Reg S-P overview › Compliance deadline
If you run a small SEC-registered advisory firm and you've been treating the amended Regulation S-P as a future project, the future arrived on June 3, 2026. That was the compliance date for "smaller entities," and it is now behind us. The rule doesn't have a grace period built in — enforceability turned on that date. This page is the plain-English version of where that leaves you: who the deadline applied to, the five things the rule now expects you to have, how to tell in an afternoon whether you're actually behind, and a sensible order to close the gaps if you are.
The one-line version: since June 3, 2026 a covered smaller RIA is expected to have a written incident response program, a customer-notification process, documented service-provider oversight, and updated safeguards and disposal policies — the same obligations larger firms have had to meet since December 3, 2025.
The SEC adopted the Regulation S-P amendments on May 16, 2024. They were published in the Federal Register on June 3, 2024, and the tiered compliance clock ran from there.
| Tier | Who | Compliance date |
|---|---|---|
| Larger entities | Covered institutions above the smaller-entity thresholds | December 3, 2025 (18 months after publication) — passed |
| Smaller entities | Includes SEC-registered investment advisers with under $1.5 billion in regulatory assets under management | June 3, 2026 (24 months after publication) — passed |
If you're an SEC-registered adviser under $1.5B in RAUM, you fell in the smaller-entity tier, and your date was June 3, 2026. Broker-dealers, funding portals, registered investment companies and transfer agents are also "covered institutions" under the rule, with their own size lines — the $1.5B figure is the adviser cutoff. Note that this threshold set your deadline, not whether the rule applies: there is no AUM floor that exempts a small RIA — see does Reg S-P apply to my RIA?
Don't confuse this with the separate "small entity" proposal. In January 2026 the SEC proposed changing the Regulatory Flexibility Act definitions of "small business" for advisers (a $1B AUM line has been discussed). That is a different definition used for regulatory-analysis purposes and, as a proposal, is not the operative Reg S-P compliance threshold. For the June 3, 2026 deadline, the smaller-entity line that mattered was the under-$1.5B-RAUM adviser threshold. Confirm your own status against the current rule text.
The amendments don't add a single deliverable — they add a small system. In rough order of what an examiner would ask to see:
| # | Obligation | What "compliant" looks like for a small firm |
|---|---|---|
| 1 | Written incident response program | A written IRP inside your safeguards policies covering assessment, containment, and — where required — customer notification. Not a slide; a document. |
| 2 | Customer notification | A process to notify affected individuals as soon as practicable, and no later than 30 days after you become aware that unauthorized access to or use of sensitive customer information has occurred or is reasonably likely, with the notice content the rule specifies. |
| 3 | Service-provider oversight | Reasonable steps — through due diligence and monitoring — to see that service providers protect covered information and notify you of a breach so you can meet your own notification clock. |
| 4 | Expanded safeguards & disposal | Written safeguards policies extended to "customer information," and the disposal rule applied to consumer information you hold, including from other institutions. |
| 5 | Recordkeeping | Records documenting the above — the policies, and evidence they're maintained — kept per the rule's recordkeeping requirement (advisers: five years, first two easily accessible). |
You don't need a consultant to find out whether you're behind. Ask, honestly:
A "no" or "not in writing" to any of these is a gap that was due to be closed by June 3, 2026.
Behind is common and fixable. The point now is to close the highest-risk gaps first and document as you go, rather than freeze because the date slipped.
For the full picture of all five obligations and who counts as a smaller entity, start with the plain-English Reg S-P overview.
Solo or small RIA and past the date? AdviserLedger turns the amended Reg S-P into a short, dated checklist — IRP, customer-notice skeleton, vendor log, and review reminders — so "behind" becomes a finite list. The beta waitlist is open; planned pricing is $249/year.
Try AdviserLedger free →Related on this site: what the SEC's FY2026 exam priorities say about Reg S-P — what changed in examination posture once this date passed · Reg S-P vs. state breach notification laws — the five places they diverge. · the written disposal policy — an easily-missed item on the catch-up list, because § 248.30(b)(2) requires its own document · your privacy notice — worth re-reading against the safeguards policies you just rewrote