Compliance · 23 NYCRR 500

What does NYDFS Part 500 require for scanning and penetration testing?

NYDFS Part 500 requires covered financial services firms to run a penetration test at least once a year, run automated vulnerability scans at a risk-based frequency, and fix what they find in order of risk. It also requires a complete asset inventory and a written policy for overseeing third-party service providers.

Who it covers

Firms operating under a license, registration, charter or similar authorization under New York’s Banking, Insurance or Financial Services Law, such as banks, insurers, mortgage bankers and brokers, and money transmitters.

Small firms may qualify for the limited exemption in §500.19(a): fewer than 20 employees and independent contractors, less than $7.5 million in gross annual revenue in each of the last three fiscal years, or less than $15 million in year-end total assets. A firm that qualifies is exempt from §500.5, among other sections, but the third-party service provider policy (§500.11) and the asset inventory (§500.13) still apply.

What it requires for testing

  • §500.5(a)(1). Penetration testing from inside and outside the information systems’ boundaries, at least once a year, by a qualified internal or external party.
  • §500.5(a)(2). Automated scans of information systems, and a manual review of systems the scans don’t cover, at a frequency set by the risk assessment and promptly after any material system change.
  • §500.5(b). A monitoring process that promptly tells the firm about new security vulnerabilities.
  • §500.5(c). Timely remediation, prioritized by the risk each vulnerability poses.

What it requires for assets and suppliers

  • §500.13. A complete, accurate and documented asset inventory, required since November 1, 2025.
  • §500.11. A written policy for third-party service providers, covering how they are identified and assessed for risk, the minimum practices they must meet, due diligence, and periodic assessment. NYDFS published guidance on managing these providers on October 21, 2025.

How an MSP evidences it with Outerwall

  • Automated external scans of the internet-facing assets your client approved, and alerts when a new known-exploited flaw matches its software, toward §500.5(a)(2) and §500.5(b).
  • Risk-ranked fixes. Findings ranked by blast radius and sent to your PSA, toward §500.5(c).
  • An inventory of internet-facing assets, unlisted ones included, toward §500.13. Internal assets need other tools.
  • A supplier map with breach alerts, toward the periodic assessment in §500.11.
  • The annual penetration test needs a qualified tester. Outerwall doesn’t replace it.

Not legal advice. This page summarizes the rule for MSPs. Your client’s counsel or compliance lead decides what it requires of them. Outerwall’s output supports a client’s compliance evidence. It does not, by itself, make a client compliant.

Sources

Turn scans into a record your clients can show.

Design partners shape the evidence packs mapped to NYDFS Part 500.