ARTICLE
23 December 2025

Amended Regulation S-P: Here To Stay And Being Examined In 2026

FL
Foley & Lardner

Contributor

Foley & Lardner LLP looks beyond the law to focus on the constantly evolving demands facing our clients and their industries. With over 1,100 lawyers in 24 offices across the United States, Mexico, Europe and Asia, Foley approaches client service by first understanding our clients’ priorities, objectives and challenges. We work hard to understand our clients’ issues and forge long-term relationships with them to help achieve successful outcomes and solve their legal issues through practical business advice and cutting-edge legal insight. Our clients view us as trusted business advisors because we understand that great legal service is only valuable if it is relevant, practical and beneficial to their businesses.
Last month, the U.S. Securities and Exchange Commission (SEC) Division of Examinations released its Fiscal Year 2026 "Examination Priorities." In this year's release...
United States Corporate/Commercial Law
Peter D. Fetzer’s articles from Foley & Lardner are most popular:
  • within Corporate/Commercial Law topic(s)
  • with Inhouse Counsel
  • with readers working within the Insurance industries

Last month, the U.S. Securities and Exchange Commission (SEC) Division of Examinations released its Fiscal Year 2026 "Examination Priorities." In this year's release, the SEC announced that it will begin examining covered investment advisers, investment companies, and broker-dealers for compliance with amendments to Regulation S-P that, among other things, requires them to report data breaches involving customer information within 30 days.

These amendments, adopted on May 16, 20241, and commonly known as "Amended Reg S-P," survived the June 2025 revocation of fourteen rules adopted by the prior SEC Chair Gary Gensler. Amended Reg S-P appears to not only have survived this rule revocation onslaught but now may thrive in the upcoming year and beyond under the Division of Examinations. Specifically, in the Examination Priorities, the SEC advises:

In preparation for the compliance dates for the Commission's amendments to Regulation S-P, the Division will engage firms during examinations about their progress in preparing incident response programs reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. After the applicable compliance dates, the Division will examine whether firms have developed, implemented, and maintained policies and procedures in accordance with the rule's new provisions that address administrative, technical, and physical safeguards for the protection of customer information.2

While there have been swift and significant revisions to many SEC priorities in 2025, cybersecurity remains a focus. This should not be a surprise, as one would hope that cyber-risk management endures as a SEC priority, regardless of who is sitting in the "Chair."

The compliance date for Amended Reg S-P for larger reporting firms was December 3, 2025, and for smaller reporting firms it is June 3, 2026. The key changes required by this rule are:

  • Developing and implementing written policies and procedures for an incident response plan;
  • Developing and implementing written policies and procedures providing for service provider oversight, including procedures reasonably designed to ensure service providers notify covered firms within 72 hours of security incidents involving "customer information systems";
  • Notifying customers (including customers of certain other financial institutions) within 30 days in the event their "sensitive customer information" has been compromised; and
  • Broadening the scope of information covered by the original "Reg S-P", implementing additional recordkeeping obligations for covered institutions, and providing an exception to the annual privacy notice delivery requirement.

Thus, firms need to be prepared for the Division of Examinations Staff to examine them for readiness for Amended Reg S-P. Further, earlier this year, in announcing the priorities for the SEC's Cyber and Emerging Technologies Unit, the SEC included the following: "Regulated entities' compliance with cybersecurity rules and regulations." This priority, coupled with the Examination Priorities described in this article, show that, even if SEC Chair Paul Atkins has retired "regulation by enforcement" more generally, cybersecurity remains an area of focus for the Commission.

Footnotes

1. https://www.sec.gov/newsroom/press-releases/2024-58.

2. https://www.sec.gov/files/2026-exam-priorities.pdf, see page 13.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More