3 min read

Amendments to SEC Regulation S-P Took Effect for Smaller Entities on June 3, 2026

Amendments to SEC Regulation S-P Took Effect for Smaller Entities on June 3, 2026

Smaller broker-dealers, registered investment advisers, investment companies, funding portals, and transfer agents now operate under a new set of data protection obligations. The compliance date for the 2024 amendments to Regulation S-P arrived for these firms on June 3, 2026, six months after the same requirements took hold for larger entities on December 3, 2025. Firms that put off preparation now face active exposure to both a data breach and an SEC examiner asking to see the paperwork.

What the Regulation S-P Amendments Changed

The Securities and Exchange Commission adopted the amendments to Regulation S-P in May 2024, the first substantial update to the rule in over two decades. Regulation S-P governs how covered institutions handle nonpublic personal information about consumers, and the original rule dated back to 2000, when data breaches looked nothing like they do now. The SEC built a staggered rollout into the final rule: entities that qualify as "larger" under the rule's asset thresholds, generally funds with $1 billion or more in net assets, advisers managing $1.5 billion or more, and broker-dealers with total capital of $500,000 or more, had to comply by December 3, 2025. Every other covered institution, the "smaller entities" that make up the bulk of SEC-registered firms, had until June 3, 2026.

That second date has now passed. Firms in this category are not in a transition period or a grace window. They are expected to have the required program built, tested, and documented.

Four Regulation S-P Obligations Every Firm Now Carries

The amendments center on what happens when customer data is exposed, not just how it gets protected on the front end. A covered institution needs a written incident response program that outlines how the firm will detect, contain, and recover from a breach. The program can't just exist as a policy binder sitting in a compliance folder. It must function as an operational plan that staff can actually follow when something goes wrong at 2am.

Notification duties run alongside that program. When sensitive customer information has been accessed without authorization, or is reasonably likely to have been, the rule requires notice describing what happened and what the customer can do about it. Notice is not required if a reasonable investigation shows the information is not reasonably likely to be used in a way causing substantial harm or inconvenience. That notice generally has to go out within 30 days of the firm learning of the incident, a timeline tight enough that firms without a rehearsed process will struggle to meet it.

Oversight of service providers is the third piece, and it is often the one that firms underestimate. Most smaller advisers and broker-dealers rely on outside vendors for custody, technology, or back-office functions, and a breach at any one of those vendors can expose the same customer data the firm is responsible for protecting. The rule requires due diligence and ongoing monitoring of these providers. It also requires written policies designed to ensure a provider notifies the firm no later than 72 hours after becoming aware of a breach of a customer information system it maintains.

Finally, the amendments require records proving that all of it happened. For broker-dealers, that documentation belongs inside the written supervisory procedures rather than in a standalone file no one maintains. Firms need to retain documentation of their policies and procedures; records of any actual or suspected incidents and how they were investigated; copies of notices sent to customers; and evidence of service provider agreements and oversight. An examiner is not going to take a firm's word that a program exists. The file has to be there.

FINRA and SEC Guidance on Regulation S-P

FINRA issued a cybersecurity advisory in November 2025, reminding member firms of the two compliance dates and urging firms to determine early which category, larger or smaller, applies to them under the rule's asset thresholds. FINRA noted that its own definitions of large and small firms don't align with the SEC's Regulation S-P categories. This distinction has tripped up more than one compliance officer trying to map internal firm classifications onto the rule. The advisory also pointed firms to the SEC's own guidance on determining which bucket they fall into.

The SEC backed that reminder with enforcement weight. The agency's Division of Examinations designated Regulation S-P as a fiscal year 2026 exam priority, placing implementation of the 2024 amendments alongside other information security and operational resiliency work. That means examiners walking into a routine exam this year are likely to ask for the written incident response program, request evidence of vendor oversight, and check whether the firm's recordkeeping matches the rule's requirements. A firm that treated the June deadline as a formality rather than a hard requirement is the firm most likely to draw follow-up questions.

Closing the Regulation S-P Compliance Gap Now

Firms that have not finished building out their programs are past the point where "in progress" is a defensible answer. The practical starting point is to confirm which entity category applies, since the thresholds turn on assets under management or, for broker-dealers, total capital, rather than on headcount or revenue.

From there, four pieces of work remain:

  • Assign roles so it is clear who does what during a breach
  • Build a notification template and a 30-day clock that someone actually watches
  • Review vendor contracts for data security and breach notification terms
  • Centralize recordkeeping somewhere an examiner can find it quickly

None of this eliminates the risk of a breach. It does mean that when an examiner asks how the firm handled an incident, there is a documented answer instead of a reconstruction.

PK Tech has spent 16 years managing IT and security for small and mid-sized firms in regulated industries. PK Tech holds AICPA SOC 2 Type II attestation, a third-party audit of the same security and privacy controls Reg S-P expects firms to require of their own service providers.

Schedule a compliance review with our team.

What is SEC Regulation S-P and How Is It Changing?

1 min read

What is SEC Regulation S-P and How Is It Changing?

The SEC is adopting significant cybersecurity amendments to Regulation S-P.

Read the Full Article
LPL's Cybersecurity Mandate: What Advisors Need to Know Before the September Deadline

1 min read

LPL's Cybersecurity Mandate: What Advisors Need to Know Before the September Deadline

Disclaimer: This post is not legal, tax, or compliance advice. Regulatory questions should go to your attorney and compliance consultant. Some of the...

Read the Full Article
FINRA “Highly Recommends” Including Penetration Testing in Firms’

1 min read

FINRA “Highly Recommends” Including Penetration Testing in Firms’

The need for robust cybersecurity measures has become paramount in the ever-evolving landscape of financial services. Financial institutions are...

Read the Full Article