The June 3, 2026 compliance deadline for smaller entities under the amended Regulation S-P has passed. If you are a smaller registered investment adviser, broker-dealer, investment company, funding portal, or transfer agent, the deadline is no longer the concern, the examination is.
Financial firms are not a regulatory target by coincidence. IBM's 2026 X-Force Threat Intelligence Index identified financial services as the second most targeted industry globally, behind only manufacturing. The third-party risk driving that exposure is significant. The share of breaches involving a third party doubled to 30% of all incidents according to the Verizon 2025 Data Breach Investigations Report, which is a particularly relevant figure for financial firms whose operations depend on cloud platforms, fintech partners, and outsourced service providers. Regulation S-P's requirements around incident response and vendor oversight were written directly for this environment.
The SEC's Division of Examinations named Regulation S-P compliance an explicit priority in its 2026 examination priorities, announced in November 2025, stating directly that it would examine firms' compliance with the amended requirements after the applicable compliance dates. The SEC has confirmed that Regulation S-P compliance will be a priority in examinations conducted this year, and those examinations are now in progress for smaller entities.
Most small financial firms spent the months before June 3 focused on whether they had something on paper. That was a reasonable starting point. The problem is that SEC examiners are not evaluating whether your policies exist. They are evaluating whether your policies work, whether your staff knows about them, whether your vendors comply with them, and whether you have evidence that all of it was in place before an incident, not assembled afterward.
SEC examiners are not evaluating whether your policies exist. They are evaluating whether your policies work, whether your staff knows about them, whether your vendors comply with them, and whether you have evidence.
The 2024 amendments to Regulation S-P are not a modest update to an existing rule. They represent a fundamental shift in what the SEC expects from covered institutions on cybersecurity and customer data protection.
First, every covered institution must maintain a written incident response program. The program must include procedures for detecting unauthorized access to or use of customer information, assessing the nature and scope of any incident, containing and controlling security incidents to prevent further unauthorized access, notifying affected customers, and evaluating and revising the program after any incident. The program must be reasonably designed, which means it must reflect the actual systems and data flows at your firm, not a generic template that could have been drafted for any financial services company anywhere.
Second, customer notification is now time-bound. When a breach involves sensitive customer information, firms must notify affected individuals as soon as practicable but no later than 30 days after becoming aware of the unauthorized access, and must provide them with details about the incident and information to help them respond. For a small firm that has never experienced a data breach, 30 days sounds comfortable. In practice, the first two weeks of a breach are consumed by forensic investigation, legal review, and determining exactly whose information was affected. Firms that have not pre-built their notification workflow will miss this window under pressure.
Third, service provider oversight has become a documented obligation. Firms must conduct due diligence when selecting third-party service providers that access customer information, require those vendors to maintain appropriate safeguards, and monitor vendor compliance on an ongoing basis. Examiner document requests include vendor policies, risk assessments, service agreements, monitoring records, and complete vendor lists, and vendor contracts must include provisions requiring vendors to notify the firm of a security incident within 72 hours. If your current vendor agreements do not include that language, they are out of compliance.
Fourth, recordkeeping requirements have expanded. Firms must retain documentation of their incident response programs, any incidents that occurred, how those incidents were handled, evidence of customer notification, and records of vendor oversight activities. A policy created the week before an exam notice arrives raises questions rather than answering them. The metadata on your documents matters. Examiners will notice if your compliance program appears to have been assembled in anticipation of an examination rather than operating in the ordinary course of business.
In January 2026, the SEC Division of Examinations held a compliance outreach webinar specifically for smaller firms that previewed its examination approach for Regulation S-P. The session included a mock examination and a review of the initial document request list examiners will use. What emerged from that session was an unusually clear picture of the specific evidence the SEC expects to see.
Examination staff will evaluate how programs operate in practice rather than whether policies exist on paper, which is a meaningful distinction for firms whose compliance programs were built to satisfy a checklist rather than to function under operational pressure.
The document request categories fall into five areas. Governance and risk management requests will include organization charts with cybersecurity reporting lines, committee structures, IT governance documentation, and risk assessment materials. Compliance program requests will include policies and procedures under Advisers Act Rule 206(4)-7, the most recent annual compliance review, compliance testing records, and records of any non-compliance events or internal investigations. Privacy and information security requests will include privacy notices and evidence of their delivery to customers, safeguard documentation, complaints related to privacy or security, and incident response materials. Cybersecurity incident requests will cover any incidents or breaches during the review period, including records of customer harm and remediation steps taken. Service provider requests will include vendor policies, vendor risk assessments, service agreements with vendors, monitoring records, and a complete inventory of all vendors with access to customer information.
That last category carries the most risk for small firms. Most small investment advisers and broker-dealers do not maintain a comprehensive vendor inventory. They know who provides their portfolio management software and their custodian. They are less likely to have documented their document storage platform, their email provider, their CRM system, their video conferencing tool, or any other platform that may process or store customer information. Under the amended rule, all of them are in scope.
The SEC's 2026 examination priorities explicitly extend Regulation S-P's cybersecurity expectations to the use of artificial intelligence. Examiners will review training and security controls, including identification and mitigation of risks associated with artificial intelligence and malware attacks. Firms that have adopted AI tools for portfolio research, customer communications, or compliance monitoring without documenting how those tools access and process customer information have a specific gap under the amended rule.
If your firm has integrated AI-assisted tools in the past two years, the relevant question is not whether those tools are useful. The question is whether customer information flows through them, whether they are documented in your vendor inventory, and whether your incident response program addresses what happens if those tools are compromised. For a deeper look at the AI governance obligations that apply to FINRA member firms, our team has covered the FINRA 2026 regulatory expectations in detail: FINRA 2026 GenAI Governance: A Survival Guide for Small Financial Firm CEOs. The two regulatory frameworks are converging, and small firms need a coordinated response to both.
Financial firms operating under a New York license face a compounding compliance obligation. NYDFS Part 500 and SEC Regulation S-P are not the same regulation, but they impose overlapping requirements in cybersecurity governance, incident response, and vendor oversight. FINRA imposed over $95 million in fines in 2026 in what has been one of its most active enforcement years on record, which signals that the regulatory environment for financial firms is in an enforcement posture, not a guidance posture.
For firms subject to both regimes, the practical question is whether a single compliance infrastructure can satisfy both. In most cases the answer is yes, with appropriate documentation. The NYDFS Part 500 annual certification deadline passed on April 15, 2026. If your firm is NYDFS-covered and is now beginning its Regulation S-P buildout, the NYDFS work you have already done provides a foundation. For firms that have not completed either program, the gap is compounding. A detailed breakdown of the NYDFS Part 500 requirements and what the April 15 certification required is available here: The NYDFS Part 500 Ransomware Update Is Here: What Every Covered Entity Needs to Know.
For small financial firms that need a structured way to build toward both Regulation S-P and NYDFS Part 500 compliance, the NIST Cybersecurity Framework provides a control structure that maps directly to both regulatory regimes. Our team has written specifically on how NIST alignment supports SEC, FINRA, and NYDFS examination readiness: NIST CSF for Financial Services: Meeting SEC, FINRA, and NYDFS Expectations. Aligning to NIST CSF can help evidence a reasonably designed program to assist with Reg S-P compliance, which is exactly what an SEC examiner is looking for when they sit down across the table.
The firms that will navigate SEC Regulation S-P examinations successfully are the ones that can answer the following questions with documented evidence rather than explanations.
Does your written incident response program exist as a complete, firm-specific document that reflects your actual systems and customer data flows? Have any staff members been trained on the incident response program, and can you produce training records? Do your vendor contracts include the required 72-hour breach notification clause? Do you maintain a complete inventory of all vendors with access to customer information? Has your incident response program been tested, and is there a record of that test? If a breach occurred tomorrow, can you identify within 30 days every customer whose sensitive information was involved?
If any of those questions produced hesitation, the gap is worth addressing before an examiner produces the same question in a document request.
How CompassMSP Supports Regulation S-P Compliance
For small broker-dealers, registered investment advisers, and other SEC-covered entities, building a Regulation S-P-compliant program requires the intersection of regulatory knowledge, technical implementation, and documentation discipline that most small financial firms do not maintain internally. CompassMSP works with financial services organizations to build the incident response programs, vendor oversight frameworks, and compliance documentation that Regulation S-P requires and that SEC examiners will ask to see.
Ready to take the first step toward compliance? Learn about our financial services compliance practice.
NOTE: This article is for informational purposes only and does not constitute legal or compliance advice. Regulation S-P obligations should be reviewed with qualified legal counsel.