements, test results and cybersecurity events
- Runs third-party service provider due diligence at selection and keeps a record that each provider is contractually required to protect Nonpublic Information, as Section 4F requires
- Holds the records, schedules and data supporting the February 15 certification for five years, plus the documented remediation plans for anything that needs material improvement
- Keeps an investigation record for each cybersecurity event, including events at a vendor, with the determination time that starts the 72-hour notice clock
- Tracks the thirteen notice data elements in Section 6B so the first commissioner filing and every later update draw from one record
- Covers several adopting states, NYDFS Part 500 and HIPAA from one library, so a multistate agency or carrier evidences once and reports many times
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
What your existing program already covers
Model 668 obligations against what SOC 2 and ISO 27001 already give you
Most write-ups of the Insurance Data Security Model Law list the sections. This table answers the next question a security team asks: which of these do we already evidence, and what is genuinely new. Section numbers follow the NAIC model text; your state may renumber them.
| Obligation | Section | What SOC 2 or ISO 27001 usually already covers | The net-new work | Clock |
|---|---|---|---|---|
| Written information security program based on a risk assessment | 4A to 4D | An ISMS or SOC 2 control set with policies and a risk assessment | Scoping to Nonpublic Information, which includes your own business information, and folding cybersecurity risk into enterprise risk management | One year after your state's effective date |
| Annual assessment of key controls | 4C(5) | Type 2 testing or ISO 27001 internal audit, if you run one | A yearly effectiveness assessment owned by the licensee, required even with no external audit | Every year |
| Board oversight | 4E | ISO 27001 management review | A written report to the board or a committee at least annually, covering vendor arrangements, test results and cybersecurity events | Every year |
| Third-party service provider oversight | 4F | Vendor security reviews and questionnaires | Due diligence at selection and a contractual requirement that each provider protect Nonpublic Information | Two years after your state's effective date |
| Incident response plan | 4H | SOC 2 CC7 incident criteria, ISO 27001 incident controls | A written plan covering seven named areas, including decision-making authority and revision after each event | Continuous |
| Annual certification to the domiciliary commissioner | 4I | Nothing comparable | A written statement of compliance from each domestic insurer, with five years of supporting records and documented remediation plans | February 15 |
| Investigation of a cybersecurity event | 5 | Incident management records | Confirming and documenting that a vendor completed the investigation steps for an event in its systems, and keeping event records five years | Promptly, per event |
| Notice to the commissioner | 6A and 6B | Nothing comparable | A notice with up to thirteen named data elements and a continuing duty to update it | 72 hours from determination |
Good questions
Questions about NAIC model 668
Keep reading
Guides that go deeper on this framework
Best Model Audit Rule software for insurers
The other NAIC model most carriers carry, and how its three clocks line up with this one.
Read the guideHow to conduct a cybersecurity risk assessment
The Section 4C risk assessment, done in the order an examiner reads it.
Read the guideVendor tiering
Deciding which service providers get full due diligence under Section 4F and which get a lighter review.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification