Smaller Investment Advisers Face Compliance Deadline for Regulation S-P Amendments
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The SEC's 2024 amendments to Regulation S-P require smaller investment advisers to comply with new cybersecurity and data breach notification requirements by June 3, 2026. These amendments mandate the establishment of an incident response program and procedures for notifying customers of data breaches within 30 days. The SEC has prioritized compliance with these amendments for regulatory examinations in fiscal year 2026. Larger entities had a previous deadline of December 3, 2025, while smaller entities must act quickly to meet the upcoming deadline. The amendments aim to enhance the protection of sensitive customer information in light of increasing cyber threats. Registered investment advisers (RIAs) and other covered institutions are particularly affected, as they must develop tailored policies and procedures to ensure compliance. Failure to comply could lead to regulatory scrutiny and potential penalties.
Key Points: • Smaller investment advisers must comply with Regulation S-P amendments by June 3, 2026. • The amendments require incident response programs and timely customer breach notifications. • The SEC has made compliance a priority for regulatory examinations in 2026.