The DFS certification your firm signs every April is a personal legal representation. We build the evidence behind it.
IT On Demand serves New York financial services firms operating under 23NYCRR500 — building and maintaining the governance documentation that makes the annual certification defensible.
What 23NYCRR500 actually requires — and what most firms don't have.
New York’s cybersecurity regulation for financial services firms does not require tools. It requires evidence — documented proof that specific controls are implemented, tested, and operational at your firm.
The annual certification filed with DFS is not an administrative filing. It is a personal attestation by the covered entity’s senior officer that the firm’s cybersecurity program meets the requirements of the regulation. When an examiner arrives and finds a gap between what was certified and what the evidence shows, the liability belongs to the person who signed it.
Most DFS-covered firms have IT providers managing their systems and compliance officers filing on time. What they do not have is anyone producing the evidence that sits between those two functions — the penetration test remediation logs, vendor risk assessments, tested incident response plans, and MFA verification records that an examiner will request by name.
That is the documentation gap. And it is the gap IT On Demand was built to close.
When a DFS examiner arrives, here is what they ask for.
A DFS examination of a financial services firm under 23NYCRR500 is not a technology audit. It is a governance audit. Examiners work from a documentation request list. The items they request — consistently, across examinations — include:
- Third-party penetration test report with remediation evidence for all high and critical findings
- Vendor risk assessment inventory — every third party with access to nonpublic information, tiered by risk
- Tested incident response plan — including documented proof that the plan was tested, not just written
- MFA verification records — coverage documentation across all user populations, cloud infrastructure, and privileged accounts
- Written Information Security Program (WISP) — current, firm-specific, not a generic template
- Board-level governance reporting — evidence that the program is actively managed, not just filed
We own the governance layer. Your IT provider owns the systems. Your compliance officer owns the filings.
IT On Demand does not replace your IT provider or your compliance officer. We fill the gap between them — the layer that is unowned in most financial services firms and is exactly what DFS examiners examine.
We build, document, and maintain the evidence your firm needs to certify with confidence: the penetration test documentation, the vendor risk program, the tested IR plan, the MFA verification records, and the WISP that reflects your actual environment and regulatory exposure.
Year-round. Not on a deadline.
The firms we know best.
Our financial services clients are typically mid-market firms — 25 to 200 employees, $10 million to $500 million in AUM or revenue, operating under active DFS supervision with no dedicated in-house CISO.
The decision-maker is usually the managing partner or CEO whose name is on the DFS annual certification, or the CCO or General Counsel managing the compliance program. In most cases, neither has had a clear picture of what specific evidence exists behind the certification they file. The Compliance Gap Assessment changes that.
Questions we hear from financial services firms.
- Q: What is the 23NYCRR500 annual certification, and what does it require me to attest to?
- A: The annual certification requires a covered entity's senior officer to attest that the firm's cybersecurity program is in compliance with the requirements of 23NYCRR500 as of December 31 of the prior year. The certification covers the existence and implementation of specific controls — not just their documentation. Signing the certification without independent verification of the evidence behind it is the most common governance risk we see in this market.
- Q: What happens if a DFS examination finds a gap in our documentation?
- A: An examination finding results in a formal DFS response requirement — a remediation plan with documented timelines and follow-up examination. In cases of significant non-compliance or repeated findings, DFS has issued consent orders that name individual senior officers personally, imposing financial penalties and, in some cases, restrictions on future conduct. The specific consequences depend on the nature and severity of the finding.
- Q: Is my current IT provider responsible for the governance documentation DFS requires?
- A: No. Your IT provider is responsible for managing your technology systems — uptime, security tooling, infrastructure. Governance documentation — penetration test remediation logs, vendor risk assessments, tested incident response plans — is not a deliverable that IT providers are built to produce. The gap between what your IT provider delivers and what a DFS examiner examines is the gap IT On Demand was built to fill.
- Q: We haven't had an examination in several years. Does that mean our program is adequate?
- A: It means you have not been examined. Those are different things. DFS examination cycles vary by firm and are not publicly announced in advance. The firms that enter examinations with adequate documentation are the firms that maintained it year-round — not the firms that built it on the news of an incoming examination.