Regulation S-P in 2026: The Customer-Data Controls FINRA Candidates Should Understand
The SEC's amended Regulation S-P is now in force for smaller entities. Learn how incident response, customer notification, and vendor oversight connect to broker-dealer compliance and FINRA exam preparation.
Turn this guide into a study plan
Take a free diagnostic and let Lurne AI adapt the next practice set to the concepts you miss.
Customer information is not just an IT concern. For a broker-dealer, it is part of the firm’s supervisory, privacy, business-continuity, and investor-protection obligations. That is why the SEC’s amended Regulation S-P matters to people entering the industry—even if they never work on a cybersecurity team.
The key date is now behind us: smaller covered entities were required to comply with the amendments by June 3, 2026. Larger entities had an earlier December 3, 2025 compliance date. The rule is final, not a proposal. But the exact way a firm implements it depends on its business, systems, customers, and service providers.
What Regulation S-P does
Regulation S-P governs the treatment of nonpublic personal information by covered financial institutions. The 2024 SEC amendments modernized the safeguards framework and expanded the responsibilities of broker-dealers, investment companies, SEC-registered investment advisers, funding portals, and certain transfer agents.
At the center of the amendments is a written incident-response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. A compliant program must address more than prevention. It should help the firm assess the nature and scope of an incident, contain and control it, and recover while reducing the risk of further unauthorized access.
The amendments also broaden the information covered by some safeguards and disposal requirements, require written records documenting compliance, and address oversight of service providers. The practical message is straightforward: a firm needs a repeatable process that connects technology, operations, compliance, legal, communications, and supervision.
Customer notification: the clock matters
When sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, the covered institution generally must notify affected individuals. The notification must be provided as soon as practicable, but no later than 30 days after the institution becomes aware that the incident occurred or is reasonably likely to have occurred.
There is an important qualification. After a reasonable investigation, a firm may determine that the sensitive customer information was not, and is not reasonably likely to be, used in a way that would result in substantial harm or inconvenience. The rule therefore requires a reasoned assessment; it does not turn every security alert into an automatic customer mailing.
That distinction is not permission to delay casually. A firm’s procedures should define who investigates, what facts are collected, how the risk assessment is documented, who approves a notification decision, and how the firm meets the applicable deadline. A candidate or new representative does not need to make that legal determination personally, but should understand why escalation and documentation matter.
Service providers are part of the control environment
Broker-dealers commonly rely on cloud platforms, custodians, clearing firms, CRM systems, call-center providers, email vendors, and other outside providers. The SEC amendments require written policies and procedures reasonably designed to oversee service providers, including through due diligence and monitoring.
Those procedures should address whether a provider protects customer information and whether it promptly alerts the covered institution when an incident occurs. The SEC’s small-entity compliance guide explains that service-provider procedures should require notification to the covered institution as soon as possible, but no later than 72 hours after the provider becomes aware of a breach in a customer information system that resulted in unauthorized access.
The 72-hour provider notice is not the same thing as the firm’s customer-notification deadline. It is an upstream escalation expectation that gives the firm time to investigate and decide whether customer notice is required. A vendor contract can allocate tasks, but outsourcing a function does not eliminate the covered institution’s responsibility to maintain an effective compliance process.
What FINRA examiners may connect to Regulation S-P
Regulation S-P is an SEC rule, but FINRA member firms should expect it to intersect with FINRA supervision and operational controls. FINRA’s 2026 Annual Regulatory Oversight Report identifies cybersecurity incidents as a source of customer-information exposure, financial loss, reputational risk, and operational failure. It points firms toward related obligations and controls, including FINRA Rules 3110 on supervision and 4370 on business continuity plans and emergency contact information.
FINRA has also highlighted practical failure modes: written supervisory procedures that do not reflect the firm’s current cybersecurity practices, failure to enforce those procedures, and inadequate supervisory systems for safeguarding customer records and information. These observations are not a new Regulation S-P rule. They are examination and compliance context that helps explain how a firm’s written program can be tested in practice.
For an early-career professional, this creates a useful mental model. Examiners may look beyond whether a policy exists. They may ask whether employees know how to report a suspected incident, whether escalation records are complete, whether service providers are monitored, whether the business-continuity plan works, and whether the firm can show that its procedures were followed.
A practical checklist for new finance professionals
- Know what counts as customer information. Think beyond account numbers. The amended framework reaches a broader range of information linked to a customer’s account or identity.
- Escalate quickly. A suspicious email, account takeover, lost device, misdirected file, or vendor alert may require immediate reporting under firm procedures.
- Preserve the record. Do not delete messages or alter evidence. Record what happened, when it was discovered, who was notified, and what instructions were received.
- Follow the approved channel. Use the firm’s incident-response and supervisory contacts rather than improvising a customer communication or contacting an outside party independently.
- Understand vendor dependencies. Know which systems or providers handle customer information and where the firm’s procedures require escalation.
- Separate facts from conclusions. Report observable facts. Whether notice is legally required is a firm-level assessment made through the designated process.
What candidates should remember for the exams
For the SIE and Series 7, connect Regulation S-P to the broader themes of customer protection, broker-dealer supervision, books and records, privacy, and business continuity. The high-value idea is that a firm must protect customer information through written controls and respond appropriately when those controls are tested.
For Series 63, Series 65, and Series 66 candidates, the topic fits into the larger framework of ethical conduct, fiduciary or best-interest responsibilities where applicable, safeguarding client information, and state or federal regulatory oversight. Do not memorize the 30-day customer-notice period as though it were a universal breach-notification rule for every business. On an exam, first identify the regulated entity and the governing rule.
Also keep the status straight. The SEC’s Regulation S-P amendments are a final rule with compliance dates—not a proposed rule awaiting approval. FINRA’s materials and compliance resources provide context and reminders, but they do not replace the text of the SEC rule or a firm’s own written procedures.
Why this matters beyond the test
Data incidents are increasingly operational events, customer-service events, and regulatory events at the same time. A new representative may be the first person a customer tells about an unauthorized login or suspicious transfer. The representative’s job is not to investigate independently or promise an outcome. It is to recognize the signal, protect the customer relationship, and trigger the firm’s established response.
That is the durable lesson of Regulation S-P in 2026: investor protection depends on controls that work under pressure. Candidates who understand the relationship between written procedures, escalation, vendor oversight, documentation, and customer communication will be better prepared for exam questions—and for the responsibilities that begin after the exam.
Sources and further reading
- SEC: Regulation S-P amendments press release
- SEC: Regulation S-P final rule release
- SEC: Small Entity Compliance Guide
- FINRA: Regulation S-P compliance-date reminder
- FINRA: 2026 Annual Regulatory Oversight Report
This article is for educational purposes only and is not legal or compliance advice. Always consult the current rule text, official guidance, and your firm’s written procedures.
Keep Studying
All articlesTurn this guide into a study plan
Take a free diagnostic and let Lurne AI adapt the next practice set to the concepts you miss.