Get Reg S-P ready →

Reg S-P overview › Compliance deadline

The smaller-entity Reg S-P deadline (June 3, 2026) has passed — here's what that means

Last reviewed July 19, 2026 · official SEC sources linked below

If you run a small SEC-registered advisory firm and you've been treating the amended Regulation S-P as a future project, the future arrived on June 3, 2026. That was the compliance date for "smaller entities," and it is now behind us. The rule doesn't have a grace period built in — enforceability turned on that date. This page is the plain-English version of where that leaves you: who the deadline applied to, the five things the rule now expects you to have, how to tell in an afternoon whether you're actually behind, and a sensible order to close the gaps if you are.

The one-line version: since June 3, 2026 a covered smaller RIA is expected to have a written incident response program, a customer-notification process, documented service-provider oversight, and updated safeguards and disposal policies — the same obligations larger firms have had to meet since December 3, 2025.

The two compliance dates

The SEC adopted the Regulation S-P amendments on May 16, 2024. They were published in the Federal Register on June 3, 2024, and the tiered compliance clock ran from there.

TierWhoCompliance date
Larger entitiesCovered institutions above the smaller-entity thresholdsDecember 3, 2025 (18 months after publication) — passed
Smaller entitiesIncludes SEC-registered investment advisers with under $1.5 billion in regulatory assets under managementJune 3, 2026 (24 months after publication) — passed

If you're an SEC-registered adviser under $1.5B in RAUM, you fell in the smaller-entity tier, and your date was June 3, 2026. Broker-dealers, funding portals, registered investment companies and transfer agents are also "covered institutions" under the rule, with their own size lines — the $1.5B figure is the adviser cutoff. Note that this threshold set your deadline, not whether the rule applies: there is no AUM floor that exempts a small RIA — see does Reg S-P apply to my RIA?

Don't confuse this with the separate "small entity" proposal. In January 2026 the SEC proposed changing the Regulatory Flexibility Act definitions of "small business" for advisers (a $1B AUM line has been discussed). That is a different definition used for regulatory-analysis purposes and, as a proposal, is not the operative Reg S-P compliance threshold. For the June 3, 2026 deadline, the smaller-entity line that mattered was the under-$1.5B-RAUM adviser threshold. Confirm your own status against the current rule text.

The five obligations that are now live

The amendments don't add a single deliverable — they add a small system. In rough order of what an examiner would ask to see:

#ObligationWhat "compliant" looks like for a small firm
1Written incident response programA written IRP inside your safeguards policies covering assessment, containment, and — where required — customer notification. Not a slide; a document.
2Customer notificationA process to notify affected individuals as soon as practicable, and no later than 30 days after you become aware that unauthorized access to or use of sensitive customer information has occurred or is reasonably likely, with the notice content the rule specifies.
3Service-provider oversightReasonable steps — through due diligence and monitoring — to see that service providers protect covered information and notify you of a breach so you can meet your own notification clock.
4Expanded safeguards & disposalWritten safeguards policies extended to "customer information," and the disposal rule applied to consumer information you hold, including from other institutions.
5RecordkeepingRecords documenting the above — the policies, and evidence they're maintained — kept per the rule's recordkeeping requirement (advisers: five years, first two easily accessible).

A 20-minute self-check

You don't need a consultant to find out whether you're behind. Ask, honestly:

  1. Can you produce a written incident response program today — a file, dated, that someone at the firm owns?
  2. If a laptop with client data were stolen tonight, is there a written path that ends in notifying affected clients within the rule's window — and do you know what that notice has to say?
  3. For each vendor that touches client data (custodian, CRM, portfolio tool, email, cloud storage), do you have anything on file showing you assessed their safeguards and their breach-notification behavior?
  4. Do your safeguards and disposal policies reference the broader "customer information" scope, not just the older narrower language?
  5. Could you hand an examiner records showing all of the above exists and is maintained?

A "no" or "not in writing" to any of these is a gap that was due to be closed by June 3, 2026.

If you're behind: a catch-up order of operations

Behind is common and fixable. The point now is to close the highest-risk gaps first and document as you go, rather than freeze because the date slipped.

  1. Write the IRP first. It's the spine everything else hangs on and the single document most small firms still lack. Our section-by-section IRP outline walks the required elements in incident order.
  2. Draft the customer notice now, not during an incident. The rule specifies the minimum content; pre-drafting a skeleton means the 30-day clock is a fill-in exercise, not a scramble. See what the breach notice must contain.
  3. Inventory vendors and get breach-notification terms in writing. You can't meet your own clock if a vendor sits on a breach for weeks.
  4. Update safeguards and disposal policies to the amended scope, and calendar a periodic review so they don't go stale.
  5. Keep the records. Dated policies plus evidence of maintenance is what "compliant" is made of.

For the full picture of all five obligations and who counts as a smaller entity, start with the plain-English Reg S-P overview.

Solo or small RIA and past the date? AdviserLedger turns the amended Reg S-P into a short, dated checklist — IRP, customer-notice skeleton, vendor log, and review reminders — so "behind" becomes a finite list. The beta waitlist is open; planned pricing is $249/year.

Try AdviserLedger free →

Related on this site: what the SEC's FY2026 exam priorities say about Reg S-P — what changed in examination posture once this date passed · Reg S-P vs. state breach notification laws — the five places they diverge. · the written disposal policy — an easily-missed item on the catch-up list, because § 248.30(b)(2) requires its own document · your privacy notice — worth re-reading against the safeguards policies you just rewrote

Official sources