← All intelligence

Regulation S-P is live for emerging managers: the breach-response rules you now own

Amended Regulation S-P reached advisers under $1.5B AUM on June 3, 2026. New duties — incident-response program, 30-day breach notice, 72-hour vendor clause.

On June 3, 2026, the SEC’s amended Regulation S-P compliance deadline passed for smaller entities — which, for registered investment advisers, means every firm with less than $1.5 billion in assets under management. That threshold captures essentially the entire emerging-manager population. The amended Safeguards Rule is no longer approaching; it is in effect. This brief explains what it now requires of a sub-$1.5B adviser, then turns to the question allocators and their operational due diligence teams will be asking next.

What changed and who it now binds

Regulation S-P has governed adviser privacy and data-security obligations since 2000. The SEC adopted substantial amendments on May 16, 2024 — Release Nos. IA-6604 and 34-100155 — modernizing the Safeguards Rule and the Disposal Rule for registered investment advisers, broker-dealers, investment companies, and transfer agents. Larger entities, defined for investment adviser purposes as firms with $1.5 billion or more in AUM, had until December 3, 2025. Smaller entities — the sub-$1.5B advisers — had until June 3, 2026.

The SEC’s 2026 Division of Examinations priorities listed compliance with the amended Regulation S-P, specifically incident response programs, as a focus area, naming both compliance dates explicitly. That framing is significant: examiners will be asking about programs that exist and function, not programs that are in progress.

The five obligations a smaller adviser now owns

Incident response program. The amended rule requires each covered institution to adopt written policies and procedures for an incident-response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. The program is not a general cybersecurity policy. It must address response and recovery specifically — which systems were affected, the scope of the incident, steps taken to contain it, and the process for notifying affected individuals.

Customer notification within 30 days. When an incident involving sensitive customer information has occurred — or is reasonably likely to have occurred — the firm must notify affected individuals as soon as practicable but no later than 30 days after becoming aware. The notice must describe the incident, the data involved, and how individuals can protect themselves. Sensitive customer information is the rule’s higher-risk subset. Broadly, it covers information that identifies an individual on its own — government identification and taxpayer numbers, biometric records, unique electronic identification numbers, addresses, or routing codes, and telecommunications identifying information or access devices — together with account numbers, names, or online user names paired with authenticating details such as an access code, security code, partial Social Security number, or security question. It is the category whose compromise could create a reasonably likely risk of substantial harm or inconvenience.

There is one documented exception. Notice is not required if the firm determines, after a reasonable investigation, that the sensitive customer information has not been and is not reasonably likely to be used in a manner that would result in substantial harm or inconvenience. Critically, the SEC did not define “substantial harm or inconvenience” in the final rule — that determination falls to the firm, which means the investigation itself and the reasoning behind any no-notice conclusion must be documented to withstand scrutiny.

Service-provider oversight and the 72-hour vendor clause. Written policies must require oversight of service providers designed to ensure they protect customer information against unauthorized access and notify the firm as soon as possible, but no later than 72 hours, after becoming aware of a breach resulting in unauthorized access to a customer information system. The SEC noted in the adopting release that a covered institution could satisfy this through contractual representations from each provider, though such a contract is not strictly required. In practice, advisers are reaching out to fund administrators, custodians, OMS providers, and cloud vendors to obtain written confirmation that the 72-hour window will be met.

Expanded scope of customer information. The amended Safeguards and Disposal Rules now cover not only nonpublic personal information about the firm’s own customers but also such information received from another financial institution about that institution’s customers. A sub-adviser receiving an institutional investor’s information from a referring adviser is now a covered institution with respect to that data under the rule.

Recordkeeping. New requirements mandate documentation of compliance with the incident-response program, service-provider oversight, and any notification decisions — including the reasoning behind a no-notice determination. Records are the evidence of compliance in an examination; a program that cannot be demonstrated through documentation is, for exam purposes, a program that does not exist.

The diligence turn: what an ODD team now asks

For allocators and their operational due diligence teams, the June 3 date created a concrete checkpoint. A manager who is SEC-registered and sub-$1.5B in AUM either has a compliant incident-response program or does not. The ambiguity that existed before the compliance date — “we’re working toward it” — is no longer an acceptable response.

The questions an experienced ODD reviewer will now ask are not conceptual:

  • Can the manager produce the written incident-response program with a date on it preceding June 3, 2026?
  • Does the program identify who is responsible for breach detection, containment, investigation, and the notification decision?
  • Has the 30-day notification timeline been operationalized — meaning, is there a named individual who owns the clock once awareness is established?
  • Has the manager contacted its critical service providers — particularly fund administrator, prime broker, and any custodian — to confirm the 72-hour vendor notification obligation and obtain written acknowledgment?
  • Does the expanded scope of customer information appear in the firm’s data mapping, including any data received from other financial institutions?
  • Are records being maintained in a form the firm could produce in an exam?

A thin answer to any of these is an ODD signal. It does not mean the manager is dishonest; it means the control environment is not yet commensurate with the regulatory standing the firm holds.

A policy document filed in a drawer is not a program. The reviewable artifacts are the written procedures, the service-provider communications, the named notification path, and the dated records — in that order.

For exempt reporting advisers and offshore managers without SEC registration, the rule does not directly apply, which makes the contractual ask more important, not less. An allocator whose capital is in a structure where Regulation S-P does not reach should be asking for the functional equivalent — a written incident-response commitment — rather than assuming the absence of a legal obligation means the absence of a risk.

Building the program now, not in response to an exam

For the manager who cleared the June 3 deadline but whose program is thin, the remediation list is bounded. The SEC’s small entity compliance guide and the adopting release identify the components; the work is implementation, not design:

  • Draft or update written policies and procedures covering detection, containment, investigation, the notification decision tree, and the harm-threshold analysis.
  • Identify and contact every service provider with access to customer information; obtain written confirmation of the 72-hour notification commitment and reflect it in service-provider agreements or addenda at the next amendment cycle.
  • Map all customer information, including information received from other financial institutions, and verify it is covered by the program’s scope.
  • Name the individual responsible for each step — detection, investigation, notification decision, regulatory recordkeeping — so the program has owners, not just text.
  • Establish a records-retention practice for incident-response documentation, service-provider communications, and notification decisions, including no-notice determinations.

This is table stakes, not a project. Larger managers have been building these programs since late 2025. An ODD team that reviewed a large adviser in January will arrive at a smaller manager’s office with calibrated expectations.

To discuss how a sub-$1.5B adviser’s incident-response program holds up against current ODD standards, begin a conversation.

SetOne Labs provides advisory services and general information. Nothing here is legal, tax, or investment advice.

Discuss this topic with the firm

SetOne Labs prepares decision-grade analysis for funds, family offices, and private investors. Engagements begin under NDA.

Published for informational purposes only; not investment, legal, or tax advice.