
Updated on
September 2, 2026
New York's cybersecurity regulation, 23 NYCRR Part 500, applies to entities licensed by the Department of Financial Services, including virtual currency firms operating under a BitLicense or a limited-purpose trust charter. Its second amendment, effective 1 November 2023, strengthened the incident response and business continuity requirements in Section 500.16 and the 72-hour event notification in Section 500.17. This page focuses on the incident response and continuity obligations. For how Part 500 sits alongside the other frameworks, see the regulatory requirements overview.
23 NYCRR Part 500 is a cybersecurity regulation issued by the New York State Department of Financial Services (DFS). It applies to covered entities, meaning persons operating under a licence, registration, charter, or similar authorisation under New York banking, insurance, or financial services law. Virtual currency businesses licensed under the BitLicense framework (23 NYCRR Part 200) or chartered as limited-purpose trust companies are covered entities and must comply with Part 500. The regulation was first adopted in 2017 and substantially amended by the second amendment, which took effect 1 November 2023 with phased compliance dates.
The second amendment expanded Section 500.16 to require covered entities to maintain both an incident response plan (IRP) and a business continuity and disaster recovery (BCDR) plan. Key elements include:
Compliance with the amended Section 500.16 was required from 1 November 2024.
Section 500.17(a) requires a covered entity to notify DFS as promptly as possible, and no later than 72 hours, after determining that a cybersecurity incident has occurred. A cybersecurity incident is defined in Section 500.1(g) as a cybersecurity event that either requires notice to any government body, self-regulatory agency, or supervisory body; has a reasonable likelihood of materially harming a material part of the entity's normal operations; or results in the deployment of ransomware within a material part of its information systems.
Section 500.17(c) addresses extortion payments: a covered entity that makes a payment in connection with a cybersecurity event must notify DFS within 24 hours of the payment and, within 30 days, provide a written description of the reasons the payment was necessary, the alternatives to payment considered, and the diligence performed, including compliance with sanctions and OFAC rules.
Section 500.16 requires the ability to restore critical data and to maintain the availability of services during and after a cybersecurity event. For a virtual currency firm, the most critical asset is the digital assets themselves, and a wallet compromise is precisely the disruptive scenario the IRP and BCDR plan must anticipate. Restoring systems from backup does not restore control of assets an attacker already holds, and backing up a key does not help if the key is the thing that was compromised.
Keyless recovery, meaning recovery that does not depend on your private keys, set up in advance, addresses this gap: it can move assets to a pre-approved destination on a defined trigger, which is a concrete, testable component of a BCDR plan for a digital asset operator. Circuit Security provides operational resilience for institutional digital assets. Its Recovery and Response products, powered by Automatic Asset Extraction (AAE), give a recovery path that does not depend on the private keys when wallets are compromised or inaccessible. Circuit's Key Backup offering is a trustless encrypted backstop for critical key material, which also supports these regimes' recovery and continuity obligations. Circuit is not a custodian and cannot access, use, or reconstruct your keys, and this supports rather than replaces a firm's Part 500 incident response and continuity program. See /learn/incident-response and /recovery.
This page covers the incident response, business continuity, and notification obligations of Part 500 as they apply to virtual currency firms. Part 500 also imposes governance, risk assessment, access management, encryption, multi-factor authentication, and CISO reporting obligations that are out of scope here, as are the separate BitLicense (Part 200) requirements. This is educational and not legal advice. Section numbering and timelines should be confirmed against the current DFS text.
Does NYDFS Part 500 apply to crypto companies?
Yes. Virtual currency firms licensed under the BitLicense framework or chartered as limited-purpose trust companies are covered entities under Part 500 and must comply with its cybersecurity requirements, including incident response and business continuity.
What is the NYDFS 72-hour reporting rule?
Section 500.17(a) requires a covered entity to notify DFS no later than 72 hours after determining that a cybersecurity incident has occurred, as defined in Section 500.1(g): an event that requires notice to a government or self-regulatory body, has a reasonable likelihood of materially harming a material part of operations, or involves ransomware deployed within a material part of its systems.
Does Part 500 require a business continuity plan?
Yes. As amended, Section 500.16 requires covered entities to maintain and test both an incident response plan and a business continuity and disaster recovery plan, including the ability to restore critical data and systems.
When did the current Part 500 requirements take effect?
The second amendment took effect 1 November 2023 with phased compliance dates; compliance with the amended incident response and business continuity requirements in Section 500.16 was required from 1 November 2024.
Want to keep up to date with Circuit? Sign up below

We believe asset recoverability is table stakes for the next era of digital assets.