SEC Regulation S-P: What Smaller Financial Firms Must Do Now That the Deadline Has Passed
Originally Published: May 10, 2026
Last Updated: Aug. 19, 2026
By Tracey Birkenhauer, journalist and Chief Impact Officer, STACK Cybersecurity
Update History: This post was originally published on May 10, 2026. It was updated on June 4, 2026 to reflect the passage of the June 3 deadline, and again on Aug. 19, 2026 to add examination and enforcement context.
Executive Summary
The June 3, 2026 compliance deadline for smaller financial firms under the SEC's amended Regulation S-P has passed. Firms must now maintain a written incident response program, notify customers within 30 days of a breach involving sensitive information, hold service providers to a 72-hour breach notification standard, and document all of it in a way examiners can test.
Regulation S-P has appeared on the SEC's examination priority list for five straight years, and two recent settlements, Robinhood's $45 million penalty and the M Holdings case, show what examiners consider a violation of the underlying safeguards rule. Firms that treated June 3 as a policy-signing deadline rather than an operational one are the ones most exposed heading into exam season.
The June 3, 2026 compliance deadline for smaller financial firms under the Securities and Exchange Commission's amended Regulation S-P (PDF) has now passed. Firms that have not implemented the required safeguards, incident response procedures, customer notification processes, and vendor oversight controls face examination findings, and possibly enforcement referrals, as the SEC's Division of Examinations works Regulation S-P into its active exam schedule for the fiscal year.
The SEC adopted these amendments in May 2024, giving larger entities 18 months and smaller firms 24 months to comply. Larger firms, including those with $1.5 billion or more in assets under management and certain broker-dealers, became subject to the amendments on Dec. 3, 2025.
As of June 3, 2026, the amended requirements apply to smaller registered investment advisers, broker-dealers, investment companies, funding portals, and transfer agents that fall below those thresholds.
Regulation S-P has appeared on SEC's list of examination priorities for five straight years, according to Bates Group. Their analysis says: "Five consecutive years means these are not trends, they are program expectations."
Read the Bates Group analysis:SEC 2026 Exam Priorities Chart: What Five Years of Data Reveal About Your Examination Risk
"Examiners now know exactly what adequate looks like, what weak looks like, and what will generate a finding," Bates Group said. "Firms that treat these areas as 'background' compliance are the ones most likely to generate avoidable findings."
What Is Regulation S-P?
Regulation S-P was enacted by the SEC in 2000 to implement privacy provisions of the Gramm-Leach-Bliley Act, the federal law requiring financial institutions to safeguard sensitive consumer data and maintain transparent communication with clients about how their information is handled.
The regulation's name follows the SEC's internal coding conventions. "S" refers to the securities section of the Code of Federal Regulations. "P" designates the privacy protections established under that section.
4 Requirements
The original rule established four core requirements that remain in effect today, now strengthened by the 2024 amendments, which took effect Aug. 2, 2024.
1. Privacy Notices
Covered firms must deliver initial and annual privacy notices to clients explaining the firm's information-sharing practices and the customer's right to opt out of certain disclosures to non-affiliated third parties.
2. Opt-Out Rights
Customers have the right to limit how their information is shared with affiliates and third parties, with certain exceptions specified by law. Firms must provide a clear and functional mechanism for exercising those rights.
3. Safeguards Rule
Companies must adopt written policies and procedures to protect client information from unauthorized access or use. Those safeguards must address administrative, technical, and physical controls. The 2024 amendments significantly expanded this requirement by mandating a formal incident response program.
4. Restrictions on Disclosure
The regulation prohibits unauthorized disclosure of nonpublic personal information without customer consent, except in limited, legally specified circumstances.
What the 2024 Amendments Require
The 2024 amendments modernize the safeguards framework significantly. Firms must now maintain written policies and procedures for an incident response program designed to detect, respond to, and recover from unauthorized access to customer information.
The amendments also broaden the scope of protected information. Covered firms must safeguard customer information regardless of whether it originated directly from the firm's own clients or was received from another financial institution. Those obligations also extend to customer information maintained by service providers on the firm's behalf.
The rule extends safeguarding and disposal requirements to cover all customer information, including data held by or on behalf of the firm through third-party providers.
What Counts as Sensitive Customer Information
The amended rule defines sensitive customer information broadly. It covers the obvious categories, Social Security numbers, driver's license numbers, passport numbers, and financial account credentials, but it also reaches any customer information that could reasonably be used to gain account access or facilitate identity theft or fraud.
Account numbers, login credentials, security question responses, tax identification numbers, and even combinations of otherwise ordinary personal details can qualify if unauthorized access to them creates a risk of misuse. Firms that scoped their data mapping narrowly, around Social Security Numbers alone, are likely to find gaps once they measure their inventory against the full definition.
One detail firms often get wrong: the final rule doesn't require notification to the SEC itself after a breach. The 30-day clock runs for notifying affected customers, not the commission. State breach notification laws, contractual obligations, and other federal requirements may still apply separately.
The Deadline Has Passed. What's Next?
The conversation has shifted from preparation to proof. You should now assume that SEC examiners may review whether required policies, procedures, documentation, and safeguards are in place and operating effectively.
For companies still working toward full compliance, the priority should be immediate remediation, documentation, and testing. Examiners will expect evidence that incident response procedures, client notification processes, vendor oversight controls, and record-keeping requirements have been implemented and maintained.
Early Enforcement Signals Predate the Deadline
The SEC hasn't announced a dedicated examination sweep built specifically around the smaller-entity compliance date. But two recent settlements show what the agency considers a violation under the existing Regulation S-P safeguards rule, Rule 30(a), and the related Regulation S-ID identity theft prevention requirements.
In January 2025, Robinhood Securities LLC and Robinhood Financial LLC agreed to pay $45 million in combined civil penalties after the SEC found the firms failed to safeguard customer information under Rule 30(a) and failed to maintain an adequate identity theft prevention program under Rule 201 of Regulation S-ID. The SEC's order emphasized that broker-dealers must satisfy their legal obligations to protect customer data as part of their core market functions.
"Both firms agreed to conduct an internal audit concerning off-channel communications compliance, and Robinhood Securities agreed to certify its remediation of the deficiencies that caused the Reg SHO violations," said the SEC press release. "Robinhood Securities agreed to pay a $33.5 million penalty and Robinhood Financial agreed to pay a $11.5 million penalty."
In November 2025, the SEC settled with M Holdings Securities Inc., a dually registered broker-dealer and investment adviser, over a Rule 30(a) violation.
The SEC’s order found M Holdings violated Rule 30(a) of Regulation S-P (17 C.F.R. § 248.30(a)) and Rule 201 of Regulation S-ID (17 C.F.R. § 248.201). Without admitting or denying the SEC’s findings, M Holdings agreed to cease and desist from committing or causing any violations and any future violations of Rule 30(a) of Regulation S-P and Rule 201 of Regulation S-ID, be censured, and pay a civil penalty of $325,000.
Neither case involved a smaller entity subject to the June 3, 2026 deadline, but both illustrate the fact pattern examiners look for: a documented gap between what a firm's policy says and what its systems do.
Compliance Outreach Program
The SEC ran its Compliance Outreach Program specifically to prepare firms for the amended rule, holding three sessions tailored to different registrant types. The first, on Sept. 25, 2025, focused on large firms already past their compliance date. The second, on Dec. 17, 2025, focused on transfer agents. The third, on Jan. 22, 2026, focused on small firms ahead of the June 3 deadline. Staff used the sessions to walk through the new obligations and what to expect from an exam team, according to SEC's Compliance Outreach Program.
FINRA reinforced the same message to broker-dealer member firms through its cybersecurity advisories and its 2026 Annual Regulatory Oversight Report, published Dec. 9, 2025. The advisory pointed member firms to the SEC's fact sheet and Small Entity Compliance Guide and reminded firms that compliance with Regulation S-P sits inside FINRA's broader cybersecurity and cyber-enabled fraud oversight, not as a standalone checkbox. Firms can review the details in FINRA's cybersecurity advisory.
Compliance matters beyond avoiding enforcement actions. Regulation S-P is fundamentally about consumer protection and trust. Clients share sensitive financial information with their advisers and brokers because they trust those firms to handle it responsibly. A breach, or a business that can't demonstrate it took reasonable steps to prevent one, erodes that trust.
Operational Infrastructure Challenges
Most smaller financial firms have some version of a privacy policy and a general sense of what data they hold. What they typically don't have is the operational infrastructure the amended rule demands.
The 30-day customer notification requirement is the most time-sensitive. When a breach involving sensitive customer information occurs, you have 30 days to determine what happened, assess what data was affected, and deliver a notification that explains the incident, what information was involved, and what clients can do to protect themselves.
That kind of response requires pre-approved notification templates, a clear decision-making process, and assigned roles before an incident happens, not after.
The 72-hour vendor notification requirement is arguably harder. You must ensure service providers are contractually obligated to notify within 72 hours of discovering a breach involving customer data. Many platform providers and software vendors don't include that language by default, and negotiating it after the fact can be difficult.
If you haven't audited your vendor agreements, you may find this is one of your largest compliance gaps.
Where Most Smaller Firms Stand
Partial compliance is common. You may have a privacy notice, a general IT security policy, and a sense of which vendors touch client data. What's often lacking is the documented, testable framework the SEC expects to see during an examination. This includes written incident response plans, vendor contracts with enforceable notification timelines, data maps that identify every location customer information resides, and records showing staff have been trained and controls have been tested.
You must be prepared to demonstrate not only that policies exist, but also that they've been implemented, communicated to staff, tested, and documented.
Map, Audit, Update
Start with data mapping. Before you can assess the impact of a breach, you must know exactly where customer information lives, including systems managed or maintained by third-party vendors.
Next, audit vendor contracts. Review every agreement with a service provider that has access to customer information and confirm whether breach notification timelines are defined. The 72-hour expectation should be explicit and enforceable.
Then build or update your incident response plan. The plan needs to define how to detect an incident, assess its scope, determine whether notification is required, and execute customer notifications within 30 days. Roles should be assigned in advance.
Finally, run a tabletop exercise. Walk through a scenario where sensitive customer information is exposed and determine, honestly, whether your firm could meet the notification deadline. The gaps that surface are often the same gaps an SEC examiner will identify.
Download the Readiness Checklist
To help your firm assess where it stands, STACK made a Regulation S-P Readiness Checklist covering seven compliance areas: data awareness, incident response, breach notification, vendor oversight, policy updates, recordkeeping, and training.
Use it as a post-deadline compliance assessment to identify gaps, document remediation efforts, and prepare for future SEC examinations.
If you work through that checklist and find gaps, a structured gap assessment with STACK can help you determine what needs to be built, updated, or documented so your firm can demonstrate compliance if SEC examiners request documentation, policies, testing records, or incident response evidence. Schedule a conversation with our team.
Frequently Asked Questions
Does a Regulation S-P breach require notifying the SEC directly?
No. The final rule requires notification to affected customers within 30 days of discovering a breach that poses a risk of harm. It does not create a separate obligation to notify the SEC. Other laws, contracts, or state breach notification statutes may still apply.
What counts as sensitive customer information under the amended rule?
The definition extends beyond Social Security numbers, driver's license numbers, passport numbers, and financial account credentials. It also covers login credentials, security question answers, tax identification numbers, and combinations of personal details that could reasonably be used to gain account access or facilitate identity theft or fraud.
Has the SEC brought enforcement actions related to Regulation S-P?
Yes. Robinhood Securities and Robinhood Financial paid $45 million in combined penalties in January 2025 for failing to safeguard customer information and maintain an adequate identity theft prevention program. M Holdings Securities settled with the SEC in November 2025 after examiners found the firm had no written information security policies covering its member network.
Is Regulation S-P still an SEC examination priority?
Yes. It has appeared on the SEC Division of Examinations' priority list for five consecutive years, including the fiscal year 2026 priorities released Nov. 17, 2025, which named compliance with the 2024 amendments as a standalone focus area.