The amended Regulation S-P requires SEC-registered investment advisers, broker-dealers and other covered institutions to have a written incident response program, notify affected customers within 30 days of becoming aware of unauthorized access to sensitive customer information, and oversee the service providers that handle that information. Larger firms had to comply by December 3, 2025, and smaller firms by June 3, 2026.
Regulation S-P has applied to advisers and broker-dealers for more than two decades, but for most of that time its safeguards requirement was a few sentences long. The SEC's May 2024 amendments turned it into a specific set of obligations with deadlines, documentation and customer-facing consequences. This article walks through what changed, who is covered, and what a firm should be able to show an examiner today.
Regulation S-P is the SEC's privacy rule for the financial firms it regulates, codified at 17 CFR Part 248, Subpart A. It implements the privacy provisions of the Gramm-Leach-Bliley Act (GLBA) for SEC registrants. It has three main parts:
For a broader picture of who regulates whom, see SEC and FINRA: who regulates financial firms.
The amended rule applies to:
State-registered advisers are not covered by Regulation S-P, though state rules and the FTC Safeguards Rule may apply to them. The amendments also widened the definition of "customer information" so that it includes information a firm receives about customers of other financial institutions, not only its own clients.
Every covered institution must now have written policies and procedures for an incident response program reasonably designed to detect, respond to and recover from unauthorized access to or use of customer information. The program has to address three things:
A plan that lives only in someone's head does not meet this standard. It needs to be written, assigned to named roles, and practiced. Our guide to a cybersecurity incident response plan covers the general structure.
When sensitive customer information has been, or is reasonably likely to have been, accessed or used without authorization, the firm must notify affected individuals as soon as practicable, and no later than 30 days after becoming aware that the unauthorized access occurred or is reasonably likely to have occurred.
"Sensitive customer information" is a defined subset of customer information: information that, if compromised, could create a reasonably likely risk of substantial harm or inconvenience to the individual. Examples include Social Security numbers, account numbers combined with access codes or passwords, and other identifying information that could be used to open or access an account.
The notice must be clear and conspicuous and must describe, in general terms, what happened, what type of information was involved, the date or estimated date of the incident, contact information for questions, and steps the customer can take to protect themselves.
A firm does not have to notify if, after a reasonable investigation of the facts and circumstances, it determines that the sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience. That determination must be documented. There is also a limited delay provision when the U.S. Attorney General informs the SEC in writing that notice poses a substantial risk to national security or public safety. In practice, a firm should assume notification is required unless its investigation clearly supports the exception, and the logs and records to support that investigation have to exist before the incident happens.
Your custodian, CRM, portfolio platform, archiving vendor, cloud email and IT provider may all hold or access customer information. The amended rule requires written policies and procedures for overseeing these service providers, including due diligence and monitoring, reasonably designed to ensure that each provider:
A firm may arrange for a service provider to send customer notices on its behalf, but the obligation to make sure notice happens stays with the firm. The rule frames this through the firm's policies and procedures, so expect an examiner to ask how you know each vendor's notification commitment and how you track it.
The disposal rule now covers customer information as well as consumer information, and its reach was extended to transfer agents registered with other regulatory agencies. Firms need written procedures for disposing of this information securely, which in practice covers retired laptops and phones, copier and scanner drives, decommissioned servers, cloud accounts for departed staff, and paper records.
The amendments also require covered institutions to keep written records documenting compliance with the safeguards and disposal rules. That includes the incident response program, the assessment of each incident, any determination that notice was not required, and service provider oversight. These records are kept under each registrant's existing recordkeeping rule: Advisers Act Rule 204-2 for advisers, Exchange Act Rule 17a-4 for broker-dealers, and Investment Company Act Rule 31a-1 for funds.
The amendments codified a statutory exception to the annual privacy notice. A firm does not have to deliver an annual notice if it only shares nonpublic personal information under exceptions that do not require an opt-out, and it has not changed its privacy policies and practices since its most recent notice. If either condition changes, the annual notice requirement returns.
Both dates have passed. If your firm has not finished putting these pieces in place, treat it as a current gap rather than an upcoming project.
NerdSquad Managed IT Services, a Managed Service Provider (MSP) based in Naples, Florida, works with advisory firms and broker-dealers on the technology side of Regulation S-P. Your compliance officer owns the program. We help put the controls, documentation and evidence in place:
More detail on the wider rule set is in SEC, FINRA and GLBA requirements for financial firms, and our approach to IT support for financial services firms is on our main site.
NerdSquad is not a law firm. Confirm your firm's obligations with your compliance counsel.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.