Back to Blog
    ftc-safeguards-rule
    safeguards-compliance-guide
    ftc-data-protection-rules
    understanding-safeguards-rule
    how-to-meet-ftc-safeguards

    30/90/180 Day Roadmap for FTC Safeguards Rule Compliance Officers

    Dustin CollettSeptember 14, 2026
    30/90/180 Day Roadmap for FTC Safeguards Rule Compliance Officers

    The FTC Safeguards Rule applies to non-bank financial institutions, from mortgage brokers to tax preparers to auto dealers that extend financing, and requires each one to run a written information security program built around a documented risk assessment, a named Qualified Individual, encryption, multi-factor authentication, ongoing testing, and a vendor oversight process. If your firm handles customer financial data and isn't a bank or credit union, you're almost certainly covered, and the 30-day breach reporting rule for incidents affecting 500 or more consumers is the deadline most compliance teams miss first.


    TL;DR:

    • Most small financial firms have scattered, outdated security documentation that fails to prove compliance; evidence like signed reports and logs is essential.
    • Encryption and multi-factor authentication are mandatory for all customer data systems, with testing required every six months unless continuous monitoring is in place.
    • Breach notification obligations now demand reporting any unauthorized access of unencrypted data affecting 500 or more customers within 30 days of discovery.
    • Vendors handling customer information must meet safeguards standards through contractual obligations, ongoing reassessment, and the ability to verify their security posture.
    • Achieving compliance involves a phased approach, focusing on inventory, MFA, encryption, incident plans, and regular testing, especially for smaller institutions with limited resources.

    Table of Contents

    FTC Safeguards Rule Checklist: What to Verify First

    Before you rebuild anything, find out what's already broken. Most non-bank financial institutions we talk to have pieces of a security program scattered across IT tickets, old vendor contracts, and someone's memory of a meeting from two years ago. The FTC doesn't grade on effort. It grades on documentation.

    Start with this sequence, in order:

    • Appoint a Qualified Individual. This person needs actual authority to build and run the program, whether they're an employee, an affiliate, or a contracted security provider.
    • Complete a current data inventory. List every system that touches customer information, including cloud apps, backup vendors, and the spreadsheet your loan officer keeps on a laptop.
    • Verify MFA and encryption coverage. Check every system that stores or transmits customer information, not just the "important" ones.
    • Confirm your incident response plan exists in writing and names who does what during a breach, not just who gets notified.
    • Build an FTC reporting playbook so nobody is Googling "how to report a data breach to the FTC" at 2 a.m. during an actual incident.

    Verification is where most of this falls apart. A policy document proves nothing to an examiner. What proves compliance is evidence: signed risk assessment reports, MFA enrollment logs, penetration test results with remediation timestamps, and board meeting minutes showing the Qualified Individual actually reported. If your program exists only as a PDF nobody's touched since it was written, you don't have a program under 16 CFR Part 314. You have a liability.

    Some of this work genuinely requires outside help. Risk assessments, penetration testing, and encryption architecture typically call for security expertise most small financial firms don't keep on staff full time. Inventory building and policy drafting, on the other hand, are things an internal compliance lead can usually knock out with a template and a few weeks of focused attention.

    Pro Tip: Run a "tabletop" walkthrough of your incident response plan before an examiner or a breach forces you to. Sit your Qualified Individual, IT lead, and a company officer in a room and simulate a ransomware event affecting 600 customer records. If nobody can answer "who calls the FTC and by when," your plan isn't ready.

    Who Has to Comply, and What Counts as Customer Information?

    The Safeguards Rule defines a "financial institution" broadly, and the definition catches far more businesses than the name suggests. Under 16 CFR Part 314, a financial institution is any business "significantly engaged" in activities the Bank Holding Company Act or Federal Reserve Board classifies as financial in nature.

    That sweeps in a long list of businesses that rarely think of themselves as regulated:

    • Mortgage brokers and non-bank lenders
    • Payday and installment lenders
    • Tax preparation services
    • Debt collection agencies
    • Motor vehicle dealers that arrange financing or leasing
    • Retailers issuing their own credit cards
    • Investment advisers not otherwise regulated by the SEC
    • Check-cashing businesses and money transmitters
    • Any company that acts as a "finder," bringing buyers and sellers of financial products together

    "Customer information" is any record containing nonpublic personal information about a customer, whether your firm handles it directly or a service provider handles it on your behalf. That includes Social Security numbers, account numbers, income data, credit histories, and even the fact that someone applied for a loan and was denied. It does not include information that's already publicly available through lawful means, like a business address listed in a public directory.

    Banks, credit unions, and other depository institutions are conspicuously absent from this list, and that's not an oversight. Those entities answer to the Gramm-Leach-Bliley Act's parallel framework enforced through the OCC, the FDIC, the Federal Reserve, and the NCUA, each of which maintains its own interagency guidelines covering essentially the same ground the FTC Safeguards Rule covers for everyone else. If your firm holds a bank charter, this rule isn't yours. If it doesn't, and you touch consumer financial data, it almost certainly is.

    Core Program Requirements: Risk Assessment, Qualified Individual, and Documentation

    Section 314.4 spells out the specific elements a compliant program needs, and treating any one of them as optional is how firms end up in enforcement conversations. The rule requires covered institutions to build a written information security program with administrative, technical, and physical safeguards scaled to the size, complexity, and sensitivity of the data involved, according to FTC guidance.

    The program breaks into three pillars that reinforce each other:

    1. Written risk assessment. This isn't a checkbox exercise. It has to identify reasonably foreseeable internal and external risks to customer information, assess the sufficiency of existing safeguards against those risks, and establish written criteria for evaluating and mitigating identified gaps. The assessment needs periodic reassessment, not a one-time write-up that sits untouched for five years while your systems and vendors change underneath it.

    2. A designated Qualified Individual. This person can be an employee, an affiliate, or someone at a contracted service provider, but the responsibility for the program's adequacy stays with your institution regardless of who holds the title. The Qualified Individual has to report in writing to your board of directors or an equivalent senior governing body at least annually, covering the program's overall status, material risks, recommendations for changes, and any notification events from the prior year.

    3. Program documentation and lifecycle management. Section 314.4 treats your security program as a living document, not a static one. That means change management processes when you add new systems or vendors, and firm rules on data retention: customer information should be disposed of within two years of the last date it's needed for business purposes, unless retention is required by law, necessary for legitimate business reasons, or targeted for deletion isn't reasonably feasible given how the data is stored.

    Pro Tip: Examiners and enforcement staff care less about how sophisticated your controls sound and more about whether you can produce evidence. Keep a running folder of test results, remediation logs, board reporting minutes, and vendor assessment records. That documentation is often the deciding factor in how an FTC enforcement action actually resolves.

    What Technical Controls Does the Rule Actually Require?

    The 2021 amendments made the Safeguards Rule more prescriptive than its original 2003 version, and this is the section where most firms discover gaps they didn't know they had.

    Encryption is required both for customer information at rest and in transit over external networks. The rule builds in a practical caveat: encryption protects you only if the encryption key hasn't also been accessed by whoever got the data. An attacker who steals encrypted records and the keys that unlock them has effectively stolen unencrypted data, and your notification obligations follow accordingly, per the Final Rule text.

    Multi-factor authentication is mandatory for anyone accessing customer information, whether that access happens from inside your network or remotely. Your Qualified Individual can approve an equivalent or more secure access control in place of MFA, but that decision needs to be documented and defensible, not a workaround adopted because MFA felt inconvenient to roll out, especially when using proven enhances overall protection. Firms weighing their MFA rollout options usually find the deployment friction is smaller than expected once legacy systems are mapped.

    Secure development practices apply to any in-house applications your firm builds or maintains, and the rule extends oversight to third-party applications your business relies on to handle customer information.

    Testing and monitoring is where the rule gets specific about frequency. Institutions have two paths: implement continuous monitoring, or, absent that, run annual penetration testing paired with vulnerability assessments, including system-wide scans at intervals of six months or less, according to 16 CFR Part 314. Either path also requires testing after any material change to your systems or operations, not just on a fixed calendar.

    • Continuous monitoring satisfies the testing requirement on its own, without a separate annual pen test
    • Institutions without continuous monitoring need both an annual penetration test and vulnerability scans at least every six months
    • Any material system change (new vendor, new application, infrastructure migration) triggers a fresh testing cycle regardless of where you are in the annual schedule

    The six-month vulnerability scan cadence catches firms off guard more than any other requirement in the rule, largely because most small institutions historically treated an annual scan as sufficient. It no longer is.

    Breach Notification: The 500-Consumer, 30-Day Rule

    If unauthorized parties acquire unencrypted customer information affecting 500 or more consumers, you have to report it to the FTC as soon as possible, and no later than 30 days after discovery. This amendment, announced in October 2023, is the single biggest operational change non-bank financial institutions have faced under this rule, and it created an entirely new administrative reporting duty separate from whatever your state's breach law already requires.

    A "notification event" is defined as unauthorized acquisition of unencrypted customer information. The rule presumes unauthorized access to unencrypted data constitutes unauthorized acquisition unless you have reliable evidence proving otherwise, meaning the burden sits on you to demonstrate data wasn't actually taken, not on the FTC to prove it was.

    A few operational details matter here:

    • The clock starts at "discovery," which the FTC interprets as when you know, or reasonably should have known, that a notification event occurred, not when your forensic investigation formally concludes.
    • The report goes through an online reporting form and must include the nature of the event, the number of consumers affected, and a description of what customer information was involved.
    • Notification can be delayed if a law enforcement agency requests it in writing to avoid interfering with an active investigation, but that delay has to be documented, not assumed.
    • This FTC obligation runs alongside, not instead of, your state's own breach notification law. Meeting one doesn't automatically satisfy the other, so your incident response plan needs both tracks mapped out in advance.

    How Should You Manage Service Providers Under This Rule?

    Your obligations under the Safeguards Rule don't stop at your own network perimeter. Any vendor that touches customer information on your behalf, a payment processor, a cloud backup provider, a document management system, needs to meet safeguards standards comparable to your own, and you're expected to select vendors capable of maintaining them in the first place.

    That expectation has to show up in contract language, not just good intentions. Contracts with service providers should include:

    • Explicit requirements to implement and maintain appropriate safeguards for customer information
    • Obligations to notify you promptly if the provider experiences a security incident involving your data
    • Audit rights letting you verify the provider's security posture, not just take their word for it
    • Controls extending to any subprocessors the vendor uses downstream

    Periodic reassessment matters as much as the initial vetting. A vendor that looked solid during onboarding two years ago may have changed ownership, cut security staff, or expanded into subprocessors you've never reviewed. Risk-based reassessment, weighted toward vendors handling your most sensitive data, keeps that drift from becoming a blind spot, and documenting each assessment and any remediation that followed gives you the paper trail an examiner will ask for.

    A 30/90/180-Day Roadmap for Getting Compliant

    The FTC has said explicitly that programs should scale to an institution's size and complexity, meaning a five-person tax prep firm isn't expected to build the same infrastructure as a regional lender, according to the FTC's 2025 guidance. Here's a proportional sequence that works for most small and mid-sized institutions:

    1. Days 1 to 30: Complete your data inventory, designate a Qualified Individual, run a quick audit of MFA and encryption coverage across systems handling customer information, and update your incident response plan with FTC reporting steps included.
    2. Days 31 to 90: Finish a written risk assessment, prioritize remediation based on what that assessment surfaces, and either stand up continuous monitoring or schedule your first penetration test and vulnerability scan cycle.
    3. Days 91 to 180 and ongoing: Deliver your first formal board report, reassess key vendors, and lock in a recurring cadence for testing, documentation updates, and staff training.

    Smaller institutions generally see the fastest return by prioritizing inventory, MFA, encryption of high-value systems, and a tested incident response playbook before chasing anything more elaborate. A small business cybersecurity checklist built around this kind of scaled approach tends to outperform a rushed attempt at enterprise-grade controls that nobody on staff can maintain.

    Pro Tip: Managed and co-managed IT arrangements often compress the 90-day phase significantly, since monitoring infrastructure and testing relationships are already in place rather than built from scratch.

    Three-phase FTC compliance roadmap

    A Managed-IT Perspective on Making This Rule Actually Work

    Most of the technical requirements in this rule, monitoring, MFA, encryption, testing cadence, are things a managed IT provider handles as standard practice, which is exactly why so many non-bank financial institutions lean on outside partners to operationalize compliance rather than building it alone. But outsourcing the work doesn't outsource the responsibility. The Qualified Individual obligation, board reporting, and ultimate accountability for the program's adequacy stay with your institution no matter who's running the monitoring dashboard. The firms that pass examinations cleanly are the ones that treat their IT partner as an extension of the compliance function, with contracts and evidence that prove active oversight, not the ones that assume a vendor relationship equals a completed obligation.

    , Dustin Collett

    How Collett Systems LLC Supports Safeguards Rule Compliance

    Building a compliant security program while running a mortgage brokerage, a collection agency, or a tax practice isn't a fair fight if you're doing it with a part-time IT contractor and a spreadsheet. Collett Systems LLC delivers the fixed-cost, fully-loaded IT stack that turns Safeguards Rule obligations into standing infrastructure rather than a scramble every time an examiner calls: 24/7 monitoring, MFA rollout across every system touching customer information, encryption management, and documented incident response support built specifically for financial services firms in Wisconsin.

    Collett Systems LLC

    We also handle the pieces most firms underestimate: penetration testing and vulnerability management on the six-month cadence the rule requires, and the documentation trail (test results, remediation logs, board reporting materials) that examiners actually ask to see. Every service runs on flat per-user pricing, so there's no surprise invoice when your risk assessment surfaces a gap that needs closing. If you're not sure where your program stands today, start with an IT & Security Assessment and get a clear picture of what's covered, what's exposed, and what needs to happen next.

    Primary Sources for the FTC Safeguards Rule

    Verify anything in this article against the rule's actual text before making compliance decisions. These are the sources that matter:

    Sources

    FAQ

    What Are the Latest Updates to the FTC Safeguards Rule?

    The most significant recent change is the 2023 amendment requiring non-bank financial institutions to report data breaches affecting 500 or more consumers to the FTC within 30 days of discovery, layered on top of the 2021 amendments that added specific technical requirements like MFA and encryption.

    Is the FTC Safeguards Rule Part of GLBA?

    Yes. The Safeguards Rule was issued by the FTC under the authority of the Gramm-Leach-Bliley Act, which requires financial institutions to protect the security and confidentiality of customer information.

    Does the FTC Safeguards Rule Apply to Banks?

    No. Banks, credit unions, and other depository institutions are covered by parallel data security guidelines enforced through their own federal regulators, including the OCC, FDIC, Federal Reserve, and NCUA, rather than by the FTC.

    What Is the Federal Legislation That Includes the Safeguards Rule?

    The Safeguards Rule exists because of the Gramm-Leach-Bliley Act, a federal law that directed the FTC and other agencies to establish standards protecting the security of consumer financial information.

    How Long Do We Have to Keep Customer Information Before Disposal?

    Under §314.4, customer information should generally be disposed of within two years after the last date it's needed for business purposes, unless a legal requirement, legitimate business need, or storage limitation makes targeted disposal impractical.