Your portfolio management software provider gets breached. Client names, account numbers, and social security numbers are exposed. You find out on a Tuesday afternoon. Under the SEC’s amended Regulation S-P, you now have 30 days to notify affected clients - and the clock started the moment you became aware.
Are you ready for that?
The Problem: Small RIAs Thought These Rules Were for Bigger Firms
It’s a common assumption in boutique advisory firms: securities regulations scale with AUM. The big wirehouses have compliance departments. The large broker-dealers have legal teams. Small registered investment advisers (RIAs) figure they operate under a lighter framework.
The SEC’s 2024 amendments to Regulation S-P made that assumption dangerous.
Adopted in May 2024, the amended rule expands incident response and client notification obligations for both broker-dealers and investment advisers - including firms with a handful of employees and a modest book of business. The compliance deadline for smaller entities is April 2026, but that window is shorter than it sounds when you consider how long it actually takes to build a written incident response program from scratch.
Here’s what’s tripping up small RIAs right now:
They don’t have a written incident response program. A general IT security policy isn’t the same thing. The SEC is explicit: firms need a formal, documented program that outlines how they’ll detect, respond to, and recover from a breach.
They haven’t mapped their “covered data.” Most small RIAs haven’t taken inventory of where client information actually lives - and under the amended rule, that data doesn’t have to sit on your own servers to trigger your obligations.
They haven’t addressed vendor risk. If your custodian, your portfolio management platform, or your CRM provider experiences a breach involving your clients’ information, that’s your problem to notify. Not theirs. Yours.
The rule doesn’t grade on a curve for small firms. It just has a different deadline.
Why This Matters for Boutique RIAs: The Regulatory and Financial Stakes
Regulation S-P was originally enacted in 2000 to protect the financial privacy of consumers. The 2024 amendments significantly modernize it, and they reflect the SEC’s recognition that the threat environment has changed dramatically since the dial-up era.
Here’s the specific language that should get your attention: the amended rule requires firms to develop, implement, and maintain written policies and procedures for an incident response program designed to detect, respond to, and recover from unauthorized access to or use of “customer information.” That definition - customer information - is broader than most small RIA principals realize.
It includes data held by your third-party service providers. If your custodian, your cloud-based financial planning software, or your document management vendor stores or processes nonpublic personal information (NPI) on your behalf, a breach at that vendor can trigger your S-P notification obligations.
The 30-day notification requirement is the headline, but the vendor oversight provision is the sleeper issue. The amended rule explicitly requires firms to oversee service providers through written contracts that include appropriate safeguards - which means your vendor agreements need to be reviewed through a compliance lens, not just a commercial one.
What happens if you miss this? SEC examiners have been prioritizing data protection in RIA exams for several years. A failure to maintain a written incident response program - or to notify clients within the required window - can result in enforcement action, monetary penalties, and reputational damage that hits especially hard at small firms where client trust is the entire business model.
Thirty days sounds reasonable until you realize most small RIAs don’t have a documented process for even identifying that a breach occurred, let alone notifying affected clients.
How to Address This Before the Compliance Deadline
You don’t need to hire a full-time compliance officer or rearchitect your entire IT environment. But you do need three specific documents in place before April 2026.
Document 1: A Written Incident Response Program (IRP)
This is not your cybersecurity policy. An IRP is a procedural document that answers: What happens the moment we suspect a breach? It should define:
- Who is responsible for declaring an incident
- How you determine whether “covered data” was involved
- The internal escalation chain (including outside counsel, if applicable)
- How and when you notify affected clients (within 30 days of discovering a breach)
- How you document the incident for regulatory purposes
The SEC wants to see that you’ve thought this through before an incident happens - not that you’re improvising in the middle of one.
Document 2: A Data Inventory and Classification Map
You can’t protect data you can’t find. This document identifies every system, application, and vendor that stores or processes client NPI. It should note where each data set lives, who has access, and whether each vendor has signed a data protection agreement.
This also becomes the foundation for your vendor oversight program - which the amended rule now makes an explicit compliance requirement.
Document 3: Vendor Contract Addenda with Data Protection Language
Review your existing agreements with custodians, portfolio management software providers, CRMs, and any cloud service that touches client data. Many of these contracts were signed years ago and predate the current regulatory environment. You’ll likely need addenda - or new agreements - that include:
- Breach notification obligations (the vendor must notify you promptly so your 30-day clock doesn’t run out while you’re waiting for them)
- Data handling and security standards
- Your right to audit or request attestations
Don’t assume your technology vendors are automatically compliant. Verify it in writing.
Beyond these three documents, firms should also run tabletop exercises - walking through a simulated breach scenario with key stakeholders to find the gaps in your IRP before a real event does.
What to Look for in an IT Partner
Not every IT provider understands the regulatory context small RIAs operate in. When you’re evaluating whether your current provider - or a potential new one - can support your S-P compliance posture, ask these questions:
Can you help us build and maintain a written incident response program? A general “we handle security” answer isn’t enough. You want a partner who can document procedures in the format your compliance consultant or SEC examiner will recognize.
How do you handle vendor risk on our behalf? If your IT provider manages your software stack, they need to understand that each vendor relationship carries regulatory implications.
What’s your breach notification process? How quickly will they alert you if they detect something? Your 30-day window starts at discovery. Delayed detection is delayed compliance.
Have you worked with RIAs or financial advisory firms before? Regulatory familiarity matters. You don’t want to spend hours explaining what NPI means or why your client data falls under SEC oversight.
A good IT partner should make your compliance program stronger, not leave gaps your examiner will find.
The Bottom Line
The SEC’s amended Regulation S-P isn’t a large-firm problem. Small RIAs have until April 2026 to have a written incident response program, a mapped inventory of covered data, and vendor contracts with appropriate data protection language in place. The 30-day client notification requirement is real, and the vendor oversight obligations are broader than most firms expect. Start building now - the deadline will arrive faster than the compliance workload shrinks.
Frequently Asked Questions
What is the compliance deadline for small RIAs under the amended Regulation S-P?
Smaller entities - generally those not classified as “large traders” - have until April 3, 2026, to comply with the amended Regulation S-P requirements. Larger entities had an earlier deadline of December 3, 2025. The SEC defines the size thresholds in the adopting release, so firms should confirm their classification with their compliance counsel.
Does the 30-day notification requirement apply if one of my vendors gets breached, not my own systems?
Yes. If a third-party service provider experiences a breach that involves your clients’ nonpublic personal information, your 30-day notification obligation is triggered. This is why your vendor contracts must include language requiring the vendor to notify you promptly after they discover a breach - their delay becomes your compliance problem.
What counts as “covered data” under amended Regulation S-P?
Covered data under the amended rule includes “customer information,” which the SEC defines broadly as nonpublic personal information about customers that a firm collects or maintains. This includes data held by third-party service providers on the firm’s behalf. It’s not limited to data stored on the firm’s own systems.
What’s the difference between a cybersecurity policy and an incident response program?
A cybersecurity policy describes your firm’s general approach to security - acceptable use, password requirements, access controls, and so on. An incident response program is a specific procedural document that governs what your firm does when a breach or suspected breach occurs. The SEC’s amended Regulation S-P requires the latter, and examiners will look for it as a standalone document.
If you’re working through SEC Regulation S-P compliance challenges at your firm, let’s talk. One82 works exclusively with CPA firms, law firms, and financial advisory companies in the Bay Area - we know your world.