Skip to main content
Title 23 NYCRR Part 500 is the New York State Department of Financial Services (NYDFS) cybersecurity regulation. It establishes minimum cybersecurity standards for financial services companies operating in New York, including banks, insurance companies, and financial service providers.

Who needs NYCRR 500 compliance?

All entities operating under a license, registration, or charter under the New York Banking, Insurance, or Financial Services Law — regardless of size.

Key requirements

How DSALTA helps

  • NYCRR 500 controls mapped to regulatory requirements
  • CISO role assignment through security roles
  • Penetration testing tracking through tests and evidence
  • Vendor management for third-party security policies
  • Cross-framework mapping — overlaps with SOC 2, DORA, and ISO 27001

Frequently asked questions

Both are financial sector cybersecurity regulations with similar requirements. NYCRR 500 is US (New York) specific, while DORA is EU-wide. If you serve both markets, DSALTA maps overlapping controls.
Cybersecurity events must be reported to the NYDFS within 72 hours of determination that a reportable event has occurred.

How DSALTA automates this

8 of DSALTA’s automated checks contribute evidence to this framework, drawn from 3 integrations. Browse them in the Compliance Tests catalog.