Regulatory Tracker

Regulatory tracker

Last reviewed: August 19, 2026

This page lists deadlines and status changes the firm’s two audiences actually face. It is maintained. It is not legal, tax, or audit advice. Confirm the current text of each rule before you rely on a date.

If a date here disagrees with a regulator’s site, the regulator’s site wins. Email [email protected] if you spot a conflict.

Subscribe via RSS — regulatory alerts, not marketing.

23 NYCRR 500 — annual cybersecurity certification

DeadlineApril 15 each year. NYDFS moved the annual filing from its original February window; 23 NYCRR § 500.17(b) now requires that each covered entity submit the certification “by April 15.” Do not treat the original February window as the current deadline.
Who it applies toCovered entities under 23 NYCRR 500 — persons licensed or required to be licensed, registered, or otherwise authorized under the New York Banking Law, Insurance Law, or Financial Services Law, and their affiliates to the extent the regulation reaches them. Confirm coverage against the definition in 500.1, not against a shorthand.
What it requiresA certification to the Superintendent, under 500.17(b), that the covered entity maintains a cybersecurity program that complies with the regulation — or a written acknowledgment of noncompliance that identifies the open items. Behind that filing sits the program itself: written policies (500.3), a qualified CISO and board reporting (500.4), pentest and vulnerability-scan cadence (500.5), audit trail (500.6), access privileges (500.7), MFA and encryption (500.12, 500.15), incident response, and the 72-hour notice to the Superintendent under 500.17(a) when a covered cybersecurity event occurs.
Explainer23 NYCRR 500 Cybersecurity Requirements for Financial Services Companies (January 17, 2018). That post was written against the first filing window. Read it for the fifteen program elements; do not take its original filing-window date as current.

Single audit — 2 CFR 200 Subpart F

DeadlineTypically the earlier of 30 calendar days after receipt of the auditor’s report or nine months after the fiscal year end (2 CFR 200.512). A June 30 year-end therefore usually points to a March 31 submission; a December 31 year-end to September 30.
Who it applies toNon-federal entities that expend $1,000,000 or more in federal awards during the fiscal year, under the threshold now in 2 CFR 200.501 as revised in the 2024 Uniform Guidance update (effective for fiscal years beginning on or after October 1, 2024). The long-standing $750,000 threshold applied to earlier years. Confirm the threshold against the version of 200.501 in force for the fiscal year under audit. Entities below the threshold still account for federal funds; they do not automatically file a single audit.
What it requiresA financial-statement audit plus a compliance audit of major federal programs, a Schedule of Expenditures of Federal Awards (SEFA), a schedule of findings and questioned costs, and corrective-action plans where findings exist. Uniform Guidance (2 CFR 200) also sits underneath the audit: allowable costs, procurement, time and effort, and indirect-cost rates. Late or incomplete submission is a federal-award problem, not only an audit-logistics problem.
ExplainerNo dedicated single-audit explainer is on the site yet. Related: nonprofit finance material on Who we serve — Nonprofits and Financial Advisory.

Form 990 — annual information return

DeadlineGenerally the 15th day of the 5th month after the organization’s year-end (IRS). Calendar-year organizations: May 15. An automatic six-month extension is available on Form 8868. Some organizations file 990-EZ or 990-N instead; eligibility is a revenue-and-form question, not a preference.
Who it applies toMost organizations exempt under IRC 501(a), including 501(c)(3) public charities and many other 501(c) entities, unless a specific filing exception applies. Churches and certain church-related organizations are excepted from Form 990 filing; that exception is narrower than “we are faith-based.”
What it requiresAn annual information return that is, for 990 and 990-EZ filers, a public document: governance, compensation, related-party transactions, program service accomplishments, and — where applicable — Schedule B donor information (not always public) and schedules that have to reconcile to the audited financials and, for federal awardees, to the SEFA. Three consecutive years of failure to file can cost exemption automatically.
ExplainerNo dedicated Form 990 explainer is on the site yet.

Puerto Rico Hacienda — tax-exemption standing

DeadlineAnnouncement 18-08 established an expedited application path for Puerto Rico tax-exempt status, with a CPA-certified package and a fee scaled to gross proceeds. That announcement is not, by itself, a renewal calendar. Confirm the current Hacienda circular or successor announcement before relying on a renewal date or the 2018 fee range.
Who it applies toNonprofit organizations that need or hold tax-exempt status under the Puerto Rico Internal Revenue Code, including organizations that already hold a federal 501(c)(3) determination. Federal exemption does not, by itself, create Hacienda exemption.
What it requiresFor a new application, the forms Hacienda currently lists, CPA certifications where required, and the applicable fee. For organizations that already hold the exemption: whatever periodic filing or certificate-of-compliance Hacienda currently requires to keep the exemption in force. A lapsed Hacienda exemption is a Puerto Rico tax problem even when the IRS determination letter is still on the wall.
ExplainerPuerto Rico Expedited Tax Exempt Application (January 12, 2018). Read it as history of 18-08. Confirm whether a successor announcement has replaced any of its mechanics before you cite the 60-day path or the 2018 fee range as current.

CTA / FinCEN beneficial-ownership reporting

Deadline / statusU.S. companies and U.S. persons no longer report. FinCEN’s final rule is effective August 14, 2026. Foreign reporting companies still report foreign beneficial owners. FinCEN has announced deletion of prior U.S.-person BOI records. As of August 19, 2026, FinCEN had not posted a deletion-complete notice. Do not treat deletion as finished until that notice exists.
Who it applies toAfter the August 2026 final rule: foreign reporting companies remain in scope for foreign beneficial owners. Domestic reporting companies and U.S. persons are out of the federal BOI reporting obligation created by the Corporate Transparency Act, as that obligation now stands. State-level entity-transparency rules and bank KYC/AML requests are a separate question — they did not disappear with the FinCEN rule.
What it requiresIf you are a foreign reporting company still in scope, file (or update) BOI with FinCEN on the timeline that applies to you. If you previously filed as a U.S. company or U.S. person, keep your own copies until FinCEN confirms deletion is complete; do not assume the government file is gone because an announcement said it would be. If a bank, insurer, or state filing asks for ownership information, answer that request on its own terms.
ExplainerFinCEN Permanently Ends BOI Reporting for U.S. Companies (August 19, 2026).

How this page is maintained

Last reviewed August 19, 2026. When a rule in this table moves, the date at the top of the page should move with it. A tracker that is six months stale is worse than no tracker.

This page will be maintained. It is not a complete compliance calendar, and it is not legal advice.