
A smaller registered investment adviser receives notice that a technology provider exposed customer information. The provider cannot yet identify everyone affected.
This is where Regulation S-P stops being a policy update and becomes an operating test. The smaller-entity compliance date was June 3, 2026. The larger-entity date was December 3, 2025. As of September 2026, both dates have passed.
The amended rule requires a written incident response program, service provider oversight, customer notification procedures, and compliance records. The Securities and Exchange Commission (SEC) Division of Examinations also named the amendments in its fiscal 2026 priorities.
What Is Regulation S-P?
Regulation S-P governs consumer financial privacy and safeguards for customer information. The SEC adopted the amendments on May 16, 2024. They became effective on August 2, 2024.
The revised safeguards rule requires covered institutions to develop, implement, and maintain written incident response policies and procedures. The program must be reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information.
The amended safeguards and disposal requirements appear in Title 17 of the Code of Federal Regulations, section 248.30 (17 CFR 248.30). The SEC Small Entity Compliance Guide summarizes the amendments and compliance dates.
Which Firms Must Comply Now?
Covered institutions include broker-dealers, including funding portals, investment companies, SEC-registered investment advisers, and registered transfer agents. A private fund adviser is covered as a registered investment adviser if it is SEC-registered.
Apply the relevant test:
- A registered investment adviser is a larger entity at $1.5 billion or more in assets under management.
- An investment company is larger at $1 billion or more in net assets, combined with other investment companies in the same related group.
- A broker-dealer or transfer agent is larger when it is not a small entity under the Securities Exchange Act standards used for Regulatory Flexibility Act purposes.
- Every other covered institution is a smaller entity.
What the Written Incident Response Program Must Contain
Make these elements easy to activate:
- Procedures to detect, respond to, and recover from unauthorized access to or use of customer information.
- Steps to assess an incident’s nature and scope.
- Steps to contain and control the incident to prevent further unauthorized access or use.
- A customer-notice process tied to the rule’s investigation, timing, content, and exception standards.
- Written service provider oversight procedures, established, maintained, and enforced through due diligence and monitoring.
For institutions other than registered transfer agents, customer information includes records containing nonpublic personal information about a financial institution’s customer. That covers records the firm possesses and records handled or maintained by it or on its behalf. Safeguarding reaches all customer information. Disposal requirements cover customer and consumer information.
Sensitive customer information is information whose compromise could create a reasonably likely risk of substantial harm or inconvenience to an identified person. Examples include Social Security, driver’s license, or government identification numbers. A user name or account number paired with a security code or credit-card expiration date can also qualify.
Unless the reasonable-investigation exception applies, notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. Use a written method designed so each person can reasonably be expected to receive actual notice.
If the firm cannot identify the affected individuals, notify everyone whose sensitive customer information resides in the system that was, or was reasonably likely to have been, accessed or used without authorization. The firm may exclude a specific person it reasonably determines was not affected.
Covered institutions must make and maintain written records documenting compliance with the safeguards and disposal rules. Have compliance confirm the institution-specific retention period and record owner.

The 72-Hour and 30-Day Clocks
The firm’s policies must be reasonably designed to ensure provider notice as soon as possible, and no later than 72 hours after the provider becomes aware of a breach. The trigger is a security breach resulting in unauthorized access to a customer information system the provider maintains.
When notice arrives, the covered institution must initiate its incident response program. Record provider awareness, firm receipt, and response start times.
The customer clock starts when the institution becomes aware that unauthorized access to or use of customer information occurred or is reasonably likely to have occurred. Notice is due as soon as practicable, but no later than 30 days after awareness.
Notice is not needed if a reasonable investigation supports one conclusion. The institution must determine that sensitive customer information has not been, and is not reasonably likely to be, used in a manner resulting in substantial harm or inconvenience. Preserve the investigation, evidence considered, decision maker, and conclusion.
The rule lists eight required notice elements, from a plain incident description to account-review, fraud-alert, free-credit-report, and identity-theft instructions. A provider may send the notice under a written agreement, but ultimate responsibility stays with the institution.
Notice may be delayed only if the U.S. Attorney General determines it poses a substantial risk to national security or public safety and notifies the Commission in writing.
Vendor Due Diligence and Monitoring Checklist
The rule requires written policies for service provider oversight through due diligence and monitoring. The policies must be reasonably designed to ensure providers protect customer information and give the required breach notice. The amendments do not require a written contract with every provider, but the oversight duties still apply.
These are evidence examples, not a required form or review frequency.
| Control point | Evidence to consider keeping current |
|---|---|
| Customer information handled for the firm | Systems, information categories, provider access, approved use, and the internal owner |
| Due diligence | Review date, reviewer, services assessed, evidence examined, protection gaps, approval decision, and conditions |
| Monitoring | Review date, evidence checked, findings, action owner, follow-up date, and closure status |
| Breach notification | Notice route, named recipients, escalation backup, and fields for provider awareness and firm receipt times |
| Incident handoff | Activation owner, response procedure, open fact requests, and the person responsible for the notice decision |
| Customer notice support | Responsibilities for incident facts, breached-data details, affected individuals, and any notice sent for the firm |
For one type of vendor evidence, see how to read a System and Organization Controls (SOC) 2 Type 2 report.
Treat an artificial intelligence (AI) vendor that handles customer information for the firm as a service provider. For the separate large language model (LLM) data-flow issue, see Private LLM vs. Public LLM: Where Your Financial Data Actually Goes.

What SEC Examiners Identified for Fiscal 2026
The SEC’s fiscal 2026 priorities say examinations will cover compliance with the 2024 amendments. After the compliance dates, staff will examine whether firms have developed, implemented, and maintained policies and procedures addressing administrative, technical, and physical safeguards.
The same fiscal 2026 priorities identify third-party vendor oversight, internal controls, governance, mission-critical service interruptions, AI, and polymorphic malware attacks.
Be ready to produce incident response policies and compliance records. Organize them to show approvals, providers and systems in scope, and the path to a documented notice decision.
The SEC’s final small-firm outreach event on January 22, 2026, included an incident response tabletop, a sample document request list, and a mock examination.
Use the opening scenario for an exercise. Log when the firm and provider became aware, name who activates the response, and identify who makes the notice decision. Preserve the evidence, decision, and unresolved actions.
How Nu-Age Approaches This
Connect vendor evidence to in-scope services and customer information.
Nu-Age states that it serves hedge funds, collateralized loan obligation managers, credit funds, and registered investment advisers. On its hedge fund cybersecurity page, the company says it maintains a “DDQ-ready vendor risk register for every subprocessor and downstream vendor in our delivery chain.” DDQ means due diligence questionnaire. The company also reports coordinating directly with clients’ outside counsel and running tabletop exercises.
In its April 2026 SOC 2 announcement, Nu-Age reported that its Type 2 examination covered January through December 2025 and returned zero exceptions. The company says the report is available under a nondisclosure agreement. A SOC 2 report is an attestation, not a certification, and it does not by itself show Regulation S-P compliance.
Use those statements to frame the review. Inspect the register and report if provided, confirm how outside counsel enters the response, and ask whether documentation of tabletop exercises is available. Compare any materials provided with the firm’s procedures before approval or renewal.
Key Takeaways
- Both larger- and smaller-entity compliance dates have passed.
- The amendments require a written incident response program, service provider oversight, customer notice procedures, and compliance records.
- Provider notice has a 72-hour outer limit, while customer notice has a separate trigger and 30-day outer limit.
- For examination readiness, organize evidence showing how policies operate, who makes decisions, and how follow-up closes.
Frequently Asked Questions
What is Regulation S-P?
Regulation S-P is the SEC rule covering consumer financial privacy and safeguards for customer information. Its 2024 amendments require a written incident response program, service provider oversight, customer notices, and compliance records. The amended safeguards and disposal requirements appear at 17 CFR 248.30.
Who must comply with the Regulation S-P amendments?
Covered institutions include broker-dealers, investment companies, SEC-registered investment advisers, and registered transfer agents. Larger entities had a December 3, 2025, compliance date. Smaller entities had a June 3, 2026, date. A registered investment adviser is larger at $1.5 billion or more in assets under management.
What is the 72-hour Regulation S-P requirement?
Policies must be reasonably designed to ensure notice no later than 72 hours after a provider becomes aware of a security breach resulting in unauthorized access to a customer information system it maintains. The institution must then initiate its incident response program. Recording the provider’s awareness time, the firm’s receipt time, and the response start time can support its compliance records.
When is customer notice required under Reg S-P?
Customer notice is due as soon as practicable, and no later than 30 days after the institution becomes aware of the incident. Awareness means knowing that unauthorized access to or use of customer information occurred or is reasonably likely to have occurred. The exception applies only after a reasonable investigation determines that sensitive customer information has not been, and is not reasonably likely to be, used in a manner resulting in substantial harm or inconvenience.
What does vendor due diligence under Regulation S-P require?
The incident response program must require service provider oversight through due diligence and monitoring. Procedures must be reasonably designed to ensure providers protect customer information and deliver the required breach notice. The amendments do not require a written contract with every provider. A written agreement may authorize provider-sent customer notices, but responsibility remains with the institution.
Test the Program Against a Provider Incident
Run one exercise from provider alert through the customer-notice decision. Confirm named recipients can receive the alert, activate the response, obtain missing facts, identify affected individuals, and preserve the investigation. Assign each gap an owner and follow-up date. Complete the test before the next renewal. Review Nu-Age’s published Cybersecurity Strategy and Compliance service information, then contact The Nu-Age Group at (866) 640-3999 or sales@thenuagegroup.us.








