Under the New York Department of Financial Services (DFS) cybersecurity regulation, 23 NYCRR Part 500, every covered entity must certify each year that it complied with the regulation during the prior calendar year. Section 500.17(b) sets the deadline at February 15. The certification covering 2019 was due on February 15, 2020, and the one covering 2020 is due by February 15, 2021.
The best way to prepare is to treat the certification as the last step of a year-long evidence cycle rather than a February paperwork task. That means a current risk assessment, approved policies, a CISO report to the board, completed testing, and gaps fixed or documented before anyone signs. This post covers what the filing requires and gives you a checklist to work through.
What does the NYDFS annual certification require?
Section 500.17(b) requires each covered entity to submit a written statement covering the prior calendar year, in the form set out in Appendix A, certifying that it is in compliance with Part 500. DFS has directed that certifications be filed electronically through the DFS Portal.
Three details matter for planning:
- Who signs. Appendix A is signed by the Chairperson of the Board of Directors or a Senior Officer (or Senior Officers).
- Supporting records. You must keep "all records, schedules and data supporting this certificate for a period of five years" and make them available to DFS for examination.
- Remediation. If you've identified areas, systems or processes that require material improvement, updating or redesign, you must document them along with the remedial efforts planned and underway. That documentation must be available for DFS inspection.
The person signing is attesting to compliance for the whole year. Give them evidence they can rely on, not a summary slide.
Where does Part 500 stand in 2020?
Part 500 took effect on March 1, 2017, with staggered transitional periods under Section 500.22. The last of them ended on March 1, 2019.
| Date | Milestone |
|---|---|
| March 1, 2017 | Part 500 took effect |
| August 2017 (180 days) | Most requirements applied, including the cybersecurity program, policy, CISO, access privileges, incident response plan and 72-hour notice |
| February 15, 2018 | First annual certification due |
| March 1, 2018 (one year) | CISO board reporting (500.04(b)), penetration testing and vulnerability assessments (500.05), risk assessment (500.09), multi-factor authentication (500.12) and training (500.14(b)) |
| September 2018 (18 months) | Audit trail (500.06), application security (500.08), data retention limits (500.13), monitoring (500.14(a)) and encryption (500.15) |
| March 1, 2019 (two years) | Third-party service provider security policy (500.11) |
| February 15, 2021 | Certification due for calendar year 2020 |
Because the third-party requirements took effect partway through 2019, the certification for 2020 will be the first to cover a full calendar year with every requirement in force. Your third-party program will need a full year of evidence behind it.
Who has to file, and what are the exemptions?
A covered entity is any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under New York's Banking, Insurance or Financial Services Laws.
Section 500.19(a) gives a limited exemption to covered entities with:
- Fewer than 10 employees, including independent contractors, of the covered entity or its affiliates located in New York or responsible for its business
- Less than $5,000,000 in gross annual revenue in each of the last three fiscal years from New York business operations of the covered entity and its affiliates
- Less than $10,000,000 in year-end total assets, calculated under GAAP and including the assets of all affiliates
Entities that qualify are exempt from Sections 500.04, 500.05, 500.06, 500.08, 500.10, 500.12, 500.14, 500.15 and 500.16. They still need a cybersecurity program, policy, access controls, risk assessment, third-party policy and data retention limits. Section 500.17 isn't on the exempted list, so they still file the annual certification.
Other exemptions cover employees and agents of a covered entity who are covered by its program (500.19(b)), and entities that don't operate or control information systems and don't hold nonpublic information (500.19(c)). An entity claiming an exemption must file a Notice of Exemption within 30 days of determining that it qualifies.
What is the 72-hour notice requirement?
Section 500.17(a) is the other half of the notice section, and your certification covers it too. You must notify DFS "as promptly as possible but in no event later than 72 hours from a determination that a Cybersecurity Event has occurred" when the event is either:
- One that requires notice to any government body, self-regulatory agency or other supervisory body, or
- One that has a reasonable likelihood of materially harming any material part of your normal operations
The clock starts at determination, not discovery. Your incident response plan should say who makes that determination and who files the notice. Keep records of how each event was assessed, including the ones you decided weren't reportable.
NYDFS certification checklist: what to verify before you sign
Work through each item during the year, not in the two weeks before the deadline. For each one, gather the evidence you would show an examiner.
| Requirement | Section | Evidence to have on file |
|---|---|---|
| Risk assessment | 500.09 | A current, documented assessment and the process for updating it |
| Cybersecurity policy | 500.03 | Policy approved by a Senior Officer or the board |
| CISO report | 500.04(b) | The written report to the board and the date it was presented |
| Penetration testing and vulnerability assessments | 500.05 | Test reports, scope and remediation tracking |
| Audit trail | 500.06 | Records kept for five years (financial transactions) or three years (cybersecurity events) |
| Access privileges | 500.07 | Access review records and evidence of limits on privileged access |
| Third-party service providers | 500.11 | The policy, vendor risk assessments and contract provisions |
| Multi-factor authentication | 500.12 | Configuration evidence for external network access |
| Training and monitoring | 500.14 | Training completion records and monitoring procedures |
| Encryption | 500.15 | Encryption coverage, plus any compensating controls and the CISO's annual review of them |
| Incident response plan | 500.16 | The written plan and any tests or post-incident updates |
Start with the risk assessment
Section 500.09 requires a periodic risk assessment that informs the design of your program. Several other requirements, including training content and access controls, are supposed to reflect it. If your assessment is more than a year old or predates significant system changes, update it first.
Confirm the policy and the CISO report
Your written policy must be approved by a Senior Officer or the board and must cover the areas listed in Section 500.03, from asset inventory and access controls to business continuity, vendor management and incident response.
Under Section 500.04(b), the CISO reports in writing to the board, or an equivalent governing body, at least annually. The report covers the confidentiality, integrity and security of your systems and nonpublic information, your policies, material cybersecurity risks, the program's overall effectiveness and material cybersecurity events. Schedule it so the board sees it before the certification is signed.
Complete testing and access reviews
Absent effective continuous monitoring, Section 500.05 requires annual penetration testing, scoped on the risks identified in your risk assessment, and bi-annual vulnerability assessments. Keep the reports along with evidence that you fixed what they found.
Section 500.07 requires you to limit user access privileges to systems that provide nonpublic information and to review those privileges periodically. Document the reviews and the changes they produced.
Check MFA and encryption coverage
Section 500.12 requires multi-factor authentication for anyone accessing your internal networks from an external network, unless the CISO has approved in writing reasonably equivalent or more secure controls. If you expanded remote access this year, recheck coverage.
Section 500.15 requires encryption of nonpublic information in transit over external networks and at rest. Where encryption isn't feasible, effective compensating controls reviewed and approved by the CISO are allowed. The CISO must then review the feasibility of encryption and the effectiveness of those controls at least annually.
Review training and third-party oversight
Section 500.14 requires monitoring of authorized users and regular cybersecurity awareness training that reflects the risks in your risk assessment. Keep completion records.
Your third-party service provider policy under Section 500.11 must address how you identify and assess vendors, the minimum practices they must meet, due diligence, and periodic assessment. Check that contracts and assessments actually follow it.
Close gaps before certifying
The certification states that you comply. If the review turns up material gaps, fix them before the filing date where you can, and document the identification and the remediation under way as Section 500.17(b) requires. Talk to counsel before signing if anything significant is still open.
Frequently asked questions
When is the NYDFS certification due?
February 15 each year, covering the prior calendar year. The certification for 2020 is due by February 15, 2021.
Who signs the certification?
The Chairperson of the Board of Directors or a Senior Officer. Have the CISO and compliance lead walk the signer through the supporting evidence before they sign.
How long do we keep supporting records?
Five years under Section 500.17(b). Separately, Section 500.06 sets retention periods for audit trail records: at least five years for records needed to reconstruct material financial transactions and three years for records needed to detect and respond to cybersecurity events.
Do exempt entities still certify?
Yes. The limited exemption in Section 500.19(a) doesn't cover Section 500.17, so those entities still file the annual certification.
Next steps
This post summarizes Part 500 as of March 2020 and isn't legal advice, so confirm how it applies to your organization with counsel. To be ready for the February 15, 2021 filing:
- Assign an owner for each checklist item and a date to have its evidence in place.
- Update the risk assessment early in the year so everything else can build on it.
- Schedule penetration testing, vulnerability assessments and access reviews now.
- Bring your third-party program up to a full year of documented oversight.
- Book the CISO's board report for well before the deadline.
- Hold a pre-certification review in January to confirm evidence and remaining gaps before the signer attests.