04/15/2026
Today is April 15th, and most people only know it as tax day.
But if you work in financial services in New York, today is also your deadline to certify compliance with 25 NYCRR 500.
Two major deadlines. Same day. Every year.
If you're not familiar, 25 NYCRR 500 is the New York State cybersecurity regulation for financial services companies. It requires things like a written cybersecurity program, regular pe*******on testing, multi-factor authentication across critical systems, and a 72-hour window to report a breach.
The annual certification is what's due today. It goes to the superintendent of the Department of Financial Services, and it's essentially your firm saying, "Yes, we've been doing everything we're supposed to be doing."
The firms that stress over this filing every April are usually the ones that treated compliance as a checklist at the start of the year and then moved on. The firms that breeze through it are the ones that made it part of how they actually operate.
That's not a knock. It's just the reality.
If you got it filed today, good. Now, do yourself a favor and set a reminder for Q3 to audit where you actually stand before the next cycle sneaks up on you.
And if you're a tax professional grinding through today, respect. You're both filing under the same deadline and probably haven't slept properly in weeks. đ
Drop a comment if you want the ongoing compliance checklist we use throughout the year. Happy to share it.