ValaisOS tool · runs in your browser

Regulation S-P clock

My firm just learned that client information may have been accessed without authorization. What are the deadlines, what must the notice say, and what do I have to write down?

Amended Regulation S-P gives an SEC-registered adviser two clocks after unauthorized access to customer information: a service provider must notify the firm within 72 hours of becoming aware of a breach of a system it maintains, and the firm must notify affected individuals as soon as practicable and no later than 30 days after becoming aware. This page computes both deadlines from the dates you enter, lists what the notice must contain, and lists the records Rule 204-2(a)(25) requires the firm to create along the way. Everything runs in your browser.

Key facts

  • Amended Regulation S-P (17 CFR 248.30) has applied to every SEC-registered investment adviser since June 3, 2026, and to advisers with $1.5 billion or more in assets under management since December 3, 2025.
  • A firm must notify each affected individual "as soon as practicable, but not later than 30 days" after becoming aware that unauthorized access to customer information has occurred or is reasonably likely to have occurred (248.30(a)(4)(iii)).
  • A firm's policies must be reasonably designed to ensure a service provider notifies the firm "as soon as possible, but no later than 72 hours" after becoming aware of a breach of a customer information system the provider maintains (248.30(a)(5)(i)(B)).
  • The duty to ensure affected individuals are notified stays with the firm even when a service provider is involved (248.30(a)(5)(iii)).
  • Rule 204-2(a)(25) requires the firm to keep the incident documentation, the notification determination and its basis, and a copy of any notice sent.

Enter the dates your firm knows

Both fields are optional. Enter what you know; the page computes the deadlines the rule attaches to each date. Times are interpreted in your browser's local time zone.

This starts the firm's 30-day clock under 17 CFR 248.30(a)(4)(iii).

This starts the provider's 72-hour notification window under 17 CFR 248.30(a)(5)(i)(B). Leave blank if the incident was on the firm's own systems.

What the notice to affected individuals must contain

17 CFR 248.30(a)(4)(iv) specifies the contents. Draft the notice in advance with the incident-specific fields blank; writing it during an incident is the wrong time.

  • A general description of the incident and the type of sensitive customer information that was, or is reasonably believed to have been, accessed or used without authorization.
  • The date, the estimated date, or the date range of the incident, if reasonably possible to determine when the notice is provided.
  • Contact information sufficient for the individual to inquire: a telephone number (toll-free if available), an email address or equivalent, a postal address, and the name of a specific office to contact.
  • If the individual has an account with the firm, a recommendation to review account statements and report suspicious activity immediately.
  • An explanation of what a fraud alert is and how to place one on credit reports.
  • A recommendation to obtain credit reports periodically from each nationwide credit reporting company and to have fraudulent transaction information deleted.
  • An explanation of how to obtain a credit report free of charge.
  • Information about Federal Trade Commission and usa.gov guidance on identity theft, encouragement to report incidents to the FTC, and the FTC's website address.

What the firm must write down

Rule 204-2(a)(25) (17 CFR 275.204-2(a)(25)) makes these required records for an SEC-registered adviser, retained for five years from the end of the fiscal year of the last entry, the first two in an appropriate office.

  • The written safeguards policies and procedures required by 248.30(a)(1).
  • Written documentation of the detected unauthorized access and of the response to and recovery from it (248.30(a)(3)).
  • Written documentation of the investigation and the determination whether notice was required, including the basis, any Attorney General correspondence about delay, and a copy of any notice sent (248.30(a)(4)).
  • The written service-provider oversight policies required by 248.30(a)(5)(i).
  • Written documentation of any contract or agreement entered into under 248.30(a)(5), including a written agreement for a provider to notify individuals on the firm's behalf.
  • The written disposal policies required by 248.30(b)(2).

If the firm is state-registered instead

Regulation S-P covers advisers registered with the SEC. A state-registered adviser is generally a financial institution under the FTC Safeguards Rule (16 CFR part 314), which requires notice to the FTC within 30 days of discovering a notification event involving the unencrypted information of at least 500 consumers; notice to affected individuals under that regime comes from state breach-notification statutes, which vary. The dates computed above use the Regulation S-P periods and do not apply to a state-registered firm.

Questions

When does the 30-day clock start?

When the firm becomes aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred (17 CFR 248.30(a)(4)(iii)). It does not wait for the investigation to finish, and the rule says as soon as practicable, so 30 days is the limit rather than the plan.

When does the 72-hour clock start?

When the service provider becomes aware that a breach in security has occurred resulting in unauthorized access to a customer information system the provider maintains (17 CFR 248.30(a)(5)(i)(B)). It runs to the firm, not to clients, and it is a standard the firm's policies must be reasonably designed to ensure, not a clause the rule writes into any contract.

Is notice always required?

No. A firm may forgo notice if, after a reasonable investigation, it determines the sensitive customer information has not been and is not reasonably likely to be used in a manner resulting in substantial harm or inconvenience. That determination and its basis must be documented and kept under Rule 204-2(a)(25)(iii).

Does this tool store what I enter?

No. The dates you enter are used only in your browser to compute the deadlines shown. Nothing is transmitted, saved, or measured.

Primary sources

General information from ValaisOS LLC, not legal, compliance, tax, or investment advice. Confirm requirements for your firm with counsel. See Terms of Use.

ValaisOS is building a more enduring operating foundation for private-wealth professionals.

Request early access