Technology governance

Regulation S-P Now Applies to Every SEC-Registered Adviser. Here Is What Changed for a Small Firm.

My firm is small. Does the amended Regulation S-P apply to us, and what do we actually have to do?

Yes, it applies to you. Since June 3, 2026, amended Regulation S-P (17 CFR 248.30) has applied to every SEC-registered investment adviser regardless of size. A firm must maintain written safeguards for customer information, run a written incident response program, notify affected individuals within 30 days of becoming aware of a breach of sensitive customer information, oversee service providers with due diligence and monitoring, and keep records of all of it under Rule 204-2(a)(25). This article walks the rule paragraph by paragraph and ends with what a small firm should do this quarter and what the file should contain.

Key facts

  • Amended Regulation S-P took effect for SEC-registered advisers with $1.5 billion or more in assets under management on December 3, 2025, and for all other SEC-registered advisers on June 3, 2026.
  • Regulation S-P requires an adviser to notify each affected individual "as soon as practicable, but not later than 30 days" after becoming aware that unauthorized access to customer information has occurred or is reasonably likely to have occurred.
  • An adviser's policies must be reasonably designed to ensure a service provider notifies the adviser "as soon as possible, but no later than 72 hours" after the provider becomes aware of a breach of a customer information system the provider maintains.
  • The duty to ensure affected individuals are notified stays with the adviser even when a service provider is involved.
  • Rule 204-2(a)(25) requires SEC-registered advisers to keep the written policies, incident documentation, notification determinations, and any service-provider agreements made under Regulation S-P.
  • State-registered advisers are generally outside Regulation S-P and inside the FTC Safeguards Rule, which has its own notification requirement.

Regulation S-P has covered every SEC-registered adviser, regardless of size, since June 3, 2026

Regulation S-P's safeguards rule, 17 CFR 248.30, applies to every "covered institution," which the rule defines to include "any investment adviser or transfer agent registered with the Commission" alongside broker-dealers and investment companies (248.30(d)(3)). Registration with the SEC is the test, not size. The 2024 amendments set two compliance dates: December 3, 2025 for larger entities, which for investment advisers means $1.5 billion or more in assets under management, and June 3, 2026 for everyone else. Both dates have passed. A two-person SEC-registered adviser is now under the same rule as a national firm. A state-registered adviser is not a covered institution under Regulation S-P; for a state-registered adviser the federal safeguards obligation comes from the FTC Safeguards Rule, which is addressed at the end of this article.

The amended rule requires four written documents, and none of them can be generic

Regulation S-P requires four written things. First, written policies and procedures "that address administrative, technical, and physical safeguards for the protection of customer information" (248.30(a)(1)), reasonably designed to ensure security and confidentiality, protect against anticipated threats, and protect against unauthorized access that could cause substantial harm or inconvenience (248.30(a)(2)). Second, as part of those policies, a response program "reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information, including customer notification procedures" (248.30(a)(3)). Third, within that response program, written policies for oversight of service providers (248.30(a)(5)(i)). Fourth, written policies for proper disposal of consumer and customer information (248.30(b)(2)). For a small firm these can be short. What they cannot be is absent, and they cannot be generic documents that do not describe what the firm actually does.

The incident response program must assess the incident, contain it, and decide on notice

The response program under 17 CFR 248.30(a)(3) must include procedures to do three things. Assess the nature and scope of any incident and identify the customer information systems and types of customer information involved. Take appropriate steps to contain and control the incident. And notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, unless the adviser determines after a reasonable investigation that the information "has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience." That last determination is a decision the firm makes and documents; it is not automatic. Rule 204-2(a)(25)(iii) requires the adviser to keep "the written documentation of any investigation and determination made regarding whether notification is required," including the basis for the determination.

The 30-day notification clock starts when the adviser becomes aware, not when the investigation ends

Regulation S-P requires an adviser to provide notice to affected individuals "as soon as practicable, but not later than 30 days, after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred" (17 CFR 248.30(a)(4)(iii)). Three features of that sentence matter for a small firm. The clock starts at awareness, not at confirmation. The trigger is unauthorized access to customer information generally, while the duty to notify runs to individuals whose sensitive customer information was involved. And 30 days is the outer limit, not the target; the rule says "as soon as practicable." The only permitted delay is a written determination by the United States Attorney General that notice poses a substantial risk to national security or public safety, which is not a scenario a small advisory firm should plan around. If the firm cannot identify which individuals were affected, it must notify everyone whose sensitive customer information resides in the affected system (248.30(a)(4)(ii)). The Regulation S-P clock computes both deadlines from the dates a firm enters, in the browser, without sending anything anywhere.

The notice to affected individuals has required contents, and it can be drafted in advance

Regulation S-P specifies the contents of the notice (17 CFR 248.30(a)(4)(iv)). It must describe the incident and the type of sensitive customer information involved in general terms; give the date, estimated date, or date range if reasonably possible; provide contact information including a telephone number, an email address or equivalent, a postal address, and the name of a specific office to contact; recommend that account holders review statements and report suspicious activity; explain what a fraud alert is and how to place one; recommend periodic credit reports and explain how to obtain them free of charge; and point to Federal Trade Commission and usa.gov guidance on identity theft. A small firm can draft this notice once, in advance, with blanks for the incident-specific details, and keep it with the incident response program. Writing it during an incident is the wrong time.

Sensitive customer information covers most of what a client file contains

Regulation S-P defines sensitive customer information as "any component of customer information alone or in conjunction with any other information, the compromise of which could create a reasonably likely risk of substantial harm or inconvenience to an individual" (17 CFR 248.30(d)(9)(i)). The rule's examples include Social Security numbers, driver's license and passport numbers, biometric records, account numbers, and a name or username combined with authenticating information such as a security question, a partial Social Security number, or a date of birth (248.30(d)(9)(ii)). For an advisory firm the practical reading is that nearly every client file contains sensitive customer information, because client files contain account numbers alongside names and dates of birth. The definition is what makes the notification duty apply to most incidents involving client records, not only to incidents involving Social Security numbers.

The 72-hour service-provider clock starts when the provider becomes aware, not when the firm does

The service-provider provision of Regulation S-P, 17 CFR 248.30(a)(5), is the one most often misdescribed, so the rule's own words come first. An adviser's response program "must include the establishment, maintenance, and enforcement of written policies and procedures reasonably designed to require oversight, including through due diligence and monitoring, of service providers" (17 CFR 248.30(a)(5)(i)). Those policies must be reasonably designed to ensure service providers protect customer information and "provide notification to the covered institution as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the service provider" (248.30(a)(5)(i)(B)). Three points follow. The rule requires policies, diligence, and monitoring; it does not require a contract clause, although a clause is the easiest evidence that diligence happened. The 72 hours runs from when the provider becomes aware, and applies to a breach of a system the provider maintains. And a service provider is only an entity that "receives, maintains, processes, or otherwise is permitted access to customer information" through services to the adviser (248.30(d)(10)); a vendor that never touches customer information is not one. Whatever the provider promises, the duty to ensure clients are notified "rests with the covered institution" (248.30(a)(5)(iii)). What nineteen AI vendors actually publish on this point is in If Your AI Vendor Is Breached, You Have Thirty Days to Tell Your Clients.

Rule 204-2(a)(25) requires an adviser to keep six kinds of Regulation S-P records for five years

The 2024 amendments added paragraph (a)(25) to Rule 204-2, the adviser books-and-records rule. An SEC-registered adviser must make and keep: the written safeguards policies required by 248.30(a)(1); written documentation of any detected unauthorized access and of the response and recovery; written documentation of any investigation and determination about whether notification was required, including the basis, any Attorney General correspondence, and a copy of any notice sent; the written service-provider oversight policies required by 248.30(a)(5)(i); written documentation of any contract or agreement entered into under 248.30(a)(5); and the written disposal policies required by 248.30(b)(2) (17 CFR 275.204-2(a)(25)(i) through (vi)). These records fall under the general retention rule in 204-2(e)(1): five years from the end of the fiscal year of the last entry, the first two in an appropriate office of the adviser. A firm that has done the work but cannot produce these documents has, for examination purposes, not done the work.

What should a small SEC-registered adviser do this quarter?

A small SEC-registered adviser can meet amended Regulation S-P with five actions, in order. Write the safeguards policy in plain language describing the systems the firm actually uses, who has access, and how access is removed when someone leaves. Write the incident response program as a checklist: who is called, how the scope is assessed, how the incident is contained, how the notification determination is made and documented, and who sends the notice. Draft the client notice now with the incident-specific fields blank. List every vendor that receives, maintains, processes, or can access client information, ask each in writing what it commits to on breach notification and where that commitment is written (the nine questions are the short form), and file the answers. Write the disposal policy, including what happens to laptops and phones when they are retired. None of these needs to be long. All of them need to exist, describe reality, and be dated.

What should the Regulation S-P file contain when an examiner asks?

For the compliance officer at an SEC-registered adviser, the Regulation S-P examination question will be whether the program is written, whether it is reasonably designed, and whether it was followed. The record that answers all three contains the dated policies; the vendor inventory with each vendor's written notification commitment and the date it was obtained; any incident file with the scope assessment, containment steps, the notification determination and its basis, and the notice sent; and the annual review of the policies under Rule 206(4)-7, noting any change. Vendor answers should be filed with the vendor contract, because Rule 204-2(a)(25)(v) makes any agreement under 248.30(a)(5) a required record in its own right. The vendor side of that file is the subject of the Technology governance articles as a set. The single cheapest control that keeps most firms out of this file altogether is two-factor authentication on every account that touches client files.

Which rule applies if the adviser is state-registered instead of SEC-registered?

Regulation S-P covers advisers registered with the SEC. An adviser registered with a state is generally a "financial institution" under the FTC Safeguards Rule (16 CFR part 314), which requires a written information security program and, since May 13, 2024, notice to the FTC within 30 days of discovering a notification event involving the unencrypted information of at least 500 consumers. The Safeguards Rule's notice runs to the regulator; notice to affected individuals under it comes from state breach-notification statutes, which vary. A state-registered adviser should treat the structure of this article as applicable and the citations as not: written program, incident procedures, vendor oversight, and records, under the FTC rule and state law rather than Regulation S-P. The Safeguards Rule path sorts the elements of 16 CFR 314.4 for a state-registered firm, including the small-firm exemptions in 16 CFR 314.6. Registration status is the first question to settle; confirm it with counsel before choosing which rule to build the program around.

Questions

Does Regulation S-P apply to an SEC-registered adviser with two employees?

Yes. Since June 3, 2026, 17 CFR 248.30 applies to every investment adviser registered with the SEC. The only size distinction in the 2024 amendments was the compliance date, which was December 3, 2025 for advisers with $1.5 billion or more in assets under management and June 3, 2026 for all others.

Do I have to put a 72-hour clause in every vendor contract?

No. Regulation S-P requires written policies reasonably designed to ensure service providers notify you within 72 hours, "including through due diligence and monitoring." A written clause is the simplest evidence of diligence, but the rule does not mandate one.

When does the 30-day clock start?

When the firm becomes aware that unauthorized access to customer information "has occurred or is reasonably likely to have occurred." It does not wait for the investigation to finish. The rule also says "as soon as practicable," so 30 days is the limit, not the plan.

Is every software vendor a service provider under Regulation S-P?

No. A service provider is an entity that receives, maintains, processes, or is permitted access to customer information through services it provides to the firm (17 CFR 248.30(d)(10)). A tool that never receives client information is not a service provider under the rule.

What if we investigate and conclude no harm is likely?

Regulation S-P permits a firm to forgo notice if, after a reasonable investigation, it determines the sensitive customer information has not been and is not reasonably likely to be used in a manner resulting in substantial harm or inconvenience. That determination and its basis must be documented and kept under Rule 204-2(a)(25)(iii).

Advisor Insights provides general professional information, not individualized investment, legal, cybersecurity, or compliance advice. Whether and how the rules described apply to your firm depends on your registration, systems, and contracts, and should be confirmed with counsel. Regulatory descriptions are U.S. federal and current as of September 2026.

Primary sources

General information from ValaisOS LLC, not legal, compliance, tax, or investment advice. Confirm requirements for your firm with counsel. See Terms of Use.

ValaisOS is building a more enduring operating foundation for private-wealth professionals.

Request early access