β‘ Quick Facts
Does the FTC Safeguards Rule Apply to Your Business?
The rule applies to "financial institutions" β but the FTC defines this term much more broadly than you expect. It is not just banks and credit unions. If your business is "significantly engaged" in financial activities, you are covered. This includes:
- Auto dealers that arrange financing or leasing
- Mortgage brokers and real estate settlement agents
- Payday lenders and check-cashing businesses
- Tax preparers and accounting firms
- Investment advisors and wealth managers
- Debt collectors and credit counselors
- Retailers that offer store credit or financing plans
- Fintech companies handling payments, lending, or digital wallets
The rule uses a "significantly engaged" test β if more than a small fraction of your business involves financial activities, you are likely covered. When in doubt, assume it applies. The cost of compliance is far less than the cost of a violation.
Security Assessment: Are You FTC-Ready?
Our 20-question assessment checks your security posture against the Safeguards Rule requirements. Takes 3 minutes.
Start Free Assessment βThe 9 Requirements of the FTC Safeguards Rule
The updated Safeguards Rule (effective June 2023, with some provisions extended to 2024 for smaller businesses) requires financial institutions to develop, implement, and maintain a comprehensive information security program. Here are the 9 specific requirements:
1. Designate a Qualified Individual (QI)
One person must be responsible for your information security program. This can be an employee or a managed service provider. The QI must report to your board or senior management at least annually.
2. Conduct a Risk Assessment
Identify foreseeable internal and external risks to customer information. Assess the sufficiency of existing safeguards. This must be documented in writing and updated periodically as your business or threat landscape changes.
3. Implement Access Controls
Limit access to customer information to employees who need it. Require unique user IDs and strong passwords. Implement MFA for anyone accessing customer information systems β this is mandatory, not optional.
4. Inventory Data, Personnel, Devices, and Systems
Know where customer data lives, who can access it, and what devices and systems process it. You cannot protect what you do not know exists.
5. Encrypt Customer Information
Encrypt data at rest and in transit. If encryption is not feasible, you must document why and use alternative compensating controls β but "it would be inconvenient" is not a valid reason.
6. Secure Application Development and Testing
Follow secure development practices for any in-house software. Conduct penetration testing and vulnerability scanning at least annually. Remediate findings promptly.
7. Monitor and Log Activity
Log authorized user activity and monitor for unauthorized access. Review logs regularly. Retain logs for a defined period to support forensic analysis if a breach occurs.
8. Assess Service Provider Security
Select service providers (IT vendors, cloud services, data processors) that can maintain appropriate safeguards. Contractually require them to implement and maintain security measures. Reassess periodically.
9. Create an Incident Response Plan
Document what you will do when (not if) a security event occurs. Include: goals, decision-making authority, internal and external communications, remediation steps, legal and regulatory reporting obligations, and post-incident review.
Data Breach Response Guide
Step-by-step guide: contain the breach, notify customers, report to regulators. Includes notification letter templates.
Read Breach Response Guide βThe Written Information Security Plan (WISP)
The WISP is the cornerstone document of Safeguards Rule compliance. It describes your security program and must address all 9 requirements above. For most small businesses, a WISP is 5-10 pages. It should be reviewed and updated at least annually. The FTC will ask for this document first in any investigation.
Your WISP should cover: the QI designation, risk assessment findings, access controls, data inventory, encryption practices, secure development standards, monitoring and logging, service provider oversight, and your incident response plan. It does not need to be written by a lawyer, but having one review it is advisable.
Key Takeaway for Small Business Owners
The FTC Safeguards Rule is not going away β enforcement is increasing. In 2025, the FTC brought multiple actions against small and mid-sized businesses for Safeguards violations. The good news: the requirements are essentially good security practices you should be doing anyway. MFA, encryption, risk assessments, and incident response planning are not regulatory overhead β they are what protect your business from real threats. Start with MFA and a risk assessment. Those two alone address the majority of your exposure.