Regulation

Amended Regulation S-P and what it means for your data room vendor

The SEC's amendments to Regulation S-P became binding on a two-tier schedule, 3 December 2025 for larger entities and 3 June 2026 for smaller ones. They put written incident response, 30-day customer notification and documented service provider oversight into the rulebook, and a virtual data room is a service provider. This is the checklist a covered firm should be able to evidence about any VDR, including ours.

By the CogniSuite team

What the amendments added, and which compliance date applied to whom

The SEC adopted the amendments on 15 May 2024 and they were published in the Federal Register on 3 June 2024, according to FINRA's cybersecurity advisory on the rule. That advisory sets out four obligations for covered institutions: a written incident response program, notification of affected individuals, oversight of service providers, and records documenting compliance.

FINRA's reminder advisory of 14 November 2025 confirms the two compliance dates, 3 December 2025 for larger entities and 3 June 2026 for smaller entities, and notes that these size categories are defined in the SEC's final rule rather than by FINRA's own firm size bands. A Holland & Knight alert dated 7 May 2026 describes larger entities as investment companies with more than $1 billion in net assets, registered investment advisers with more than $1.5 billion in assets under management, and most broker-dealers with capital above $500,000. Everything else that is a covered institution is a smaller entity, so both dates have now passed.

On notification, covered institutions must tell affected individuals as soon as practicable and no later than 30 days when sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. A Goodwin alert dated 5 November 2025 sets out the exception: a firm may forgo notice if it determines the information has not been and is not reasonably likely to be used in a manner that would result in substantial harm or inconvenience. The same alert notes that where a firm cannot identify which individuals were affected, notice goes to everyone whose data was in the compromised system.

Why a data room is squarely a service provider under this rule

Covered institutions must maintain written policies and procedures reasonably designed to require oversight, including through due diligence and monitoring, of service providers. A VDR holds diligence material for the life of a deal, and that material routinely contains sensitive customer information as the rule defines it. Holland & Knight quotes the definition as any component of customer information whose compromise could create a reasonably likely risk of substantial harm or inconvenience, giving Social Security numbers, account credentials and investment history as examples. In an M&A process that turns up in HR files, employee payroll data, cap tables and customer contracts.

The point law firms repeat is that a firm can outsource the operation but not the obligation. If the data room is breached, the notification duty is still yours.

The 72-hour term is the one that changes your vendor contract

The service provider oversight requirement carries a specific clock. Holland & Knight states that a service provider must notify the covered institution as soon as possible, and no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system. The same alert records that the SEC accepted more than one route to satisfying this, including contractual representations, independent certifications and attestations from the service provider, or other reasonable assurances, and observes that full compliance here has proven difficult for some firms.

A Proskauer alert dated 21 November 2025 describes the notification as written notice within 72 hours. Goodwin notes that once the notice arrives, the covered institution activates its own incident response program. Read the two clocks together. The vendor has up to 72 hours to reach you. You then have up to 30 days to reach individuals, running from when you became aware. A vendor that uses its full window has consumed three of your thirty days before you start.

The checklist you should be able to evidence about a VDR

The Sidley compliance checklist frames vendor oversight as due diligence before engagement, ongoing monitoring, and written contracts carrying specific security and breach notification obligations. Translated into questions you can put to a data room vendor and file the answers to:

1. A written 72-hour breach notice commitment in the contract, naming who at your firm gets told and through what channel.

2. A named list of the vendor's own sub-processors, covering hosting, email delivery and any AI inference provider, with advance notice of changes.

3. Where deal data is stored, and how it is encrypted at rest and in transit.

4. Which vendor personnel can read your documents, under what process, and how that is logged.

5. Which authentication controls you can enforce on your own users and on counterparties, and whether the two sides get the same options.

6. An audit log you can export yourself, showing who viewed or downloaded which document and when, without asking the vendor to produce it for you.

7. What that audit record captures, whether it is tamper-evident, and who inside the deal is allowed to read it.

8. What deletion actually means. Soft deletion inside a database is not the same as erasure from backups. Reg S-P also carries a disposal requirement, so end-of-deal handling belongs in the contract.

9. A monitoring cadence you can show, not a questionnaire completed once at onboarding.

10. Your own retained file: the policies, the diligence record, the contract terms and any incident determinations. Proskauer lists policies, incident reports and copies of notifications as the records to keep.

An AI-native data room adds a service provider you may not have listed

If the data room runs AI over documents, document text leaves the data room and reaches an inference provider. That provider is handling customer information, so it belongs on your sub-processor list and inside your oversight program. Ask what the provider retains, for how long, whether inputs are used for training, and in which region processing happens.

Two things are true about CogniSuite here and worth separating. Text generation runs through one shared path, and the embedding calls that carry document text run through one other, and both reach the same provider, so the list of external destinations for your documents is short enough to enumerate in a file rather than something you have to reconstruct feature by feature. Separately, AI retrieval is filtered by the same per-folder permissions that gate the document itself, so an answer cannot draw on a file the person asking is not allowed to open. Both are access control properties. Neither is a statement about what a third-party provider does with text once it arrives. That question has to be answered by the provider's terms, and you should ask for them.

Where CogniSuite's controls stop, said plainly

Audit coverage is broad. Document views, downloads, deletes, permission changes, organization and user lifecycle events, request and Q&A transitions and AI questions are all recorded, each event carries the source IP it came from, and the trail is filterable and exportable as CSV. Two limits sit on top of that and belong in your file. The record is written as ordinary database rows with no hash chain and no signature, so it is not tamper-evident in the sense a forensic examiner would want. And audit access is restricted to the advising firm's team, so a counterparty cannot pull its own activity record and cannot use the log to answer an oversight question of its own.

Authentication is a passwordless emailed one-time code, with lockout after repeated failures and a cap on how many codes can be requested. Single sign-on is available on the advisory workspace through your own identity provider. It uses OpenID Connect, the authorization code flow with PKCE, and a per-firm allowlist of email domains, so only addresses on domains you have named can come through it. It is enabled per workspace rather than switched on everywhere by default, it sits alongside the emailed code rather than replacing it, and it is not offered on the per-deal subdomain where counterparties sign in. Single sign-on here means OpenID Connect and nothing else. There is no enforced second factor, so if your policy requires MFA on third-party systems that hold customer information, record that as a gap, and check /security for the current authentication options before you write your answer down.

Watermarking is applied at the moment a file is served rather than baked into what is stored, and it covers PDF, Word documents, images, spreadsheets and presentations. A file that cannot be watermarked is refused rather than handed over clean, which is the behaviour you want if the point of the control is that nothing leaves unmarked. The thing to check is that it is switched on for the people you think it applies to. Watermarking is a configuration on an organization or a folder rather than a default posture, so a counterparty organization nobody has adjusted can be sitting on ordinary download rights. If your process assumes marked distribution, set it deliberately and confirm it folder by folder.

Deletion of documents and folders is a soft delete within the deal's own database. If your disposal policy requires certified erasure on a defined schedule, get that commitment in writing.

Certification status is not something to take from an article, because an article cannot be relied on to track an audit cycle. /security carries the current position, and that is the reference to put in your diligence file.

What to have in the file before the next examination cycle

Much of what the amendments require is documentation. For each data room you use, hold the vendor's written 72-hour notice commitment, a dated diligence record, the sub-processor list, an exported sample of the audit log to prove you can produce one, and the template you would use to record a substantial-harm determination. If a vendor will not give you the first three in writing, that is itself the finding, and it is a finding an examiner can read off your own file.

General information, not legal, tax or financial advice. For how CogniSuite handles security and access, see Security. To see it on a live deal, book a walkthrough.

← All articles