01
500.11(a)(1): Identify and assess third-party risks
02
500.11(a)(2): Establish minimum cybersecurity practices
03
500.11(a)(3): Due diligence on third-party cybersecurity
04
500.11(a)(4): Periodic assessment based on risk
New York DFS Cybersecurity Regulation (23 NYCRR 500)
23 NYCRR 500 is one of the most prescriptive cybersecurity regulations. Section 500.11 requires written policies for third-party security.
500.11(a)(1): Identify and assess third-party risks
500.11(a)(2): Establish minimum cybersecurity practices
500.11(a)(3): Due diligence on third-party cybersecurity
500.11(a)(4): Periodic assessment based on risk
Automated scoring against 500.11 requirements.
QFX maps to 23 NYCRR 500 sections.
Frequency adjusts based on vendor risk tier.
Documentation for DFS examinations.
NYDFS compliance is critical for organizations in these sectors.
Assess your first vendors free — no credit card, no contract, no gym membership required.
Try 5 Vendors for Free →