
The FTC Safeguards Rule requires non-bank financial institutions to run a written information security program with specific controls: a Qualified Individual in charge, a written risk assessment, encryption, multi-factor authentication, testing, an incident response plan and an annual report to leadership. Since May 13, 2024, it also requires many of them to notify the Federal Trade Commission of certain breaches within 30 days.
If you run an auto dealership that arranges financing, a mortgage brokerage, a tax practice or a consumer lender, this probably means you. This guide covers who is covered, the nine program elements, what small firms can skip and breach reporting. Our IT governance, risk and compliance team runs the risk assessment, gap analysis and policy work behind a compliant program.
This article is general information, not legal advice. Confirm how the rule applies to your business with your counsel.
Key takeaways
- Coverage turns on activities: arranging car loans, brokering mortgages, preparing tax returns and consumer lending all count.
- Section 314.4 lists nine program elements, from a Qualified Individual to a written annual report to the board.
- MFA is required for anyone accessing any information system, and customer information must be encrypted at rest and in transit.
- Without continuous monitoring, you need an annual penetration test and vulnerability assessments at least every six months.
- Firms with customer information on fewer than 5,000 consumers skip four requirements, but not the core controls.
- Breaches of unencrypted information on 500 or more consumers go to the FTC within 30 days of discovery.
Where this guidance comes from. We used the current text of 16 CFR Part 314 on eCFR, the FTC’s small entity compliance guide, its 2025 auto dealer FAQs, its May 2024 blog post and breach reporting form, the November 2023 Federal Register notice and an August 2026 IRS release. The practical advice reflects our team’s field experience building security programs, testing networks and responding to incidents.
What the FTC Safeguards Rule is and why it changed
The Safeguards Rule implements the Gramm-Leach-Bliley Act. The FTC’s small entity compliance guide says it took effect in 2003 and was amended in 2021 to give more concrete direction. Under 16 CFR 314.3, your program must be written and include administrative, technical and physical safeguards suited to your size, activities and the sensitivity of the data.
Two dates matter most. The FTC’s May 2024 business blog post says the 2021 updates took effect on June 9, 2023, after a six-month extension the agency announced in a November 2022 press release. A second amendment, published in the Federal Register on November 13, 2023, added breach reporting to the FTC, effective May 13, 2024.
Who the FTC Safeguards Rule covers
The FTC Safeguards Rule applies to financial institutions under FTC jurisdiction that no other regulator oversees under the Gramm-Leach-Bliley Act. That generally leaves out banks and pulls in many non-bank businesses. An entity qualifies if it is significantly engaged in an activity that is financial in nature.
Drawing on Section 314.2(h), the FTC guide lists mortgage lenders, payday lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, collection agencies, credit counselors and financial advisors, tax preparation firms, non-federally insured credit unions and investment advisors not required to register with the SEC. The 2021 amendments added finders.
A retailer is not covered merely because it accepts other issuers’ credit cards, offers occasional layaway or lets a customer run a tab.
Auto dealers
The FTC’s 2025 FAQs for automobile dealers state that the rule covers most dealers who finance or lease vehicles. A dealer that finances or helps arrange financing is a financial institution, and so is one that leases vehicles for longer than 90 days. Arranging a loan creates a continuing relationship even if you never hold the paper, and you must protect that information as long as you keep it.
Service records and names collected from every buyer are not customer information on their own. But systems connected to those holding customer information must be secured, so most dealership networks fall in scope.
Tax preparers, CPA firms and other professionals
Section 314.2(h) names an accountant or tax preparation service in the business of completing income tax returns as a financial institution. In release IR-2026-92 dated August 18, 2026, the IRS reminded tax professionals that federal law requires tax and accounting professionals to create and maintain a written information security plan and pointed them to Publication 5708.
The nine elements of a Safeguards Rule information security program
Section 314.4 lists nine elements, (a) through (i), plus the FTC notification duty in paragraph (j). Use this table as a requirements checklist. The last column shows what Section 314.6 removes for institutions holding customer information on fewer than 5,000 consumers.
| Section 314.4 element | What the rule requires | Evidence to keep | Fewer than 5,000 consumers |
|---|---|---|---|
| (a) Qualified Individual | One person oversees and enforces the program; may be an employee, affiliate or provider. | Written designation and named senior overseer | Applies |
| (b) Risk assessment | Written, with criteria for rating risks and controls and for mitigating or accepting each risk; repeated periodically. | Dated assessment and risk register | (b)(1) exempt |
| (c) Safeguards | Access controls, inventory, encryption, secure development, MFA, disposal, change management, logging. | Policies, settings, access reviews, logs | Applies |
| (d) Testing and monitoring | Continuous monitoring, or annual penetration test plus six-month vulnerability assessments. | Test reports, remediation tickets | (d)(2) exempt |
| (e) Training and personnel | Awareness training for all staff; qualified security personnel. | Training records | Applies |
| (f) Service provider oversight | Select capable providers, require safeguards by contract, reassess periodically. | Vendor list, contracts, assessments | Applies |
| (g) Keep the program current | Adjust after tests, assessments and business changes. | Program revision history | Applies |
| (h) Incident response plan | Written plan covering seven required areas. | Approved plan, exercise records | Exempt |
| (i) Report to the board | Written report at least annually to the board or a senior officer. | Signed report | Exempt |
| (j) FTC notification | Notify the FTC within 30 days of discovering an event involving 500 or more consumers. | Decision log, FTC submission | Applies |
(a) and (b): Qualified Individual and risk assessment
The FTC guide says the Qualified Individual needs no particular degree or title, only know-how suited to your business. The written risk assessment needs criteria for rating risks and judging controls, plus how each risk will be mitigated or accepted. Start with an inventory of the customer information you hold, including paper files.
(c) through (g): safeguards, testing, training and vendors
The safeguards in (c) are covered in the next section. You must also test or monitor key controls, train all staff, use qualified security personnel, and oversee service providers through selection, contract terms and periodic assessments. Then adjust the program as results and the business change.
(h) and (i): incident response plan and annual board report
The plan must cover goals, internal processes, roles and decision authority, communications, remediation, documentation and post-event review. The Qualified Individual’s annual written report goes to the board, or a senior officer if there is none, and covers program status, risk decisions, vendor arrangements, test results and security events.
Need a starting point? We can map your current controls to each Section 314.4 element, write the risk assessment and give you a prioritized remediation list. Request a Safeguards Rule gap assessment online, or book a consultation online to talk through your situation first.
Safeguards requirements: MFA, encryption, access and disposal
Section 314.4(c) is where most small institutions find gaps.
- Multi-factor authentication. Required for any individual accessing any information system, using at least two of knowledge, possession and inherence factors. The only alternative is an equivalent control approved in writing by the Qualified Individual. Our guide to phishing-resistant MFA explains which methods hold up best against phishing.
- Encryption. Customer information must be encrypted at rest and in transit over external networks. If that is infeasible, the Qualified Individual can approve effective compensating controls.
- Access controls. Authenticate users and limit each one to the customer information needed for their job, then review access periodically.
- Inventory. Identify and manage your data, personnel, devices, systems and facilities by importance.
- Secure disposal. Dispose of customer information in any format no later than two years after it was last used for that customer, unless you need it for business or legal reasons or targeted disposal is not feasible. Review your retention policy periodically.
- Change management and logging. Adopt change management procedures, and monitor and log authorized users’ activity so you can detect unauthorized access or tampering.
The auto dealer FAQs add that providers with direct network access should use MFA, and providers storing your customer information should encrypt it.
Penetration testing and vulnerability assessment requirements
Section 314.4(d)(2) gives you a choice. You can run effective continuous monitoring that detects changes creating vulnerabilities, or you must perform annual penetration testing based on your risk assessment and vulnerability assessments at least every six months. Vulnerability assessments are also required whenever there are material changes to your operations or business arrangements.
Few small firms can show monitoring strong enough to replace testing. Scope the test to systems that hold or connect to customer information, often including the dealer management or loan system, email and remote access. Our penetration testing service scopes tests in writing and delivers a prioritized remediation roadmap, and our article on penetration testing cost and scope explains what drives the price.
The 5,000-consumer small-entity exemption
Section 314.6 says four provisions do not apply to institutions that maintain customer information concerning fewer than 5,000 consumers: the written risk assessment in 314.4(b)(1), the testing schedule in 314.4(d)(2), the written incident response plan in 314.4(h) and the annual board report in 314.4(i).
That is narrower than many owners assume. You still need a Qualified Individual, a written program, encryption, MFA, access controls, training, vendor oversight and FTC notification. Count carefully: the threshold covers every consumer whose information you maintain, including past customers whose files you never purged.
Breach notification: reporting to the FTC within 30 days
Section 314.4(j) requires you to notify the FTC as soon as possible, and no later than 30 days after discovery, of a notification event involving the information of at least 500 consumers. A notification event is unauthorized acquisition of unencrypted customer information. Encrypted data counts as unencrypted if the key was also accessed, and unauthorized access is presumed to be acquisition unless you have reliable evidence it was not.
Discovery is the first day the event is known to any employee, officer or other agent other than the person committing the breach. Build that decision into your incident response plan. Our guide to building and testing an incident response plan shows how to rehearse it, and our cyber incident response team can triage, contain and document an event for regulators and insurers.
The FTC’s online reporting form asks for the institution’s contact, event dates, number of consumers affected, types of information and a summary. The FTC guide says to report what you know, update later, and expect that reports may be made public. If law enforcement determines in writing that public notice would impede an investigation, it can request a delay of up to 30 days, extendable by up to 60 more.
State laws may add duties. For example, Arizona’s breach statute, A.R.S. 18-552(N), says it does not apply to a person subject to Title V of the Gramm-Leach-Bliley Act. Other states handle this differently, so confirm your state obligations with counsel.
Choosing a Qualified Individual: in-house, vCISO or provider
Most small institutions have no security leader on staff. The rule lets an employee, affiliate or service provider fill the role, with a senior employee overseeing the work. A fractional security leader is a common fit, and our vCISO services guide compares engagement models and what to expect.
Ask each candidate how they will produce the risk assessment, approve exceptions in writing, oversee vendors and deliver the board report. Our virtual CISO service covers risk assessment, policy, vendor risk and board-ready reporting on a fractional basis.
FTC Safeguards Rule compliance roadmap
Starting from scratch, this order produces evidence as you go.
- Confirm coverage with counsel and count the consumers whose information you hold.
- Designate the Qualified Individual and any senior overseer.
- Inventory customer information, systems, devices, vendors and paper records.
- Write the risk assessment, even under 5,000 consumers.
- Enforce MFA and encryption; document approved exceptions.
- Set access reviews, logging, change management and a disposal schedule.
- Add security requirements to vendor contracts.
- Train all staff and schedule refreshers.
- Run a vulnerability assessment and penetration test, then fix and retest.
- Write and rehearse the incident response plan, including the FTC reporting decision.
- Deliver the first written board report and set the annual cycle.
How Honeybadger Solutions helps with the FTC Safeguards Rule
We are a veteran-owned SDVOSB based in Casa Grande, Arizona, delivering compliance and cyber services nationwide. For Safeguards Rule work, our governance team runs the gap analysis and risk assessment, writes policies that match how you operate, builds an evidence repository and assesses your vendors. Our vCISO can lead the program and board reporting, our testers handle penetration testing and vulnerability assessments, and our incident response team helps you prepare for a breach.
Lenders and other financial businesses with branches or cash operations can pair this with our banking and financial security services, which cover branch and operations-center physical security and licensed fraud and insider investigations. We build and evidence the program; your counsel provides the legal judgment.
To get started, submit a service request online with your business type, the rough number of consumers whose information you hold and your main systems, or book a consultation if you would rather talk it through first. Use the buttons below.
Why the online intake is faster than a phone call: it takes about two minutes, and your answers are routed straight to the specialist team that handles your kind of matter, whether that is cyber and forensics, investigations or field security. That team sees the full picture before it replies, so you skip phone tag and get a real answer and next steps sooner. If it cannot wait for business hours, use the urgent intake form, which is read seven days a week.
Frequently asked questions
Does the FTC Safeguards Rule apply to my small business?
It applies if your business is significantly engaged in a financial activity and no other federal regulator enforces the Gramm-Leach-Bliley Act against you. Auto dealers that arrange financing, mortgage brokers, payday lenders, finance companies, tax preparers and collection agencies are common examples.
Are CPA firms and tax preparers covered?
Yes, when they complete income tax returns. The rule names an accountant or tax preparation service in that business as a financial institution, and the IRS said in August 2026 that federal law requires tax and accounting professionals to maintain a written information security plan.
What does the 5,000-consumer exemption remove?
Section 314.6 removes four items for institutions with customer information on fewer than 5,000 consumers: the written risk assessment, the testing schedule, the written incident response plan and the annual board report. Every other element of the FTC Safeguards Rule still applies.
When do I have to notify the FTC of a breach?
As soon as possible and no later than 30 days after discovery, if unencrypted customer information of at least 500 consumers was acquired without authorization. Encrypted data counts as unencrypted if the key was also accessed. Reports may be made public.
Can an outside provider be our Qualified Individual?
Yes. The Qualified Individual may work for you, an affiliate or a service provider. If you outsource the role, you keep responsibility for compliance and must designate a senior employee to oversee that person.
Sources and further reading
- eCFR: 16 CFR Part 314 (current as of October 2026) — Rule text and definitions.
- eCFR: 16 CFR 314.4, Elements — Program elements and FTC notice.
- eCFR: 16 CFR 314.6, Exceptions — 5,000-consumer exemption.
- FTC: What Your Business Needs to Know (December 2024) — Small entity compliance guide.
- FTC: Auto Dealer Safeguards FAQs (2025) — Dealer coverage and vendors.
- FTC Business Blog: Notification requirement now in effect (May 2024) — Effective dates.
- FTC press release: six-month extension (November 2022) — June 9, 2023 deadline.
- Federal Register: 88 FR 77499 (November 13, 2023) — Breach notification amendment.
- FTC: Safeguards Rule reporting form — Required fields.
- IRS IR-2026-92 (August 2026) — WISP requirement for tax professionals.
- A.R.S. 18-552 — Arizona breach law GLBA exemption.
Written and reviewed by the Honeybadger Solutions security and investigations team, a veteran-led Arizona firm (Arizona DPS private investigation agency license No. 1759795). Facts checked against the cited sources on October 2, 2026. This article is general information, not legal advice.
Browse by topic
Security guard services  · Private investigations  · Cybersecurity  · Digital forensics  · Financial fraud investigation  · Executive protection  · All articles