Skip to content
VITI Security

Compliance · SEC Regulation S-P

SEC Regulation S⁠-⁠P compliance for investment advisers and broker-dealers.

The SEC's 2024 amendments added a written incident response program, a 30-day deadline to notify affected individuals, and oversight of service providers, including notice to you within 72 hours of a breach. We build the program and the mechanics behind it, and get your evidence ready for an examination. Your securities counsel keeps the legal calls.

What the 2024 amendments require

What does Regulation S-P require now?

The SEC adopted the amendments on May 16, 2024 (Release No. 34-100155). They apply to broker-dealers (including funding portals), investment companies, SEC-registered investment advisers and registered transfer agents, which the rule calls covered institutions.

A written incident response program

Written policies and procedures for a program reasonably designed to detect, respond to and recover from unauthorized access to or use of customer information. It must include procedures to assess the nature and scope of an incident and to contain and control it.

Customer notice within 30 days

Notify individuals whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization: as soon as practicable, and no later than 30 days after becoming aware of the incident. The notice must cover what happened, the data involved and how the individual can protect themselves.

A limited exception

No notice is required if, after a reasonable investigation, the firm determines the sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience. Making that call is a legal judgment.

Service-provider oversight and the 72-hour notice

Written policies and procedures to oversee service providers, including through due diligence and monitoring, so they protect customer information and notify you as soon as possible, and no later than 72 hours after becoming aware of a breach in security that results in unauthorized access to a customer information system they maintain.

A broader definition of customer information

The safeguards and disposal rules now cover nonpublic personal information about your own customers and the information you receive from another financial institution about its customers.

Written records of compliance

Covered institutions other than funding portals must make and maintain written records documenting compliance with the safeguards rule and the disposal rule.

The deadlines written into the rule

30 days
Outer limit to notify affected individuals, counted from becoming aware of the incident
72 hours
Outer limit for a service provider to tell you about a breach in security
June 3, 2026
Compliance date for smaller entities. Larger entities had until December 3, 2025

Who had to comply, and when

Both compliance dates have passed.

The SEC set a tiered schedule. Every covered institution is now past its date.

Larger entities: December 3, 2025

SEC-registered investment advisers with $1.5 billion or more in assets under management; investment companies that, with their group of related investment companies, have net assets of $1 billion or more; and broker-dealers and transfer agents that are not small entities under the SEC's small-entity definitions.

Smaller entities: June 3, 2026

Every covered institution that does not meet the larger-entity standard, which includes any SEC-registered adviser with less than $1.5 billion in assets under management.

What examiners will look at

The SEC Division of Examinations' fiscal year 2026 priorities say that after the compliance dates it will examine whether firms have developed, implemented and maintained policies and procedures under the amended rule.

What we deliver

What we build for your Regulation S-P program.

The security work and the operating procedures, written down so you can show an examiner what you do and that you do it.

Gap assessment against the amended rule

We check your current controls and documents against each requirement: safeguards, incident response, customer notification, service providers, disposal and records. You get a ranked list of gaps with owners.

Written safeguards and incident response program

Policies and procedures covering administrative, technical and physical safeguards, and an incident response runbook that walks from detection through scoping, containment and recovery to the decision on customer notice.

Customer notification mechanics

A procedure with the 30-day clock built in, a notice template that covers the content the rule calls for, and a delivery and record step. Your counsel approves the wording and decides whether a notice is owed.

Service-provider oversight

An inventory of the vendors that touch customer information, a due-diligence and review cadence, and an intake procedure so a vendor's breach notice reaches the right person without delay. Counsel drafts the contract terms, including the 72-hour notice.

Technical safeguards, tested

Access control, multi-factor authentication, encryption, logging and monitoring around the systems that hold customer information, then a penetration test and an incident response tabletop to show the controls and the runbook work.

Examination evidence pack

The records that document compliance, indexed so you can produce them when examiners ask: the program, the risk assessment, incident assessments and notices, vendor reviews and training records.

Who does what

We do the security work. Your securities counsel makes the legal calls.

We are a security firm, not a law firm, and nothing on this page is legal advice. We work alongside your counsel and compliance team.

What we do

Build the safeguards and incident response program. Implement and test the technical controls. Run the gap assessment, the tabletop and an internal readiness review. Set up the 30-day notification procedure and the vendor notice intake. Assemble the evidence pack.

What stays with your securities counsel

What counts as sensitive customer information. Whether an incident triggers a notice or the exception applies. The legal wording of notices and privacy notices. Enforceable contract terms with service providers. Your examination posture and anything you say to the SEC.

How an engagement runs

From scoping call to an examination-ready program.

Scoped to your firm after a short call, with a fixed price agreed before we start.

01

Scoping call

Thirty minutes on what you are registered as, what already exists, which vendors touch customer information, and who your counsel is.

02

Gap assessment

We assess your firm against each requirement of the amended rule. Output: a ranked gap list and a remediation plan with a fixed quote.

03

Build

We write the program and runbook, implement the technical controls, and set up the notification and vendor procedures. Counsel reviews the legal content as we go.

04

Rehearse and package

A tabletop exercise against a realistic incident, fixes from what it shows, and an indexed evidence pack ready for an examination.

Regulation S-P FAQ

Does Regulation S-P apply to my firm?
It applies to broker-dealers (including funding portals), investment companies, SEC-registered investment advisers, and transfer agents registered with the SEC or another appropriate regulatory agency. There are edge cases, such as notice-registered broker-dealers, so confirm your status with your securities counsel.
What were the compliance dates?
Larger entities had to comply by December 3, 2025 and smaller entities by June 3, 2026. For SEC-registered investment advisers, a larger entity is one with $1.5 billion or more in assets under management. Both dates have passed.
When do we have to notify customers after an incident?
As soon as practicable, and no later than 30 days after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred. The notice goes to individuals whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. You do not have to notify if, after a reasonable investigation, you determine the information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience. Whether that exception applies is for your counsel; we build the process that gets the facts to them quickly.
What is the 72-hour requirement for vendors?
Your service-provider oversight must be reasonably designed to ensure providers notify you as soon as possible, and no later than 72 hours after becoming aware of a breach in security resulting in unauthorized access to a customer information system they maintain. You can agree in writing that a provider sends the customer notices on your behalf, but responsibility for the notice stays with your firm.
Are you giving us legal advice?
No. We build and run the security side: the program, the controls, the procedures and the evidence. What counts as sensitive customer information, whether a notice is required, contract terms and how you deal with the SEC belong to your securities counsel. We are happy to work alongside them.
We also prepare tax returns. Can you cover that too?
Yes. If the tax side of your firm needs a written information security plan (WISP), much of the control work is shared, so we scope both together and build the shared controls once. See IT and WISP support for CPA firms.
Where are you based?
We are based in India and work remotely with US firms, with the time-zone overlap agreed in writing before we start. If our work gives us access to your customer information, we are one of your service providers under the rule, and we expect to go through the same due diligence and sign the same breach-notification terms as your other vendors.
What does it cost?
We scope it after a short call and quote a fixed price before we start. What moves the price: how much of the program already exists, how many service providers touch customer information, and how much you want us to do versus advise on.

Get your Regulation S-P program built and examination-ready.

A short scoping call, then a fixed-price proposal. Bring your securities counsel; we handle the security work.