Reg S-P overview › FY2026 exam priorities
The SEC's Division of Examinations publishes its priorities once a year, and the fiscal-year 2026 edition was released on November 17, 2025. It names the 2024 Regulation S-P amendments explicitly — twice in the press release and in a dedicated subsection of the document itself. This page reproduces the operative language rather than paraphrasing it, and then reads it from the position most of our audience is actually in: a solo or small SEC-registered adviser, past the June 3, 2026 compliance date, who has never been examined.
Read the disclaimer first — the SEC put one on page ii. The priorities document states, in its own words, that it "represents the views of the staff of the Division of Examinations. It is not a rule, regulation, or statement of the U.S. Securities and Exchange Commission… it does not alter or amend applicable law, and it creates no new or additional obligations for any person." Nothing on this page changes what the rule requires. The priorities are useful because they tell you where staff attention is going, not because they add obligations.
Regulation S-P appears in Section VII.A.2 of the document, "Regulation S-ID and Regulation S-P," inside the broader "Information Security and Operational Resiliency" risk area. The two sentences that matter most for advisers:
"The Division will assess compliance with Regulations S-ID and S-P, as applicable. Examinations will focus on firms' policies and procedures, internal controls, oversight of third-party vendors, and governance practices."
— SEC Division of Examinations, Examination Priorities: Fiscal Year 2026, § VII.A.2
"In preparation for the compliance dates for the Commission's amendments to Regulation S-P, the Division will engage firms during examinations about their progress in preparing incident response programs reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. After the applicable compliance dates, the Division will examine whether firms have developed, implemented, and maintained policies and procedures in accordance with the rule's new provisions that address administrative, technical, and physical safeguards for the protection of customer information."
— same document, § VII.A.2
The press release accompanying the priorities put the same point in one line: for fiscal year 2026, alongside core areas such as fiduciary duty and the custody rule, "the Division will also examine for compliance with new rules, such as the 2024 amendments to Regulation S-P."
Look again at the second quote. It contains two different postures separated by one clause, and which side of that clause you are on is determined by a date, not by your firm's size or readiness:
| Posture | The document's words | Who is here now |
|---|---|---|
| Before the applicable compliance date | The Division will "engage firms … about their progress in preparing" an incident response program. | Nobody, as of this writing. Larger entities passed December 3, 2025; smaller entities passed June 3, 2026. |
| After the applicable compliance date | The Division will "examine whether firms have developed, implemented, and maintained policies and procedures in accordance with the rule's new provisions." | Every covered institution, including every SEC-registered adviser under $1.5B in regulatory AUM, since June 3, 2026. |
"Progress in preparing" is a conversation. "Developed, implemented, and maintained" is a document request. The distinction is worth internalizing because a lot of the commentary written in late 2025 — when the smaller-entity date was still six months out — was describing the first posture, and is still circulating. If you are a smaller entity reading a 2025 article that says examiners will ask how your preparation is going, that framing expired on June 3, 2026. See the smaller-entity deadline page for what the date itself changed.
Note the third verb, too. Maintained is not satisfied by a policy adopted the week before the date and never touched since. It is the word that makes dated evidence — a review log, a drill record, a vendor register with dates on it — worth more than a longer policy document.
The first quote names four things by name. Mapping them to artifacts a one-to-five-person firm can realistically produce:
| Named focus | What it means under Reg S-P | What a small firm can put on the table |
|---|---|---|
| Policies and procedures | The written incident response program, and the expanded safeguards and disposal policies. | A dated written IRP covering detect / respond / recover, plus safeguards and disposal policies that reach the broadened "customer information" scope. See the IRP outline. |
| Internal controls | Whether the written thing corresponds to anything you actually do. | Access reviews, MFA and offboarding records, a tabletop-drill log with a date on it. An unexercised IRP and an exercised one look identical on paper and different in a file. |
| Oversight of third-party vendors | The rule's service-provider element — reasonable steps, through due diligence and monitoring, to see that providers protect covered information and notify you of a breach in time for you to meet your own clock. | A vendor register naming each provider that touches customer information, the contract language or attestation covering breach notification, and dates of review. See service-provider oversight. |
| Governance practices | Who owns this, who reviewed it, and when. | In a solo firm the honest answer is "me" — write that down with a review date rather than leaving the ownership line blank. Governance in a two-person shop is a signature and a calendar entry, not a committee. |
Everything above has to be findable later, which is the point of the rule's separate recordkeeping requirement — for investment advisers, five years, the first two in an easily accessible place.
Solo or small RIA? AdviserLedger keeps the Reg S-P paper trail as a short, dated set of records — IRP, incident log, notification-decision template, and a vendor register — so "developed, implemented, and maintained" has dates attached to it. The beta waitlist is open; planned pricing is $249/year.
Get Reg S-P ready →The Reg S-P subsection is not the only part of the FY2026 priorities that matters to a small firm. Section I.C is three sentences long and easy to skim past:
"As with previous years, the Division will prioritize examinations of advisers that have never been examined, with particular emphasis on recently registered advisers."
— same document, § I.C, "Never-Examined Advisers and Recently Registered Advisers"
Put the two sections side by side. The Division has said it will prioritize never-examined and recently registered advisers, and it has said that after the compliance date it will examine whether firms developed, implemented and maintained Reg S-P policies and procedures. Smaller advisers are heavily represented in the never-examined population, and the smaller-entity compliance date is the more recent of the two. [Inference — this is our reading of two separate sections read together, not a statement the Division made. The document names each priority independently and does not describe them as a combined focus.]
The Chairman's framing in the accompanying press release is worth keeping in view alongside that: examinations "should not be a 'gotcha' exercise," and the release describes the priorities as intended to let firms "prepare to have a constructive dialogue with SEC examiners." That is a reason to have the file assembled, not a reason to panic about it.
Section VII.A.2 covers both, and the phrase "as applicable" is doing real work. Regulation S-ID concerns a written Identity Theft Prevention Program aimed at red flags in covered accounts — the priorities say the Division will look at whether such programs are "reasonably designed to identify and detect red flags, particularly during customer account takeovers and fraudulent transfers" and whether they "include firm training on identity theft prevention." That is a different program, from a different rule, with different applicability tests. A firm that folds its Reg S-ID obligations into its Reg S-P IRP and calls it one document should be able to explain how each rule's elements are covered. Whether Reg S-ID applies to your firm at all turns on the rule's own definitions — confirm it rather than assuming either way.
Section VII.A.1 is its own item, and it is broader than the rule: governance practices, data loss prevention, access controls, account management, response and recovery including ransomware, plus training and controls around risks associated with artificial intelligence. Being able to produce a Reg S-P IRP does not close out the cybersecurity item, and the two are listed as separate subsections for a reason.
The SEC's fiscal year 2026 runs to September 30, 2026, so as of this review there is roughly one month left in the period these priorities describe. In recent years the following year's priorities have been published in the autumn — the FY2026 edition landed on November 17, 2025. Treat this page as current for the FY2026 window and re-check when the next edition is released; the underlying rule obligations do not move with the fiscal year, but staff focus areas can. [Inference — based on the FY2026 publication date; we are not stating when FY2027 priorities will be released.]
Related on this site: the Reg S-P overview for small RIAs · does Reg S-P apply to my RIA? · the June 3, 2026 smaller-entity deadline · writing the incident response program · service-provider oversight · the four records you have to keep · Reg S-P vs. state breach notification laws. · the written disposal policy — a document an examiner can ask for that many small firms have never drafted · privacy notices — the older half of Reg S-P, and still examinable · Regulation S-ID — the other half of the same FY2026 subsection (VII.A.2 is headed "Regulation S-ID and Regulation S-P," and names S-ID first), with the two focus points the priorities call out for it