Larger advisers’ Regulation S-P compliance deadline was December 3, 2025. Smaller RIAs followed on June 3, 2026. Both dates have now passed, and something important happened in between: the SEC stopped talking about what the rule requires and started asking firms to prove they’d done it.
That distinction matters more than most of the compliance content published before either deadline let on. Law firm alerts and compliance consultants spent 2024 and early 2025 explaining what the amended rule says. Almost none of them could tell you what an examiner would actually ask for in the room, because no one had been examined against it yet. Now firms have. The SEC’s Division of Examinations named the Reg S-P amendments a formal FY2026 priority, and the requests coming out of that priority look different from what most compliance memos predicted.
For RIAs still treating this as a policy-drafting exercise, that gap is worth closing before an exam letter shows up.
The Deadline Passing Was Never the Finish Line
The amended rule isn’t complicated to summarize: covered institutions need a written incident response program, a defined process for notifying affected individuals when customer information is compromised, documented oversight of service providers that touch that data, and records proving it is actually happening. Firms with $1.5 billion or more in assets under management had to be compliant by December 3, 2025. Everyone else had until June 3, 2026, a timeline Holland & Knight’s compliance alert confirmed in detail as the smaller-entity deadline approached.
Once both dates passed, the requirement stopped being hypothetical. The SEC’s own examination priorities confirmed that alongside core areas like fiduciary duty and the custody rule, examiners would specifically test compliance with the 2024 Reg S-P amendments, not just ask whether a policy document existed. A firm that spent 2025 drafting a privacy policy update and calling it done built the wrong deliverable.
Examiners Aren’t Asking to See Your Policy. They’re Asking to See It Work.
This is the part that got lost in a lot of the pre-deadline coverage. Having an incident response program is table stakes. What examiners are testing for now is evidence that the program functions, not that it exists.
That means restore test logs with timestamps, not a statement that backups run. It means access review records showing who approved what and when, not an access control policy sitting in a binder. It means a documented vendor risk assessment for every third party touching client data, not a vendor list. A written policy answers “what did you intend to do.” An examiner in 2026 is asking “show me the last time you did it.”
This is exactly where firms tend to overinvest in the wrong place. A polished 40-page incident response plan means very little if nobody can produce a tabletop exercise record from the past year. We’ve walked into new financial services clients with backup jobs that had been “running” for months without a single tested restore. Under the old regulatory posture, that was a risk. Under active FY2026 exams, it’s a documented deficiency. Our SEC compliance work with financial firms is built around closing exactly that gap between having a control and being able to prove it.
Your Vendor’s Notification Clock Is Now Your Liability
One of the more consequential pieces of the amended rule is the requirement that service providers report a breach involving customer information back to the RIA within a defined window. Most firms read that as their vendor’s problem. It isn’t. The obligation to notify affected clients still sits with the RIA, and that clock starts running whether or not the vendor’s contract was updated to reflect it.
Firms coming through onboarding with us consistently have the same gap: cloud platforms, portfolio management systems, and CRM providers under contracts that predate the amendment, with no explicit breach-reporting language and no confirmed point of contact for a notification. An examiner asking to see the incident response program will also ask to see the vendor agreements that support it. If those two documents don’t line up, that’s the deficiency.
Smaller RIAs Just Inherited a Playbook Written for Large Advisers
Firms under $1.5 billion in AUM had an extra six months, and the temptation for many was to treat that runway as evidence the requirement was lighter for them. It isn’t. The rule text doesn’t scale down for smaller firms, and neither does what an examiner asks for. A three-person RIA managing $400 million is expected to produce the same category of evidence, an incident response program, tested backups, documented vendor oversight, that a firm ten times its size produces. The difference is smaller firms usually have less infrastructure in place to generate that evidence automatically, which means more of it has to be built deliberately rather than assumed to already exist.
That’s the group most exposed right now. The June 2026 deadline has passed, exam cycles are already underway, and a smaller RIA that spent the extra runway on other priorities is walking into the same review standard as a firm ten times its size, without the same paper trail to show for it. Our RIA-focused compliance support exists specifically because that gap shows up in nearly every smaller advisory firm we onboard.
What “One Year On” Actually Looks Like in Practice
The honest read on where things stand: the rule hasn’t changed since it was finalized in 2024, but the risk profile around it has. A year ago, a firm’s exposure was theoretical, a rule on the books with a future compliance date. Now it’s a live examination item with a documented enforcement pattern behind it. Firms that treated the deadline as a paperwork exercise are the ones most likely to hear from an examiner that a policy without evidence isn’t a compliance program.
For financial services firms we work with, Reg S-P readiness isn’t a separate project bolted onto existing IT. Restore testing, vendor risk documentation, and audit logging are the same infrastructure that should already be supporting FINRA, GLBA, and SOC 2 obligations. Firms that had that foundation in place before December 2025 largely walked into this year’s exams without surprises.
If your firm hasn’t had its documentation tested against what examiners are actually asking for this year, that’s worth confirming before an exam letter forces the question. Contact us for a Reg S-P readiness assessment built around what current exams are requesting, not what the rule said back in 2024.