A full exemption under NYDFS Part 500 applies only to a narrow set of entities whose business activities place them outside the regulatory scope of the cybersecurity rule altogether. Unlike the limited exemption—which reduces obligations but still requires substantial compliance—the full exemption removes the entity from Part 500’s requirements entirely because the entity does not engage in regulated financial activity that triggers coverage.
Entities that qualify for a full exemption
NYDFS Part 500 § 500.19(b)–(d) identifies several categories of entities that are fully exempt from the regulation. These exemptions apply when the entity’s activities do not involve handling nonpublic information in a way that creates cybersecurity risk within the meaning of the rule.
- Entities that do not control, possess, access, receive, or maintain Nonpublic Information (NPI)
If a covered entity does not and cannot access NPI—whether its own or that of customers—it is fully exempt from Part 500. This applies most often to entities whose business model involves no data processing, customer information, or operational systems that store sensitive information.
- Entities that are not directly regulated by NYDFS but are listed only for limited purposes
Some entities appear in NYDFS licensing or registration systems but do not engage in regulated financial activity. These entities may be fully exempt because they are not “covered entities” under the rule.
- Employees, agents, or representatives of another covered entity
Individuals or entities that operate entirely under the cybersecurity program of another covered entity—for example, an insurance agent whose systems are fully controlled by the insurer—are exempt because the supervising entity’s cybersecurity program governs their activities.
- Charitable annuity societies
These organizations are exempt because they operate under a distinct regulatory framework and do not present the same cybersecurity risks as financial institutions.
What a full exemption means in practice
A full exemption removes all obligations under Part 500, including:
- No cybersecurity program
- No written cybersecurity policies
- No CISO or equivalent governance structure
- No risk assessments
- No MFA, encryption, or technical controls
- No incident reporting to NYDFS
- No annual certification or compliance filings
The entity is treated as outside the scope of the regulation.
Filing requirements for full exemptions
Even though the entity is exempt, NYDFS still requires a Notice of Exemption to be filed under § 500.19(e). The exemption must be updated or withdrawn if circumstances change (e.g., the entity begins handling NPI or becomes a true covered entity).
Practical implications
A full exemption is rare and applies only when the entity’s operations pose no cybersecurity risk of the type Part 500 was designed to regulate. For organizations that qualify:
- Compliance burden is eliminated
- No annual certification is required
- No cybersecurity program needs to be maintained
- The exemption must be defensible if NYDFS reviews the entity’s status
A limited exemption under NYDFS Part 500 narrows the scope of cybersecurity requirements for certain small or low‑complexity financial entities, but it does not eliminate compliance obligations entirely. It simply reduces the number of controls that must be implemented. The thresholds and structure of these exemptions are defined in 23 NYCRR § 500.19(a).
What the limited exemption covers
A covered entity may claim a limited exemption if it meets any one of the following criteria:
- Fewer than 20 employees, including independent contractors, across the entity and its affiliates.
- Less than $7.5 million in gross annual revenue in each of the last three fiscal years from all operations of the entity and the New York operations of its affiliates.
- Less than $15 million in year‑end total assets, calculated under generally accepted accounting principles.
If any one of these thresholds is met, the entity may file a Notice of Exemption under § 500.19(a).
What the limited exemption does not exempt
Even with a limited exemption, the entity must still comply with core cybersecurity requirements, including:
- Maintaining a cybersecurity program
- Implementing written policies
- Managing third‑party risk
- Reporting cybersecurity events
- Filing an annual Certificate of Compliance
Regulators emphasize that exempt entities must still implement meaningful controls and cannot treat the exemption as a safe harbor.
What the limited exemption does exempt
The exemption primarily reduces obligations related to:
- Maintaining a full‑scale cybersecurity program aligned with all technical requirements
- Appointing a dedicated Chief Information Security Officer (CISO)
- Conducting certain risk assessments and penetration testing at the same depth required for larger institutions
- Implementing some of the more resource‑intensive controls (e.g., full multi‑factor authentication across all systems, except where the amended rule narrows the exemption)
The exact list of exempted sections depends on the version of Part 500 in effect and the specific exemption claimed, but the limited exemption under § 500.19(a) is the most common.
Filing requirements
Entities must file a Notice of Exemption with NYDFS and must update or withdraw the exemption if circumstances change. The filing process is governed by § 500.19(f).
Practical implications
For small or narrowly scoped financial entities, the limited exemption:
- Reduces administrative and technical burdens
- Still requires a defensible cybersecurity posture
- Requires annual attestation of compliance
- Does not shield the entity from enforcement if controls are inadequate
