Reg S-P Resource
The Reg S-P deadline passed. Your incident response program is now an exam item.
The SEC’s amended Regulation S-P now requires covered institutions to maintain written incident response procedures, customer-notification workflows, and service-provider oversight records. The question is no longer whether the deadline is coming. It is whether your firm can prove the program operates.
Last updated: August 2026
The short version
Reg S-P moved from privacy policy to operational proof.
Covered institutions already had to protect customer information through written safeguards. The 2024 amendments add a formal incident response program, customer notification no later than 30 days after awareness of qualifying unauthorized access, and service-provider notification obligations. Larger-entity and smaller-entity compliance dates have both passed.
Who is covered
RIAs, broker-dealers, investment companies, transfer agents
The SEC describes these as covered institutions. FINRA member firms also see Reg S-P through FINRA examinations and cybersecurity guidance.
What changed
Incident response is now explicit
The rule requires written procedures reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information.
What examiners test
Evidence, not intent
Firms need dated documents, control records, escalation evidence, vendor oversight, and customer-notification decision trails.
This is the baseline: written policies that protect customer information against unauthorized access or use. But a policy alone is not enough. Examiners can ask whether the controls named in the policy are actually deployed, monitored, reviewed, and updated.
The practical issue is operational: who detects the event, who determines whether customer information was involved, who starts the notification clock, who documents the decision, and who can show the record later.
The 30-day requirement turns incident documentation into a compliance requirement. A firm must be able to show when it became aware, what it knew, how it investigated, what it concluded, and when any required customer notice was sent.
If a third party touches customer information, the firm needs more than a vendor inventory. It needs contract language, monitoring, escalation paths, and evidence that a provider can notify the firm quickly enough for the firm to meet its own obligations.
Exam-ready checklist
What your firm should be ready to produce.
A Reg S-P exam request usually does not stop at “send us your policy.” The hard part is proving the policy matches what is actually happening in the environment.
| Area | Evidence an examiner may request |
|---|---|
| Governance | Approved safeguards policy, incident response program, owner list, review dates, board or senior-management reporting. |
| Customer information | Where customer information lives, which systems process it, who can access it, and which vendors touch it. |
| Access controls | MFA coverage, account reviews, joiner/mover/leaver records, privileged access restrictions, and exception handling. |
| Endpoint and device controls | Protection status across firm-owned devices, branch devices, and BYOD where applicable, including remediation records. |
| Data loss prevention | DLP configuration, encryption status, backup and recovery records, data disposal practices, and alert handling. |
| Incident response | Detection, escalation, containment, recovery, investigation, notification decisions, and post-incident review. |
| Service providers | Contracts, due diligence, 72-hour breach notification provisions, vendor contacts, and oversight review records. |
Broker-dealers, RIAs, insurance organizations, and branch networks often have customer information and endpoint risk distributed across field offices, advisors, agents, home-office systems, cloud applications, and third-party vendors. That makes Reg S-P less of a document project and more of an evidence-production problem.
FCI’s work is built around that gap: enforce controls across the distributed environment, document what happened, and make the record available when compliance, an examiner, or a cyber insurer asks for proof.
Reference
Source documents
| Source | Document | Date |
|---|---|---|
| SEC | Regulation S-P Amendments — Press Release 2024-58 | May 2024 |
| SEC | 17 CFR § 248.30 — Safeguards and Incident Response | Current |
| SEC | FY2026 Examination Priorities | Nov 2025 |
| FINRA | SEC Regulation S-P Compliance Date Reminder | Nov 2025 |
| FINRA | 2026 Annual Regulatory Oversight Report — Cybersecurity | Dec 2025 |
Find the gaps before an examiner does.
Start with the 16-question readiness assessment, or ask FCI to identify whether your safeguards, incident response workflow, service-provider oversight, and evidence records line up with what Reg S-P now requires.