What the SEC’s Amended Reg S-P Actually Requires of Your IT Stack

Key Takeaways

  • Deadline: RIAs with under $1.5B AUM have until June 3, 2026 to comply with the SEC’s amended Regulation S-P. Larger firms were required to comply by December 3, 2025.
  • Five new requirements: written incident response program, 30-day customer breach notification, service provider oversight (with 72-hour vendor notification), recordkeeping, and disposal protocols.
  • The gap most firms have: policies exist on paper, technical controls partially exist in the environment — but the documentation tying the two together is missing.
  • What “done” looks like: an examiner asks a question; you answer it with a document, screenshot, or log query in the same meeting.

If your firm is an SEC-registered investment adviser with less than $1.5 billion in assets under management, you have until June 3, 2026 to comply with the SEC’s amended Regulation S-P. Larger firms were required to comply by December 3, 2025. The amendments substantially expand what “safeguarding customer information” means in practice, and the gap between policy language and operational reality is wider than most firms realize.

This post is not a legal interpretation. Your compliance consultant or outsourced CCO is the right place for that. What this post does is translate the rule’s requirements into the specific IT controls, configurations, and documentation your environment actually needs to demonstrate compliance — and where we see most firms fall short.

Who the rule applies to

Reg S-P, as amended, covers SEC-registered investment advisers, broker-dealers, investment companies, funding portals, and transfer agents. Compliance dates split by size:

  • Larger entities (RIAs with $1.5B+ AUM, certain BDs, and investment companies): deadline was December 3, 2025.
  • Smaller entities (RIAs with less than $1.5B AUM): deadline is June 3, 2026.

If you’re reading this and aren’t sure which bucket you fall into, that’s the first conversation to have with your compliance consultant.

The five requirements, mapped to IT controls

Written incident response program

The amendments require a written program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. The program must include procedures to assess the nature and scope of an incident, contain and control it, and notify affected individuals.

What this looks like in your environment: an EDR platform deployed on every endpoint with alert routing into a documented response runbook; centralized logging that retains at least 90 days of authentication, file access, and email events; documented IR playbooks that name who decides what, in what order, when an alert fires. Most RIAs do not have the EDR. Most do not have the runbook.

30-day customer notification

If unauthorized access to sensitive customer information has occurred or is reasonably likely to have occurred, the firm must notify each affected individual as soon as practicable, and no later than 30 days after becoming aware. “Sensitive customer information” includes Social Security numbers, tax IDs, driver’s license numbers, and any combination of identifiers (like a username and password) that could be used to access an account.

What this looks like in your environment: the technical capability to determine, within days, not weeks, what data was accessed and which individuals were affected. That requires logging that actually captures file-level access, email forensics that can reconstruct what was sent and to whom, and an inventory of where sensitive data lives, not just in the CRM, but in shared drives, individual mailboxes, and exported reports. Without this, the 30-day clock runs out before you can scope the breach.

Service provider oversight

The amendments require written policies and procedures for due diligence and monitoring of service providers, including contractual requirements that vendors notify the firm within 72 hours of discovering a breach affecting customer information.

What this looks like in your environment: a vendor inventory listing every third party that touches client data, your CRM, custodian, financial planning software, document management, e-signature provider, payroll, and the dozens of niche tools that have crept in over the years. Each vendor should have a documented review of their SOC 2 or equivalent attestation, contract language requiring 72-hour breach notification, and a periodic re-review cadence. Most RIAs have a vendor list. Few have all of these elements together.

Recordkeeping

Firms must maintain written records documenting their compliance with the Safeguards and Disposal Rules, retained for the periods specified in the rule. Examiners will ask for them.

What this looks like in your environment: a single, organized location where your incident response program, vendor reviews, training records, risk assessments, and any actual incident documentation live with date stamps, version history, and clear ownership. SharePoint, a documentation platform, or a compliance-specific tool, all work. A scattered mix of email attachments and PDFs in someone’s Downloads folder does not.

Disposal of consumer information

Reasonable measures must be taken to protect against unauthorized access to or use of consumer information in connection with its disposal. This applies to paper, electronic, and physical media.

What this looks like in your environment: documented data destruction protocols for retired hardware (laptops, drives, mobile devices, printers with internal storage), an actual workflow for what happens when an employee leaves, and a vendor for paper destruction with a certificate of destruction on file. The hardware piece trips up firms most often; retired devices sitting in a closet for two years are a finding waiting to happen.

Where most RIAs fall short

Across the firms we work with, the patterns are remarkably consistent. The policies exist on paper. The technical controls partially exist in the environment. The documentation tying the two together — the proof that policy and reality match — is what’s missing.

Specifically, the gaps we see most often: incident response runbooks that exist as a Word document but have never been rehearsed, EDR coverage that’s missing on a handful of endpoints (often laptops issued to part-time admins or contractors), vendor inventories that are a year out of date, and customer-data inventories that simply don’t exist.

None of these are difficult to fix. They are time-consuming. If your firm is in the smaller-entity bucket, you have until June 3, 2026, to close them.

Closing the gap

If your compliance consultant or outsourced CCO has provided a recommendation set and you’re looking at the work needed to implement it, that’s exactly the engagement we’re built for. Rival IT is a technology provider focused specifically on financial services. We don’t interpret regulations; we implement them, document the work in a defensible form at exam time, and continue managing the environment afterward.

Ready to close the gap?

Walk us through your current state and we’ll tell you, candidly, where the implementation gaps are. No pitch deck. No commitment.

Schedule a Readiness Review → Call (704) 960-9739

Comments are closed.