Skip to content

Evidence request lists

NY DFS 23 NYCRR 500

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

§500.1

§500.1
Definitions

Defines key terms including Covered Entity, Class A Company, Cybersecurity Event, Cybersecurity Incident, Nonpublic Information, Information System, Senior Governing Body, CISO, Privileged Account, and Multi-Factor Authentication.

Artefacts an auditor will ask for
  • Covered Entity determination memo
  • Class A Company threshold analysis (employees, revenue, assets)
  • Nonpublic Information inventory and classification scheme
  • Senior Governing Body charter naming
  • Affiliate and subsidiary scoping matrix
  • Glossary aligned to §500.1
  • Limited Exemption eligibility worksheet
Where this commonly fails
  • No documented Class A determination
  • Nonpublic Information not defined consistently with §500.1(k)
  • Affiliate scope unclear
  • No Senior Governing Body identified

§500.10

§500.10
Cybersecurity Personnel and Intelligence

Utilize qualified cybersecurity personnel sufficient to manage cybersecurity risks and perform core functions, provide cybersecurity updates and training sufficient to address relevant risks, and verify personnel maintain current knowledge of changing threats and countermeasures.

Artefacts an auditor will ask for
  • Cybersecurity staffing plan and org chart
  • Role descriptions with required qualifications
  • Training and certification records for cyber staff
  • Threat intelligence feeds and subscription evidence
  • Annual update on threats briefed to staff
  • Use of affiliate or third-party services with oversight documentation
  • Continuing education budget and policy
Where this commonly fails
  • No formal threat intel function
  • Outsourced staff without Covered Entity oversight
  • No continuing education tracking

§500.11

§500.11
Third Party Service Provider Security Policy

Implement written policies and procedures for security of information systems and Nonpublic Information accessible to or held by Third Party Service Providers. Address identification and risk assessment, minimum cybersecurity practices, due diligence, periodic reassessment, and contractual representations on MFA, encryption, breach notice, and representations.

Artefacts an auditor will ask for
  • Third Party Service Provider policy
  • Vendor inventory with risk tiering
  • Due diligence questionnaires and evidence
  • Contract clauses for MFA, encryption, breach notice, and representations
  • Periodic vendor reassessment schedule and outputs
  • Termination and offboarding procedures
  • Subcontractor (fourth party) review evidence
Where this commonly fails
  • No documented tiering
  • Contracts lack §500.11 required terms
  • Reassessment overdue
  • Subcontractor risk not addressed

§500.12

§500.12
Multi-Factor Authentication

MFA required for any individual accessing the Covered Entity's information systems. Specifically required for remote access to information systems, remote access to third-party applications including cloud-based, and all privileged accounts other than service accounts that prohibit interactive login. Reasonably equivalent or more secure controls require CISO written approval and annual review.

Artefacts an auditor will ask for
  • MFA architecture diagram
  • Coverage report by user population (employees, contractors, customers, privileged)
  • VPN and SSO MFA configuration screenshots
  • Cloud application MFA enforcement evidence
  • CISO-approved compensating controls register with annual review
  • Service account inventory with interactive login disabled
  • Phishing-resistant MFA roadmap (Second Amendment alignment)
Where this commonly fails
  • Legacy applications without MFA and no documented exception
  • Service accounts permit interactive login
  • MFA not enforced for cloud admin consoles
  • No CISO written approval for exceptions

§500.13

§500.13
Asset Management and Data Retention Requirements

Implement written policies and procedures for asset inventory tracking (hardware, software, and data including end-of-life), and for secure disposal of Nonpublic Information that is no longer necessary for business operations or other legitimate purposes (except where required to retain).

Artefacts an auditor will ask for
  • Hardware and software inventory with owner, location, end-of-life tracking
  • Data inventory and classification register
  • Retention schedule by record type
  • Secure disposal procedures and certificates of destruction
  • End-of-life and end-of-support tracking dashboard
  • Reconciliation of inventory to CMDB or equivalent
  • Annual review of asset and retention procedures
Where this commonly fails
  • No end-of-life tracking
  • Stale data retained beyond business need
  • No certificates of destruction
  • Cloud assets missing from inventory

§500.14

§500.14
Monitoring and Training

Implement risk-based controls including monitoring of authorized user activity and detection of unauthorized access or tampering, malware protection, annual cybersecurity awareness training including social engineering. Class A must implement endpoint detection and response solution and centralized logging.

Artefacts an auditor will ask for
  • UEBA or user activity monitoring outputs
  • Anti-malware deployment coverage report
  • Annual training completion records with phishing simulation results
  • Class A EDR coverage dashboard
  • Class A centralized SIEM logging design and coverage
  • CISO-approved compensating control register if EDR/SIEM not implemented (Class A)
  • Training content review covering social engineering
Where this commonly fails
  • Class A without EDR and no documented compensating control
  • Training annual but not role-specific
  • Phishing simulation absent
  • Monitoring blind spots in OT or cloud

§500.15

§500.15
Encryption of Nonpublic Information

Implement controls including encryption to protect Nonpublic Information held or transmitted by the Covered Entity in transit over external networks and at rest. Where encryption at rest is infeasible, CISO may approve effective alternative compensating controls, reviewed at least annually.

Artefacts an auditor will ask for
  • Encryption standards and approved algorithms list
  • TLS configuration scans for external endpoints
  • At-rest encryption coverage report by data store
  • Key management procedures and HSM evidence
  • CISO-approved compensating control register for at-rest exceptions with annual review
  • Discovery scans for unencrypted Nonpublic Information
  • Email and file transfer encryption configuration
Where this commonly fails
  • Legacy databases not encrypted at rest without CISO approval
  • Weak TLS versions still enabled
  • Key rotation not enforced
  • No annual review of compensating controls

§500.16

§500.16
Incident Response and Business Continuity Management

Establish written Incident Response Plan and Business Continuity and Disaster Recovery Plan reasonably designed to respond to and recover from material cybersecurity events. Plans must address specified elements (internal processes, goals, roles, communications, remediation, documentation, evaluation). Test plans annually with all critical staff and proactively maintain backups isolated from network connections.

Artefacts an auditor will ask for
  • Incident Response Plan addressing all required §500.16(a)(1) elements
  • BCDR plan including ransomware scenarios
  • Annual tabletop and technical test results with lessons learned
  • Backup architecture demonstrating isolation (immutable, offline, or air-gapped)
  • Backup restore test evidence
  • Communication plan including regulator and customer notifications
  • Post-incident review and improvement records
Where this commonly fails
  • IR plan missing required elements
  • No ransomware-specific scenario tests
  • Backups not isolated and recoverable
  • No documented restore tests

§500.17

§500.17
Notices to Superintendent

Notify the Superintendent within 72 hours of a Cybersecurity Incident affecting the Covered Entity. Provide notice of extortion payment within 24 hours, with detailed explanation within 30 days. File annual Notice of Compliance or Acknowledgment of Noncompliance by April 15 signed by highest-ranking executive and CISO. Maintain supporting records for five years.

Artefacts an auditor will ask for
  • Incident notification SOP with §500.17(a) criteria
  • Sample submitted 72-hour notices via DFS portal
  • 24-hour ransom payment notice procedure and 30-day explanation template
  • Signed annual Notice of Compliance covering prior calendar year
  • Acknowledgment of Noncompliance with remediation plan if applicable
  • Five-year retention of supporting records and schedules
  • Internal escalation runbook ensuring CISO and CEO sign-off
Where this commonly fails
  • 72-hour clock starts late (at confirmation rather than determination)
  • Annual certification signed only by CISO not CEO
  • Insufficient supporting documentation retained
  • Ransom payment 24-hour clock missed

§500.18

§500.18
Confidentiality

Information provided to the Superintendent under Part 500 is subject to exemptions from disclosure under applicable confidentiality laws, including Banking Law, Insurance Law, Financial Services Law, and Public Officers Law.

Artefacts an auditor will ask for
  • Submission procedure that marks notices confidential
  • Legal review record citing applicable confidentiality statutes
  • Internal handling protocol for DFS submissions
  • FOIL response runbook referencing exemptions
  • Records access log for sensitive submissions
Where this commonly fails
  • Submissions not marked confidential
  • No internal protocol for FOIL referrals
  • Sensitive content over-shared internally

§500.19

§500.19
Exemptions

Limited Exemption for entities with fewer than 20 employees and independent contractors, less than $7.5M gross annual revenue (3-year avg from NY operations), or less than $15M year-end total assets, exempted from specified sections. Full exemption categories include employees of an affiliate, certain charitable annuity societies, inactive insurance agents, risk retention groups not chartered in NY, and entities not directly or indirectly operating systems holding Nonpublic Information. File Notice of Exemption within 30 days.

Artefacts an auditor will ask for
  • Exemption eligibility worksheet (employees, revenue, assets)
  • Notice of Exemption filed via DFS portal
  • Annual recertification of eligibility
  • Documentation of which sections still apply under Limited Exemption
  • Affiliate scope analysis for full exemption claims
  • Trigger procedure for loss of exemption
Where this commonly fails
  • Notice of Exemption not refiled when status changes
  • Misapplied exemption (e.g., counting only NY employees)
  • No trigger to reassess

§500.2

§500.2
Cybersecurity Program

Maintain a written cybersecurity program based on the Risk Assessment that performs the core functions: identify, protect, detect, respond, recover, and fulfill reporting obligations.

Artefacts an auditor will ask for
  • Written cybersecurity program document
  • Mapping of program elements to identify/protect/detect/respond/recover functions
  • Risk Assessment linkage matrix
  • Board or Senior Governing Body approval record
  • Annual program review minutes
  • Program scope statement including affiliates
  • Evidence of integration with enterprise risk
Where this commonly fails
  • Program not tied to documented Risk Assessment
  • Missing recover function documentation
  • No annual review of program
  • Program adopted from affiliate without §500.2(c) adoption record

§500.20

§500.20
Enforcement

Regulation enforced by the Superintendent under Banking Law, Insurance Law, and Financial Services Law. A single act of noncompliance with any section constitutes a violation. Mitigation factors include cooperation, good faith, history of compliance, and remediation actions.

Artefacts an auditor will ask for
  • Examination response runbook
  • Examiner interaction log
  • Internal remediation tracker tied to findings
  • Legal hold and document preservation procedure
  • Voluntary disclosure protocol
  • Track record of timely remediation
Where this commonly fails
  • No examination response procedure
  • Remediation evidence not retained
  • Findings closed without verification

§500.21

§500.21
Effective Date

Part 500 took effect March 1, 2017. The Second Amendment took effect November 1, 2023 with transitional periods for specified subsections.

Artefacts an auditor will ask for
  • Compliance roadmap aligned to Second Amendment effective and transitional dates
  • Internal go-live tracker for each new requirement
  • Evidence of program updates post November 2023
  • Communication to stakeholders of new effective dates
Where this commonly fails
  • No tracking of Second Amendment phased dates
  • Stale program documentation predating amendments

§500.22

§500.22
Transitional Periods

Provides phased transitional compliance periods for new and amended requirements (commonly 180 days, one year, 18 months, and two years from November 1, 2023), with specific deadlines for governance, MFA, asset management, BCDR, encryption, EDR, and centralized logging.

Artefacts an auditor will ask for
  • Section-by-section transitional date register
  • Milestone closure evidence for 180-day, 1-year, 18-month, and 2-year requirements
  • Executive sponsor sign-off on closure
  • Gap remediation plan for any missed milestones
  • Updated annual Notice of Compliance reflecting transitional posture
Where this commonly fails
  • Missed November 2024 or November 2025 milestones
  • No documented closure evidence per section
  • Mismatch between actual posture and certification

§500.23

§500.23
Severability

If any provision of Part 500 is held invalid, the remainder of the regulation remains in effect.

Artefacts an auditor will ask for
  • Legal memo acknowledging severability for compliance design purposes
  • Program design notes preserving controls even if specific provisions are challenged
Where this commonly fails
  • Not typically subject to evidence requests

§500.24

§500.24 (Second Amendment, Class A Companies)
Class A Company Enhanced Obligations (cross-section)

Class A Companies face enhanced obligations: independent audits of cybersecurity program based on risk, external pen testing at least every three years, automated vulnerability scans with manual review, privileged access management and password blocklisting, endpoint detection and response, centralized logging.

Artefacts an auditor will ask for
  • Class A threshold calculation worksheet
  • Independent cybersecurity audit reports based on Risk Assessment
  • External penetration test reports (triennial minimum)
  • PAM tooling deployment evidence
  • Banned password list enforcement evidence
  • EDR coverage report across endpoints
  • Centralized SIEM coverage report and retention
  • CISO-approved compensating controls for any EDR or SIEM gap with annual review
Where this commonly fails
  • No independent audit performed
  • EDR or SIEM not enterprise-wide
  • No banned password enforcement
  • Triennial external pen test missed

§500.3

§500.3
Cybersecurity Policy

Implement and maintain written policies approved at least annually by a Senior Officer or Senior Governing Body addressing 14 enumerated areas including information security, data governance, access controls, BCDR, third-party security, vendor management, and incident response.

Artefacts an auditor will ask for
  • Cybersecurity policy set covering all 14 §500.3 topics
  • Annual approval record by Senior Officer or Senior Governing Body
  • Policy index mapping each topic to a document
  • Version history and change log
  • Distribution and acknowledgment records
  • Exception and deviation register
  • Policy review cycle calendar
Where this commonly fails
  • Missing topics (often data retention, BCDR, customer data privacy)
  • Approval at staff level rather than Senior Officer or Governing Body
  • Policies not updated post Second Amendment

§500.4

§500.4
Cybersecurity Governance (CISO)

Designate a qualified CISO responsible for overseeing and implementing the program and enforcing policy. CISO reports in writing at least annually to Senior Governing Body on program status, risks, and material events. Senior Governing Body must exercise oversight and have sufficient cybersecurity expertise.

Artefacts an auditor will ask for
  • CISO appointment letter with qualifications
  • Annual CISO written report to Senior Governing Body
  • Board or committee minutes evidencing oversight
  • Material event notifications to governing body
  • Evidence of cybersecurity expertise on governing body (training, advisors)
  • CISO independence and reporting line diagram
  • Third-party CISO arrangement and oversight if applicable
Where this commonly fails
  • CISO report missing required content (material risks, mitigation, plans)
  • No documented board cybersecurity expertise
  • CISO lacks authority or budget
  • Outsourced CISO without Covered Entity oversight

§500.5

§500.5
Vulnerability Management

Conduct penetration testing at least annually by qualified internal or external party, automated scans of information systems and manual reviews of systems not covered by scans, document and report material issues, prioritize and remediate. Class A must use external experts at least every three years.

Artefacts an auditor will ask for
  • Annual penetration test report from qualified party
  • Automated vulnerability scan schedule and outputs
  • Manual review records for non-scannable systems
  • Remediation tickets with SLAs and closure evidence
  • Risk-based prioritization methodology
  • Class A external expert engagement letter (triennial)
  • Monitoring of publicly disclosed vulnerabilities and CISA KEV tracking
Where this commonly fails
  • No coverage of non-scannable systems
  • Scans not authenticated
  • Remediation SLAs not tracked or breached
  • Pen test scope too narrow

§500.6

§500.6
Audit Trail

Securely maintain systems that, based on Risk Assessment, are designed to reconstruct material financial transactions and include audit trails to detect and respond to cybersecurity events that have material likelihood of harming operations. Retain transaction records five years and audit trails three years.

Artefacts an auditor will ask for
  • Logging and SIEM design document
  • List of in-scope financial systems and event logs
  • Five-year transaction record retention proof
  • Three-year audit trail retention proof
  • Log integrity protection controls (WORM, hashing)
  • Log review and alerting procedures
  • Risk Assessment driving logging scope
Where this commonly fails
  • Audit trails fewer than three years
  • No log integrity protection
  • Critical systems not logging
  • No documented retention schedule

§500.7

§500.7
Access Privileges and Management

Limit user access privileges to Nonpublic Information based on least privilege, limit privileged accounts, periodically review access (at least annually), promptly terminate access on role change or separation, disable or securely configure remote access, implement password policy aligned with industry standards. Class A must implement privileged access management and prohibit commonly used passwords.

Artefacts an auditor will ask for
  • Access control policy with least privilege standard
  • Privileged account inventory and PAM tooling for Class A
  • Annual user access reviews with attestations
  • Joiners movers leavers process with timing metrics
  • Password policy aligned to NIST or equivalent
  • Banned password list enforcement (Class A)
  • Remote access architecture and MFA evidence
Where this commonly fails
  • No PAM for Class A
  • Stale accounts not deprovisioned
  • Annual reviews missing for vendor accounts
  • Shared admin accounts in use

§500.8

§500.8
Application Security

Cybersecurity program shall include written procedures, guidelines, and standards for secure development practices for in-house developed applications and procedures for evaluating, assessing, or testing the security of externally developed applications. Reviewed and updated by CISO at least annually.

Artefacts an auditor will ask for
  • Secure development standard (OWASP ASVS or equivalent)
  • SAST/DAST/SCA tool outputs and remediation logs
  • Code review records for in-house applications
  • Third-party application security assessment records
  • Annual CISO sign-off on application security procedures
  • Developer secure coding training records
  • Production deployment gating checklist
Where this commonly fails
  • No SCA for open source dependencies
  • Externally developed apps not assessed
  • No CISO annual review of procedures

§500.9

§500.9
Risk Assessment

Conduct a written Risk Assessment of the Covered Entity's information systems, reviewed and updated at least annually and whenever a change in business or technology causes material change to risk. Assessment must follow written policies and procedures and account for emerging technologies and changes in nonpublic information.

Artefacts an auditor will ask for
  • Written Risk Assessment methodology
  • Current annual Risk Assessment report
  • Risk register with treatments and owners
  • Change-triggered reassessments log
  • Inventory of information systems and data flows feeding the assessment
  • Linkage of Risk Assessment to controls in §500.2 program
  • Board or governing body briefing on top risks
Where this commonly fails
  • Risk Assessment more than 12 months old
  • No reassessment after material change (M&A, cloud migration)
  • Risks not mapped to controls
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.