Reg S-P compliance roadmap
Reg S-P compliance roadmap for RIAs
The SEC's 2024 amendments to Regulation S-P added an express incident response program, a 30-day customer notification standard, and stronger service-provider oversight. This page tracks every dated milestone, split by firm size, so you can see exactly where your firm should be today.
Last reviewed against the SEC's 2026 Division of Examinations priorities. This is a readiness reference, not legal advice.
Dated timeline
May 16, 2024
All RIAs and broker-dealers
SEC adopts the Reg S-P amendments
The Commission finalized amendments to Regulation S-P, adding an incident response program requirement, a 30-day customer notification standard, and expanded vendor oversight and recordkeeping obligations.
- Identify the covered customer information categories that touch your firm.
- Map which systems, custodians, and vendors process that information.
- Assign an accountable owner for the incident response program.
August 2, 2024
All RIAs and broker-dealers
Amendments take effect
The rule became effective 60 days after Federal Register publication, starting the compliance-date clock for larger and smaller entities.
- Confirm which tier applies to your firm based on assets under management.
- Add the applicable compliance date to your compliance calendar.
December 3, 2025
RIAs with $1.5B+ in assets under management
Compliance deadline for larger entities
Larger entities must be in full compliance with the incident response, customer notification, service-provider oversight, and recordkeeping requirements. Firms that have not yet finished implementation are past due.
- Adopt a written incident response program covering assessment, containment, and notification.
- Wire the 30-day customer notification workflow into your incident playbook.
- Update vendor contracts to require prompt breach notice from service providers.
- Set retention on incident and notification records for the required period.
June 3, 2026
RIAs under $1.5B in assets under management
Compliance deadline for smaller entities
Smaller entities must be in full compliance by this date. The Division of Examinations' 2026 priorities include Reg S-P compliance, so early exam activity is expected in the second half of 2026.
- Same requirements as larger entities — no smaller-firm carve-out on substance, only timing.
- Have written policies, evidence of testing, and vendor-oversight records on hand for a first-year exam.
2026 exam cycle
All RIAs and broker-dealers
SEC examinations on the 2024 amendments begin in earnest
The Division of Examinations named Reg S-P compliance in its 2026 priorities. Expect document requests for your incident response program, breach-notification workflow, and vendor oversight files.
- Assemble the exam binder: policies, incident log, notification templates, vendor list.
- Run a tabletop exercise to confirm the program works end-to-end.
- Take the Reg S-P Readiness Score to see how your program would present in an exam.
What changed in the 2024 amendments
Incident response program. Every covered firm must maintain written policies and procedures for assessing, containing, and controlling incidents involving customer information.
30-day customer notification. When sensitive customer information has been or is reasonably likely to have been accessed or used without authorization, affected individuals must be notified as soon as practicable and no later than 30 days after discovery.
Service-provider oversight. Firms must take reasonable steps to require service providers to protect customer information and to notify the firm of a breach so the firm can meet its own notification obligations.
Recordkeeping. Written policies, incident records, and notification evidence must be retained on the schedule that applies to your firm type.
Where does your firm stand today?
The Reg S-P Readiness Score is a 6-minute, 11-question check that scores your program against these deadlines in the language of an SEC exam.
