Key points
- Since November 1, 2025, NYDFS Part 500 requires MFA for every individual accessing a covered entity’s information systems and a documented asset inventory with defined fields.
- The CEO and the CISO sign the annual filing to DFS, and the filing due April 15, 2027 is the first to cover a full calendar year under both rules.
- CMMC is paused in Phase 1, but self-assessments and annual affirmations in SPRS remain a condition of award and a source of False Claims Act exposure.
- A Microsoft 365 tenant can produce most of the evidence, but default log retention and device inventories fall short of what the rules ask for.
For years, MFA everywhere and a complete asset list were advice from auditors and insurers. For New York regulated financial companies they are now rules with a signature attached. Under the amended NYDFS Part 500, universal MFA and the asset inventory requirement took effect on November 1, 2025, and the annual filing to the regulator is signed by the highest-ranking executive and the CISO (23 NYCRR Part 500, DFS). In the defense supply chain, the CMMC rules moved the same controls from contract language into award decisions.
The practical question for a CIO is not whether these controls exist in the tenant. It is whether the company can show, with data, that they covered every user, every asset and every privileged session for the whole year that the CEO is about to certify.
NYDFS Part 500 now asks the CEO to sign for controls the CISO runs
DFS adopted the second amendment to Part 500 effective November 1, 2023 and phased it in over 2 years. Section 500.12 now requires MFA for any individual accessing any information system of a covered entity. Section 500.13 requires a complete, accurate and documented asset inventory that tracks owner, location, classification or sensitivity, support expiration date and recovery time objective for each asset. Both carried a 2 year transition that ended on November 1, 2025 (DFS).
By April 15 of each year a covered entity files either a certification of material compliance for the prior calendar year or an acknowledgment of noncompliance with a remediation timeline. Supporting records must be kept for 5 years. That means the filing due April 15, 2027 is the first one that must stand behind 12 full months of universal MFA and a maintained inventory.
The scope reaches beyond New York institutions. A bank or insurer from Singapore, Tokyo or Sydney that operates a state-licensed New York branch or insurance license is a covered entity, and its global tenant is often the system the branch uses.
DFS enforces with specifics. In August 2025 it settled with Healthplex for $2 million and cited, among other failures, that MFA was not set up on its Microsoft Outlook 365 email environment (DFS press release). In April 2026 Delta Dental paid $2.25 million over incident response and late notification (DFS press release).
CMMC compliance is paused in Phase 1, the affirmation is not
The CMMC program rule in 32 CFR Part 170 took effect on December 16, 2024 (Federal Register). The acquisition rule in 48 CFR followed on November 10, 2025. Contracting officers may not award to an offeror without a current CMMC status in the Supplier Performance Risk System (SPRS), and an affirming official must affirm continuous compliance annually or when the status changes (Federal Register).
On July 13, 2026 the Department of War suspended Phase II, which would have required third-party Level 2 certification from November 10, 2026, and set up a reform task force (DoD CIO). Phase 1 self-assessments remain in place. Level 1 covers the 15 requirements of FAR 52.204-21, Level 2 the 110 requirements of NIST SP 800-171 Rev 2, including multifactor authentication for privileged accounts and for network access by all users.
A pause in third-party assessment does not lower the bar. It moves the weight onto the self-attestation, and the Department of Justice continues to treat inaccurate SPRS scores as potential False Claims Act exposure (Jenner & Block, July 14, 2026). For a defense supplier, the affirming official is signing for the tenant in the same way a New York CEO is.
MFA for all users has to be provable from sign-in data
In Entra ID the control is a conditional access policy that targets all users and all resources and requires MFA. The evidence is different. An examiner or assessor will ask who is excluded, why, and since when. Typical gaps in a 3,000 user environment: break-glass accounts, a legacy service account still using basic authentication, guest users, and a policy that was in report-only mode for 3 weeks after a change.
Part 500 allows the CISO to approve reasonably equivalent compensating controls in writing, reviewed at least annually. Every exclusion in conditional access therefore needs a matching approval document. For the method itself, MFA that satisfies the rule is not automatically MFA that resists phishing. We covered that gap in our note on phishing-resistant MFA and token theft.
Intune and Defender give you devices, not an asset inventory
Intune and Microsoft Defender for Endpoint list managed and discovered devices well. They do not record the business owner, the data classification, the support expiration date or the recovery time objective that 500.13 names. They also miss network equipment, on-premises servers outside Defender coverage, SaaS applications and Azure resources.
The workable model is a configuration management database that pulls from Intune, Defender and Azure Resource Graph and adds the 5 fields the rule asks for. The policy must also define how often the inventory is updated and validated. An inventory that nobody reconciles is a document, not a control.
Privileged access and logging fail on retention more often than on design
Part 500 requires limiting privileged accounts, using them only when needed and reviewing all access at least annually. Class A companies, broadly those with at least $20 million in annual revenue plus either over 2,000 employees or over $1 billion in revenue including affiliates, must also run a privileged access management solution, endpoint detection and centralized logging. In Entra ID that maps to Privileged Identity Management with time-bound activation and access reviews.
The weak spot is retention. Section 500.6 requires audit trails for cybersecurity events to be kept for 3 years. Entra ID keeps sign-in and audit logs for 30 days with P1 or P2 licenses and 7 days on Free (Microsoft Learn). Without export to Log Analytics, Microsoft Sentinel or a storage account, the evidence for most of the certified year is already gone, and retention changes are not retroactive.
| Requirement | NYDFS Part 500 | CMMC Level 2 | Evidence in Microsoft 365 |
|---|---|---|---|
| MFA | 500.12, all individuals | NIST 3.5.3 | Conditional access coverage, sign-in logs, approved exclusions |
| Asset inventory | 500.13(a), 5 tracked fields | NIST 3.4.1 | CMDB fed by Intune, Defender, Azure Resource Graph |
| Privileged access | 500.7, annual review | NIST 3.1.5, 3.1.6 | PIM activations, access review results |
| Logging | 500.6, 3 years | NIST 3.3.1 | Exported Entra and Purview audit logs |
What to do now
- CEO and CISO: agree now on the evidence pack behind the April 15, 2027 filing, and decide early whether a certification or an acknowledgment is the honest answer.
- CISO: export conditional access coverage for all users, list every exclusion and attach a written approval or remove it before year end.
- IT Operations: extend the device inventory into a CMDB with owner, location, classification, support expiration and recovery time objective, and set a validation cycle.
- CIO: route Entra sign-in and audit logs to long-term storage with at least 3 years of retention, and confirm that PIM and access reviews cover every privileged role.
- Board: for defense suppliers, name the affirming official, review the SPRS score against actual tenant state and treat the annual affirmation like a financial attestation.
Note
As of October 8, 2026. CMMC is under review by a reform task force and timelines may change. This is not legal advice. Check the primary sources and your counsel before any filing or affirmation.
We approach these filings from the evidence backwards: read access to the tenant first, then a gap list against the specific sections, then automated evidence collection that runs all year rather than in March. Our Executive IT & AI Review covers the gap assessment, and our Microsoft Platform Services carry the remediation in Entra ID, Intune and Sentinel. A senior partner signs off on the evidence before your CEO signs the filing.
Sources
- 23 NYCRR Part 500 Cybersecurity Regulation, New York State Department of Financial Services
- Superintendent announces $2 million cybersecurity settlement with Healthplex, DFS, August 14, 2025
- Cybersecurity settlement with Delta Dental Insurance Company and Delta Dental of New York, DFS, April 30, 2026
- Cybersecurity Maturity Model Certification (CMMC) Program, 32 CFR Part 170, Federal Register, October 15, 2024
- DFARS: Assessing Contractor Implementation of Cybersecurity Requirements, 48 CFR, Federal Register, September 10, 2025
- About CMMC, DoD Chief Information Officer, accessed October 8, 2026
- Department of War suspends CMMC Phase II, Jenner & Block, July 14, 2026
- Microsoft Entra data retention, Microsoft Learn



