The amended NYDFS Part 500 turns three cybersecurity duties into personal signatures and hard clocks. A board that treats them as the CISO’s paperwork has misread who is on the hook.
The second amendment to 23 NYCRR Part 500, adopted on 1 November 2023 and now fully phased in, is usually summarised as a list of new controls: multi-factor authentication everywhere, asset inventories, privileged-access governance. Those matter, but they are not where a director’s personal exposure sits. The exposure sits in three obligations that are about accountability rather than technology: what the CISO must report to the board, what the annual certification signatories are attesting to, and how fast a cybersecurity incident must be notified to the superintendent. Each of these fails the same way. Not because the control is absent, but because the evidence that the control operated cannot be produced on the day someone asks.
What the CISO actually has to tell you
Section 500.4 splits the CISO’s reporting into two distinct duties, and boards routinely collapse them into one. The first, in 500.4(b), is a written report to the senior governing body at least annually. Its content is prescribed: the confidentiality, integrity and availability of the entity’s information systems and nonpublic information, its cybersecurity policies and procedures, material cybersecurity risks, the overall effectiveness of the programme, and — the phrase that does the work — plans for remediating material inadequacies. The second, in 500.4(c), is a duty to report timely on material cybersecurity issues as they arise: significant cybersecurity events and significant changes to the programme.
The distinction is not pedantic. An annual report satisfies 500.4(b) and tells you nothing about whether 500.4(c) is being met. A board that receives a polished deck every January and hears nothing in between has evidence of the first duty and none of the second. Worse, the annual report’s requirement to disclose plans for remediating material inadequacies means the document is, by design, a record of what the CISO knows is wrong. If that report is anodyne — no inadequacies, no remediation plans, everything green — it is either untrue or it is not the report the rule asks for. Directors should be more worried by a flawless report than by one that names problems and dates for fixing them.
What the two signatures are attesting to
Section 500.17(b) is the provision with teeth. Each covered entity must file electronically with the superintendent by 15 April every year, covering the prior calendar year, one of two things. Either a certification of material compliance with Part 500, or an acknowledgement that the entity did not materially comply, identifying the specific sections and providing a remediation timeline. The filing must be signed by the entity’s highest-ranking executive and its CISO — or, where there is no CISO, by the highest-ranking executive and the senior officer responsible for the cybersecurity programme.
Two people put their names to it. That is the design. The certification is not a corporate act absorbed into the entity; it is two individuals attesting that they have a reasonable basis for the statement. The certification of material compliance must be supported by documentation, including records and schedules, sufficient to demonstrate the basis for the attestation — and the department can ask for it. A signatory who certifies material compliance without holding that documentation has signed something they cannot stand behind. This is why the acknowledgement route exists and why it is often the honest choice: naming the gaps and committing to a remediation timeline is a defensible position; certifying compliance you cannot evidence is not.
The board’s job is to make the signature safe to give. That means the certification is not a spring exercise assembled in the fortnight before 15 April. It is the readout of an evidence pipeline that has been running all year — the same discipline we describe in turning framework alignment into evidence of control. If the highest-ranking executive is asked what the CISO’s certification rests on and the answer is a project that starts in March, the answer is wrong.
The 72-hour clock is an evidence problem, not a form
Section 500.17(a) requires notification to the superintendent, electronically and in the prescribed form, as promptly as possible but no later than 72 hours after determining that a cybersecurity incident has occurred. The clock starts at determination, not at first alert, and that word carries the whole obligation. Notification is triggered where the incident requires notice to any other government body, self-regulatory agency or supervisory body; where it has a reasonable likelihood of materially harming a material part of normal operations; or where ransomware has been deployed within a material part of the entity’s information systems. The obligation is continuing: material changes and new information have to be filed as they emerge.
Seventy-two hours is not the hard part. The hard part is that, after the fact, you must be able to show when determination happened and why the clock was read the way it was. If a firm decides an event was not notifiable, that decision is itself the thing a supervisor will examine. Which means the triage, the classification, the timestamps and the person who made the call have to be captured contemporaneously, not reconstructed. Firms that already run this muscle for the federal regime — the same 72-hour reflex we set out in building the CIRCIA reporting muscle — have most of the pipeline. Firms treating each notification as a bespoke drafting task under pressure do not.
The extortion-payment corner
Section 500.17(c) adds a tighter clock for a narrower event. Where a covered entity makes an extortion payment in connection with a cybersecurity event, it must notify the superintendent within 24 hours of the payment and, within 30 days, provide a written description of the reasons payment was necessary, the alternatives considered, the diligence performed and the sanctions-compliance steps taken. This is not a duty that can be improvised at 2am during an active ransomware negotiation. The decision to pay, and the record justifying it, need a pre-agreed playbook with the board’s authority behind it — the ground we cover in the 24-hour extortion-payment playbook.
The questions a board should be asking now
Three of them, and they are all evidential rather than technical. Where is the documentation that our next 15 April certification will rest on, and is it being maintained now rather than assembled later? When we last decided an event was not notifiable under 500.17(a), can we produce the determination, the timestamp and the reasoning? And does the CISO’s timely reporting under 500.4(c) actually reach us between annual reports, or do we only hear the good version once a year?
Part 500 has quietly moved the failure mode. The regulator is no longer only asking whether you had the control. It is asking whether two named people can prove it, on a clock, in writing. That is an infrastructure question, and it will not answer itself in April.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Governance is what happens when nobody is watching.
Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming