Florida  ·  Puerto Rico  ·  New York  ·  Washington, DC [email protected] +1 917 410 3335
Sosa & Arvelo, LLC Request a consultation
Sosa & Arvelo, LLC
ServicesCyber & InnovationFinancial AdvisoryRisk & ComplianceStrategy & OperationsSectorsAll sectorsFinancial Services & CommercialNonprofits & Faith-BasedInsightsFirmAboutTeamHow we workCareersContact Request a consultation

September 28, 2026  ·  Technology · Business

NYDFS Sets Out What a Part 500 Risk Assessment Has to Contain

On September 10, 2026, the New York State Department of Financial Services issued an industry letter titled “Guidance on How to Conduct and Use Risk Assessments Required by the DFS Cybersecurity Regulation.” It is addressed to every covered entity under 23 NYCRR Part 500. DFS says up front that the letter creates no new obligations. What it does is put in writing what examiners look for when they read a risk assessment under section 500.9, and what they keep finding wrong.

The rule itself says little. Section 500.9(a) requires a periodic risk assessment “sufficient to inform the design of the cybersecurity program,” reviewed and updated at least annually and whenever a change in the business or technology materially changes the entity’s cyber risk. Section 500.9(b) requires written policies with three sets of criteria: how risks are rated, how the adequacy of existing controls is judged, and how each risk will be mitigated or accepted. That short section carries a lot of weight. Section 500.2(b) says the whole cybersecurity program “shall be based on” the risk assessment, so a thin assessment weakens everything built on top of it.

DFS lists five deficiencies it sees in examinations:

  • Incomplete scope. Asset inventories are out of date or incomplete, and the entity cannot say where nonpublic information resides or how it flows.
  • Weak methodology. Risks are not identified, analyzed, prioritized, and documented consistently from one cycle to the next.
  • Evolving risks left out. The assessment misses emerging technology, changes in the threat landscape, and interdependencies.
  • Thin governance. Nobody owns individual risks, and decisions about how to respond to them are not recorded.
  • No link to the program. Policies, controls, and budget decisions cannot be shown to follow from the risks the assessment identified.

The body of the letter is organized in five parts, and together they describe what the file should contain.

Governance. A CISO or Senior Officer oversees the process. Business units, operations, compliance, and legal take part, and results go to senior management and, where appropriate, the Senior Governing Body. Part 500 does not require the board to approve the risk assessment. DFS expects the board to see it anyway, because section 500.4(b)(3) requires the CISO to report material cybersecurity risks to the board, and the letter describes the assessment as the input to board-level decisions on investment, control selection, and risk acceptance.

Methodology. The method has to be defined and repeatable. It draws on threat intelligence, incident trends, vulnerability scans, penetration tests, and audit findings. It estimates likelihood and impact with consistent rating criteria and separates inherent risk from residual risk. Threats include insiders, misconfiguration, and natural disasters as well as outside attackers. Impacts include regulatory, legal, and reputational harm as well as lost data. DFS does not require a particular framework. It names NIST CSF 2.0, the Cyber Risk Institute Profile v2.2, and ISO 27005:2022 as ones many entities use, and says the chosen approach has to be tailored to the entity. It also expects the same risk criteria to be used in third-party risk, IT operations, and business continuity, so that a “high” means the same thing in each.

Scope. The assessment covers every asset that could affect the confidentiality, integrity, or availability of information systems. The letter calls the asset inventory required by section 500.13(a) “the foundational input.” It also has to cover:

  • where nonpublic information resides, how it moves, and who can reach it;
  • emerging technology, including artificial intelligence and advances in quantum computing that may weaken current cryptography;
  • third-party service providers, weighted by how critical the service is, how sensitive the data is, how connected the provider is to the entity’s systems, and what an outage would do to operations;
  • interdependencies and concentration risk, meaning single points of failure across shared platforms, security services, and providers.

Documentation and traceability. The file has to show how each risk was identified and assessed, what data was used, and why the conclusions were reached. Each identified risk has to be linked to the control or compensating measure that addresses it. Where management accepts a risk, the file records the justification and the residual risk. DFS expects a risk register or a comparable tracking process that follows remediation and changes in residual risk over time. It also notes that the same traceability is what makes internal audit and testing well targeted.

Integration and updates. The assessment is not a stand-alone annual exercise. Its results should drive changes to policies, procedures, controls, and testing plans. Annual review is the minimum. The letter gives the following as examples of material change that should trigger an update between annual cycles:

  • major system migrations;
  • mergers and acquisitions;
  • significant outsourcing;
  • significant developments in cybersecurity technology, with frontier AI models named;
  • changes in threat-actor capabilities;
  • adoption of emerging technologies;
  • identification or active exploitation of critical hardware or software vulnerabilities;
  • geopolitical events likely to increase ideologically motivated attacks.

Two of those triggers are already the subject of DFS advisories this year: heightened risk from frontier AI models (May 21, 2026) and heightened threats tied to global conflict (March 3, 2026). An entity that received those advisories and did not revisit its risk assessment will have trouble explaining that under this guidance.

The obligation reaches further than many entities assume. The limited exemption for small entities in section 500.19(a) does not exempt section 500.9. Neither do the exemptions in 500.19(c) and (d), which cover entities that neither operate information systems nor hold nonpublic information, and Article 70 insurers whose only nonpublic information belongs to their parent or affiliates. Filing for one of those exemptions does not remove the risk assessment obligation.

The timing matters as well. The last transitional periods under the second amendment closed on November 1, 2025, when the multi-factor authentication requirement in section 500.12 and the asset inventory requirement in section 500.13(a) took full effect. Every section of Part 500 is now live and open to examination. Under section 500.17(b), each covered entity must file by April 15 either a certification that it materially complied during the prior calendar year or an acknowledgment of the sections where it did not. The certification has to be “based upon data and documentation sufficient to accurately determine and demonstrate such material compliance.” It is signed by the highest-ranking executive and the CISO, and the supporting records must be kept for five years. The risk assessment refreshed in the fourth quarter of 2026 is the document that the April 15, 2027 filing will rest on.

What this means for clients:

  • Read the current assessment against the five deficiencies above before reading it against anything else. If you cannot trace a control back to a risk, or a risk forward to a control, DFS has told you that is the finding.
  • Fix the inventory first. The letter treats the section 500.13(a) inventory as the foundation of the assessment, and it has been fully enforceable since November 1, 2025. An assessment built on an incomplete inventory is incomplete by definition.
  • Put risk acceptance in writing. For each accepted risk, record who accepted it, why, and what residual risk remains. A risk that was left alone without a recorded decision was not accepted. It was ignored.
  • Write the off-cycle triggers into the section 500.9(b) policy. The letter’s list gives you a ready basis for them, and it shows an examiner that updates between annual cycles are governed by policy rather than left to judgment in the moment.
  • Treat the assessment as certification evidence. The executive and the CISO who sign the April filing are attesting to material compliance with a program that section 500.2(b) says is built on this document.

The practical next step is a scoped review, not a new program. Compare this year’s assessment with the letter’s five parts, close the gaps in the inventory and the risk register, and have both finished before the calendar year ends. That way the assessment covers the full 2026 period the April 15, 2027 filing will certify.

Sources: https://www.dfs.ny.gov/industry_guidance/industry_letters/il20260910-cyber-risk-assessment
https://www.dfs.ny.gov/system/files/documents/2026/07/NYCRR-part-500-Cybersecurity-Regulation.pdf
https://www.dfs.ny.gov/industry_guidance/industry_letters


Published September 28, 2026. Insights are general information, not legal, tax, or audit advice. Rules change — check the date on this page and confirm the current text of the rule before you rely on it. See Terms of use.

Next step

Tell us what you’re facing.

A 30-minute conversation, no charge, no obligation. We will tell you whether an assessment is the right next step, whether we are the right firm — and if we are not, who is more likely to be.