Most firms discover they are a NYDFS Class A company the hard way: in an examination, when the supervisor asks for the independent audit report and the endpoint-detection coverage they never stood up.
The Second Amendment to 23 NYCRR Part 500 created a tier that most commentary glosses over. Above the baseline that every covered entity owes sits the Class A company, carrying a set of heightened duties that materially change the security architecture and the budget. None of the extra controls is exotic. What catches firms out is the definition that switches them on, and the assumption that ordinary Part 500 coverage will be enough. It will not, if you are Class A and have not noticed.
What actually makes you Class A
Section 500.1 defines a Class A company as a covered entity with at least 20 million dollars in gross annual revenue in each of the last two fiscal years from all business operations, that also meets one of two further tests: over 2,000 employees averaged over the last two fiscal years, counting the entity and all of its affiliates wherever located; or over one billion dollars in gross annual revenue in each of the last two fiscal years, again counting the entity and all of its affiliates.
Free · 4 minutes
Would you survive contact with a determined attacker — or an auditor?
Fourteen questions on access, patching, detection, and recovery — the basics that prevent most real incidents, and the ones most often assumed rather than verified. Banded finding on screen, full sheet by email.
The trap is in the affiliate arithmetic. Affiliates are counted only where they share information systems, cybersecurity resources, or any part of the cybersecurity programme with the covered entity. A modest New York-licensed subsidiary can therefore be pulled over the line by the headcount or revenue of a much larger group, purely because it shares a security operations centre, an identity platform, or a common programme. Firms that look only at their own standalone numbers routinely misclassify themselves. This is a determination worth documenting deliberately, with the affiliate map and the shared-resource analysis written down, rather than a status you assume you have escaped.
The four controls scale actually triggers
Cross the threshold and four specific obligations attach on top of everything else in Part 500:
- Independent cybersecurity audits (500.2(c)). A Class A company must design and conduct independent audits of its cybersecurity programme, at a frequency set by its risk assessment. Independent means the auditor is free from influence by the people who run the controls being examined, whether internal audit or an external firm.
- External-expert risk assessment (500.9). Beyond the annual risk assessment every covered entity owes, a Class A company must use external experts to conduct a risk assessment at least once every three years.
- Privileged access controls (500.7(c)). A Class A company must monitor privileged access activity and implement both a privileged access management solution and an automated method for blocking commonly used passwords on the systems it owns or controls, and wherever feasible on all other accounts.
- EDR and centralised logging (500.14(b)). A Class A company must implement an endpoint detection and response solution to monitor anomalous activity, including lateral movement, and a solution that centralises logging and security-event alerting, unless the CISO has approved in writing the use of reasonably equivalent or more secure compensating controls.
That last carve-out matters. Only 500.14(b) grants the CISO a written-equivalence route. The privileged-access duties in 500.7(c) carry no such escape hatch, and neither does the independent audit. If you are planning to argue that your existing tooling is good enough, the argument only lands for EDR and logging, and only if it is documented and signed.
Why these are architecture decisions, not policy edits
None of this is satisfied by a document. Centralised logging and security-event alerting is SIEM-class capability, with the data-volume, retention and staffing cost that implies. EDR means an agent on every endpoint that matters, tuned to surface lateral movement rather than just malware signatures, and a team able to act on what it raises. The privileged access management bar Part 500 now sets means vaulting, session monitoring and a credential model that most firms have to rebuild, not reconfigure. The independent audit requires genuine separation between the people who operate the programme and the people who assess it, which is an organisational decision before it is a procurement one.
These land on the same budget line and the same team at the same time. Treating them as four discrete compliance items, each bought from a different vendor, is how firms end up with overlapping tools, an alerting backlog nobody reads, and an audit that finds all of it. The sane sequence is to model the estate first, decide where EDR and centralised logging actually have to reach, and let the tooling follow the coverage decision.
The dates, stated accurately
The Class A controls in 500.7(c), 500.14(b) and 500.2(c) fell due on 1 May 2025, at the end of the eighteen-month transition from the Second Amendment. The 1 November 2025 milestone was the final phase-in, and it was not Class A specific: it brought the general multi-factor authentication and asset-inventory duties into force for every covered entity. If you are Class A, the heightened set has been live for over a year. An examiner in 2026 expects it evidenced, not in flight.
What an examiner will ask to see
Expect the request to be concrete: the most recent independent audit report and evidence of the auditor’s independence; the privileged access management deployment and the proportion of privileged accounts actually brought under it; the EDR console and its coverage across the endpoint estate, including where lateral movement would show; the centralised log store, its retention, and the alerting built on top; the external-expert risk assessment from within the last three years; and, if you took the equivalence route on EDR or logging, the CISO’s written approval of the compensating controls. All of this feeds the same evidence trail your CISO signs in the annual certification, where a gap is now a signed-for gap rather than an oversight.
Class A status is not a badge you apply for. It is a line you cross, often without noticing, the moment an affiliate’s headcount tips you over. Confirm which side of it you are on before an examiner does it for you.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming