About

Smaller Entities Face June 3, 2026 Deadline for Reg S-P Amendments

Published
Score
11

Why it matters

The SEC's 2024 amendments to Regulation S-P take effect for smaller financial entities on June 3, 2026—less than three weeks away. The rule overhauls privacy and data safeguarding requirements for registered investment advisers with less than $1.5 billion in assets under management, smaller broker-dealers, and investment companies. Smaller entities must now implement written policies for incident detection, response, and recovery; notify clients of breaches involving sensitive data within 30 days if misuse risk exists; oversee service providers; maintain enhanced records; and properly dispose of customer information. The SEC adopted these amendments on May 16, 2024, with larger firms already complying by December 3, 2025.

The amendments build on the original Regulation S-P framework from 2000 but reflect two decades of technological change and escalating cybersecurity threats. The SEC's Division of Examinations has flagged Reg S-P compliance as a priority for 2026 examinations and has conducted outreach events to prepare the industry. The agency published a small entity compliance guide and staggered deadlines to allow preparation time.

Firms should treat this deadline as imminent. Compliance requires reviewing and updating incident response policies, revising vendor contracts to reflect new oversight obligations, training staff on breach notification procedures, and conducting incident response testing. The SEC will begin examining smaller entities' compliance shortly after June 3. Non-compliance exposes firms to enforcement action and reputational risk. Major law firms including Holland & Knight, Sidley, and Baker Donelson have issued guidance; firms without updated policies should prioritize implementation now.

mail Subscribe to Privacy email updates

Primary sources. No fluff. Straight to your inbox.

Also on LawSnap