Scrutineer · By framework
NYDFS cybersecurity regulation software for 23 NYCRR Part 500
Part 500 is fully phased in: universal MFA and the written asset inventory have been in force since November 1, 2025.
Scrutineer maps your controls to each section and keeps the evidence the April 15 certification has to rest on.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with NYDFS cybersecurity regulation software
Every section mapped, including the ones you may be exempt from
Part 500 is not one obligation, it is roughly twenty of them with different scopes. Scrutineer maps your controls section by section and marks which ones the 500.19(a) limited exemption actually covers, so you stop preparing evidence you do not owe and stop missing the ones you do.
Evidence dated across the period, not screenshotted in April
The certification covers a calendar year, and 500.17(b) requires you to keep the supporting data and records for five years. Scrutineer pulls proof from your cloud, identity and ticketing systems on a schedule and timestamps it, so the filing is supported by a year of records rather than a week of scrambling.
You see the gap before you sign your name to it
The amended rule makes the highest-ranking executive and the CISO both sign. That changes the stakes of an optimistic answer. Scrutineer flags drifted controls, stale evidence and uncovered systems while there is still time to remediate, so the choice between a certification and an acknowledgment of noncompliance is made on data.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps your control set to each Part 500 section, from 500.2 through 500.17
- Flags which sections the 500.19(a) limited exemption covers and which it does not
- Tracks MFA coverage under 500.12 and keeps every written exception with its approval
- Maintains the 500.13 asset inventory with owner, location, classification and recovery time
- Runs the annual access review 500.7 requires and keeps the reviewer sign-off
- Holds the 500.9 risk assessment and the third-party due diligence 500.11 expects
- Assembles the April 15 filing package with five years of supporting records behind it
- Reuses the same evidence for SOC 2, ISO 27001 and PCI DSS instead of collecting it twice
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Scope reference
Which parts of 23 NYCRR 500 actually apply to you, and what proves each one
Most Part 500 summaries list the requirements without saying who is off the hook for which. That is the question a smaller covered entity actually has. The third column reads the 500.19(a) limited exemption against each section, and the row worth stopping on is 500.12: multi-factor authentication is not on the exemption list, so it reaches even the smallest licensee.
| Part 500 section | What it requires | Covered by the 500.19(a) limited exemption? | Evidence an examiner asks for |
|---|---|---|---|
| 500.2 Cybersecurity program | Maintain a documented program designed on the findings of your risk assessment, covering identification, protection, detection, response and recovery. | No. Applies to every covered entity. | The program documentation and the risk assessment it is built on, with dates. |
| 500.3 Cybersecurity policy | Written policies approved at least annually by a senior officer or the board, covering the areas the section enumerates. | No. | The approved policy set showing the approver and the approval date. |
| 500.4 CISO | Designate a qualified CISO, who reports in writing to the board at least annually on program effectiveness and material risks. | Yes, exempt. | The designation and the dated annual written report, plus the board minute receiving it. |
| 500.5 Penetration testing and vulnerability assessments | Annual penetration testing of information systems, plus automated scans and manual review at a frequency set by risk. | Yes, exempt. | The penetration test report and scan records, with remediation tracked to closure. |
| 500.7 Access privileges and access review | Limit access to what is needed, review all user access privileges at least annually, and remove access promptly when it is no longer required. | No. | A completed access review with reviewer sign-off, plus termination records showing when access was actually removed. |
| 500.9 Risk assessment | A written risk assessment sufficient to inform the program, reviewed and updated at least annually and when the business changes materially. | No. | The dated assessment and the written policy and procedure that governs how it is conducted. |
| 500.11 Third-party service provider policy | Written policies for due diligence on service providers and for the security requirements you put in their contracts. | No. | The policy, the due diligence records for sampled vendors, and the security clauses in executed contracts. |
| 500.12 Multi-factor authentication | MFA for any individual accessing any information system, in force since November 1, 2025. A CISO may approve a written exception using reasonably equivalent or more secure compensating controls. | No. This is the one small entities get wrong. | MFA coverage across remote access, privileged accounts and third-party applications, plus every written exception with its approval and annual review. |
| 500.13 Asset inventory | A written policy and procedure for asset management, and an inventory tracking owner, location, classification, support expiration and recovery time objectives. In force since November 1, 2025. | No. | The inventory itself and the documented procedure that keeps it current. |
| 500.15 Encryption | Encrypt nonpublic information in transit over external networks and at rest, or apply CISO-approved alternative compensating controls where encryption is infeasible. | Yes, exempt. | Encryption configuration evidence and, where used, the CISO approval for a compensating control. |
| 500.16 Incident response and business continuity | Written incident response plans and business continuity and disaster recovery plans, tested at least annually, with backups tested for restoration. | Yes, exempt. | The plans, the annual test record, the after-action notes and evidence of a restore test. |
| 500.17 Notices and annual filing | Notice to the superintendent within 72 hours of determining a cybersecurity event occurred, within 24 hours of an extortion payment, and an April 15 filing signed by the highest-ranking executive and the CISO. | No. | The dual-signed certification of material compliance or acknowledgment of noncompliance, plus five years of supporting data and records. |
Section content and the 500.19(a) exemption list are read from the text of 23 NYCRR Part 500 as amended, current at August 2026. The exemption in 500.19(a) is written with "or" between its three thresholds, so meeting any single one qualifies; several widely circulated summaries render it as "and". Exemption status turns on facts about your own entity and its affiliates, and 500.19 requires you to file a notice of exemption, so confirm your position with counsel rather than relying on a table. Scrutineer prepares and maintains the evidence; your covered entity makes and signs the filing.
Good questions
Questions about NYDFS cybersecurity regulation software
Keep reading
Guides that go deeper on the controls Part 500 tests
FTC Safeguards Rule requirements
The other US financial-sector security mandate, its nine required elements, and who the under-5,000-consumer exemption really covers.
Read the guideThe user access review process
What 500.7 expects once a year, the evidence auditors sample, and the five exceptions that get written up most often.
Read the guideHow to conduct a cybersecurity risk assessment
The annual written assessment 500.9 requires, and how to produce one that actually informs the program.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification