What Is NYDFS 23 NYCRR 500?
The New York Department of Financial Services Cybersecurity Regulation, known as 23 NYCRR Part 500, is one of the most prescriptive and aggressively enforced cybersecurity mandates in the United States. First enacted in 2017 and significantly amended in November 2023, it applies to every entity operating under a license, registration, or charter from the New York Banking Law, Insurance Law, or Financial Services Law, including banks, insurance companies, mortgage companies, money transmitters, and licensed lenders.
The 2023 amendments introduced personal accountability for senior leadership. Under Section 500.17(b), the annual compliance certification must now be co-signed by both the CEO and the CISO, creating direct personal liability for cybersecurity failures.
The Penetration Testing Requirement
Section 500.5 of the regulation requires every covered entity to conduct annual penetration testing of its information systems based on the entity's risk assessment. Specifically, the regulation requires:
- Annual penetration testing of information systems
- Bi-annual vulnerability assessments (at minimum)
- Testing must be risk-based and cover systems identified in the entity's risk assessment
- Results must be documented and retained for at least five years
- Identified vulnerabilities must be remediated on a defined schedule
Class A Companies Face Additional Requirements
The 2023 amendment created a new category ("Class A Companies") defined as entities with over $20 million in gross annual revenue in each of the last two fiscal years from New York operations, or over $1 billion in total gross annual revenue. Class A Companies face stricter requirements including mandatory independent audits, privileged access management (PAM) solutions, and endpoint detection and response (EDR) systems.
What NYDFS Examiners Look For
NYDFS has ramped up enforcement significantly since 2022, issuing consent orders and fines reaching into the tens of millions of dollars. During examinations, regulators typically request:
- The most recent penetration test report: including scope, methodology, and findings
- Evidence of remediation for critical and high findings
- Documentation showing the test was conducted by a qualified firm
- The risk assessment that informed the testing scope
- Vulnerability assessment results and remediation tracking
How a NYDFS-Aligned Penetration Test Is Scoped
The regulation ties testing to your risk assessment rather than prescribing a fixed checklist, so scope should follow where your nonpublic information and critical systems actually live. For most covered entities that means external network testing of internet-facing systems, internal network testing that models an attacker who has already gained a foothold, and testing of any web applications or customer portals that handle nonpublic information. Firms with remote access, cloud workloads, or third-party integrations should bring those into scope as well. Grid32 helps define a scope that maps to your risk assessment, so the test covers the systems examiners expect and the paths an attacker would actually use. Our guides to external and internal network testing explain how each is performed.
NYDFS Testing Requirements at a Glance
The regulation combines several testing and assessment obligations. The summary below covers the ones most relevant to a covered entity's security testing program. Your risk assessment determines the exact scope and cadence.
| Requirement | Frequency | Section |
|---|---|---|
| Penetration testing of information systems | At least annually, based on the risk assessment | 500.5 |
| Vulnerability assessments and automated scanning | Periodic, at a cadence set by the risk assessment, and after material changes | 500.5 |
| Risk assessment | Reviewed and kept current | 500.9 |
| Compliance certification, co-signed by CEO and CISO | Annually | 500.17(b) |
| Cybersecurity event notification to NYDFS | Within 72 hours of a determination | 500.17(a) |
Documentation and Remediation Examiners Expect
Passing an examination is as much about documentation as it is about testing. NYDFS requires records to be retained for at least five years, so keep each penetration test report, the risk assessment that scoped it, and evidence that critical and high findings were remediated on a defined schedule. Remediation cannot sit open indefinitely: examiners want to see that serious findings were prioritized and closed, and that a plan exists for the rest. When fixes are complete, retesting produces the verification that turns a list of findings into demonstrable compliance.
What Grid32 Provides for NYDFS Compliance
Grid32 has conducted NYDFS-aligned penetration tests for financial institutions in New York since the regulation's inception. Our reports are structured to satisfy examiner requests directly: an executive summary suitable for board review, detailed technical findings with severity ratings and remediation guidance, evidence of methodology, and a client-facing attestation letter confirming scope and completion. We retain documentation that supports the five-year retention requirement.
How NYDFS Testing Overlaps With Other Frameworks
A single well-scoped engagement often satisfies more than one obligation. The annual testing NYDFS requires also supports a SOC 2 examination and the expectations of cyber insurers, and it aligns with the broader security program most financial institutions maintain. If you are subject to several frameworks, scoping one test to the union of their requirements avoids paying for overlapping engagements while still producing the documentation each examiner wants.
Frequently Asked Questions
Does NYDFS require penetration testing?
Yes. The NYDFS Cybersecurity Regulation, 23 NYCRR 500, requires covered financial services companies to conduct penetration testing at least annually based on their risk assessment. Grid32 provides testing and attestation documentation aligned to these requirements.
What are the Class A company requirements under 23 NYCRR 500?
Class A companies, the largest covered entities, face heightened obligations that include independent audits and more rigorous controls such as enhanced monitoring and access management. Their testing programs are typically broader and more frequent than the annual baseline.
What do NYDFS examiners look for in penetration testing?
Examiners expect evidence of annual, risk-based testing by qualified testers, clear scope tied to the risk assessment, documented findings, and remediation tracking. Grid32 delivers reporting and attestation that maps directly to these examiner expectations.
Ready to satisfy your NYDFS requirement?
Grid32 has completed NYDFS-compliant penetration tests for financial institutions across New York since 2009. Our reports are built for examiners, not just engineers.
Get a Quote →