Skip to main content
36 questions answered

Frequently asked questions

Straight answers about BlackSheep, pricing, SEC Reg S-P, NYDFS 500, NIST CSF 2.0, and what the product actually does. No fluff.

General

What is BlackSheep?

BlackSheep is cybersecurity compliance software for Registered Investment Advisors. It was built by a CISSP-certified practitioner who spent 20 years in financial services cybersecurity. It covers SEC Reg S-P, NYDFS 23 NYCRR 500, NIST CSF 2.0, DOL EBSA, FINRA, and SOC 2 in one dashboard with templates, guided workflows, and evidence tracking. The templates and framework mappings come from building compliance programs for 100+ RIA firms.

Who built BlackSheep?

Our founder holds a CISSP and has been doing financial services cybersecurity for 20 years. He was a bank CISO and then Director of Cybersecurity at a top 25 CPA firm, where he built compliance programs for 100+ RIA firms. Every one of those firms that went through an SEC exam in 2025 passed clean. BlackSheep puts that experience into software.

Who is BlackSheep for?

SEC-registered RIAs that need to get their cybersecurity compliance in order. Solo advisors use it, and so do firms with a few hundred employees. If the SEC or NYDFS regulates you and you handle client data, this is built for you.

Do I need a consultant to use BlackSheep?

No. BlackSheep is designed so you can run your compliance program yourself -- or alongside a consultant. The platform tracks where you stand every day with live dashboards, evidence collection, incident tracking, and reporting. Many consultants use BlackSheep to manage their clients more efficiently. Starting at $249/mo. See how we compare to other options.

How long does it take to set up?

Most firms finish setup in an afternoon. The onboarding wizard walks you through picking your frameworks, importing your firm details, and generating your first policies. There is no multi-week implementation.

Do I need technical skills to use BlackSheep?

No. It is built for compliance officers and firm principals, not engineers. Everything uses plain language and guided steps. If you can use a web browser, you can use BlackSheep.

How do I know where my firm stands right now?

Take the free Cyber Readiness Assessment. About five minutes, and it scores you across the major compliance areas. You will see where the gaps are before you commit to anything.

Pricing & Plans

How much does BlackSheep cost?

DIY is $249/mo, Builder is $499/mo, and Professional is $1,499/mo. Every plan includes a 14-day free trial with no credit card required. All plans cover SEC Reg S-P out of the box.

What's included in each plan?

DIY covers all frameworks (SEC Reg S-P, NYDFS 500, NIST CSF 2.0, DOL EBSA, FINRA) with policy templates, incident tracking, and vendor oversight. Builder adds hands-on services like led IR testing, audit support, and annual training. Professional adds biweekly compliance calls, dedicated onboarding, and priority support.

How does the free trial work?

Sign up, pick your plan, and start using BlackSheep immediately. No credit card required for the first 14 days. You get full access to every feature in your chosen tier. If you don't want to continue, just don't add a payment method.

Is there a money-back guarantee?

Yes. If you pay for a subscription and decide BlackSheep isn't right for your firm within the first 30 days, we'll refund you in full. No questions, no hoops.

Is there an annual discount?

Yes. Paying annually saves you roughly two months compared to monthly billing. The discount is applied automatically when you choose annual billing during checkout.

How do I cancel?

Go to Settings > Billing and click Cancel. Your access continues through the end of your billing period. No phone calls, no retention desks, no guilt trips.

SEC Reg S-P

What is SEC Regulation S-P?

Reg S-P is the SEC's rule requiring investment advisers and broker-dealers to protect customer information. The 2024 amendments added mandatory incident response programs, 30-day breach notification, 72-hour vendor alerts, and vendor oversight requirements. Read the full Reg S-P overview.

When is the Reg S-P compliance deadline?

June 3, 2026for smaller RIAs (under $1.5 billion AUM). Larger entities had an earlier deadline of December 3, 2025. If you haven't started preparing, now is the time. Read more about the June 2026 deadline.

What does BlackSheep cover for Reg S-P?

Everything the amended rule requires: written incident response program, breach notification tracking with 30-day timelines, vendor oversight with 72-hour alert contracts, policy templates, evidence collection, and five-year recordkeeping. See the full Reg S-P feature breakdown.

What happens if I miss the Reg S-P deadline?

The SEC can cite you in an examination, issue a deficiency letter, or bring an enforcement action. Penalties range from fines to censure. More practically, being non-compliant when a breach happens makes everything worse. Learn what happens during a failed SEC exam.

Do small RIAs really need to comply with Reg S-P?

Yes. Every SEC-registered adviser must comply, no matter how small. The SEC gave smaller firms extra time (until June 2026), but the requirements are the same. See the small RIA requirements breakdown.

What is an incident response plan and why do I need one?

It is a written set of procedures your firm follows when a data breach or cybersecurity event happens -- who does what, how you contain it, how you recover. The amended Reg S-P makes it mandatory. Without one, you're not compliant. Read our incident response plan guide or check the glossary for related terms.

NYDFS 500

What is NYDFS 23 NYCRR 500?

It is New York's cybersecurity regulation for financial services companies. It requires a cybersecurity program, a designated CISO, risk assessments, penetration testing, MFA, encryption, and detailed incident reporting. The 2023 amendments added a lot of new requirements. See the full NYDFS 500 overview.

Who needs to comply with NYDFS 500?

Any entity operating under a license, registration, or charter from the New York Department of Financial Services. That includes banks, insurance companies, mortgage brokers, money transmitters, and some RIAs if they're dual-registered or operate under a NY license.

What's the 72-hour notification requirement?

When a covered entity determines a qualifying cybersecurity event has occurred, it must notify DFS within 72 hours. This is separate from Reg S-P's 30-day customer notification. BlackSheep tracks both timelines so nothing slips. Learn more about how these rules differ in our NYDFS 500 vs Reg S-P comparison.

Does NYDFS 500 require a CISO?

Yes. Every covered entity needs a designated Chief Information Security Officer. You can hire one, use someone at an affiliate, or outsource it. Read our CISO requirement guide.

What is the annual certification?

By April 15 each year, covered entities must certify they were compliant with NYDFS 500 for the prior calendar year. It gets signed by the highest-ranking executive and the CISO. See our annual certification guide.

How does NYDFS 500 relate to Reg S-P?

They overlap but aren't identical. Reg S-P is federal (SEC), NYDFS 500 is state (New York). If you're subject to both, you need to satisfy each independently. BlackSheep maps the overlap so you're not doing double work. See our Reg S-P vs NYDFS 500 comparison.

NIST CSF 2.0

What is NIST CSF 2.0?

NIST CSF 2.0 is a voluntary framework for managing cybersecurity risk. It breaks cybersecurity down into six core functions and gives you a shared vocabulary for talking about your security program with auditors, regulators, and vendors. See the full NIST CSF overview.

Is NIST CSF required for RIAs?

Not directly -- it is voluntary. But the SEC keeps referencing NIST CSF in their guidance and exam priorities, and aligning to it shows examiners your program follows recognized practices. That matters during SEC examinations.

How does NIST CSF map to Reg S-P?

The Protect function lines up with Reg S-P's Safeguards Rule. Detect and Respond map to the incident response requirements. Govern covers the oversight and policy side that Reg S-P also demands. BlackSheep shows you these mappings automatically. See our NIST CSF vs Reg S-P mapping.

What are the 6 core functions?

Govern (strategy and oversight), Identify (assets and risks), Protect (safeguards), Detect (monitoring for events), Respond (acting on incidents), and Recover (restoring operations). Govern was added in the 2.0 update. Read about the new Govern function.

Why should my RIA use NIST CSF?

It gives you a structured way to build and describe your cybersecurity program that SEC examiners actually recognize. It maps well to Reg S-P and NYDFS 500, and it scales with your firm so you're not starting over when things change. See how BlackSheep handles NIST CSF for SEC exam prep.

Product & Features

What compliance frameworks does BlackSheep support?

SEC Reg S-P, NYDFS 23 NYCRR 500, NIST CSF 2.0, DOL EBSA cybersecurity requirements, FINRA cybersecurity requirements, Cyber Insurance Readiness, and SOC 2. Each framework has its own module with requirement tracking, policy templates, and evidence mapping. You can run one framework or all of them from the same dashboard.

Can multiple people at my firm use BlackSheep?

Yes. Builder and Professional plans support multi-user access with role-based permissions. Your CCO, operations manager, and IT contact can each have their own login with appropriate access levels.

Does BlackSheep handle vendor management?

Yes. You can track vendors, store due diligence documents, manage contract provisions (including Reg S-P's 72-hour notification clauses), and keep an eye on vendor risk. Read more about RIA vendor management requirements.

How does incident tracking work?

Log an incident, and BlackSheep automatically starts the relevant timelines: 30 days for Reg S-P customer notification, 72 hours for NYDFS DFS notification. You document what happened, what you did about it, and who was notified. Everything is timestamped for your records.

Can I export evidence for an SEC exam?

Yes. You can export evidence packages with your policies, incident logs, vendor records, risk assessments, and audit trails. PDF or CSV. Hand it to the examiner and you are done.

Does BlackSheep include policy templates?

Yes. There are RIA-specific policy templates for every framework we support. They are written in plain language, mapped to the actual regulatory requirements, and you can customize them for your firm. Learn more about cybersecurity policy templates for RIAs.

Still have questions? Start for free.

14-day free trial. No credit card. See your compliance gaps in 30 minutes. If it doesn't work for you, you pay nothing. 30-day money-back guarantee.

$249/mo DIY. $499/mo Builder. $1,499/mo Professional.