Adoption Date

500.19: Exemption Parameters 500.20: Enforcement Provisions

11/1/2023

30 Days In

500.17(a): Cybersecurity Incident Notifications 500.17(b): Annual Notification Requirements 500.17(c): New Extortion Payment Notifications

12/1/2023

180 Days in

500.2(c) Class A requirement to design and conduct independent audits 500.3: New Areas to incldue in cybersecurity policies 500.5(a)-(c): new vulnerability management requirements 500.9: New Risk Assessment requirements 500.14(a)(3): new cybersecurity awareness training All other provisions not mentioned elsewhere

4/29/2024

1 Year In

500.4: Cybersecuritygovernance 500.15: Encryption 500.16: Incident response and business continuity 500.19(a): Small businesses increased requirements (MFA, cybersecurity training)

11/1/2024

18 Months In

500.5(a)(2): Automated information systems scan requirements 500.7: Access privileges & management; Class A requirements to monitor privileged access, implement PAM and commonly-used password blocking 500.14(a)(2): protect against malicious code 500.14(b): Class A requirements for EDR and SIEM

5/1/2025

2 Years in

500.12: MFA 500.13(a): Asset Inventory

5/1/2025
I BUILT MY SITE FOR FREE USING