Timeline for Compliance
While NYDFS did not change the Regulation’s 180-day conformance period, it did add three exceptions to that deadline.
- First, Covered Entities are now given until March 1, 2018, to comply with:
- The reporting obligations of the CISO.
- The requirement to conduct periodic risk assessments.
- Any requirement to conduct annual penetration testing and bi-annual vulnerability assessments.
- Any requirement to implement multifactor authentication or risk-based authentication; and
- The obligation to provide regular up-to-date cybersecurity awareness training for all
- Second, Covered Entities are now given until Sept. 1, 2018, to comply with:
- Any requirement to maintain audit trail systems.
- The requirements to implement:
- Written procedures, guidelines, and standards on application security.
- Policies and procedures for the secure disposal of Nonpublic Information; and
- Policies, procedures, and controls to monitor authorized users; and
- Any requirement to encrypt Nonpublic
- Finally, Covered Entities are now given until March 1, 2019, to comply with the requirement to implement written policies and procedures regarding the security of systems and information accessible to, or held by, Third-Party Service


Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics