Scrutineer.ai

Scrutineer · By framework

NYDFS cybersecurity regulation software for 23 NYCRR Part 500

Part 500 is fully phased in: universal MFA and the written asset inventory have been in force since November 1, 2025.

Scrutineer maps your controls to each section and keeps the evidence the April 15 certification has to rest on.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with NYDFS cybersecurity regulation software

Every section mapped, including the ones you may be exempt from

Part 500 is not one obligation, it is roughly twenty of them with different scopes. Scrutineer maps your controls section by section and marks which ones the 500.19(a) limited exemption actually covers, so you stop preparing evidence you do not owe and stop missing the ones you do.

Evidence dated across the period, not screenshotted in April

The certification covers a calendar year, and 500.17(b) requires you to keep the supporting data and records for five years. Scrutineer pulls proof from your cloud, identity and ticketing systems on a schedule and timestamps it, so the filing is supported by a year of records rather than a week of scrambling.

You see the gap before you sign your name to it

The amended rule makes the highest-ranking executive and the CISO both sign. That changes the stakes of an optimistic answer. Scrutineer flags drifted controls, stale evidence and uncovered systems while there is still time to remediate, so the choice between a certification and an acknowledgment of noncompliance is made on data.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps your control set to each Part 500 section, from 500.2 through 500.17
  • Flags which sections the 500.19(a) limited exemption covers and which it does not
  • Tracks MFA coverage under 500.12 and keeps every written exception with its approval
  • Maintains the 500.13 asset inventory with owner, location, classification and recovery time
  • Runs the annual access review 500.7 requires and keeps the reviewer sign-off
  • Holds the 500.9 risk assessment and the third-party due diligence 500.11 expects
  • Assembles the April 15 filing package with five years of supporting records behind it
  • Reuses the same evidence for SOC 2, ISO 27001 and PCI DSS instead of collecting it twice
NYDFS CYBERSECURITY REGULATION SOFTWARE readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Scope reference

Which parts of 23 NYCRR 500 actually apply to you, and what proves each one

Most Part 500 summaries list the requirements without saying who is off the hook for which. That is the question a smaller covered entity actually has. The third column reads the 500.19(a) limited exemption against each section, and the row worth stopping on is 500.12: multi-factor authentication is not on the exemption list, so it reaches even the smallest licensee.

Part 500 section What it requires Covered by the 500.19(a) limited exemption? Evidence an examiner asks for
500.2 Cybersecurity program Maintain a documented program designed on the findings of your risk assessment, covering identification, protection, detection, response and recovery. No. Applies to every covered entity. The program documentation and the risk assessment it is built on, with dates.
500.3 Cybersecurity policy Written policies approved at least annually by a senior officer or the board, covering the areas the section enumerates. No. The approved policy set showing the approver and the approval date.
500.4 CISO Designate a qualified CISO, who reports in writing to the board at least annually on program effectiveness and material risks. Yes, exempt. The designation and the dated annual written report, plus the board minute receiving it.
500.5 Penetration testing and vulnerability assessments Annual penetration testing of information systems, plus automated scans and manual review at a frequency set by risk. Yes, exempt. The penetration test report and scan records, with remediation tracked to closure.
500.7 Access privileges and access review Limit access to what is needed, review all user access privileges at least annually, and remove access promptly when it is no longer required. No. A completed access review with reviewer sign-off, plus termination records showing when access was actually removed.
500.9 Risk assessment A written risk assessment sufficient to inform the program, reviewed and updated at least annually and when the business changes materially. No. The dated assessment and the written policy and procedure that governs how it is conducted.
500.11 Third-party service provider policy Written policies for due diligence on service providers and for the security requirements you put in their contracts. No. The policy, the due diligence records for sampled vendors, and the security clauses in executed contracts.
500.12 Multi-factor authentication MFA for any individual accessing any information system, in force since November 1, 2025. A CISO may approve a written exception using reasonably equivalent or more secure compensating controls. No. This is the one small entities get wrong. MFA coverage across remote access, privileged accounts and third-party applications, plus every written exception with its approval and annual review.
500.13 Asset inventory A written policy and procedure for asset management, and an inventory tracking owner, location, classification, support expiration and recovery time objectives. In force since November 1, 2025. No. The inventory itself and the documented procedure that keeps it current.
500.15 Encryption Encrypt nonpublic information in transit over external networks and at rest, or apply CISO-approved alternative compensating controls where encryption is infeasible. Yes, exempt. Encryption configuration evidence and, where used, the CISO approval for a compensating control.
500.16 Incident response and business continuity Written incident response plans and business continuity and disaster recovery plans, tested at least annually, with backups tested for restoration. Yes, exempt. The plans, the annual test record, the after-action notes and evidence of a restore test.
500.17 Notices and annual filing Notice to the superintendent within 72 hours of determining a cybersecurity event occurred, within 24 hours of an extortion payment, and an April 15 filing signed by the highest-ranking executive and the CISO. No. The dual-signed certification of material compliance or acknowledgment of noncompliance, plus five years of supporting data and records.

Section content and the 500.19(a) exemption list are read from the text of 23 NYCRR Part 500 as amended, current at August 2026. The exemption in 500.19(a) is written with "or" between its three thresholds, so meeting any single one qualifies; several widely circulated summaries render it as "and". Exemption status turns on facts about your own entity and its affiliates, and 500.19 requires you to file a notice of exemption, so confirm your position with counsel rather than relying on a table. Scrutineer prepares and maintains the evidence; your covered entity makes and signs the filing.

Good questions

Questions about NYDFS cybersecurity regulation software

The NYDFS cybersecurity regulation is 23 NYCRR Part 500, a rule issued by the New York State Department of Financial Services that requires companies it licenses to run a documented cybersecurity program, appoint a CISO, assess risk annually, control access, encrypt nonpublic information, report incidents on a clock, and certify compliance to the regulator once a year. It took effect in 2017 and was significantly expanded by a Second Amendment adopted November 1, 2023.
23 NYCRR 500 is the citation for the same rule: title 23 of the New York Codes, Rules and Regulations, Part 500. People use "23 NYCRR 500", "NYDFS Part 500" and "the NYDFS cybersecurity regulation" interchangeably. Individual requirements are cited by section, so 500.12 is multi-factor authentication and 500.17 is the notice and certification section.
NYDFS stands for the New York State Department of Financial Services, the state agency that regulates banks, insurers, mortgage lenders and servicers, money transmitters and virtual currency businesses operating in New York. It is the regulator that writes and enforces Part 500, and it is also the body you file the annual cybersecurity certification with.
It applies to covered entities, meaning any person or business operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization from NYDFS. In practice that is banks and trust companies, insurers and insurance agents and brokers, mortgage lenders, brokers and servicers, money transmitters, check cashers, licensed lenders and virtual currency businesses.
It applies based on your NYDFS authorization, not your address. A company headquartered in Texas that holds a New York license is a covered entity and owes the same obligations as one based in Manhattan. Conversely, a New York business with no NYDFS license is not covered by Part 500 at all, though it may still fall under the FTC Safeguards Rule or other regimes.
Yes. Since November 1, 2025, section 500.12 requires multi-factor authentication for any individual accessing any information system of a covered entity. That is broader than the earlier version, which reached only remote access, privileged accounts and third-party applications. The CISO may approve a written exception with reasonably equivalent or more secure compensating controls, but the exception has to be documented and reviewed at least annually.
The core set is a written cybersecurity program (500.2) and policy (500.3), a designated CISO reporting to the board (500.4), penetration testing and vulnerability assessments (500.5), audit trails (500.6), access privilege limits and an annual access review (500.7), an annual written risk assessment (500.9), a third-party service provider policy (500.11), MFA (500.12), an asset inventory (500.13), training and monitoring (500.14), encryption (500.15), incident response and business continuity plans (500.16), and the notice and certification duties in 500.17.
The Second Amendment was adopted November 1, 2023 and rolled out on a phased schedule that finished on November 1, 2025. It created the Class A company tier with extra obligations, extended MFA to all information systems, required a written asset inventory, added a 24 hour deadline for reporting extortion payments, required both the highest-ranking executive and the CISO to sign the annual filing, and added the option to file an acknowledgment of noncompliance instead of a certification.
Section 500.19(a) grants a limited exemption to a covered entity with fewer than 20 employees and independent contractors, or less than $7,500,000 in gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets. Read the connector carefully: the regulation joins those three tests with "or", so meeting any one of them qualifies you. Plenty of secondary summaries render it as "and", which wrongly excludes firms that do qualify.
Under 500.19(a) a qualifying entity is exempt from sections 500.4, 500.5, 500.6, 500.8, 500.10, 500.14(a)(1), 500.14(a)(2), 500.14(b), 500.15 and 500.16. It is a partial exemption, not a pass. You still owe the cybersecurity program, the policy, access limits, the risk assessment, third-party oversight, the asset inventory, the notices and the annual filing. Note that 500.12 is not on the exemption list, so multi-factor authentication applies even to the smallest covered entity.
A Class A company is a covered entity with at least $20,000,000 in gross annual revenue in each of the last two fiscal years from New York operations of itself and its affiliates, and either more than 2,000 employees or more than $1,000,000,000 in average gross annual revenue over the last three fiscal years across all operations. Class A companies carry extra duties including independent audits of the cybersecurity program and enhanced privileged access management and monitoring.
April 15 each year, covering the prior calendar year. Since the Second Amendment the filing must be signed by both the highest-ranking executive and the CISO, and you must retain the data and records supporting it for five years. Filing late, or filing a certification the records do not support, is itself an enforcement exposure.
A certification of material compliance states that the covered entity materially complied with Part 500 for the prior calendar year. An acknowledgment of noncompliance identifies the sections you did not comply with and includes a remediation timeline. The Second Amendment added the second option deliberately, so that a firm with a known gap has a truthful filing available instead of a choice between signing something unsupported and filing nothing.
72 hours from determining that a reportable cybersecurity event has occurred, under 500.17(a). Separately, if you make an extortion or ransom payment in connection with a cybersecurity event, you must notify NYDFS within 24 hours of the payment and provide a written explanation of why it was necessary within 30 days.
Part 500 is a regulation enforced by a state agency with civil penalties behind it. SOC 2 and ISO 27001 are voluntary assurance products that customers ask for, issued by a CPA firm or a certification body. You cannot substitute one for the other, because no auditor can absolve you of a regulatory obligation. The overlap is in the evidence: access reviews, risk assessments, encryption, vendor due diligence and incident response satisfy all three, which is why mapping controls once and pointing several regimes at the same proof is worth doing.
No. Scrutineer prepares and maintains the control mapping and the evidence behind it, and shows you where the gaps are before the deadline. The filing is made by your covered entity through the NYDFS portal and signed by your own senior officer and CISO. We are explicit about that line because the accountability sits with the signers, not with a vendor.

Keep reading

Guides that go deeper on the controls Part 500 tests

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification