New York's Department of Financial Services has one of the most consequential cybersecurity rules in U.S. financial services, and the Second Amendment to 23 NYCRR Part 500, signed in October 2023 and effective November 1, 2023, sharpened it in two ways that matter for offensive testing. It made the penetration testing requirement explicit about coverage, and it raised the accountability behind the annual certification. The transitional periods have since passed, so for covered entities operating in New York, this is fully in effect today.
If you are a covered financial institution, the combination of those two changes is the part worth sitting with.
What Part 500 requires
After the 2023 amendment, the testing and vulnerability obligations read clearly:
- Annual penetration testing from both inside and outside the information systems boundaries, performed by a qualified internal or external party.
- Automated vulnerability scanning at a frequency set by your own risk assessment and promptly after any material system change, with manual review of systems the scans do not cover, a process to stay promptly informed of newly disclosed vulnerabilities, and timely remediation prioritized by the risk each vulnerability poses.
- An annual certification of material compliance (or a written acknowledgment of material non-compliance identifying each non-compliant section and a remediation timeline), submitted to the Superintendent by April 15 and signed by the highest-ranking executive and the CISO.
The phrase to underline is "both inside and outside." Part 500 does not let you treat the external perimeter as the whole job. It names the internal network as testing scope in its own right.
One carve-out is worth knowing. Section 500.19(a) grants a limited exemption to entities below all of its thresholds, currently fewer than 20 employees and contractors, under $7.5 million in gross annual revenue from New York operations across the last three fiscal years, or under $15 million in year-end total assets. Entities that qualify are exempt from Section 500.5 altogether, penetration testing included. The thresholds are low enough that most covered financial institutions are squarely in scope, but it is worth confirming which side of the line you are on before building a program around the requirement.
Why traditional penetration testing strains under it
Inside and outside, explicitly. Many programs test the external perimeter thoroughly and under-test the internal network, which is exactly where an attacker pivots toward crown-jewel systems once they are in. Part 500 closes that gap on paper. A single external assessment does not close it in practice.
Annual is the floor, not the goal. The certification is annual, but your risk is continuous. One yearly test gives you a single data point to certify against, taken in an environment that changed every week of the year you are certifying for. A test proves a point and stops; a continuous adversary campaign never stops, so it keeps surfacing the ways in that the annual snapshot never sees.
The certification raises personal accountability. The highest-ranking executive and the CISO both sign that the program is in place. Signing off on a posture you validated once, twelve months ago, is an uncomfortable position. Signing off on a posture that has been continuously validated, with evidence on file, is a defensible one. The amendment deliberately moved this from a paperwork exercise toward genuine accountability.
Qualified and consistent is hard to guarantee by hand. "Qualified party" and a consistent methodology are difficult to sustain with internal testing that happens between other priorities.
How SpartanX supports your Part 500 program
SpartanX is the first Autonomous Exposure Management (AEM) platform: an autonomous adversary that runs the full offensive loop continuously, inside and outside, and proves every finding with evidence.
For a Part 500 program specifically:
- Inside and outside, on equal footing. SpartanX tests your external attack surface, including your mobile apps and the APIs behind them, and, with NodeX, your internal environment, including Active Directory and Entra, machine identities, and east-west paths, continuously. That is exactly the inside-and-outside coverage Part 500 calls out, and it is run as one capability rather than two disconnected engagements.
- Continuous evidence behind an annual certification. Instead of certifying against a single snapshot, the executives who sign certify against a posture that has been validated and retested all year, with exploit-proof evidence on file.
- A qualified, consistent, autonomous testing capability that produces audit-ready reporting and a documented, repeatable methodology.
The boundary, stated plainly: SpartanX supports your Part 500 testing and vulnerability-management obligations and gives you the evidence that stands behind your certification. It does not by itself make you compliant, and it does not replace your own governance and sign-off. It makes the certification something you can defend, because the work behind it is real, continuous, and documented.
Why now
The 2023 amendment's transitional periods have passed, so the inside-and-outside annual testing requirement is fully in effect, and the annual certification now expects real evidence behind it rather than a best-effort attestation. Regulators have shown they are willing to act: DFS reported in October 2025 that it had entered into consent orders with 27 entities for violations of the cybersecurity regulation, totaling over $144 million in penalties. The cost of certifying to a posture you cannot actually demonstrate has gone up.
Meanwhile, attackers are using autonomous tooling to move from an initial foothold to domain control in minutes. The distance between an annual snapshot and continuous, inside-and-outside validation is the distance a real intrusion travels in the eleven months between your tests. That gap is what gets certified over, and later exploited.
The shift in one line
Part 500 now expects you to prove resilience inside and outside, and to put your name on it. Autonomous Exposure Management is how you make that signature defensible, with continuous evidence instead of a yearly snapshot.
SpartanX is The Ultimate Adversary™, pointed at yourself, inside and outside, continuously. Request a guided proof-of-value, or learn what Autonomous Exposure Management is.
Ready to see SpartanX in action?
See how a continuous adversary maps your whole attack surface, inside and out, and proves what is actually exploitable.
