US State Law New York, USA

NYDFS Annual Certification: Section 500.17(b) Guide

The Part 500 annual compliance filing after the Second Amendment: certification vs acknowledgment, CISO and CEO signatures, the April 15 deadline, and the evidence file.

Regulation

23 NYCRR 500.17(b), as amended November 2023

Max Penalty

False certifications support enforcement and penalties under the underlying financial services laws; certifications featured in the First American and other DFS actions

Enforcing Authority

New York State Department of Financial Services (NYDFS)

Official Source

www.dfs.ny.gov

Executive Summary

  • Every covered entity must file annually with DFS, by April 15 for the prior calendar year, either a certification of material compliance with Part 500 or a written acknowledgment of non-compliance.
  • The Second Amendment made the choice explicit: certify material compliance, or acknowledge non-compliance identifying the sections not complied with and describing a remediation timeline, there is no silent middle path.
  • Signatures come from the two highest-ranking people: the CISO and the CEO (or their highest-ranking equivalents), importing SOX-style personal accountability into cybersecurity.
  • The filing must be supported by data and documentation sufficient to demonstrate compliance, records retained for five years and producible on examination.
  • Certifications are enforcement evidence: DFS's First American action alleged certifications filed while a known vulnerability went unremediated, and false filings compound whatever underlying failure exists.

Section 500.17(b) is where Part 500 stops being a security framework and becomes a personal representation. Two named executives sign, annually, either that the program materially complied all year or that it did not and here is the plan. The regulation’s genius is that the filing itself is easy; being entitled to make it is the entire compliance program, and DFS reads certifications back to companies during enforcement.

RequirementAnnual certification or acknowledgment, 23 NYCRR 500.17(b)
DeadlineApril 15, for the prior calendar year
SignersCISO + highest-ranking executive
RecordsSupporting documentation retained 5 years
PrecedentFirst American ($1M): certifying over a known flaw

Running a defensible certification cycle

Build the evidence file continuously. A section-mapped repository, updated as controls operate (quarterly access reviews, test reports, board minutes), turns the April filing into an export rather than an archaeology project. The Part 500 guide lists the control set the file must mirror.

Gap-test before the signers see it. A January internal review against each applicable section, including the Second Amendment provisions phased in during the covered year, determines certify-vs-acknowledge on evidence. Where the answer is acknowledgment, drafting the remediation timeline early keeps it credible.

Brief the signers like principals, not signatories. The CISO and CEO should see the gap analysis, the open items, and the prior year’s incident and notification record before signing. First American’s lesson prices the alternative.

Coordinate with the rest of the filing calendar. Event notices under 500.17(a) filed during the year must be consistent with the certification; third-party assessment records are part of the evidence; and entities relying on Part 500 for SHIELD Act deemed compliance inherit the same documentation discipline.

Public-facing systems are part of the attack surface examiners ask about; verify what your web properties expose with a free scan.

Frequently Asked Questions

Who signs, and what does 'highest-ranking' mean?

Section 500.17(b) requires the certification or acknowledgment to be signed by the covered entity's highest-ranking executive and its CISO. For a company without a CEO title, the functional top officer signs; where the CISO role is outsourced, the senior member of internal management responsible for overseeing the third-party CISO signs alongside. Delegating the signature down the org chart defeats the provision's purpose and invites examiner scrutiny.

Certify or acknowledge: how should we decide?

Certify only if, after reviewing the evidence, both signers can stand behind material compliance with every applicable section for the entire calendar year. Any known material gap, an MFA rollout finishing in Q3, an incomplete asset inventory, means the honest filing is the acknowledgment: identify the specific sections, describe remedial efforts, and give a timeline. DFS treats a candid acknowledgment as cooperation; it treats an aspirational certification as a false filing.

What evidence should stand behind a certification?

A compliance file mapped section-by-section: the written program and policies (500.2, 500.3), risk assessment (500.9), CISO board report (500.4), penetration test and vulnerability scan results (500.5), asset inventory (500.13), MFA coverage evidence (500.12), training records (500.14), vendor policy and assessments (500.11), incident response test results (500.16), and event notices filed (500.17(a)). Section 500.17(b) expressly requires maintaining records supporting the filing for five years.

What happened in the First American case?

DFS's first Part 500 enforcement action (2020, settled 2023 for $1M) alleged First American Title left hundreds of millions of document images exposed through a predictable-URL vulnerability its own testing had flagged, while continuing to file annual certifications. The lesson: a certification filed over a known, unremediated material vulnerability converts a security failure into a filing violation with named-executive exposure.

What are the practical mechanics of filing?

File electronically through the DFS cybersecurity portal by April 15 each year, covering the prior calendar year. Exempt entities file exemption notices instead but must still comply with the sections applicable to them. Calendar the internal cycle backward from April: evidence collection in January, gap review in February, executive review and signature in March, board briefing before or alongside. Treat it like a financial close, not a checkbox.

Regulatory Crosswalk

23 NYCRR 500SOX 302 certificationsNY SHIELD Act

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.