Skip to content

Compliance

NYDFS 23 NYCRR 500
Penetration Testing

New York’s cybersecurity regulation for licensed financial services companies.

Component tests from $4,200, one fixed quote for your scope, free retest included. See all pricing →

Get a Fixed Quote

Three fields. A senior tester reads it and replies within one business day.

Prefer the full scoping questionnaire? 
OSCP & OSCE3 certified testers150+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When you need NYDFS 23 NYCRR 500 penetration testing

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • The annual certification of compliance due April 15 is approaching and the §500.5(a)(1) testing has not been done in the last twelve months.
  • A NYDFS examination is scheduled and examiners have asked for penetration test reports and tester qualifications.
  • Your CISO’s annual report to the board needs testing results and remediation status behind it.
  • A material system change happened, which under §500.5(a)(2) means scanning and manual review promptly, not at the next annual cycle.
  • You are a Class A company and the amended requirements for independent audit, EDR, and privileged access management need technical evidence.

The amended §500.5

What the amended §500.5 requires

The Department of Financial Services adopted the second amendment to 23 NYCRR Part 500 on November 1, 2023, with most provisions taking effect on April 29, 2024 and the remaining ones phased in through November 2025. The amended §500.5 replaced the earlier language with specific obligations: penetration testing of information systems at least annually, from both inside and outside the information systems’ boundaries, by a qualified internal or external party, based on the risk assessment (§500.5(a)(1)); automated scans of information systems, plus a manual review of systems not covered by such scans, at a frequency set by the risk assessment and promptly after any material system change (§500.5(a)(2)); and a monitoring process to ensure the entity is promptly informed of new security vulnerabilities (§500.5(b)).

Two words in that text drive the scope. “Inside and outside” means an external test alone does not satisfy the requirement; an internal test from within the boundary is mandatory. “Qualified” means examiners will ask who performed the test and what their credentials are, which is why our report includes tester qualifications as an evidence item.

Class A

Class A companies and everyone else

Class A companies

The largest covered entities, defined in §500.1 by New York revenue combined with employee count or total revenue including affiliates. Beyond §500.5 they must obtain independent audits of the cybersecurity program, run a privileged access management solution with automated blocking of commonly used passwords, and deploy endpoint detection and response with centralized logging and alerting. The penetration test should exercise those controls, and the report should say whether they detected the activity.

All other covered entities

Every organization operating under a DFS license, registration, or authorization: banks, insurers, mortgage lenders and brokers, money transmitters, and virtual currency businesses. Section 500.5 applies in full, alongside the multi-factor authentication, asset inventory, and incident notification requirements the amendment added. Limited exemptions under §500.19 reduce some obligations for the smallest entities, but a notice of exemption must still be filed.

What we assess

What your NYDFS 500.5 test covers

Section 500.5 requires annual penetration testing from inside and outside your network boundary. We run both, scoped to the systems that handle nonpublic information, and give your examiner evidence rather than a raw scan.

External Penetration Testing

Testing the internet-facing boundary the way an outside attacker would, as §500.5(a)(1) requires.

We test for

  • Internet-facing host and service discovery
  • Exploitation of exposed services
  • Perimeter authentication and VPN testing
  • Evidence for the annual requirement

Internal Penetration Testing

Testing from inside the boundary to show how far a foothold near nonpublic information can reach.

We test for

  • Segmentation around NPI systems
  • Lateral movement and privilege escalation
  • Active Directory abuse paths
  • Access to nonpublic information stores

Vulnerability Management (500.5(a)(2))

The automated scans and manual review the regulation expects alongside the annual test.

We test for

  • Authenticated and unauthenticated scanning
  • Manual review of material findings
  • Testing after material system changes
  • Risk-based prioritization

Examination Evidence

The documentation NYDFS examiners and your certifying officer actually ask to see.

We test for

  • Test reports and scope statements
  • Remediation tracking and retest evidence
  • Tester qualifications
  • Support for the §500.17(b) certification

The examination

The examination and the April 15 certification

Section 500.17(b) requires an annual certification of material compliance, or an acknowledgment of non-compliance with a remediation plan, submitted by April 15 and signed by the highest-ranking executive and the CISO. The penetration test is a core piece of the evidence behind it.

  • External and internal penetration test reports dated within the certification year, with scope statements that name the systems handling nonpublic information.
  • Tester qualifications and a statement of independence from the systems tested.
  • Remediation tracking for every finding, with retest evidence showing closure, which is what turns a report into proof of a functioning program.
  • Vulnerability scan records and manual review notes on the cadence your risk assessment set, including scans run after material changes.
  • An executive summary written for the CISO’s annual report to the board, as §500.4 requires.

We serve DFS-regulated entities across the state from our office in Manhattan, including the Jersey City operations centers many of them run across the river in New Jersey.

Methodology

How we test

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your compliance test runs through.

  1. 01

    Scope the boundary

    The systems your framework actually covers, and nothing you would pay to test twice.

  2. 02

    Test

    The component penetration tests run to PTES and OWASP standards by senior testers.

  3. 03

    Map to controls

    Every finding tied to the requirement or control it evidences.

  4. 04

    Report for the auditor

    Evidence formatted the way your assessor, examiner, or QSA expects to read it.

  5. 05

    Fix & retest

    A free retest so the audit shows closed findings, not open ones.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope NPI systems

    We identify the information systems handling nonpublic information in your §500.5 scope.

  2. 02

    500.5 testing

    Annual external and internal penetration testing from inside and outside the boundary.

  3. 03

    Examiner report

    Findings mapped to §500.5, formatted as evidence for a NYDFS examination.

  4. 04

    Fix & retest

    Close the findings, then a free retest so remediation is documented for your certification.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type. The findings and outcomes are real.

All case studies →

Free

Retest on every penetration test

150+

Years combined experience

13

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

Fintech · Payments

Post-Incident Web App Assessment

Medium risk

Excessive data exposure: API responses leaked transaction metadata, including precise geolocation, enabling real-world tracking of users.

Outcome. Surfaced the exposure and hardening gaps, prioritized by how readily an attacker could chain them, and delivered fixes plus a retest to confirm closure.

8

Findings

3

Medium

Post-incident

Engagement

Read the case study

FAQ

Frequently asked questions

What teams most often ask before NYDFS 500 testing.

Still have questions? 
01Does NYDFS 23 NYCRR 500 require penetration testing?

Yes. Section 500.5(a)(1) requires covered entities to conduct penetration testing of their information systems at least annually, based on the risk assessment, from both inside and outside the information systems’ boundaries. Section 500.5(a)(2) additionally requires automated vulnerability scans, and a manual review of systems not covered by such scans, at a frequency determined by the risk assessment and after any material system changes.

02Who does the regulation apply to?

It applies to “covered entities”, meaning individuals and businesses operating under a NYDFS license, registration, or authorization, such as banks, insurers, mortgage brokers, and money transmitters. Certain small businesses qualify for limited exemptions under §500.19, though they still file a notice of exemption; confirm your status against the current regulation and your counsel.

03How does this support our annual certification?

Section 500.17(b) requires an annual certification of material compliance signed by your highest-ranking executive and your CISO. Our test report, remediation tracking, and retest evidence give you the documentation behind the §500.5 portion of that certification, in the form an examiner expects.

04Who is qualified to perform NYDFS penetration testing?

Section 500.5 requires testing to be performed by a qualified internal or external party, and examiners ask for documented tester qualifications: relevant certifications, experience, and independence from the systems being tested. Our OSCP- and OSCE3-certified senior team provides those qualifications as part of the evidence pack, which is one reason many covered entities use an external firm for the annual test.

05How much does a NYDFS penetration test cost?

Because §500.5 requires both external and internal testing, most NYDFS engagements combine our external network test (from $4,200) and internal network test (from $6,000), quoted as a fixed scope after we confirm which systems handle nonpublic information. Starting prices for every service are on our pricing page.

06We are a Class A company. What changes?

The 2023 amendment created a Class A tier for the largest covered entities, defined by New York revenue and by employee count or total revenue including affiliates. Class A companies carry extra obligations on top of §500.5: independent audits of the cybersecurity program, privileged access management with automated blocking of commonly used passwords, and endpoint detection and response with centralized logging and alerting. Penetration testing for a Class A company therefore also exercises those controls, and examiners expect the test to show whether the EDR and logging actually saw the activity, which is where our red team assessment often fits alongside the annual test.

Ready to test your defenses?

Talk to our team about what your NYDFS 500 compliance requires.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.