Regulation S-P deadline passed: what do SEC examiners check now?

Summary

Smaller SEC-registered investment firms are now expected to demonstrate that their amended Regulation S-P programs work in practice, including tested incident response, timely customer notification, vendor oversight, and governance of AI-related data risks. Magna5 can support cybersecurity monitoring, incident-response readiness, vendor-risk assessment, and compliance-readiness efforts, while legal and regulatory determinations remain with qualified counsel.
Table of Contents

Smaller registered investment advisers, broker-dealers, and funds had to comply with amended Regulation S-P by June 3, 2026. That deadline did not end the obligation. The SEC has named Regulation S-P an examination priority for fiscal year 2026, meaning examiners now test whether a firm’s incident response program, breach notification process, and vendor oversight are operational, not just filed paperwork.

Last updated September 24, 2026.

Who the deadline applied to, and why passing it changes nothing.

Regulation S-P’s amended cybersecurity requirements apply to broker-dealers, registered investment advisers, investment companies, funding portals, and transfer agents registered with the SEC. Larger entities, meaning RIAs with at least $1.5 billion in assets under management and funds with at least $1 billion in net assets, had to comply by December 3, 2025. Smaller entities had until June 3, 2026.

That deadline was a filing checkpoint, not a finish line. The SEC identified compliance with the 2024 amendments to Regulation S-P as an examination focus for fiscal year 2026. Its published priorities state that, after the applicable compliance dates, examinations will assess whether firms have developed, implemented, and maintained policies and procedures addressing the rule’s new safeguards.

A written plan that has never been tested, a vendor list that has never been reviewed, or a notification process nobody on staff can execute inside 30 days may not hold up in an exam. For a firm with a two-person IT team, that gap is the entire risk.

Regulation S-P requires three things of every covered institution:

  • A written incident response program designed to detect, respond to, and recover from unauthorized access to or use of customer information.
  • Notification to affected individuals within 30 days of determining that a breach of sensitive customer information occurred.
  • Documented oversight of every service provider with access to customer information, including a 72-hour breach notification commitment from each vendor.
 

Larger entities

Smaller entities

Registered investment advisers

$1.5 billion or more in assets under management

Under $1.5 billion in assets under management

Funds

$1 billion or more in net assets

Under $1 billion in net assets

Compliance deadline

December 3, 2025

June 3, 2026

What counts as sensitive customer information?

The rule defines sensitive customer information broadly: any component of customer information that, alone or combined with other information, could create a reasonably likely risk of substantial harm or inconvenience if compromised. That standard is wider than most state breach laws, which typically list specific categories such as Social Security numbers or account credentials. For an investment firm, portfolio holdings, account balances, and identifying details combined together can trigger the notification requirement even when no single data point looks sensitive by itself.

What does the vendor oversight requirement actually demand?

Third-party exposure remains a growing concern. Verizon’s 2026 Data Breach Investigations Report found that 48% of breaches involved a third party, up from 30% in the prior year’s dataset—a 60% increase. Regulation S-P’s vendor oversight requirement targets that exact exposure. Covered institutions must maintain due diligence and ongoing monitoring of every service provider with access to customer information, and the SEC’s adopting release points to a contractual 72-hour breach notification clause as the practical way to enforce it. A fund administrator, portfolio management system provider, or cloud host needs a documented review cycle and a signed notice clause, not an annual check-in.

How does the AI governance gap add to exam risk?

AI-related cyber risk is becoming more material for regulated firms. IBM’s 2026 Cost of a Data Breach Report found that one in four malicious breaches was AI-enabled—a 56% increase from the prior year—and that these breaches cost an average of $6 million. Verizon’s 2026 DBIR also found that employee use of unapproved “shadow AI” rose from 15% to 45%, increasing the risk of data leakage through unapproved tools. Unsanctioned use of AI tools, often called shadow AI, was a contributing factor in 20% of breaches studied and added an average of $670,000 to the cost of those incidents. Investment firms are adopting AI in trading, research, and compliance workflows faster than they are governing it. An analyst who uploads deal data or limited partner information into an ungoverned AI tool creates exposure that falls inside Regulation S-P’s incident response and vendor oversight scope, whether or not anyone intended it to.

That exposure compounds an already difficult year. Financial services reported more confirmed data breaches than any other sector in 2025, at 739 incidents, according to the Identity Theft Resource Center. IBM’s 2026 research reports that financial-services breaches cost an average of $6.3 million.

What should a lean IT team verify in the next 90 days?

A firm with a small internal IT team does not need to rebuild its program from scratch. It does need to confirm four things work in practice, not only on paper:

  • The incident response plan has been tested against a realistic scenario in the last 12 months.
  • Every vendor with access to customer information has a signed 72-hour breach notification clause.
  • Someone on staff can execute the 30-day customer notification process without outside help.
  • AI tools in use across trading, research, or compliance workflows are inventoried and approved, not adopted ad hoc.

Any one of these that cannot be verified today may represent a gap an SEC examiner could identify.

How Magna5 helps investment firms close the gap between paperwork and practice.

Magna5 supports regulated, uptime-dependent organizations with cybersecurity, governance, and compliance-readiness services tailored to the client’s environment and engagement scope.

Building and testing an incident response program—including tabletop exercises that help teams practice their roles—can be part of Magna5’s vCISO services. Magna5 vCISO engagements can also support security governance, risk assessments, policy management, executive reporting, and incident-response planning.

Magna5 Managed SIEM and 24/7/365 SOC services provide continuous monitoring, triage, investigation, and response support for in-scope identities, endpoints, cloud services, networks, and log sources. These services can help organizations improve visibility into security events and support response activities under agreed-upon playbooks.

Magna5 can also support security documentation, gap assessment, vendor-risk assessment, incident-response planning, and evidence-oriented reporting as part of a scoped compliance-readiness engagement.

If your firm filed a Regulation S-P program by the June 2026 deadline and has not tested it against a real scenario, it may be time to validate that the program works in practice. Talk to Magna5 about a cybersecurity and compliance-readiness assessment tailored to your environment.

Important: Magna5 provides cybersecurity, governance, and compliance-readiness support. Magna5 does not provide legal advice, legal interpretations of Regulation S-P, or legal breach-notification determinations. Firms should consult qualified legal and compliance counsel regarding their specific regulatory obligations.

FAQs about cybersecurity for Regulation S-P.

Q: Did the Regulation S-P deadline for smaller investment advisers already pass?

A: Yes. Smaller entities, meaning RIAs under $1.5 billion in assets under management and funds under $1 billion in net assets, had to comply by June 3, 2026. Larger entities complied five months earlier, by December 3, 2025.

Q: Is Regulation S-P compliance still a risk if my firm filed by the deadline?

A: Yes. The SEC identified compliance with the 2024 amendments to Regulation S-P as an examination focus for fiscal year 2026. After the applicable compliance dates, its examination priorities state that examinations will assess whether firms have developed, implemented, and maintained policies and procedures addressing the rule’s new safeguards.

Q: What happens if a service provider cannot meet the 72-hour breach notification requirement?

A: Regulation S-P places the compliance obligation on the covered institution, not the vendor. If a vendor cannot meet the 72-hour notice standard, the exposure sits with the investment firm, which is why the SEC’s adopting release points to a contractual notice clause as the practical way to enforce it.

Q: How does AI use inside an investment firm affect Regulation S-P compliance?

A: Verizon’s 2026 Data Breach Investigations Report found that employee use of unapproved “shadow AI” tripled to 45%, increasing the potential for sensitive data to be exposed through unapproved tools. If an employee uploads customer or limited partner information into an ungoverned AI tool and that data is exposed, it may fall under the same incident response and notification obligations as any other breach of customer information.

Q: Can Magna5 help us meet every Regulation S-P requirement?

A: Magna5 can support cybersecurity operations, incident-response readiness, security governance, risk assessment, vendor-risk assessment, and compliance-readiness activities based on the agreed engagement scope. Legal interpretation of Regulation S-P, vendor-contract requirements, and customer-notification obligations should be handled with qualified legal and compliance counsel.

Bristol, Pennsylvania

1414 Radcliffe St, Suite #100A,
Bristol, PA 19007
/

Atlanta, Georgia

5000 Research Court Suite 750,
Johns Creek, GA 30024
/

Boston, Massachusetts

945 Concord St, Suite 127
Framingham, MA 01701
/

Charlotte, North Carolina

10811 Pineville Rd, Suite 12,
Pineville, NC 28134
/

Charlottesville, Virginia

355 Rio Rd W, Suite 201,
Charlottesville, VA 22901​
/

Mobile, Alabama

2866 Dauphin Street, Suite S,
Mobile, AL 36606
/

New York, New York

903 Montauk Hwy, Unit C, PMB 7018,
Copiague, NY 11726
/

Philadelphia, Pennsylvania

1730 Walton Rd, Suite 307,
Blue Bell, PA 19422
/

Pittsburgh, Pennsylvania

1000 Noble Energy Dr, Suite 290,
Canonsburg, PA 15317
/

Phoenix, Arizona

890 W. Elliot Rd, Suite 110,
Gilbert, AZ 85233
/