NYDFS Part 500

Cybersecurity Requirements for Financial Services Companies

23 NYCRR Part 500 applies to entities authorised under the New York Banking Law, Insurance Law, or Financial Services Law, including state-chartered banks, licensed lenders, insurance companies, and licensed money transmitters. Covered Entities operate in scope independently of size when they fall under one of those licences.

Asqav signs every AI agent action with ML-DSA, hash-chains receipts, anchors them via RFC 3161 timestamps, and retains them for at least 1827 days when the nydfs_500 regime tag is set on the organisation.

The receipt format is profiled in the IETF Internet-Draft draft-marques-asqav-compliance-receipts, which binds the format to 23 NYCRR Part 500 with a 5-year retention floor and an incident_class vocabulary covering 500.1(f) Cybersecurity Events and 500.1(g) Cybersecurity Incidents.

Obligations

Section Requirement Asqav binding
500.6(a) Audit trail designed to detect and respond to Cybersecurity Events with a reasonable likelihood of materially harming material operations. Hash-chained, ML-DSA-signed receipts with RFC 3161 anchors. Receipts re-verifiable independently of the producing system.
500.6(b) Retain audit-trail records for not fewer than five years. Cleanup job enforces a 1827-day floor when the nydfs_500 regime tag is set.
500.17(a)(1) Notify the Superintendent within 72 hours of determining a Cybersecurity Incident has occurred. incident_class token marks the reportable 500.1(g) subset so downstream notice workflows can fire programmatically. The audit trail preserves the determination and the surrounding chain.
500.1(f), 500.1(g) Distinguish Cybersecurity Events from the reportable Cybersecurity Incident subset. Two canonical tokens: nydfs_cybersecurity_event and nydfs_cybersecurity_incident.

Bring-your-own KMS, customer-owned storage, and on-prem mode are available for Covered Entity profiles that disallow outbound traffic. See the docs for the full mapping and the IETF draft for the binding text.