NYDFS Part 500
Proven Identity. Nonpublic Information Protected.
Support NYDFS Part 500 cybersecurity requirements with phishing-resistant MFA
NYDFS Part 500 requires covered entities to run effective multi-factor authentication and protect nonpublic information. TokenCore™ delivers FIDO2-certified, hardware-bound authentication that proves the authorized person before access is granted.
No shared secret. No code to phish. No fallback.
The Rule
Written for Covered Entities.
Understanding NYDFS Part 500 cybersecurity requirements
NYDFS Part 500 sets cybersecurity obligations for financial institutions operating in New York, with authentication and the protection of nonpublic information at the center.
Overview of Part 500
A cybersecurity regulation for institutions under NYDFS supervision. Identity controls sit at its core.
Covered Entities
Banks, insurers, and financial services operating in New York fall in scope. The obligation is direct.
Protection of Nonpublic Information
Sensitive data has to be defended at the point of access. That point is identity.
Annual Compliance Certification
Covered entities certify their program each year. Evidence has to hold up.
Identity as a Critical Control
Strong identity strengthens the access controls required throughout Part 500.
The Requirement
MFA That Actually Holds.
What does NYDFS require for multi-factor authentication?
Part 500 names multi-factor authentication as a core control across remote and internal access. The intent is strong authentication that an attacker cannot bypass.
Section 500.12 Multi-Factor Authentication
Strong authentication across remote and internal access.
- Remote access requirements
- Internal network access
- Risk-based authentication
- Strong authentication controls
Why Authentication Is Central
Identity is where a cybersecurity program is won or lost.
- Access protection
- Identity verification
- Credential security
- Risk reduction

The Guide
Map Every Requirement.
Download the NYDFS Part 500 Requirements Mapping Guide
The mapping guide shows how phishing-resistant authentication aligns with NYDFS cybersecurity requirements, section by section. A practical resource for teams building toward compliance.
The Support
One Standard. Every Control.
How TokenCore™ supports NYDFS cybersecurity controls
Privileged Access Security (500.7)
Privilege bound to a verified individual, and revoked cleanly.
- Access privileges
- Identity assurance
- Revocation controls
Phishing-Resistant MFA (500.12)
Possession and biometric proof, bound to the hardware.
- Possession factor
- Biometric factor
- Hardware-bound authentication
- FIDO2 security
Strong Cryptographic Protection (500.15)
Keys generated and held in a tamper-proof secure element.
- Secure elements
- Private key protection
- Strong encryption architecture
Monitoring and Auditability (500.14)
Every access event traceable to the person behind it.
- Authentication logging
- Identity telemetry
- Audit trails
Incident Response Readiness (500.16)
Close the credential path attackers rely on.
- Reducing credential-based attacks
- Ransomware prevention
- Account takeover reduction
Third-Party Security Controls (500.11)
External access held to the same proven standard.
- Contractors
- MSPs
- Vendor access
- External workforce security
Beyond Legacy MFA
The Code Is the Weakness.
Why financial institutions are moving beyond legacy MFA
Risks of OTP Authentication
A one-time code can be entered by anyone who intercepts it. A shared secret is a secret an attacker can hold too.
Push Fatigue Attacks
Approval prompts can be worn down until someone taps yes. TokenCore™ has nothing to approve and nothing to pressure.
AiTM and Reverse Proxy Phishing
Relay pages capture codes in real time and pass them through. There is no code to relay when the fingerprint stays on the device.
Why FIDO2 Delivers Stronger Protection
The credential is bound to the hardware and the person. Nothing to phish, nothing to reuse, nothing to send.
See It in Action
Make Identity Absolute
Strengthen identity security for NYDFS-regulated environments
See how TokenCore™ strengthens authentication controls, reduces identity-related cyber risk, and supports NYDFS cybersecurity requirements across your workforce and third parties.