Learn

NYDFS Part 500 for Virtual Currency Firms

Updated on

September 2, 2026

New York's cybersecurity regulation, 23 NYCRR Part 500, applies to entities licensed by the Department of Financial Services, including virtual currency firms operating under a BitLicense or a limited-purpose trust charter. Its second amendment, effective 1 November 2023, strengthened the incident response and business continuity requirements in Section 500.16 and the 72-hour event notification in Section 500.17. This page focuses on the incident response and continuity obligations. For how Part 500 sits alongside the other frameworks, see the regulatory requirements overview.

What is NYDFS Part 500 and who does it apply to?

23 NYCRR Part 500 is a cybersecurity regulation issued by the New York State Department of Financial Services (DFS). It applies to covered entities, meaning persons operating under a licence, registration, charter, or similar authorisation under New York banking, insurance, or financial services law. Virtual currency businesses licensed under the BitLicense framework (23 NYCRR Part 200) or chartered as limited-purpose trust companies are covered entities and must comply with Part 500. The regulation was first adopted in 2017 and substantially amended by the second amendment, which took effect 1 November 2023 with phased compliance dates.

What does Section 500.16 require for incident response and business continuity?

The second amendment expanded Section 500.16 to require covered entities to maintain both an incident response plan (IRP) and a business continuity and disaster recovery (BCDR) plan. Key elements include:

  • An IRP that addresses the internal processes for responding to a cybersecurity event, including the root cause analysis describing how the event occurred, its business impact, and remediation steps to prevent recurrence.
  • A BCDR plan reasonably designed to ensure the availability and functionality of services and to protect personnel, assets, and critical data during and after a cybersecurity-related disruption.
  • A requirement that the plans include the ability to restore critical data and information systems from backups.
  • Testing of the IRP and BCDR plans at least annually, with the incident response plan tested against the disruptive scenarios the entity is likely to face.

Compliance with the amended Section 500.16 was required from 1 November 2024.

What does Section 500.17 require for notification?

Section 500.17(a) requires a covered entity to notify DFS as promptly as possible, and no later than 72 hours, after determining that a cybersecurity incident has occurred. A cybersecurity incident is defined in Section 500.1(g) as a cybersecurity event that either requires notice to any government body, self-regulatory agency, or supervisory body; has a reasonable likelihood of materially harming a material part of the entity's normal operations; or results in the deployment of ransomware within a material part of its information systems.

Section 500.17(c) addresses extortion payments: a covered entity that makes a payment in connection with a cybersecurity event must notify DFS within 24 hours of the payment and, within 30 days, provide a written description of the reasons the payment was necessary, the alternatives to payment considered, and the diligence performed, including compliance with sanctions and OFAC rules.

  • Notice of a cybersecurity incident (Section 500.17(a)): within 72 hours of determination.
  • Notice of an extortion payment (Section 500.17(c)): within 24 hours of payment.
  • Written explanation of an extortion payment (Section 500.17(c)): within 30 days of payment.

What must a virtual currency firm do in practice?

  • Maintain a written incident response plan that includes root cause analysis and remediation, and a BCDR plan covering availability of services and restoration of critical data.
  • Test both plans at least annually against realistic disruptive scenarios.
  • Ensure the BCDR plan can restore critical data and systems from backups.
  • Operate a 72-hour notification workflow with clear determination criteria, plus the 24-hour extortion-payment notice process.
  • Maintain the broader Part 500 program (governance, access controls, encryption, risk assessment) that surrounds these obligations.

How does keyless recovery, set up in advance, map to Part 500?

Section 500.16 requires the ability to restore critical data and to maintain the availability of services during and after a cybersecurity event. For a virtual currency firm, the most critical asset is the digital assets themselves, and a wallet compromise is precisely the disruptive scenario the IRP and BCDR plan must anticipate. Restoring systems from backup does not restore control of assets an attacker already holds, and backing up a key does not help if the key is the thing that was compromised.

Keyless recovery, meaning recovery that does not depend on your private keys, set up in advance, addresses this gap: it can move assets to a pre-approved destination on a defined trigger, which is a concrete, testable component of a BCDR plan for a digital asset operator. Circuit Security provides operational resilience for institutional digital assets. Its Recovery and Response products, powered by Automatic Asset Extraction (AAE), give a recovery path that does not depend on the private keys when wallets are compromised or inaccessible. Circuit's Key Backup offering is a trustless encrypted backstop for critical key material, which also supports these regimes' recovery and continuity obligations. Circuit is not a custodian and cannot access, use, or reconstruct your keys, and this supports rather than replaces a firm's Part 500 incident response and continuity program. See /learn/incident-response and /recovery.

Honest limits

This page covers the incident response, business continuity, and notification obligations of Part 500 as they apply to virtual currency firms. Part 500 also imposes governance, risk assessment, access management, encryption, multi-factor authentication, and CISO reporting obligations that are out of scope here, as are the separate BitLicense (Part 200) requirements. This is educational and not legal advice. Section numbering and timelines should be confirmed against the current DFS text.

Frequently asked questions

Does NYDFS Part 500 apply to crypto companies?
Yes. Virtual currency firms licensed under the BitLicense framework or chartered as limited-purpose trust companies are covered entities under Part 500 and must comply with its cybersecurity requirements, including incident response and business continuity.

What is the NYDFS 72-hour reporting rule?
Section 500.17(a) requires a covered entity to notify DFS no later than 72 hours after determining that a cybersecurity incident has occurred, as defined in Section 500.1(g): an event that requires notice to a government or self-regulatory body, has a reasonable likelihood of materially harming a material part of operations, or involves ransomware deployed within a material part of its systems.

Does Part 500 require a business continuity plan?
Yes. As amended, Section 500.16 requires covered entities to maintain and test both an incident response plan and a business continuity and disaster recovery plan, including the ability to restore critical data and systems.

When did the current Part 500 requirements take effect?
The second amendment took effect 1 November 2023 with phased compliance dates; compliance with the amended incident response and business continuity requirements in Section 500.16 was required from 1 November 2024.

Want to keep up to date with Circuit? Sign up below

Success! Speak soon.
Oops! Something went wrong while submitting the form.

Related Posts

Discover more key terms relevant to Circuit

Learn

NIST CSF 2.0 for Digital Asset Operations

Read More
Learn

MiCA and DORA: EU Operational Resilience Requirements for CASPs

Read More
Learn

Operational Resilience Requirements for Digital Asset Firms

Read More

Built by experts who’ve made digital assets safer, and now, recoverable

We believe asset recoverability is table stakes for the next era of digital assets.