Smaller Investment Advisers Face Compliance Deadline for Regulation S-P Amendments

Smaller Investment Advisers Face Compliance Deadline for Regulation S-P Amendments

First seen 22 May 2026, 10:55 UTC DwtKroll 79% similarity 42.9

Article Content

Browse articles
ThreatCluster

The SEC's 2024 amendments to Regulation S-P require smaller investment advisers to comply with new cybersecurity and data breach notification requirements by June 3, 2026. These amendments mandate the establishment of an incident response program and procedures for notifying customers of data breaches within 30 days. The SEC has prioritized compliance with these amendments for regulatory examinations in fiscal year 2026. Larger entities had a previous deadline of December 3, 2025, while smaller entities must act quickly to meet the upcoming deadline. The amendments aim to enhance the protection of sensitive customer information in light of increasing cyber threats. Registered investment advisers (RIAs) and other covered institutions are particularly affected, as they must develop tailored policies and procedures to ensure compliance. Failure to comply could lead to regulatory scrutiny and potential penalties.

Key Points: • Smaller investment advisers must comply with Regulation S-P amendments by June 3, 2026. • The amendments require incident response programs and timely customer breach notifications. • The SEC has made compliance a priority for regulatory examinations in 2026.

ThreatCluster AI

Timeline

2024-01-01
SEC amends Regulation S-P
The SEC introduces new cybersecurity and data breach notification requirements for covered institutions.
Kroll
2025-12-03
Larger entities compliance deadline
Larger investment advisers and covered institutions were required to comply with the amendments by this date.
Dwt
2026-06-03
Smaller entities compliance deadline
Smaller investment advisers must meet the new cybersecurity requirements by this date.
Dwt

Community

Browse all →

Tracked Entities in This Story