Regulation S-P Compliance
Safeguards Rule Requirements for RIAs and Broker-Dealers
Regulation S-P is the SEC’s privacy and safeguards rule for registered investment advisers, broker-dealers, investment companies, and transfer agents. The Safeguards Rule is the part examiners test: written controls over customer information, a documented incident response program, vendor oversight, and a file that shows those controls operate.
Pylon Technology has supported RIAs and broker-dealers since 2008. This page covers the S-P program itself. For the wider exam framework see SEC & FINRA compliance for RIAs and broker-dealers. For adviser-specific operations see RIA cybersecurity.
2024–2026 Regulation S-P Amendments
The 2024 amendments require covered institutions to maintain a written incident response program for unauthorized access to customer information, to notify affected individuals, and to impose notification duties on service providers.
Compliance dates under those amendments
- Larger covered institutions: December 3, 2025
- Smaller RIAs and other smaller covered institutions: June 3, 2026
June 3, 2026 is the smaller-firm date in the adopted amendments — not a marketing window. Firms that have not finished the written program, vendor clauses, and evidence trail should treat the work as overdue, not optional.
Written Incident Response Program
The amendments require a written IR program, not an informal playbook. The program should state how the firm:
- Detects and assesses unauthorized access to customer information
- Contains the incident and documents decisions
- Determines whose information was, or is reasonably likely to have been, accessed
- Notifies customers and regulators on the clocks below
- Preserves logs and workpapers for the exam file
We draft and operationalize the IRP so it matches the WISP, the vendor inventory, and how the dual SOC in Southport, CT and Greenville, SC actually escalates alerts.
30-Day Customer Notification
Covered institutions must notify affected individuals as soon as practicable, and no later than 30 days after becoming aware that unauthorized access to customer information has occurred or is reasonably likely to have occurred.
The 30-day clock is an outer bound, not a target. The program needs:
- A decision record (what was accessed, who is affected, who approved notice)
- Notice content and delivery method
- Coordination with counsel and the CCO
- A copy of what was sent, filed with the incident workpapers
72-Hour Vendor Notification Clock
Service providers that maintain, process, or otherwise are permitted access to customer information must notify the covered institution as soon as possible, but no later than 72 hours after becoming aware of a breach in their (or a sub-processor’s) environment.
That clock only works if contracts and diligence say so. We help you:
- Inventory vendors that touch customer information
- Confirm the 72-hour notice obligation is in the agreement or addendum
- Record how notice would reach the firm after hours
- Tabletop the path from vendor email to your IRP
Vendor Oversight
Regulation S-P expects oversight, not a one-time questionnaire. For each in-scope vendor, keep:
- What customer information they hold or can access
- Diligence and SOC/attestation files you actually reviewed
- Contractual notification and use limitations
- Last review date and next review trigger
- Offboarding and data-return notes
This is the same vendor inventory used on RIA cybersecurity and in SEC exam document requests.
Evidence Trail
Examiners follow paper. A Regulation S-P file typically includes:
- Written IR program and last annual review
- WISP sections that implement the Safeguards Rule
- Customer notification procedures and any notices issued
- Vendor inventory, contracts, and 72-hour clauses
- MFA and access evidence for systems that store customer information
- Dual-SOC / incident tickets that show the program runs
We collect that trail during normal operations so it is not assembled the week of the exam.
Who This Page Is For
- Registered investment advisers (including smaller RIAs under the June 3, 2026 date)
- Broker-dealers and dual-registered firms
- Firms already mapping S-P to SEC & FINRA books-and-records work
Review Your Regulation S-P Program
Schedule a consultation to walk through the written IR program, notification clocks, and vendor file.
Call: (203) 930-3410 Email: info@pylontechnology.com
Frequently Asked Questions
Who does Regulation S-P apply to?
Regulation S-P is the SEC's privacy and safeguards rule for registered investment advisers, broker-dealers, investment companies, and transfer agents. The Safeguards Rule is the part examiners test: written controls over customer information, a documented incident response program, vendor oversight, and a file that shows those controls operate.
When do the 2024 Regulation S-P amendments take effect?
The compliance date for larger covered institutions was December 3, 2025. Smaller registered investment advisers and other smaller covered institutions have a compliance date of June 3, 2026. Firms that have not finished the written incident response program, the vendor notification clauses, and the evidence trail should treat that work as overdue rather than optional.
What is the 30-day customer notification requirement under Regulation S-P?
Covered institutions must notify affected individuals as soon as practicable, and no later than 30 days after becoming aware that unauthorized access to customer information has occurred or is reasonably likely to have occurred. The 30 days is an outer bound rather than a target, and the program needs a decision record of what was accessed and who approved notice, the notice content and delivery method, coordination with counsel and the CCO, and a copy of what was sent filed with the incident workpapers.
What is the 72-hour vendor notification clock under Regulation S-P?
Service providers that maintain, process, or are otherwise permitted access to customer information must notify the covered institution as soon as possible, and no later than 72 hours after becoming aware of a breach in their own or a sub-processor's environment. That clock only works if the obligation is written into the agreement or an addendum, the firm knows how after-hours notice would reach it, and the path from a vendor email to the firm's incident response plan has been tested.
What has to be in the written incident response program?
The amendments require a written program rather than an informal playbook. It should state how the firm detects and assesses unauthorized access to customer information, contains the incident and documents decisions, determines whose information was or is reasonably likely to have been accessed, notifies customers and regulators on the required clocks, and preserves logs and workpapers for the exam file.
What does an examiner expect to see in a Regulation S-P file?
A Regulation S-P file typically includes the written incident response program and its last annual review, the WISP sections that implement the Safeguards Rule, customer notification procedures and any notices issued, the vendor inventory with contracts and 72-hour clauses, MFA and access evidence for systems that store customer information, and incident tickets that show the program actually runs.