> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Title 23 NYCRR Part 500

> Meet New York's cybersecurity requirements for financial services companies.

Title 23 NYCRR Part 500 is the New York State Department of Financial Services (NYDFS) cybersecurity regulation. It establishes minimum cybersecurity standards for financial services companies operating in New York, including banks, insurance companies, and financial service providers.

## Who needs NYCRR 500 compliance?

All entities operating under a license, registration, or charter under the New York Banking, Insurance, or Financial Services Law — regardless of size.

## Key requirements

| Requirement               | Description                                                        |
| ------------------------- | ------------------------------------------------------------------ |
| **Cybersecurity Program** | Establish a cybersecurity program based on risk assessment         |
| **CISO Designation**      | Designate a Chief Information Security Officer                     |
| **Penetration Testing**   | Annual penetration testing and bi-annual vulnerability assessments |
| **Access Controls**       | Multi-factor authentication and access privilege management        |
| **Incident Response**     | Written incident response plan with 72-hour reporting              |
| **Third-Party Security**  | Written policies for third-party service provider security         |
| **Encryption**            | Encrypt nonpublic information in transit and at rest               |

## How DSALTA helps

* **NYCRR 500 controls** mapped to regulatory requirements
* **CISO role assignment** through security roles
* **Penetration testing tracking** through tests and evidence
* **Vendor management** for third-party security policies
* **Cross-framework mapping** — overlaps with SOC 2, DORA, and ISO 27001

## Frequently asked questions

<AccordionGroup>
  <Accordion title="How does NYCRR 500 relate to DORA?" icon="diagram-project">
    Both are financial sector cybersecurity regulations with similar requirements. NYCRR 500 is US (New York) specific, while DORA is EU-wide. If you serve both markets, DSALTA maps overlapping controls.
  </Accordion>

  <Accordion title="What are the reporting timelines?" icon="clock">
    Cybersecurity events must be reported to the NYDFS within 72 hours of determination that a reportable event has occurred.
  </Accordion>
</AccordionGroup>

## How DSALTA automates this

**8** of DSALTA's automated checks contribute evidence to this framework, drawn from **3** integrations. Browse them in the [Compliance Tests](/tests/overview) catalog.

## Related pages

* [DORA](/frameworks/dora/overview)
* [Active Frameworks](/guides/compliance/frameworks-active)
