New white paper: what the Reg S-P 72-hour vendor breach rule actually requires

Last updated: August 2026

We've published a white paper on one of the most misread provisions in the amended Regulation S-P: Service Provider Breach Notification Under the Final Regulation S-P Amendments.

Here's why we wrote it.

Reg S-P requires firms to ensure their service providers notify them as soon as possible, and no later than 72 hours, after becoming aware of a qualifying breach. Since the compliance deadlines passed, we keep hearing the same advice repeated to advisers: amend every vendor contract, collect a 72-hour acknowledgment form from every provider, get it all in writing or you're out of compliance.

That advice describes the SEC's proposed rule. It's not what the SEC adopted.

The change most firms missed

The March 2023 proposal would have required covered institutions to enter into written contracts with their service providers that included specific safeguarding and breach-notification provisions. The final rule removed that requirement. The Commission's adopting release says so directly: it "modified the proposal by removing the written contract requirement."

What replaced it is a principles-based standard. Firms must maintain written policies and procedures that are reasonably designed to ensure service providers protect customer information and provide timely notice after a breach. How you get there is up to you. Kroll, Debevoise & Plimpton, and Cleary Gottlieb each flagged this as one of the biggest differences between the proposed and final rules, and Kroll's read on the reason is worth repeating: the SEC recognized that a two-person RIA has no leverage to force contract amendments on Microsoft.

So some firms are chasing vendor paperwork the regulation doesn't require, while overlooking the documented oversight program it does.

What's in the paper

The paper walks through the proposed rule, the final rule, and what changed between them:

  • What the final rule requires, and what it doesn't — no uniform contract language, no standalone 72-hour vendor certification, no SEC-approved form

  • Why the SEC swapped the contractual mandate for a flexible oversight standard

  • What a documented oversight program looks like in practice: vendor inventories, risk assessments, due diligence, ongoing monitoring, governance records

  • What examiners are likely to ask for when they review vendor oversight

Read the white paper →

Why this matters for your exam

You don't demonstrate compliance with the 72-hour provision by producing a contract. You demonstrate it with an oversight program that's designed, documented, and running. That's a different task than most firms have been told. For many, it's a more achievable one.

Advisor Armor helps RIAs document and manage vendor oversight, cybersecurity policies, risk assessments, and ongoing monitoring as part of a complete Reg S-P compliance program.

Want to see how your current process compares? Schedule a 10-minute review →

Next
Next

The SEC Isn't Just Asking Who Your IT Provider Is. It's Asking for Your Regulation S-P Compliance Program.