The certification is signed by your CEO.

Part 500 requires an annual certification of compliance from senior leadership. We make sure the controls behind that signature are implemented, enforced, and documented.

01
Requirements mapped to real controls
02
MFA enforced without exceptions
03
Third-party risk tracked
04
Evidence ready for certification
Compliance

The Real Problem

Somebody signs it personally. That changes the question.

Part 500 is unusual among regulations because it puts a named senior officer’s signature on an annual certification. That makes the standard for “we believe we’re compliant” much higher than it is elsewhere. The person signing needs to know the controls were operating, not that a policy document says they should be.

In practice the gaps are consistent: MFA with quiet exceptions for service accounts, third-party relationships nobody inventoried, and evidence assembled in the weeks before certification rather than captured as events occurred.

What’s Included

What Part 500 support covers.

Requirement Mapping

Each obligation traced to the specific technical control satisfying it, with the proof attached.

Multi-Factor Enforcement

MFA applied across the environment, including the legacy and service accounts usually exempted.

Access Governance

Privileged access reviewed on a schedule, with entitlements matched to current responsibilities.

Third-Party Risk

A register of service providers touching firm or customer data, with obligations tracked and reviewed.

Incident Response Plan

A written, tested plan with the 72-hour notification path defined before you need it.

Certification Evidence

Documentation accruing continuously, so the annual signature rests on records rather than recollection.

Common Questions

Answers, plainly.

Do we qualify for a limited exemption?

Possibly, based on headcount, revenue, and assets — but exemptions are partial, not total, and they still require filing. Worth confirming with counsel rather than assuming.

Can you sign the certification for us?

No. It’s a senior officer certification and it stays with your leadership. Our job is making sure the controls behind it hold up.

Ready for the next certification?

The signature is only as good as the evidence behind it. We’ll show you where the gaps sit.