Get Reg S-P ready →

Reg S-P amendments for small RIAs: the deadline has passed — here's exactly what your firm is now required to have

Last reviewed July 8, 2026 · sourced to SEC, FINRA and law-firm guidance (linked below)

The SEC's May 2024 amendments to Regulation S-P became enforceable for "smaller entities" — including SEC-registered investment advisers with under $1.5 billion in AUM — on June 3, 2026. Larger firms have been subject to them since December 3, 2025. If you run a solo or small RIA, the five obligations below are no longer "upcoming" — they are current requirements your next exam can test. Here they are in plain English.

The five obligations, at a glance

RequirementWhat it means for a small RIA
1. Written incident response programWritten policies and procedures reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. A generic cybersecurity policy is not the same thing — the program must cover assessment, containment, and recovery steps.
2. 30-day customer notificationIf sensitive customer information was (or is reasonably likely to have been) accessed or used without authorization, affected individuals must be notified as soon as practicable, but no later than 30 days after you become aware — unless you determine the information is not reasonably likely to be used in a way that causes substantial harm or inconvenience.
3. Service provider oversightWritten policies requiring due diligence and monitoring of service providers (custodian, portfolio software, CRM, IT vendor, cloud storage). Your arrangements must be designed so providers protect customer information and notify you within 72 hours of discovering a breach of a system they maintain on your behalf. See the deep dive: Reg S-P service-provider oversight, explained, and the vendor-by-vendor due diligence checklist.
4. Expanded scope: "customer information"The safeguards and disposal rules now cover the newly defined term customer information — any record containing nonpublic personal information about a customer, in any form, that you hold or a service provider holds for you. It includes information about individuals who are customers of other financial institutions when that data is in your possession.
5. RecordkeepingWritten records evidencing compliance: the incident response program itself, records of any incidents and the response (investigation, notification determinations), service provider oversight documentation, and disposal practices. For RIAs these records sit inside the books-and-records regime — treat five years as the working retention floor.

The gap for most solo firms isn't the policy — it's the evidence. AdviserLedger turns the Reg S-P paper program into an exercised, timestamped record: IRP builder, drill log, vendor attestations, and the 72-hour/30-day clocks.

See how it works →

Who counts as a "smaller entity" (June 3, 2026 group)?

Everyone else — including RIAs at or above $1.5B AUM — was in the December 3, 2025 group. Practical consequence: the "overwhelming majority" of the ~16,000 SEC-registered advisers are smaller entities, and their compliance date has now passed.

The 30-day clock vs. the 72-hour clock — don't confuse them

72 hours is the service-provider-to-you notice: your vendor arrangements must be designed so a provider tells you no later than 72 hours after becoming aware of a breach of a customer-information system it maintains on your behalf.

30 days is the you-to-your-clients notice: once you become aware that sensitive customer information was or likely was accessed without authorization, affected individuals get notice as soon as practicable, and no later than 30 days — including what happened, what data was involved, and what steps they can take.

The two clocks chain together: a vendor breach can start your 30-day customer clock even though the incident happened entirely on the vendor's systems. That is exactly why the rule pairs oversight duties with the notification duty.

A practical first-week checklist for a solo/small RIA

  1. Inventory customer information — where it lives (custodian portal, CRM, email, laptops, cloud drives) and which vendors touch it.
  2. Adopt the written IRP — detect / respond / recover, with named responsibilities (in a solo firm, that's you — write it down anyway; the exam looks for the document).
  3. Paper the vendor leg — confirm each provider's breach-notification commitment meets the 72-hour standard; keep the attestation or contract language on file.
  4. Pre-draft the customer notice — a fill-in-the-blank template cuts the 30-day window stress dramatically.
  5. Exercise it once — run a tabletop drill and log it. An IRP that has never been exercised is a dead PDF; a dated drill log is compliance evidence.
  6. Update your disposal procedures — the disposal rule now covers the full customer-information scope, paper and electronic.

Sources

Related on this site: does Reg S-P even apply to my small RIA? — who's a covered institution and which client data counts (no AUM exemption) · the June 3, 2026 smaller-entity deadline — what it means now that it's passed, and a catch-up sequence · writing the Reg S-P incident response program — a section-by-section IRP outline · the customer breach notice — what it must say, with a template outline · the recordkeeping requirement — the four records you must keep and the 5-year / first-2-accessible adviser retention rule · Reg S-P vs. state breach notification laws — the five places they diverge · what the SEC's FY2026 exam priorities say about Reg S-P. · the privacy-notice half of Reg S-P — §§ 248.4–248.9 were not amended in 2024 and are the obligations this overview does not cover · the disposal rule after 2024 — the one obligation triggered by ordinary hardware decisions rather than by an incident · Regulation S-ID — the separate written Identity Theft Prevention Program that sits in Subpart C of the same CFR part, was not amended in 2024, and is named alongside Reg S-P in the FY2026 exam priorities

Related: the other recurring deadlines. Reg S-P is the securities-regulator clock. A registered investment adviser organized as an LLC or corporation runs a second, unrelated one: the state entity annual report that keeps the legal entity in good standing. It is filed with the state business-filing office, not the SEC or the state securities regulator, and lapsing it is a separate problem from any Reg S-P finding.

The recurring compliance deadlines a small U.S. business actually has (2026) — a plain-language overview of the four clocks (entity annual report, contractor license & CE, W-2 tips/overtime, Reg S-P), each with its official source. General information, not legal or tax advice.