US State Law New York, USA

NYDFS Third-Party Requirements: Section 500.11 Guide

Part 500's third-party service provider rules: written policies, due diligence, minimum contract terms, MFA and encryption for vendor access, and periodic reassessment.

Regulation

23 NYCRR 500.11 (Third-Party Service Provider Security Policy)

Max Penalty

Civil penalties under the underlying financial services laws; vendor-channel failures drove several DFS enforcement actions

Enforcing Authority

New York State Department of Financial Services (NYDFS)

Official Source

www.dfs.ny.gov

Executive Summary

  • Section 500.11 requires every covered entity to maintain written policies and procedures ensuring the security of information systems and nonpublic information accessible to, or held by, third-party service providers.
  • The policies must be risk-based and address four mandated areas: identification and risk assessment of vendors, minimum cybersecurity practices required of them, due diligence evaluating their controls, and periodic reassessment.
  • Contracts carry the load: Part 500 expects covered entities to obtain representations and protections including vendor access controls (MFA), encryption, breach notification to the covered entity, and audit or assurance rights.
  • The Second Amendment reinforced the perimeter: MFA is required for all third-party access to the covered entity's information systems and nonpublic information.
  • DFS enforcement repeatedly runs through the vendor channel, and the supervisory expectation matches federal Interagency Guidance: third-party risk management is a lifecycle, not a questionnaire.

Section 500.11 exists because financial-services breaches arrive through vendors as often as through firewalls. It converts vendor management from procurement hygiene into examined regulation: a written policy with four mandatory elements, contract terms DFS expects to see, and, since the Second Amendment, MFA on every third-party access path. When DFS investigates an incident, the vendor file, tiering, diligence, contract, reassessment, is among the first productions requested.

RequirementThird-party security policy, 23 NYCRR 500.11
Policy elementsIdentification/risk assessment, minimum practices, due diligence, periodic reassessment
Contract termsVendor MFA, encryption, event notice, security representations
Amendment impactMFA mandatory for all third-party access (500.12)

Operating the vendor lifecycle

Inventory and tier first. A complete register of providers with nonpublic-information access, risk-tiered by data sensitivity and system reach, is the foundation both 500.11 and the asset inventory duty assume. Shadow vendors found during incidents are examiner catnip.

Standardize the contract baseline. A rider with the 500.11(b) terms plus notification clocks tight enough to feed your own 72-hour DFS notice, aligned with your CCPA service-provider terms where vendors span both regimes, prevents per-deal renegotiation from eroding the floor.

Verify, then reverify. Onboarding diligence proportionate to tier, evidence-based (assurance reports over questionnaire self-attestations), and calendar-driven reassessment whose results feed the annual certification evidence file. A reassessment that never downgrades or exits a vendor is a process in name only.

Close the access loop. MFA on every vendor path, least-privilege scoping, prompt deprovisioning at termination, and logging of third-party sessions, the technical half that makes the paper half true.

Third-party exposure starts at your own perimeter: see which external scripts, trackers, and services your web properties actually load with a free scan.

Frequently Asked Questions

Who counts as a third-party service provider?

Any non-affiliate person or entity that provides services to the covered entity and maintains, processes, or otherwise is permitted access to nonpublic information through providing those services: core processors, cloud providers, claims administrators, agents, law firms, marketing platforms, and IT contractors alike. Affiliates are handled through the covered entity's own program rather than 500.11, but access by anyone outside the entity needs the policy's coverage.

What must the written policy contain?

Risk-based policies addressing, at minimum: (1) identification and risk assessment of third-party providers; (2) minimum cybersecurity practices required for them to do business with you; (3) due diligence processes to evaluate the adequacy of their practices; and (4) periodic assessment, on a defined cadence, of continued adequacy. In practice this means a vendor inventory with risk tiers, a control baseline per tier, onboarding diligence, and scheduled reassessment with documented results.

What terms belong in vendor contracts?

Section 500.11(b) directs relevant guidelines including: the provider's use of MFA to access nonpublic information, encryption in transit and at rest, prompt notice to the covered entity of cybersecurity events affecting its data, and representations regarding the provider's cybersecurity policies. Add practical enforcement terms: audit or SOC-2 delivery rights, subcontractor flow-down, data return and destruction, and cooperation duties for your own 72-hour DFS reporting clock.

How does the Second Amendment change vendor access?

Section 500.12 as amended requires MFA for any individual accessing the covered entity's information systems or nonpublic information, expressly including third parties. Vendor VPNs, support portals, and privileged remote sessions must be behind MFA; exceptions require documented CISO-approved reasonably equivalent compensating controls. Vendor MFA coverage should be verified evidence, not a contract recital.

How much diligence is enough for each vendor?

Scale by risk tier. High tier (core systems, bulk nonpublic information): independent assurance (SOC 2 Type II or equivalent), security questionnaires validated against evidence, penetration-test attestations, and annual reassessment. Medium tier: assurance reports or structured questionnaires, reassessment every one to two years. Low tier (no nonpublic-information access): contractual baseline and inventory presence. Document the tiering logic in the risk assessment; examiners test whether the cadence matches the assigned tier.

Regulatory Crosswalk

23 NYCRR 500Interagency Guidance on Third-Party RelationshipsSOC 2

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.