Law / United States /
New York
New York Department of Financial Services Cybersecurity Regulation, Multi-Factor Authentication
In force.
A sector security regimes rule binding private bodies.
- Enforcement body
- The Superintendent of Financial Services.
- Instrument type
- a regulation made under an act
- Obligation class
- Security
As of .
What it requires
- It reaches you if you operate as a Covered Entity under 23 NYCRR 500.1(e): any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether you are also regulated by other government agencies (reached by declaring that you provide financial services). Section 500.19(c) lifts section 500.12 for a covered entity that operates no information systems and holds no nonpublic information, and section 500.19(d) lifts section 500.12 for an article 70 insurer under the Insurance Law that holds no nonpublic information beyond information relating to its corporate parent or affiliates. A covered entity that qualifies for the limited exemption in section 500.19(a) owes the narrower duty in the third line below.
- Use multi-factor authentication, verification of at least two of three types of authentication factor (knowledge, possession and inherence), for any individual accessing any of your information systems.
- If you qualify for the limited exemption in section 500.19(a), use multi-factor authentication for remote access to your information systems, remote access to third-party applications (including cloud-based ones) from which nonpublic information is accessible, and all privileged accounts other than service accounts that prohibit interactive login.
- If you have a Chief Information Security Officer and rely on compensating controls in place of multi-factor authentication, have that officer approve in writing the use of reasonably equivalent or more secure compensating controls, and review those controls periodically and at least annually.
What this law does
Section 500.12 requires multi-factor authentication for any individual accessing any information system of a covered entity. Multi-factor authentication means verification of at least two of three types of authentication factor: knowledge factors such as a password, possession factors such as a token, and inherence factors such as a biometric characteristic.
A covered entity that qualifies for the limited exemption in section 500.19(a) must use multi-factor authentication only for remote access to its information systems, remote access to third-party applications from which nonpublic information is accessible, and privileged accounts other than service accounts that prohibit interactive login.
If the covered entity has a Chief Information Security Officer, that officer may approve in writing the use of reasonably equivalent or more secure compensating controls, which must be reviewed periodically and at least annually.
Section 500.19(c) and (d) name section 500.12 among the sections they lift, (c) for a covered entity that operates no information systems and holds no nonpublic information and (d) for an article 70 insurer that holds no nonpublic information beyond information relating to its corporate parent or affiliates. Part 500 took effect on , and its Second Amendment on .
Section 500.22(d)(4) gives covered entities two years from the effective date of the Second Amendment to comply with its new requirements in sections 500.12 and 500.13(a). The Department's industry letter of states that as of November 2025 the regulation will require multi-factor authentication for all authorized users attempting to access a covered entity's information systems or nonpublic information.
When LexLint raises it
When your app profile says your app provides financial services.