What happened

The SEC's 2024 amendments to Regulation S-P are now fully in effect, with both compliance deadlines behind us. Larger covered entities had to comply by December 3, 2025, and smaller ones by June 3, 2026. The rule applies to broker-dealers, investment companies, SEC-registered investment advisers, funding portals, and transfer agents registered with the SEC or another appropriate regulator.

The amendments, adopted on May 16, 2024, modernised a framework that had been largely unchanged since 2000. Their headline requirements fall into four groups. Firms must maintain a written incident response program reasonably designed to detect, respond to and recover from unauthorised access to customer information. They must notify affected individuals as soon as practicable and no later than 30 days after becoming aware of an incident, describing the incident, the data involved, and the steps people can take to protect themselves.

The other two requirements carry the operational weight. Firms must maintain policies that require service providers handling customer information to notify them no later than 72 hours after becoming aware of a breach. And the ultimate responsibility for customer notification rests with the firm even where a written agreement delegates that task to a vendor. The amendments also extend safeguarding and disposal obligations.

According to the SEC Division of Examinations Fiscal Year 2026 Examination Priorities, the division will examine whether firms have developed, implemented and maintained policies and procedures for the administrative, technical and physical safeguards required by the rule.

Why this is a GRC story

This is the transition every compliance program eventually faces: from a project that had a deadline to a control that has to work. Rules with a fixed compliance date let organisations treat readiness as a deliverable. Once the date passes, the only question left is evidence.

The vendor clause is where I would expect the first real friction. A 72 hour notification obligation is a contractual term before it is a control, and many existing agreements will not contain it. Where they do not, the firm still carries the notification duty. That gap belongs on a third-party risk register with a named owner and a remediation date, not in a folder of signed agreements nobody has reread since renewal.

The 30 day customer notification clock also forces a conversation about detection quality. A clock that starts when you become aware is generous if you detect quickly and unforgiving if you find out months later from someone else. Firms that cannot reconstruct when they knew, and what they knew, will struggle to defend the timeline.

What to watch

Watch the first examination findings in this area, because they will show how far examiners go past the policy document. Expect requests for incident logs, vendor contract clauses, escalation records and evidence that a tabletop exercise actually changed something.

Watch for amendments to standard vendor terms as firms try to backfill the 72 hour requirement at renewal. And watch whether the notification timeline becomes a recurring theme in enforcement, since date arithmetic is easy for a regulator to test and hard for a firm to argue around.

For compliance and security leads at covered firms, the near term test is concrete. Can you produce, today, the clause in each material vendor contract that obliges notification within 72 hours, and the record showing you would know if one of those vendors had an incident?

Attribution: Analysis based on JD Supra and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News