If you run security or compliance at a company licensed by New York's Department of Financial Services, penetration testing is not a best practice you can defer. It is written into the regulation, and a DFS examiner will ask for the evidence.
Most of a strong cybersecurity program runs quietly in the background. This article covers the one part the regulation makes explicit and examiners probe hardest, the penetration testing and vulnerability management obligations under Section 500.5, and exactly what you have to produce to satisfy them.
What CodeAnt AI solves here: CodeAnt AI is a defensive and offensive security platform that runs continuous, code-aware testing across your applications, APIs, cloud, and external surface. It covers the inside-and-outside testing 500.5 calls for and produces the evidence a DFS certification needs.
What 23 NYCRR 500 Requires For Penetration Testing
The obligation lives in Section 500.5, titled Vulnerability management. It requires each covered entity to develop written policies that keep the cybersecurity program effective, and it names three concrete actions.
The first is the pentest itself. Covered entities must conduct penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually.
The second is scanning. The regulation requires automated scans of information systems, and a manual review of systems not covered by such scans, for the purpose of discovering, analyzing and reporting vulnerabilities at a frequency determined by the risk assessment, and promptly after any material system changes.
The third is remediation. Entities must be promptly informed of new vulnerabilities through a monitoring process, and must timely remediate vulnerabilities, giving priority to vulnerabilities based on the risk they pose to the covered entity.
Read together, these are not a one-time event. The annual pentest is the floor, the scans run on a risk-based cadence and after every material change, and remediation is continuous.
How NYDFS Defines Penetration Testing Under 23 NYCRR 500
The definition matters, because it rules out a plain vulnerability scan dressed up as a pentest. Section 500.1(l) defines penetration testing as testing the security of information systems by attempting to circumvent or defeat the security features of an information system by authorizing attempted penetration of databases or controls from outside or inside the covered entity's information systems.
Two words carry weight. "Circumvent or defeat" means the test has to actually attempt exploitation, not just enumerate findings a scanner flagged. And the Second Amendment added "authorizing," clarifying that the covered entity must authorize the testing, which is the difference between a sanctioned assessment and an incident.
The phrase "from outside or inside" is the other half. A test that only probes the external perimeter satisfies part of the requirement, and misses the internal trust relationships where a contained breach becomes a data leak.
Who Is A Covered Entity Under NYDFS 23 NYCRR 500?
The scope is broad. A covered entity is any person operating under or required to operate under a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law.
For the insurance sector, that pulls in insurers, agencies, and licensed brokers. The regulation also makes clear this applies regardless of whether the covered entity is also regulated by other government agencies, so being subject to HIPAA or the NAIC model law does not take you out of scope.
Above a size threshold, more is required. A Class A company, defined as a covered entity with at least $20,000,000 in gross annual revenue in each of the last two fiscal years and either over 2,000 employees or over a billion dollars in revenue, faces added obligations like independent audits and privileged access management on top of the 500.5 baseline.
Which Entities Are Exempt From NYDFS Section 500.5?
Not every licensee has to run a pentest. Section 500.19(a) grants a limited exemption from 500.5 to the smallest entities.
An entity qualifies if it has fewer than 20 employees and independent contractors, less than $7,500,000 in gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets.
The catch is that this is a limited exemption, not a full pass. It lifts the 500.5 testing obligation, but the entity still owes other parts of the regulation, and it must file a Notice of Exemption with DFS within 30 days of determining it qualifies.
NYDFS Penetration Testing Vs Vulnerability Scanning Requirements
Section 500.5 asks for both, and treating them as interchangeable is the most common way to fall short. They differ in method, cadence, and what they prove.
Attribute | Penetration testing (500.5(a)(1)) | Vulnerability scanning (500.5(a)(2)) |
|---|---|---|
What it does | Attempts to circumvent or defeat controls | Discovers and reports known weaknesses |
Depth | Proves exploitability with a working path | Flags potential issues, no exploitation |
Cadence | At least annually | Risk-based frequency, plus after material changes |
Coverage | Inside and outside the boundary | Automated scans plus manual review of the rest |
Evidence value | Confirmed, prioritized findings | Breadth of coverage over time |
The takeaway is that a scan cannot substitute for the pentest, and the pentest does not replace continuous scanning. The regulation wants the depth of one and the breadth of the other.
What DFS Examiners Expect As NYDFS Penetration Testing Evidence
Compliance is proven through documentation, and 500.5 feeds directly into the annual certification. Under Section 500.17(b), each covered entity must submit, by April 15, a certification of material compliance for the prior calendar year.
That certification carries personal weight. It must be signed by the covered entity's highest-ranking executive and its CISO, which puts named individuals on record attesting that testing was done and findings were addressed.
Behind the signature sits the paper trail. Entities must maintain all records, schedules and other documentation and data supporting the certification for five years, including which systems required improvement and the remediation timelines. In practice, a pentest report that ships with a proof of exploit, a risk rating, and a retest confirming the fix is the artifact that survives examination.
Why Annual NYDFS Penetration Testing Leaves A Gap For Fast-Moving Insurers
The annual pentest is a snapshot, and insurers no longer operate at a pace a single yearly snapshot can capture. A modern insurer or insurtech ships changes to broker portals, claims systems, and APIs continuously, and every release can introduce a new exposure.
The regulation itself acknowledges this. The scanning requirement is not just periodic, it must run promptly after any material system changes, and the risk assessment must be updated whenever a change in the business or technology causes a material change to the covered entity's cyber risk.
Meeting that with a once-a-year engagement plus occasional scans is a stretch. Continuous testing, where the system re-examines the surface on every change and keeps a live record of findings and fixes, is what closes the window between the annual test and the next material release. It also happens to produce exactly the year-round evidence trail the April certification asks for.
How CodeAnt AI Supports NYDFS Penetration Testing And Evidence
CodeAnt runs the inside-and-outside testing that 500.5 describes as one continuous system rather than a yearly project. From the outside it maps the external surface, exposed services, and reachable data the way an adversary would. From the inside it reads the code, internal APIs, and cloud configuration to find the trust relationships an external scan cannot see.
Because it is code-aware, it addresses the application security obligation in Section 500.8 in the same pass, testing in-house applications as they are built. Findings arrive with a working proof of exploit, a risk priority, and a retest, which maps to the remediation and documentation 500.5 and 500.17 expect.
The result is a program that stays current between annual tests and generates the certification-ready evidence as a byproduct. You can see the offensive side on the pentesting page, and for the broader picture of what regulators accept, our guide to compliance penetration testing covers SOC 2, PCI, and HIPAA alongside it.
Conclusion: Build Continuous Evidence For NYDFS Penetration Testing
Section 500.5 is short, but it is exacting. It wants a real pentest that attempts exploitation from both sides of your boundary at least annually, scans that run after every material change, remediation prioritized by risk, and a five-year paper trail that two named executives will sign against.
The insurers who find April painless are the ones testing continuously, not scrambling to reconstruct a year of evidence the week before the certification is due.
That is the model CodeAnt runs. Launch a free black box scan for one URL to see what an adversary can reach from outside your boundary, then book a walkthrough to see continuous, inside-and-outside testing mapped to your DFS obligations. For the full compliance picture, read our guide to penetration testing for SOC 2, PCI, and HIPAA.


