NYDFS Part 500 Has No More Grace Periods Left
New York's Department of Financial Services (NYDFS) Part 500 cybersecurity regulation - which applies to banks, insurers, and other financial services entities licensed in New York, with reach well beyond the state given how many national and international firms hold a New York licence - is now in full enforcement in 2026, alongside PCI DSS 4.0.1 and the EU's DORA. Together, these three frameworks represent the clearest signal yet that transition periods across major financial cybersecurity regulation have run out at roughly the same time.
The common baseline emerging across frameworks
Regulators are converging on largely the same expectations even where the specific statutes differ: multi-factor authentication for any access to any system is no longer optional under NYDFS, PCI DSS, or NIS2, and passwordless, phishing-resistant MFA based on FIDO2 is fast becoming the practical baseline rather than a differentiator. Active, ongoing third-party vendor oversight is likewise now expected across NYDFS's TPSP guidance, PCI DSS's TPSP requirements, and DORA's Critical Third-Party Provider regime.
What this means for insurers and fintechs licensed in New York
- If you hold a New York licence for any part of your business, Part 500 obligations likely apply to more of your organisation than the New York-specific business line alone - confirm scope rather than assuming it's contained.
- Building one MFA and vendor-oversight programme that satisfies NYDFS, PCI DSS 4.0.1, and DORA simultaneously is more efficient than treating each as a separate compliance project - the substantive requirements now overlap heavily.
- "We have MFA" is no longer a sufficient answer on its own - regulators increasingly expect FIDO2-based, phishing-resistant MFA specifically, not SMS or app-based one-time codes.
Have a security question of your own?
Talk to a Security Expert →