Annual Certifications of Compliance
The Certification of Compliance is a critical governance pillar of the cybersecurity programs of all Covered Entities. Prior to April 15th of each year, all Covered Entities must file a Certification of Compliance confirming their compliance with the
Cybersecurity Regulation for the previous calendar year.
An entity or individual should only submit a Certification if they were in compliance with all portions of the regulations that applied to that Covered Entity during the time period the Certification covers. Even if a Covered Entity qualifies for an exemption
pursuant to 500.19(a), (c), or (d), it has to submit a Certification of Compliance to demonstrate that it was in compliance with the sections of the regulation that apply pursuant to the particular exemption. (The exemption set forth in 500.19(b)
is the only exemption that does not require a Covered Entity to file a Certification of Compliance.)
Certifications of Compliance for the calendar year 2021 are due by April 15, 2022. Covered Entities that hold more than one license must file a separate Certification of Compliance for each license it holds.
Instructions on how to file a Certification of Compliance can be found by clicking https://www.dfs.ny.gov/system/files/documents/2019/12/cyber_cert_compliance_filing.pdf
Covered Entities Do Not Need to File New Notices of Exemption
Any DFS regulated entity or licensed person who filed a Notice of Exemption previously
does not need to refile a Notice of Exemption. However, if your exempt status has changed, then the entity or individual should amend or terminate their filing through the DFS portal.
How to File
The DFS Cybersecurity Portal has been redesigned to assist you with your filings. To ensure that filings are matched to the appropriate Covered
Entity or licensed person, we encourage the use of an identifying number when filing. Identifying numbers are New York State License number, NAIC/NY Entity number, NMLS number or Institution number. Please make sure that you have your license number
available when you make your filing. A look-up feature is included in the Portal for anyone who does not know which number to use.
To get started please visit the DFS Cybersecurity Portal: https://myportal.dfs.ny.gov/web/cybersecurity/