Reg S-P Resource

The Reg S-P deadline passed. Your incident response program is now an exam item.

The SEC’s amended Regulation S-P now requires covered institutions to maintain written incident response procedures, customer-notification workflows, and service-provider oversight records. The question is no longer whether the deadline is coming. It is whether your firm can prove the program operates.

Last updated: August 2026

The short version

Reg S-P moved from privacy policy to operational proof.

Covered institutions already had to protect customer information through written safeguards. The 2024 amendments add a formal incident response program, customer notification no later than 30 days after awareness of qualifying unauthorized access, and service-provider notification obligations. Larger-entity and smaller-entity compliance dates have both passed.

Who is covered

RIAs, broker-dealers, investment companies, transfer agents

The SEC describes these as covered institutions. FINRA member firms also see Reg S-P through FINRA examinations and cybersecurity guidance.

What changed

Incident response is now explicit

The rule requires written procedures reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information.

What examiners test

Evidence, not intent

Firms need dated documents, control records, escalation evidence, vendor oversight, and customer-notification decision trails.

What Reg S-P requires now
17 CFR § 248.30 — Safeguards Rule
Written safeguards are still the foundation.
“Every covered institution must develop, implement, and maintain written policies and procedures that address administrative, technical, and physical safeguards for the protection of customer information.” — 17 CFR § 248.30(a)(1)

This is the baseline: written policies that protect customer information against unauthorized access or use. But a policy alone is not enough. Examiners can ask whether the controls named in the policy are actually deployed, monitored, reviewed, and updated.

Evidence to prepare: the current written safeguards policy, access-control records, encryption or disposal controls, endpoint coverage, data-loss-prevention settings, approval history, and evidence that controls are operating across the firm.
2024 amendments — Incident response
The response program must be written, maintained, and usable.
“The amendments require covered institutions to develop, implement, and maintain written policies and procedures for an incident response program that is reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information.” — SEC Press Release 2024-58

The practical issue is operational: who detects the event, who determines whether customer information was involved, who starts the notification clock, who documents the decision, and who can show the record later.

Evidence to prepare: the written incident response program, incident intake and escalation workflow, containment records, recovery procedures, tabletop or test evidence, roles and responsibilities, and documentation of prior events or false alarms.
30-day customer notification
The clock starts when the firm becomes aware.
“A covered institution must provide the notice as soon as practicable, but not later than 30 days, after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred.” — 17 CFR § 248.30(a)(4)(iii)

The 30-day requirement turns incident documentation into a compliance requirement. A firm must be able to show when it became aware, what it knew, how it investigated, what it concluded, and when any required customer notice was sent.

Evidence to prepare: awareness timestamp, investigation notes, customer-information impact analysis, notification decision memo, notification template, delivery record, exception rationale if notice was not required, and board or management reporting where applicable.
Service providers — 72-hour notification expectation
Vendor oversight now has an incident-response timer.
“Provide notification to the covered institution as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the service provider.” — 17 CFR § 248.30(a)(5)

If a third party touches customer information, the firm needs more than a vendor inventory. It needs contract language, monitoring, escalation paths, and evidence that a provider can notify the firm quickly enough for the firm to meet its own obligations.

Evidence to prepare: vendor list, customer-information-system mapping, contract or addendum language, due-diligence reviews, security questionnaires, breach-notification contacts, and records showing vendor oversight is maintained.

Exam-ready checklist

What your firm should be ready to produce.

A Reg S-P exam request usually does not stop at “send us your policy.” The hard part is proving the policy matches what is actually happening in the environment.

AreaEvidence an examiner may request
GovernanceApproved safeguards policy, incident response program, owner list, review dates, board or senior-management reporting.
Customer informationWhere customer information lives, which systems process it, who can access it, and which vendors touch it.
Access controlsMFA coverage, account reviews, joiner/mover/leaver records, privileged access restrictions, and exception handling.
Endpoint and device controlsProtection status across firm-owned devices, branch devices, and BYOD where applicable, including remediation records.
Data loss preventionDLP configuration, encryption status, backup and recovery records, data disposal practices, and alert handling.
Incident responseDetection, escalation, containment, recovery, investigation, notification decisions, and post-incident review.
Service providersContracts, due diligence, 72-hour breach notification provisions, vendor contacts, and oversight review records.
Why this is difficult for distributed firms
The policy is central. The evidence is scattered.

Broker-dealers, RIAs, insurance organizations, and branch networks often have customer information and endpoint risk distributed across field offices, advisors, agents, home-office systems, cloud applications, and third-party vendors. That makes Reg S-P less of a document project and more of an evidence-production problem.

FCI’s work is built around that gap: enforce controls across the distributed environment, document what happened, and make the record available when compliance, an examiner, or a cyber insurer asks for proof.

The operating question: if an examiner asked for Reg S-P evidence tomorrow, could your firm produce the current policy, the active controls, the incident workflow, and the vendor notification trail by the end of the day?

Find the gaps before an examiner does.

Start with the 16-question readiness assessment, or ask FCI to identify whether your safeguards, incident response workflow, service-provider oversight, and evidence records line up with what Reg S-P now requires.