Reg S-P Is Now in Force: What DFW Investment Firms Must Prove in 2026

For two years, amended Regulation S-P was a deadline. Firms tracked it on a compliance calendar, assigned it to someone, and worked toward a date.
Both dates have now passed. Larger entities came into scope on December 3, 2025. Smaller entities, which includes SEC-registered investment advisers with less than $1.5 billion in assets under management, came into scope on June 3, 2026.
That changes the nature of the question. Reg S-P is no longer a project with a due date. It is a standing condition your firm is either meeting or not, and the way it now surfaces is through an examination request or a client’s vendor questionnaire. The operative word has shifted from “prepare” to “evidence.”
This piece covers what a firm in Frisco, Plano or Irving must be able to show today, and specifically which parts of it are IT problems rather than compliance-department problems.

How Can IT Services Help Meet SEC Cybersecurity Guidance?
IT services meet SEC cybersecurity guidance by producing evidence, not just protection. Reg S-P requires a written incident response program, the ability to detect unauthorized access to customer information, customer notification within 30 days of becoming aware of an incident, and documented oversight of service providers. Each of those obligations depends on logging, alerting, retention and access records that only the technology environment can supply.
The distinction matters because firms routinely buy security tooling and still fail an examination. A firm can run good endpoint protection and still be unable to answer the question an examiner actually asks, which is some version of: show me how you would know, show me when you knew, and show me what you did.

What the Amended Rule Actually Requires
The amendments adopted May 16, 2024 updated a rule that had been largely unchanged since 2000. Four elements carry the operational weight.
1. A written incident response program
Covered institutions must maintain written policies and procedures for an incident response program reasonably designed to detect, respond to and recover from unauthorized access to or use of customer information. All three verbs matter. Detection is the one most firms underinvest in, because it is the least visible until it is needed.
2. The 30-day notification clock
When sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, the firm must notify affected individuals as soon as practicable and no later than 30 days after becoming aware that the incident occurred or is reasonably likely to have occurred.
Read that trigger carefully. The clock starts at awareness of a reasonably likely incident, not at confirmation of a confirmed breach. Firms that wait for certainty before starting the count are misreading the standard. The notice itself must describe the incident, the information involved, and what affected individuals can do to protect themselves.
3. Broader scope of covered information
The safeguarding and disposal requirements now apply to all customer information, defined as any record containing nonpublic personal information about a customer of a financial institution that is in the firm’s possession, or that is handled or maintained by the firm or on its behalf.
The phrase “or on its behalf” is the one that expands the perimeter. Data sitting with your custodian, your CRM vendor, your portfolio accounting platform or your outsourced IT provider is inside your obligation.
4. Service provider oversight
Firms must take reasonable steps to require service providers to protect customer information and to notify the firm of a breach. In practice this has produced a wave of questionnaires flowing downstream, which is why professional firms serving advisory clients are now fielding security reviews they never used to see.
One additional change is easy to miss: transfer agents registered with the Commission or another appropriate regulatory agency must now comply with both the safeguarding and the disposal requirements, where previously they faced only the disposal rules and only in some cases.
Who Counts as a “Smaller Entity”
The distinction only ever governed the compliance date, and both dates are now behind us. It remains useful for understanding where your peers are in their maturity curve.
| Entity type | Larger entity threshold (complied by Dec 3, 2025) |
|---|---|
| SEC-registered investment adviser | $1.5 billion or more in assets under management |
| Investment company | Net assets of $1 billion or more at the most recent fiscal year end |
| Broker-dealer | Any that is not a small entity under the Exchange Act |
| Transfer agent | Any that is not a small entity under the Exchange Act |
Most independent RIAs across Dallas-Fort Worth fell into the smaller-entity group and reached their date in June 2026. If your firm treated that as a documentation exercise and has not revisited it since, the gap between the written plan and the operating environment is probably where your risk now sits.
Can your firm evidence all four requirements today? We run a Reg S-P readiness review that tests the written plan against what your environment can actually produce. Call (888) 352-4832 or request a review.
The Six Gaps We Find Most Often
These come from readiness work with advisory firms across the metroplex. They are ordered by how frequently they appear, not by severity.
1. The plan names a role that no longer exists
Incident response plans written in 2024 and 2025 routinely name an individual who has since left, or a vendor the firm no longer uses. An examiner reading a plan that names a departed employee learns something about the firm beyond that one error.
2. Logs that do not reach back 30 days in a usable form
If you become aware of a possible incident on day one and need to determine scope, you need history. Default retention on many platforms is shorter than firms assume, and the retention that exists is often not searchable by the people who would need to search it at 9pm on a Friday.
3. No alerting on the events that signal unauthorized access
Detection is a rule requirement, not a best practice. At minimum a firm should alert on impossible-travel sign-ins, new mailbox forwarding rules, mass file downloads from document storage, and changes to privileged group membership. Each of these is a common first observable in an actual compromise.
4. A vendor inventory that is out of date or does not exist
Service provider oversight requires knowing who your service providers are. Firms often have an inventory built during the original compliance push and never maintained. Every system that touches customer information needs an entry, an owner and a review date.
5. Notification mechanics never tested
The 30-day clock assumes you can identify affected individuals and reach them. Many firms have never tested whether they can produce an accurate affected-party list from their systems under time pressure. That is a tabletop exercise, and it takes an afternoon.
6. Secure AI with no governance
Staff at advisory firms are pasting client information into public AI tools. This is now one of the more direct routes to an unauthorized-use problem, and it is invisible without a governed alternative. We deploy Hatz.AI so advisory firms get a private environment where client data stays inside the tenant and administrators retain visibility. Our deeper treatment is in secure AI for investment firms.
What to Look for in a Managed IT Provider Experienced With SEC Reg S-P Compliance
A provider experienced with Reg S-P should be able to do four specific things, and you can test each in a first conversation.
- Map each rule requirement to a control and an artifact. Not “we do security,” but: detection maps to these alert rules, and the artifact is this report. If they cannot draw that line, they have not done this work.
- Produce a completed vendor security questionnaire on request. Advisory clients push oversight downstream. Your IT provider is one of your service providers, and should already be answering for itself.
- Run a notification tabletop. Ask them to walk through hour one through day thirty of a suspected incident at your firm, naming who decides what.
- Retain evidence on a defined schedule. Ask what they keep, for how long, and how you get it if you leave.
The FINRA cybersecurity advisory on the amendments is a useful cross-check, as is the rule text itself at 17 CFR Part 248. For control design, the NIST Cybersecurity Framework gives you a structure examiners recognize.
Frisco, Plano and Irving: Three Different Advisory Markets
Frisco has attracted a concentration of newer independent RIAs, many founded by advisers who broke away from wirehouses in the last decade. These firms are typically cloud-native and technically current, but they crossed into Reg S-P scope while still operating with startup-era informality about documentation. Our Managed IT Frisco work with these firms is usually less about new tooling and more about turning existing capability into evidence. DKBinnovative is headquartered in Frisco, and our broader Managed IT Frisco practice supports firms across the corridor.
Plano holds many of the region’s established advisory practices and multi-family offices, firms with longer histories, more legacy systems and more accumulated data. Scope questions are harder here, because customer information has had 20 years to spread into file shares and archives nobody has catalogued. Our Managed IT Plano engagements with advisory firms often begin with discovery of where customer information actually lives, and our Managed IT Plano security team handles the remediation that follows.
Irving and Las Colinas carries a different profile again. The corridor’s institutional and corporate presence means advisory firms there interact with counterparties who run serious vendor due diligence, so the questionnaire pressure arrives earlier and lands harder. Our Managed IT Irving practice works from an office at 7301 State Hwy 161 in Las Colinas, and our Managed IT Irving team spends a disproportionate share of its time on evidence packages for exactly these reviews.
Frequently Asked Questions
Has the Reg S-P compliance deadline passed?
Yes, both of them. Larger entities had to comply from December 3, 2025, and smaller entities from June 3, 2026. There is no remaining runway. A firm that is not currently meeting the requirements is out of compliance rather than behind schedule.
What is a managed IT provider experienced with SEC Reg S-P compliance responsible for?
The provider is responsible for the technical capability behind each requirement: detection and alerting on unauthorized access, log retention sufficient to determine scope, the access and configuration records that evidence safeguarding, and its own conduct as one of your service providers. The firm retains responsibility for the written program, the notification decision and the regulatory relationship.
Does Reg S-P apply to our firm if we are a small RIA?
If you are registered with the SEC, yes. Assets under management determined only which compliance date applied to you, not whether the rule reaches you. Firms under $1.5 billion in AUM were in the smaller-entity group with a June 3, 2026 date.
When does the 30-day notification clock start?
It starts when the firm becomes aware that an incident involving unauthorized access to sensitive customer information has occurred, or is reasonably likely to have occurred. That is an awareness-of-likelihood standard, not a confirmation standard, so the clock can start before an investigation concludes.
Do we have to oversee our IT provider under Reg S-P?
Yes. Covered institutions must take reasonable steps to require service providers to protect customer information and to notify the firm of a breach. An IT provider that cannot complete your security questionnaire creates a compliance problem for you, not only an inconvenience.
How long does a Reg S-P readiness engagement take?
A readiness review takes a few weeks. If it surfaces material gaps, remediation and full onboarding typically run 45 to 90 days depending on how much discovery the environment requires.
Working With DKBinnovative
We have supported investment and professional firms across Dallas-Fort Worth since 2004. That is 22 years, currently spanning 2,632+ end users across 55+ companies, with a 78% first-call resolution rate and 98.14% client satisfaction. We standardize on Microsoft Azure and Microsoft 365 for infrastructure, and deploy Hatz.AI where firms need governed AI that keeps client information inside their own tenant.
If your firm reached its Reg S-P date and has not revisited the program since, the useful next step is a short readiness review that tests the written plan against what your systems can actually produce. We will tell you plainly which of the four requirements you can evidence today and which you cannot.
Call (888) 352-4832 or book a readiness review.
Related reading: Managed IT for RIAs & Wealth Management Firms · Investment & Professional Firms · Financial Services IT · IT Support for Law & Accounting Firms
Serving the DFW Metroplex
