Broker-dealers
Brokers and dealers, including funding portals, as identified in the adopting release. Notice-registered broker-dealers are separately defined at 17 CFR 248.30(d)(8) and their treatment is confirmed with your counsel during scoping.
The amended Regulation S-P requires covered institutions to maintain a written incident response program and, when sensitive customer information is or is reasonably likely to have been accessed without authorization, to notify each affected individual as soon as practicable and no later than 30 days after becoming aware. Both compliance dates have now passed. We assess your written program, your service-provider arrangements, and your notice mechanics against each element of the rule, and record what evidence you can actually produce today for each one.
For SEC-covered institutions as 17 CFR 248.30(d)(3) defines them. Readiness and advisory work. Not legal advice, not an audit, not a certification.
17 CFR 248.30(d)(3) defines covered institution as any broker or dealer, any investment company, and any investment adviser or transfer agent registered with the Commission or another appropriate regulatory agency as defined in section 3(a)(34)(B) of the Securities Exchange Act of 1934. The adopting release states the amendments reach brokers and dealers, investment companies, investment advisers registered with the Commission, funding portals, and registered transfer agents. That is the boundary of this lane.
Brokers and dealers, including funding portals, as identified in the adopting release. Notice-registered broker-dealers are separately defined at 17 CFR 248.30(d)(8) and their treatment is confirmed with your counsel during scoping.
Investment companies, which 17 CFR 248.30(d)(3) reaches without a registration qualifier — the adopting release is explicit that this is not limited to registered investment companies. For the tiered compliance date, net assets are measured together with other investment companies in the same group of related investment companies. Whether a specific fund or vehicle is an investment company is a legal determination for your counsel.
Investment advisers registered with the Commission. Assets under management determine whether the larger-entity or smaller-entity compliance date applied to you, not whether the rule applies at all.
Transfer agents registered with the Commission or another appropriate regulatory agency. The amendments extended the safeguards and disposal requirements to transfer agents, and 17 CFR 248.30(d)(5)(ii) gives them their own customer-information definition.
Any covered institution that lets a service provider receive, maintain, process, or access customer information. 17 CFR 248.30(a)(5) makes provider oversight and a 72-hour provider notice arrangement part of your own response program.
Firms that have worked one incident and discovered that identifying affected individuals, reconstructing what was reached, and a notice meeting the §248.30(a)(4)(iv) content elements took far longer than the rule allows.
This lane is not for you if: you are a bank, savings association, or credit union, whose GLBA safeguards obligations sit with a banking regulator or the NCUA rather than the Commission; you are a non-bank financial institution under FTC jurisdiction, in which case 16 CFR part 314 governs and the FTC Safeguards Rule readiness lane is the right route; you are an investment adviser that is not registered with the Commission, including a state-registered or exempt-reporting adviser, because 17 CFR 248.30(d)(3) is written around Commission or ARA registration; or you are an insurer, a CFTC-regulated entity, or an operating company with no securities registration. We do not claim Regulation S-P applies universally. Your registration status is a legal fact your counsel and compliance officer confirm, and we scope to what they confirm.
This page addresses 17 CFR 248.30 only. Regulation S-P's privacy-notice provisions in the rest of part 248 have their own scope and are outside this lane.
These are current obligations under 17 CFR 248.30. Both tiered compliance dates have passed. We do not overstate the rule's scope, and we quote it rather than paraphrase it where precision matters.
Written policies and procedures addressing administrative, technical, and physical safeguards, reasonably designed to ensure security and confidentiality of customer information, protect against anticipated threats, and protect against unauthorized access or use that could result in substantial harm or inconvenience.
The written policies must include a program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information, with procedures to assess the nature and scope of an incident and identify the systems and information types reached, contain and control the incident, and notify affected individuals.
Clear and conspicuous notice to each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, transmitted by a means designed to ensure actual notice in writing.
Notice as soon as practicable, but not later than 30 days after becoming aware that unauthorized access or use has occurred or is reasonably likely to have occurred. The rule provides a narrow delay path only where the United States Attorney General makes a national-security or public-safety determination and notifies the Commission in writing.
Notice is not required where the institution determines, after a reasonable investigation of the facts and circumstances, that the sensitive customer information has not been and is not reasonably likely to be used in a manner that would result in substantial harm or inconvenience. That determination has to be made and documented, not assumed.
Written policies and procedures reasonably designed to require oversight, including due diligence, of service providers, and to ensure providers protect customer information and notify you as soon as possible and no later than 72 hours after becoming aware of a breach resulting in unauthorized access to a customer information system they maintain.
Scope of the information itself matters. 17 CFR 248.30(d)(5) defines customer information to include nonpublic personal information about a customer of a financial institution held by you or on your behalf, and expressly reaches information about the customers of other financial institutions that has been provided to you. 17 CFR 248.30(d)(9) defines sensitive customer information and gives worked examples. If your inventory only covers your own direct customers, the rule is wider than your inventory.
The table scrolls horizontally on smaller screens. Keyboard users can focus the labeled table region and use horizontal navigation.
| Milestone | Citation | Date | Who it applied to |
|---|---|---|---|
| Final rule published | 89 FR 47688 (Release Nos. 34-100155; IA-6604; IC-35193) | June 3, 2024 | All covered institutions. The adopting release states the rule is effective August 2, 2024, with compliance dates discussed separately. |
| Larger-entity compliance date | Adopting release, 18-month compliance period from publication | December 3, 2025 | Investment companies with net assets of $1 billion or more together with other investment companies in the same group of related investment companies; registered investment advisers with $1.5 billion or more in assets under management; broker-dealers and transfer agents that are not small entities under the Securities Exchange Act for Regulatory Flexibility Act purposes. |
| Smaller-entity compliance date | Adopting release, 24-month compliance period from publication | June 3, 2026 | Every covered institution that does not meet the larger-entity standards above. |
This rule has phased compliance dates, and both phases have now passed. Nothing on this page relies on a proposed rule. Where a firm changed size category between 2024 and today, we record which date applied and why, rather than assuming the later one.
A structured factual worksheet recording which of your legal entities appear to engage the covered-institution definition at 17 CFR 248.30(d)(3), which compliance date would have applied to each on those facts, and what that means for the evidence you should already hold. It records facts and the rule text side by side for your chief compliance officer and counsel to reach the conclusion; it is not a legal opinion and does not state one.
Each element of §248.30(a)(3) and (a)(4) against your current written program, with the evidence produced, the gap, a severity rating, an accountable owner, and a target date.
Where customer information and sensitive customer information as §248.30(d)(5) and (d)(9) define them actually live, including information received from other financial institutions, and which systems would need to be reconstructed to identify affected individuals.
A documented path from awareness to notice: who declares awareness, how the reasonable investigation supporting a substantial-harm determination is conducted and recorded, who approves, and how the 30-day clock is tracked and evidenced.
Your providers that receive, maintain, process, or access customer information, whether a 72-hour breach-notice arrangement is actually in place with each, and the contract or policy language gap where it is not.
A content checklist mapped to the elements enumerated at §248.30(a)(4)(iv). It is a completeness aid, not a draft notice; the wording, legal review, and approval of any notice you send are your counsel's. Plus a prioritized remediation roadmap and an executive readout.
Typical timebox: 2 to 4 weeks after kickoff and timely evidence access. Multi-entity groups and firms with large provider estates are scoped separately. Fees are scoped after the diagnostic and confirmed in writing before work begins. Firms that also want the response mechanics exercised under time pressure pair this lane with incident response and ransomware readiness; firms that want the wider control picture pair it with the cybersecurity risk assessment. Where remediation implementation follows the readiness cycle, it is scoped separately in writing and may be delivered by a disclosed qualified specialist from DSE's expert network. DSE remains accountable for scope, quality, and integration.
We cite the regulation and the adopting release, not vendor explainers or blog summaries. These are the sources this page relies on.
We do not publish SEC enforcement counts, average penalty figures, or breach statistics for this rule. If a number cannot be traced to a primary source, it does not appear on this page.
This is a point-in-time readiness assessment of the systems, people, documentation, and evidence in the agreed scope. It is not legal advice, not an audit, not a certification, not an attestation, and not a regulatory examination. It does not guarantee compliance, an enforcement or examination outcome, insurance coverage, a contract award, or eligibility for anything. It does not make your organization secure and does not prevent, detect, or reduce the likelihood of any security incident; it documents risk against a defined scope at a point in time. DSE does not operate a security operations center, does not provide continuous monitoring or managed detection and response, does not perform live incident response or digital forensics and incident response (DFIR), and does not run penetration tests. Where you need any of those, we help you scope the requirement and select a provider you contract directly. Remediation implementation is the one item on this list DSE will perform, and only where it is separately scoped in writing. DSE does not act as breach counsel. Whether an incident has occurred, whether the substantial-harm exception is available, whether notice is required, and what a notice says are determinations for your counsel and your chief compliance officer. Counsel, auditors, assessors, and carriers retain their respective roles. DSE does not make notification decisions on your behalf and does not communicate with the Commission for you.