The compliance deadline for the amended Regulation S-P arrives today for larger entities regulated by the US Securities and Exchange Commission.
Key points
- Covered institutions must maintain a written incident response programme to detect, respond to and recover from unauthorised access to customer information.
- Affected individuals must be notified within 30 days of becoming aware of a breach of sensitive customer information.
- Service providers must be overseen and must notify the institution within 72 hours of a breach.
- Smaller entities must comply from 3 June 2026.
UK firms providing technology or services to US broker-dealers, investment advisers or funds should expect new contractual notification and oversight requirements.
Source: Regulation S-P amendments, Release No. 34-100155 (SEC)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.