Larger covered firms had to comply with the 2024 amendments by December 3, 2025, and smaller firms by June 3, 2026. Both deadlines have now passed.
Who SEC Reg S-P applies to
- SEC-registered investment advisers (RIAs)
- Broker-dealers and funding portals
- Investment companies and transfer agents
What SEC Reg S-P means for a small business
The Vail Valley has a large community of wealth advisors and family offices serving resort homeowners. Many are SEC-registered and now subject to the amended Regulation S-P. State-registered advisers follow Colorado Division of Securities rules instead, which carry their own cybersecurity expectations.
The amendments center on being ready for a breach: detecting it, containing it, deciding whether sensitive customer information was accessed, and notifying customers within 30 days when required.
SEC Reg S-P requirements and how we meet them
| Requirement | How Vail Valley IT handles it |
|---|---|
| Written policies and procedures to safeguard customer information | Documented security program matched to your actual configuration. Compliance & Cybersecurity |
| Incident response program | Written program for detecting, responding to and recovering from unauthorized access. Virus & Malware Removal |
| Customer notification within 30 days | Logging and forensics readiness so you can determine what was accessed and notify on time. |
| Service provider oversight | Vendor due diligence and contract terms requiring providers to notify you of breaches within 72 hours. |
| Recordkeeping | Retained records of policies, incidents and notification decisions. |
| Technical safeguards | MFA, encryption, email security, monitored endpoints and staff training. Security Awareness Training |
Common SEC Reg S-P gaps we find in valley businesses
- No written incident response program
- Logging too limited to determine what an attacker accessed
- Vendor contracts without breach-notification terms
- Advisors working from personal devices without management
Evidence to keep on file
- Written policies and incident response program
- Vendor inventory and due-diligence records
- Incident and notification records
- Training records
- Security testing reports
How we get you there
Gap assessment
We compare your current setup to SEC Reg S-P and list what is missing.
Remediation plan
Prioritized fixes with a flat price, in plain language.
Implement & train
Controls, policies and staff training put in place.
Test & document
Scans, pen tests and an evidence file you can hand to an auditor.
Frequently asked questions
Does Regulation S-P apply to small RIAs?
Yes. The amended rule applies to SEC-registered advisers of all sizes; smaller entities simply had a later compliance date of June 3, 2026.
How fast must customers be notified under Reg S-P?
As soon as practicable, but no later than 30 days after becoming aware that unauthorized access to sensitive customer information occurred or is reasonably likely to have occurred, unless a narrow exception applies.
brand