SEC 2026 Exam Priorities Expired. Reg S-P Duties Did Not.

The SEC's 2026 Exam Priorities Ran Out on September 30. The Rules Behind Them Did Not.
The SEC Division of Examinations released its fiscal year 2026 examination priorities on November 17, 2025. The fiscal year they governed ended on September 30, 2026. As of today, nothing in the public record confirms when a successor document will arrive.
But here is the part most exam-preparation commentary is missing. A priorities document is a forecast, not a calendar. The obligations it previewed keep running whether or not a new forecast exists, and one of them became binding on smaller firms only on June 3, 2026.
If you run a registered investment adviser with less than $1.5 billion in assets under management, the next examiner may test a Regulation S-P incident response program that has been mandatory for less than four months. Here is what the SEC said, why the gap between priorities and rules matters, and what your leadership team should decide this quarter.
What the First Atkins-Era Exam Priorities Actually Signaled
The Division announced the document in SEC press release 2025-132. These were the first priorities issued under SEC Chairman Paul Atkins. The SEC also states that the list is not an exhaustive account of the areas the Division will examine. That sentence carries more weight than any single priority on the list.
Crypto quietly left the page. According to Goodwin, crypto assets, a stand-alone priority in prior years, are not specifically referenced in the FY2026 document, though custody-rule issues relevant to crypto advisers remain. A WilmerHale summary of the priorities framed the overall posture as a focus on "speeding tickets, not parking tickets."
Absence from the list is a resourcing signal, not a safe harbor. An adviser that holds digital assets for clients still owes the same fiduciary duty it owed in 2025. The change tells you where examiners plan to spend their hours. It does not tell you what they will ignore once they arrive.
Dual registrants face a second checklist. FINRA released its 2026 Annual Regulatory Oversight Report in December 2025. The report covers cybersecurity and third-party risk. The two regulators converge on cyber and vendor risk. The message is unmistakable.
Priorities Expire. Regulation S-P Does Not.
The SEC adopted the Regulation S-P amendments in May 2024 in Release Nos. 34-100155; IA-6604; IC-35193. The rule set two compliance dates. Larger entities had until December 3, 2025, and smaller entities had until June 3, 2026, according to the SEC's small entity compliance guide.
Who landed in which bucket
- Larger entities: Registered investment advisers with $1.5 billion or more in AUM and investment companies with $1 billion or more in net assets, plus broker-dealers and transfer agents that are not small entities, per the Federal Register release.
- Everyone else: All other covered institutions, including most emerging and mid-sized advisers, had until June 3, 2026.
The distinction that matters
A written policy is not a functioning program. The SEC fact sheet requires covered institutions to maintain incident response programs. It requires notice to affected individuals as soon as practicable, but no later than 30 days, after becoming aware of unauthorized access to customer information. It also requires covered institutions to adopt policies reasonably designed to ensure their service providers notify them no later than 72 hours after becoming aware of a breach, according to the SEC's small entity compliance guide.
Those are not aspirations. They are clocks, and an examiner can compare clocks against your records. A firm that adopted a template policy in May 2026 and never tested it has a document, not a defense.
What Your Leadership Team Should Decide Before the Next Exam Letter
Plan for an exam without waiting for new priorities
The SEC calls its list non-exhaustive, and the FY2026 year has closed. Waiting for a fresh document before preparing is a decision to prepare late.
Test the Regulation S-P program, not just the policy
- Run a tabletop exercise against the 30-day clock. Time how long your firm takes to identify affected individuals and draft a notice.
- Inventory every vendor that touches customer information. Confirm that each contract requires notice within 72 hours. Custodians, CRM platforms, and portfolio software providers all count.
- Name one accountable owner. The CCO typically holds the policy, but the CTO or head of operations holds the systems. Decide who runs the clock on day one of an incident.
Build the document production file now
- Assemble your annual compliance review, testing results, and remediation records in one place. Exam request letters arrive with short deadlines.
- Document what you fixed, not only what you found. A remediation trail shows examiners a program that works.
- Reconcile Form ADV, marketing materials, and actual practice. Gaps between what you say and what you do are the classic speeding ticket.
Keep crypto controls on the books
If you custody or trade digital assets for clients, keep those controls in your annual testing cycle. A topic dropped from a forecast can return in the next one.
Key Takeaways for RIA Founders and CCOs
These five points stand on their own and belong in your next board or management meeting.
- The FY2026 priorities have expired, but examinations have not paused. The SEC describes its list as non-exhaustive, and the fiscal year it covered ended September 30, 2026.
- Advisers under $1.5 billion in AUM became subject to amended Regulation S-P on June 3, 2026. Those firms now face their first exam cycle with an incident response program that may never have been tested against a live incident.
- The 30-day customer notice and 72-hour vendor notice are testable deadlines. Examiners can measure your records against both clocks.
- Crypto dropped off the priorities page, not out of fiduciary duty. According to Goodwin, the FY2026 document no longer references crypto assets specifically, yet the obligations attached to client digital assets remain.
- Dual registrants should map SEC and FINRA expectations together. FINRA's 2026 oversight report reinforces cybersecurity and third-party risk.
Verified Sources
- Primary source: SEC Division of Examinations FY2026 Priorities
- Secondary source: Goodwin summary of 2026 SEC exam priorities
Where This Leaves Smaller Advisers
The gap between an expired priorities list and a live rule is where smaller advisers are most exposed this fall. Advisers below the $1.5 billion line generally need their Regulation S-P incident response program, vendor contracts, and annual compliance testing reviewed before the first post-June 3 exam request letter arrives, and that pre-exam review is the work FinTech Law's SEC exam counsel team performs. If that review is not yet on your calendar, schedule it here.
FinTech Law's data privacy counsel team conducts vendor contract reviews for the 72-hour notice requirement.
This blog post is for informational purposes only and does not constitute legal advice. No attorney-client relationship is formed by reading this content. If you need legal advice, please contact a qualified attorney.
FinTech Law fixed engagements: Startup Legal Path Review ($1,500) · Emerging Manager Launch Kit ($7,500) · Regulatory Path Outline ($7,500) · RIA/ERA Registration ($8,500) · Private Fund Formation (~$18,000) · Fractional General Counsel · $7,500/qtr (from Jan 2027). See the catalog.