Skip to content

Guide · 13 min read · Updated July 2026

Regulation S-P compliance guide for legal counsel

A plain-English walkthrough of the SEC's 2024 amendments to Regulation S-P — the incident response program requirement, the 30-day customer notification rule, and the service-provider oversight obligations — written for law firms advising broker-dealers, investment advisers, investment companies, and transfer agents.

What actually changed in 2024

The SEC's Regulation S-P has governed how broker-dealers, registered investment advisers, investment companies, and transfer agents protect customer nonpublic personal information since 2000. The 2024 amendments (Release Nos. 34-100155; IA-6604; IC-35193) modernized the rule for the reality that most covered institutions now store customer data with cloud providers, sub-advisers, and third-party fintech platforms — and that breach notification, until now, was almost entirely a state-law patchwork.

Four things are new:

  • A written incident response program is now mandatory.
  • Covered institutions must notify affected individuals within 30 days of becoming aware that sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization.
  • Written policies must extend to service-provider oversight, including contractual notification requirements.
  • The rule's protections extend to both customer information and consumer information, and expressly cover records held on behalf of another covered institution.

Who is covered — and where law firms fit

The rule's direct addressees are broker-dealers (including funding portals), SEC-registered investment advisers, investment companies, and transfer agents. Law firms are not themselves "covered institutions." But two roles pull firms in:

  • Outside counsel role. When a covered client experiences an incident, the 30-day clock is running against the client. Counsel that advises on breach response, regulator engagement, and customer notice needs the workflow ready before the call comes in.
  • Service-provider role. Firms that hold covered institutions' customer records (deal-room data rooms, litigation files, custody exception reports) land inside the service-provider oversight rule and will be contractually required to notify the covered institution — practically, within 72 hours of awareness.

The 30-day customer notification rule

The headline obligation. As soon as practicable, but no later than 30 days after the covered institution becomes aware that sensitive customer information has been, or is reasonably likely to have been, accessed or used without authorization, it must notify each affected individual. Two nuances counsel should underline for clients:

  • The clock starts at awareness of the incident, not at confirmation of exfiltration. If unauthorized access is "reasonably likely," the 30 days are running.
  • The only carve-out is a written determination that the information has not been and is not reasonably likely to be used in a manner that would result in substantial harm or inconvenience.

Required contents of the customer notice

  • Description of the incident in general terms.
  • Type of sensitive customer information involved.
  • Date, estimated date, or date range of the incident.
  • Contact information the customer can use to reach the covered institution.
  • Recommended protective steps — including how to place a fraud alert or security freeze with each of the nationwide consumer reporting agencies.

The written incident response program

The rule requires policies and procedures reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. In practice, an examiner walking into a covered client's office is going to look for four artifacts:

  1. Assessment procedures. How the institution scopes an incident, identifies which systems and information are involved, and documents that assessment.
  2. Containment and control. How access is cut off, credentials rotated, and vulnerable systems isolated.
  3. Notification workflow. Who drafts the customer notice, who signs off, and how the 30-day deadline is tracked.
  4. Recordkeeping. Written records of the incident, response actions, and notification decisions, retained per the applicable books-and-records rule.

Service-provider oversight

Covered institutions must adopt written policies reasonably designed to require — by contract or otherwise — that service providers take appropriate measures to protect customer information and to notify the covered institution of unauthorized access or use as soon as possible, and no later than 72 hours after awareness. Counsel drafting or renegotiating vendor agreements should tighten:

  • Definitions of "sensitive customer information," aligned to the Reg S-P definition.
  • 72-hour notification clauses with contact channels and required content.
  • Audit and evidence rights — SOC 2 Type II reports, penetration test summaries, and vulnerability scan results at a defined cadence.
  • Sub-processor flow-down, so downstream cloud and AI vendors carry equivalent obligations.

How Reg S-P fits with other regimes

  • SEC Cybersecurity Risk Management Rule (Item 1.05 of Form 8-K). Public-company clients also have a 4-business-day materiality-based disclosure obligation. Reg S-P is customer-facing; the 8-K is investor-facing. Both can trigger from the same event.
  • GLBA Safeguards Rule. FTC-supervised financial institutions have their own 30-day notification threshold for incidents affecting 500+ customers. Reg S-P is narrower in scope but broader in required program elements.
  • State breach notification laws. All 50 states still apply. Reg S-P does not preempt; the strictest applicable clock governs.
  • ABA Model Rule 1.6(c). Firms holding covered-institution data as counsel or vendor still owe their own competence and confidentiality duty under ABA Formal Opinions 477R and 483.

Counsel readiness checklist

  • Confirm which clients meet the 'covered institution' definition and which deadline applies.
  • Map every system and vendor that touches covered-client customer information.
  • Update engagement letters and DPAs with the 72-hour service-provider notification clause.
  • Stand up a written incident response program — even if the firm is only a service provider.
  • Pre-draft template customer notices with the five statutorily required elements.
  • Rehearse the 30-day timeline with a tabletop exercise involving IT, GC, and outside breach counsel.
  • Verify continuous vulnerability scanning and attack-surface monitoring so 'awareness' is defensible.
  • Retain assessment, notification, and remediation records to survive an SEC exam request.

What non-compliance looks like

The SEC has already signaled that Reg S-P enforcement will look a lot like its Rule 30 / Safeguards Rule actions of the last five years — settled orders with censures, cease-and-desist provisions, and civil penalties in the low-to-mid seven figures for firms that either lacked written policies or failed to follow the ones they had. For counsel, the more common exposure is the collateral one: cyber-insurance recovery denied because the client cannot prove the incident-response program existed at the time of loss, or a client relationship lost after a delayed customer notice ends up on the front page.

Frequently asked questions

What is Regulation S-P?

Regulation S-P is the SEC rule (17 CFR Part 248) governing how broker-dealers, registered investment advisers, investment companies, and transfer agents protect the nonpublic personal information (NPI) of their customers. The 2024 amendments added a written incident response program, a 30-day customer notification obligation, and expanded oversight of service providers.

When is the Regulation S-P compliance deadline?

Larger entities must comply by December 3, 2025. Smaller entities have until June 3, 2026. 'Larger' generally means investment companies with net assets of $1 billion or more, registered investment advisers with $1.5 billion or more in AUM, and broker-dealers and transfer agents that are not small entities under the Exchange Act.

Who does the amended Reg S-P apply to?

Broker-dealers (including funding portals), registered investment advisers, investment companies, and transfer agents registered with the SEC or another appropriate regulator. Law firms are not themselves 'covered institutions' — but their clients almost always are, and firms holding covered-institution data as service providers are pulled in through the oversight rule.

How quickly must customers be notified of a breach?

As soon as practicable, but no later than 30 days after the covered institution becomes aware that unauthorized access to or use of sensitive customer information has occurred or is reasonably likely to have occurred. The 30-day clock runs from awareness, not from confirmation of harm.

What has to be in the customer notice?

A description of the incident, the type of sensitive customer information involved, the date or estimated date range of the incident, contact information for the covered institution, and recommended steps customers can take to protect themselves, including guidance on placing a fraud alert or security freeze with a nationwide consumer reporting agency.

Does Reg S-P preempt state breach notification laws?

No. Reg S-P sets a federal floor. Covered institutions still have to comply with each state's breach notification statute in parallel, and the strictest applicable timeline governs the actual outreach schedule.

What counts as 'sensitive customer information'?

Any component of customer information — alone or in combination with other data elements — that could reasonably be used to commit identity theft or fraud, including SSNs, government IDs, financial account numbers, biometric data, and account credentials paired with security questions.

Do I have to notify customers of another covered institution?

Yes, in most cases. Under the amendments, when a covered institution maintains records containing sensitive customer information of another covered institution's customers (typical in clearing / introducing broker or sub-adviser arrangements), the entity that experienced the incident generally has to notify the affected individuals unless the other covered institution takes over the obligation in writing.

What incident-response program elements does Reg S-P now require?

Written policies and procedures reasonably designed to: (1) assess the nature and scope of any incident and identify the systems and information involved, (2) contain and control the incident to prevent further unauthorized access or use, and (3) notify affected individuals within the 30-day window with the prescribed content.

How does the service-provider oversight rule work?

Covered institutions must have written policies reasonably designed to require, through contract or otherwise, that service providers take appropriate measures to protect sensitive customer information and to notify the covered institution of a breach as soon as possible — and no later than 72 hours after becoming aware of unauthorized access or use — so the institution can meet its own 30-day clock.

Prove the program exists before the exam

Attorney Armor gives law firms and their covered-institution clients continuous attack-surface monitoring, evidence-grade vulnerability scans, and audit-ready reports mapped to Reg S-P, the Safeguards Rule, and ABA Formal Opinion 483. Run a free assessment in under six minutes.

Reg S-P · 17 CFR Part 248 30-day customer notice