ICYMI: Annual Compliance Submissions Due April
As a reminder, covered entities were required to submit their annual compliance submissions (either a Certification of Material Compliance or an Acknowledgement of Noncompliance) for calendar year 2023 by April 15, 2024. If not yet submitted, covered entities can still submit their annual compliance notifications through the DFS portal.
The annual compliance submission must be signed by the highest-ranking executive and Chief Information Security Officer (or, if the entity does not have a CISO, the senior officer in charge of cybersecurity). Covered entities that qualify for full exemptions from the Cybersecurity Regulation do not have to submit annual compliance notifications.
On April 29, 2024, additional requirements became effective under the amended regulation, including updates related to Risk Assessments (Section 500.9), Cybersecurity Policies (Section 500.3), Cybersecurity Awareness Training (Section 500.14(a)(3)), and Vulnerability Management (Section 500.5(a)(1), (b), and (c)).