Regulation S-P Compliance
Safeguards Rule Requirements for RIAs and Broker-Dealers
Regulation S-P is the SEC’s privacy and safeguards rule for registered investment advisers, broker-dealers, investment companies, and transfer agents. The Safeguards Rule is the part examiners test: written controls over customer information, a documented incident response program, vendor oversight, and a file that shows those controls operate.
Pylon Technology has supported RIAs and broker-dealers since 2008. This page covers the S-P program itself. For the wider exam framework see SEC & FINRA compliance for RIAs and broker-dealers. For adviser-specific operations see RIA cybersecurity.
2024–2026 Regulation S-P Amendments
The 2024 amendments require covered institutions to maintain a written incident response program for unauthorized access to customer information, to notify affected individuals, and to impose notification duties on service providers.
Compliance dates under those amendments
- Larger covered institutions: December 3, 2025
- Smaller RIAs and other smaller covered institutions: June 3, 2026
June 3, 2026 is the smaller-firm date in the adopted amendments — not a marketing window. Firms that have not finished the written program, vendor clauses, and evidence trail should treat the work as overdue, not optional.
Written Incident Response Program
The amendments require a written IR program, not an informal playbook. The program should state how the firm:
- Detects and assesses unauthorized access to customer information
- Contains the incident and documents decisions
- Determines whose information was, or is reasonably likely to have been, accessed
- Notifies customers and regulators on the clocks below
- Preserves logs and workpapers for the exam file
We draft and operationalize the IRP so it matches the WISP, the vendor inventory, and how the dual SOC in Southport, CT and Greenville, SC actually escalates alerts.
30-Day Customer Notification
Covered institutions must notify affected individuals as soon as practicable, and no later than 30 days after becoming aware that unauthorized access to customer information has occurred or is reasonably likely to have occurred.
The 30-day clock is an outer bound, not a target. The program needs:
- A decision record (what was accessed, who is affected, who approved notice)
- Notice content and delivery method
- Coordination with counsel and the CCO
- A copy of what was sent, filed with the incident workpapers
72-Hour Vendor Notification Clock
Service providers that maintain, process, or otherwise are permitted access to customer information must notify the covered institution as soon as possible, but no later than 72 hours after becoming aware of a breach in their (or a sub-processor’s) environment.
That clock only works if contracts and diligence say so. We help you:
- Inventory vendors that touch customer information
- Confirm the 72-hour notice obligation is in the agreement or addendum
- Record how notice would reach the firm after hours
- Tabletop the path from vendor email to your IRP
Vendor Oversight
Regulation S-P expects oversight, not a one-time questionnaire. For each in-scope vendor, keep:
- What customer information they hold or can access
- Diligence and SOC/attestation files you actually reviewed
- Contractual notification and use limitations
- Last review date and next review trigger
- Offboarding and data-return notes
This is the same vendor inventory used on RIA cybersecurity and in SEC exam document requests.
Evidence Trail
Examiners follow paper. A Regulation S-P file typically includes:
- Written IR program and last annual review
- WISP sections that implement the Safeguards Rule
- Customer notification procedures and any notices issued
- Vendor inventory, contracts, and 72-hour clauses
- MFA and access evidence for systems that store customer information
- Dual-SOC / incident tickets that show the program runs
We collect that trail during normal operations so it is not assembled the week of the exam.
Who This Page Is For
- Registered investment advisers (including smaller RIAs under the June 3, 2026 date)
- Broker-dealers and dual-registered firms
- Firms already mapping S-P to SEC & FINRA books-and-records work
Review Your Regulation S-P Program
Schedule a consultation to walk through the written IR program, notification clocks, and vendor file.
Call: (203) 930-3410 Email: [email protected]