The SEC's amendments to Regulation S-P are no longer a future deadline sitting on a compliance calendar — they're a current-year exam item. The SEC adopted the amendments in May 2024, and the compliance dates have already passed for most firms: larger entities were required to have an incident response program in place by December 3, 2025, and smaller entities followed on June 3, 2026. If your firm falls under either deadline, examiners aren't asking whether you're planning to build a program anymore. They're asking to see it.

Reg S-P applies broadly — registered investment advisers, investment companies, broker-dealers (including funding portals), and transfer agents are all covered. The amendments layer a formal incident response requirement on top of the existing Safeguards Rule, and the details matter more than firms often expect.

What the rule actually requires

At the center of the amendment is a written incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. That's a specific, documented program — not a general cybersecurity policy with a paragraph about breaches tacked on.

The practical challenge for most mid-sized broker-dealers and RIAs isn't disagreeing with the intent — it's operationalizing it. A written policy that hasn't been tested against a realistic incident scenario tends to fall apart exactly when it's needed, and that gap is precisely what examiners are trained to probe for during a cycle exam.

How Compliers Can Help

Our team builds and stress-tests incident response programs against your firm's actual vendor stack and account structure — not a generic template — and layers oversight in alongside whatever systems you already run. See how our Code of Ethics & Oversight engagement approaches this.

Where firms tend to fall short

In our experience working alongside broker-dealer and RIA compliance teams, three gaps show up more than any other: the 30-day notification clock isn't tied to a clear internal escalation path, vendor contracts don't specify reporting timelines that would let a firm actually hit that 30-day window, and the incident response program was written once and never run through a tabletop exercise.

None of these are difficult to fix on their own. The difficulty is usually finding the time to work through them methodically while everything else on the compliance calendar keeps moving.

This article summarizes SEC Regulation S-P amendments (Release No. 34-100155, adopted May 2024) and is provided for general informational purposes. It is not legal advice. Firms should confirm their specific compliance obligations and deadlines with counsel.