Compliance · SEC Regulation S-P
SEC Regulation S-P compliance for investment advisers and broker-dealers.
The SEC's 2024 amendments added a written incident response program, a 30-day deadline to notify affected individuals, and oversight of service providers, including notice to you within 72 hours of a breach. We build the program and the mechanics behind it, and get your evidence ready for an examination. Your securities counsel keeps the legal calls.
What the 2024 amendments require
What does Regulation S-P require now?
The SEC adopted the amendments on May 16, 2024 (Release No. 34-100155). They apply to broker-dealers (including funding portals), investment companies, SEC-registered investment advisers and registered transfer agents, which the rule calls covered institutions.
A written incident response program
Written policies and procedures for a program reasonably designed to detect, respond to and recover from unauthorized access to or use of customer information. It must include procedures to assess the nature and scope of an incident and to contain and control it.
Customer notice within 30 days
Notify individuals whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization: as soon as practicable, and no later than 30 days after becoming aware of the incident. The notice must cover what happened, the data involved and how the individual can protect themselves.
A limited exception
No notice is required if, after a reasonable investigation, the firm determines the sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience. Making that call is a legal judgment.
Service-provider oversight and the 72-hour notice
Written policies and procedures to oversee service providers, including through due diligence and monitoring, so they protect customer information and notify you as soon as possible, and no later than 72 hours after becoming aware of a breach in security that results in unauthorized access to a customer information system they maintain.
A broader definition of customer information
The safeguards and disposal rules now cover nonpublic personal information about your own customers and the information you receive from another financial institution about its customers.
Written records of compliance
Covered institutions other than funding portals must make and maintain written records documenting compliance with the safeguards rule and the disposal rule.
The deadlines written into the rule
Who had to comply, and when
Both compliance dates have passed.
The SEC set a tiered schedule. Every covered institution is now past its date.
Larger entities: December 3, 2025
SEC-registered investment advisers with $1.5 billion or more in assets under management; investment companies that, with their group of related investment companies, have net assets of $1 billion or more; and broker-dealers and transfer agents that are not small entities under the SEC's small-entity definitions.
Smaller entities: June 3, 2026
Every covered institution that does not meet the larger-entity standard, which includes any SEC-registered adviser with less than $1.5 billion in assets under management.
What examiners will look at
The SEC Division of Examinations' fiscal year 2026 priorities say that after the compliance dates it will examine whether firms have developed, implemented and maintained policies and procedures under the amended rule.
What we deliver
What we build for your Regulation S-P program.
The security work and the operating procedures, written down so you can show an examiner what you do and that you do it.
Gap assessment against the amended rule
We check your current controls and documents against each requirement: safeguards, incident response, customer notification, service providers, disposal and records. You get a ranked list of gaps with owners.
Written safeguards and incident response program
Policies and procedures covering administrative, technical and physical safeguards, and an incident response runbook that walks from detection through scoping, containment and recovery to the decision on customer notice.
Customer notification mechanics
A procedure with the 30-day clock built in, a notice template that covers the content the rule calls for, and a delivery and record step. Your counsel approves the wording and decides whether a notice is owed.
Service-provider oversight
An inventory of the vendors that touch customer information, a due-diligence and review cadence, and an intake procedure so a vendor's breach notice reaches the right person without delay. Counsel drafts the contract terms, including the 72-hour notice.
Technical safeguards, tested
Access control, multi-factor authentication, encryption, logging and monitoring around the systems that hold customer information, then a penetration test and an incident response tabletop to show the controls and the runbook work.
Examination evidence pack
The records that document compliance, indexed so you can produce them when examiners ask: the program, the risk assessment, incident assessments and notices, vendor reviews and training records.
Who does what
We do the security work. Your securities counsel makes the legal calls.
We are a security firm, not a law firm, and nothing on this page is legal advice. We work alongside your counsel and compliance team.
What we do
Build the safeguards and incident response program. Implement and test the technical controls. Run the gap assessment, the tabletop and an internal readiness review. Set up the 30-day notification procedure and the vendor notice intake. Assemble the evidence pack.
What stays with your securities counsel
What counts as sensitive customer information. Whether an incident triggers a notice or the exception applies. The legal wording of notices and privacy notices. Enforceable contract terms with service providers. Your examination posture and anything you say to the SEC.
How an engagement runs
From scoping call to an examination-ready program.
Scoped to your firm after a short call, with a fixed price agreed before we start.
Scoping call
Thirty minutes on what you are registered as, what already exists, which vendors touch customer information, and who your counsel is.
Gap assessment
We assess your firm against each requirement of the amended rule. Output: a ranked gap list and a remediation plan with a fixed quote.
Build
We write the program and runbook, implement the technical controls, and set up the notification and vendor procedures. Counsel reviews the legal content as we go.
Rehearse and package
A tabletop exercise against a realistic incident, fixes from what it shows, and an indexed evidence pack ready for an examination.
Regulation S-P FAQ
Does Regulation S-P apply to my firm?
What were the compliance dates?
When do we have to notify customers after an incident?
What is the 72-hour requirement for vendors?
Are you giving us legal advice?
We also prepare tax returns. Can you cover that too?
Where are you based?
What does it cost?
Sources
Where the rule details on this page come from.
Every requirement and date above is taken from the SEC releases and rule text below. This page is a summary to help you plan, not legal advice: rely on the rule text and your securities counsel.
- SEC press release 2024-58: SEC Adopts Rule Amendments to Regulation S-P to Enhance Protection of Customer Information (May 16, 2024)
- SEC fact sheet: Final Rules, Enhancements to Regulation S-P
- Adopting release: Regulation S-P, Release Nos. 34-100155; IA-6604; IC-35193
- Federal Register version: 89 FR 47688 (June 3, 2024)
- SEC staff: Enhancements to Regulation S-P, A Small Entity Compliance Guide
- Rule text: 17 CFR 248.30 (eCFR)
- SEC Division of Examinations: Fiscal Year 2026 Examination Priorities
Get your Regulation S-P program built and examination-ready.
A short scoping call, then a fixed-price proposal. Bring your securities counsel; we handle the security work.

