Reg S-P Deadline Is June 3. Here’s What Your Firm Still Needs to Build.
If your firm manages less than $1.5 billion in AUM, June 3, 2026 is your compliance deadline for the SEC’s amended Regulation S-P. That date is weeks away. And based on what we’re seeing across the industry, a significant number of RIAs are treating this as an IT project, assuming their existing privacy policy covers it, or working from a generic template their compliance provider handed them.
None of those positions hold up under examination.
Here is what the rule actually requires, where most firms have gaps, and what you need to build before the deadline.
This Is Not a Privacy Notice Update
Regulation S-P has been on the books since 2000, and most firms have treated it accordingly: update the privacy notice, include it in the compliance manual, move on. That approach no longer reflects what the rule demands.
The SEC updated Reg S-P because the compliance landscape changed. Data breaches have increased dramatically over the past five years. Firms are relying on more outside vendors than ever to fill operational gaps. And the SEC’s examination posture has shifted from reviewing what your policies say to testing whether your program actually works.
The amended rule requires a formal incident response plan, mandatory client notification, vendor oversight with enforceable contract requirements, expanded data mapping, and secure disposal protocols. Taken together, this is a system your firm has to build, not a checklist to complete.
The Four Requirements That Matter
1. A Written Incident Response Plan
This is the centerpiece of the amended rule, and it is where most firms are most unprepared. Many firms either have nothing in place or are relying on a generic template that does not reflect their actual operations. That will not be sufficient.
The real question is not whether a document exists. It is whether your team could actually execute if an incident happened tomorrow. Could you detect what was accessed? Stop the breach? Remediate? Notify clients within the required window?
The plan needs to address investigation, which means identifying what data was accessed and how. It needs to address containment, which means stopping the breach through password updates, system patches, or other measures specific to your environment. And it needs to address remediation, which means fixing what broke and documenting what you did. For smaller firms without in-house IT resources, this means having a relationship with an outside IT vendor who can actually conduct that investigation, not just provide general security support.
2. Client Notification Within 30 Days
If sensitive customer information was accessed, or was reasonably likely to have been accessed, affected clients must be notified within 30 days of the firm determining a breach occurred. The rule defines sensitive information broadly. It is not limited to Social Security numbers. Login credentials, account access information, and any data that could reasonably be used to access nonpublic personal information all fall within scope. When in doubt, assume notification is required.
There is one area that consistently creates compliance exposure: when firms decide notification is not necessary, that decision must be documented. The investigation steps, the reasoning, the conclusion. A firm that experienced a potential incident and concluded no notification was needed, without written rationale, has a significant gap in its compliance record regardless of whether the conclusion itself was correct. The documentation is what protects the firm, not the conclusion alone.
3. Vendor Oversight With Real Contract Requirements
This is the area that requires the most immediate operational attention. Firms that have been in business for any length of time have accumulated vendors: custodians, CRM systems, portfolio management platforms, cloud storage, financial planning tools. Each one that handles client data is now your regulatory responsibility under amended Reg S-P.
Contracts with those vendors need to require written notification within 72 hours of discovering a breach involving your customer information. Most existing agreements, particularly those established before June 2024, do not include this language. They need to be reviewed, renegotiated, or amended before the deadline.
Vendor oversight is also not a one-time exercise. Initial due diligence when onboarding a vendor is a starting point, not a finish line. Ongoing monitoring matters, and that includes understanding whether a vendor has had any security incidents, what their remediation looked like, and whether they are prepared to meet the Reg S-P requirements themselves.
One area that is commonly overlooked: what happens to your client data if a vendor goes out of business? Firms that were early adopters of newer technology platforms need to understand, in writing, how that data is handled if the vendor shuts down.
4. Data Mapping
Everything else depends on this. If you do not know what client data you have, where it lives, who has access to it, and how it flows between systems and vendors, you cannot build an incident response plan, you cannot conduct meaningful vendor oversight, and you cannot respond to a breach within the required timeframe.
For firms that have been operating for years, data mapping is often a significant undertaking. Systems change, employees come and go, and data migrates across platforms over time. Access permissions that made sense five years ago may not reflect current operations. This is foundational work, and it takes time.
What the SEC Will Actually Ask For
When an examiner reviews Reg S-P compliance, they will request documents and then test whether the answers match reality. They will ask for your compliance manual, your safeguards policies, your vendor contracts, and your cybersecurity risk assessment. Most firms cannot produce that last one today.
Examiners will also conduct interviews. That means the CCO or owner needs to be able to articulate what the cybersecurity policy is, how the incident response plan works, and how the firm’s actual processes map to the rule. A policy document that no one can explain is a red flag, not a defense.
The SEC is also looking for evidence of testing. An email review program that produces no findings month after month is not evidence of a clean firm. It may be evidence that the review is not substantive. The same principle applies here: your incident response plan needs to be tested, your vendor list needs to be reviewed regularly, and your staff needs to be trained, retrained, and tested again. Implementation is not a one-month project.
Disposal Requirements
This one is routinely overlooked. Firms must securely dispose of customer data, and contracts with vendors need to address how vendors dispose of data when the relationship ends. The question of whether a vendor is actually deleting your data when you terminate a contract, rather than retaining it, is not theoretical. It should be addressed explicitly in your agreements and verified, not assumed.
What Needs to Be in Place by June 3
- A written incident response plan tailored to your firm’s actual operations, not a template
- A documented cybersecurity risk assessment
- A complete and current vendor list with confirmed 72-hour breach notification language in all relevant contracts
- A data mapping exercise that identifies where client data lives, who has access, and how it moves
- Staff training on incident response protocols and escalation procedures
- A recordkeeping system that captures policies, vendor oversight activities, incident logs, and notification decisions for five years
What Comes Next
Larger RIAs met their Reg S-P compliance date in December 2025. For firms under $1.5 billion in AUM, June 3 is the date. There is no extension on the horizon, and given the SEC’s current examination focus on cybersecurity and data protection, this is an area where exam readiness will be evaluated.
This is not theoretical compliance. It is operational. You are building programs, not filing paperwork. And the firms that are positioned well will be the ones that started treating it that way months ago.
If your firm has gaps, the window to close them is narrow. My RIA Lawyer works with RIAs to build compliance programs structured to meet current regulatory expectations and hold up under examination. Reach out to start the conversation.
