DSE Cybersecurity · Regulated readiness lane

The Rule is broader than banks.

The FTC Safeguards Rule at 16 CFR part 314 applies to non-bank businesses that the Rule itself calls financial institutions. If that is you, the Rule already requires a named Qualified Individual, a written risk assessment, specific safeguards, a written incident response plan, and an annual written report to your board. We assess what exists, name what does not, and hand you the artifacts to close the gap.

For non-bank financial institutions under FTC jurisdiction. Readiness and advisory work. Not legal advice, not an audit, not a certification.

Entity scope

Who this is for, and who it is not for.

This lane is scoped to a specific legal status, not to an industry mood. 16 CFR 314.1(b) applies the Rule to financial institutions over which the FTC has jurisdiction, meaning those not already subject to another regulator's enforcement authority under section 505 of the Gramm-Leach-Bliley Act. 16 CFR 314.2(h) then defines financial institution by activity, and the Rule's own examples reach well past banking.

In scope

Lending and mortgage

16 CFR 314.1(b) names mortgage lenders, mortgage brokers, "pay day" lenders, finance companies, and account servicers as entities subject to the Commission's enforcement authority.

In scope

Money movement

The same paragraph names check cashers, wire transferors, and collection agencies. 16 CFR 314.2(h)(2) adds a business that regularly wires money to and from consumers.

In scope

Advice and preparation

Tax preparation firms, credit counselors and other financial advisors, and investment advisors that are not required to register with the SEC are named in 16 CFR 314.1(b).

In scope

Property and settlement

16 CFR 314.2(h)(2) treats a personal property or real estate appraiser, and an entity providing real estate settlement services, as financial institutions.

In scope

Retail and auto credit

A retailer that issues its own credit card directly to consumers, and an auto dealership that as a usual part of its business leases vehicles on a non-operating basis for longer than 90 days, are both named examples.

In scope

Finders and niche services

Entities acting as finders, non-federally insured credit unions, career counselors serving financial organizations, and travel agencies operated in connection with financial services are named.

This lane is not for you if: you are a bank, savings association, or federally insured credit union whose GLBA safeguards obligations sit with a banking regulator or the NCUA rather than the FTC; you are an SEC-registered broker-dealer, investment company, SEC-registered investment adviser, or registered transfer agent, in which case 17 CFR 248.30 is your rule and the Regulation S-P readiness lane is the right route; your financial activity is subject to CFTC jurisdiction under the Commodity Exchange Act, or you are the Federal Agricultural Mortgage Corporation or a Farm Credit Act entity, each of which 16 CFR 314.2(h)(3) excludes from the definition; or you are not significantly engaged in financial activities. 16 CFR 314.2(h)(4) is explicit that a retailer whose only credit is occasional layaway or deferred payment, a merchant that merely lets a customer run a tab, and a grocery store that merely cashes checks are not financial institutions. We do not claim the Rule applies universally. If the facts you describe in the diagnostic call suggest the Rule may not reach your business, we will say that we are not the right engagement for you and point you to your counsel — that is a qualification decision about our own scope, not a legal opinion about yours.

Whether the Rule applies to your business is a legal determination. Your counsel makes it. We scope the work to the status you and your counsel confirm.

Current requirements

Ten elements. Each one has an evidence answer.

16 CFR 314.4 lists the elements of the information security program. These are current obligations in force today, not proposals. We assess each against what you can actually produce.

§314.4(a)

Qualified Individual

A single designated person responsible for overseeing, implementing, and enforcing the program. The role may sit with an affiliate or a service provider, but you retain responsibility for compliance, must designate a senior member of your own personnel to direct and oversee that person, and must require the provider to maintain a program that protects you.

§314.4(b)

Written risk assessment

Written, with criteria for evaluating and categorizing threats, criteria for assessing confidentiality, integrity, and availability including the adequacy of existing controls, and requirements describing how identified risks will be mitigated or accepted. Periodic reassessment is required under §314.4(b)(2).

§314.4(c)

Eight named safeguards

Access controls, asset and data inventory, encryption of customer information in transit over external networks and at rest — or, where you determine encryption is infeasible, effective alternative compensating controls your Qualified Individual reviews and approves. Secure development practices. Multi-factor authentication for any individual accessing any information system, unless your Qualified Individual has approved in writing reasonably equivalent or more secure access controls. Secure disposal, change management, and controls to log authorized-user activity and detect unauthorized access. Where you rely on either written-approval path, the written approval is itself the evidence, and we check that it exists.

§314.4(d)

Testing regime

Regular testing of key controls. §314.4(d)(2) requires either continuous monitoring of information systems or, absent it, annual penetration testing plus vulnerability assessments at least every six months and on material change. DSE does not provide continuous monitoring, managed detection and response, or penetration testing; we assess whether your chosen path exists and is evidenced.

§314.4(e), (f), (g)

People, providers, and adjustment

Security awareness training updated to reflect the risk assessment, qualified information security personnel, and training sufficient to address relevant risks. Service-provider selection, contractual safeguard requirements, and periodic risk-based reassessment. And under §314.4(g), a documented obligation to evaluate and adjust the program in light of the §314.4(d) testing and monitoring results, material changes to operations, and any other circumstances you know may have a material impact.

§314.4(h), (i), (j)

Response, report, notify

A written incident response plan covering seven named areas. A written report from the Qualified Individual to the board or equivalent governing body, regularly and at least annually. And under §314.4(j), notification to the FTC of a security event involving the unencrypted customer information of 500 or more consumers.

The small-institution exception is narrow. 16 CFR 314.6 exempts financial institutions maintaining customer information concerning fewer than five thousand consumers from four provisions only: §314.4(b)(1), (d)(2), (h), and (i). Every other element still applies. We check the consumer count against your own records before relying on it, and we do not assume it.

Effective dates

What is in force, and since when.

The table scrolls horizontally on smaller screens. Keyboard users can focus the labeled table region and use horizontal navigation.

FTC Safeguards Rule rulemaking history relied on in this engagement
RulemakingCitationPublishedStatus and date relied on
Standards for Safeguarding Customer Information (2021 amendments)86 FR 70272December 9, 2021Final rule, effective January 10, 2022. Added the Qualified Individual, the written risk assessment, the eight §314.4(c) safeguards, the incident response plan, and the board report.
Delay of effective date for portions of the 2021 amendments87 FR 71509November 23, 2022Final rule, effective November 23, 2022. Delayed the effective date of specified provisions of the 2021 amendments. Those provisions are now in force.
Security event notification amendment88 FR 77499November 13, 2023Final rule. 16 CFR 314.5 states that §314.4(j) is effective as of May 13, 2024. The FTC notification duty is current.

No phased compliance dates remain outstanding for this Rule. Every element described on this page is a current obligation as of this page's last review date. We have not relied on any proposed rule for this lane, and we do not present proposals as requirements.

Deliverables

Named artifacts. Not a slide deck.

01

Applicability worksheet

A structured factual worksheet recording which of your activities appear to engage the Rule's definitions, which entity or entities would be in scope on those facts, and the consumer-count basis for any §314.6 exception. It records facts and the rule text side by side for your counsel to reach the conclusion; it is not a legal opinion and does not state one.

02

Element-by-element gap register

Every requirement in §314.4(a) through (j) with the evidence you produced, the gap, a severity rating, an accountable owner, and a target date. This is the working document the engagement is built around.

03

Written risk assessment draft

A §314.4(b)(1)-shaped draft containing the threat evaluation and categorization criteria, the confidentiality, integrity, and availability assessment criteria, and the mitigation-or-acceptance requirements, populated from your environment for your Qualified Individual to own and adopt.

04

Incident response plan draft

A written plan addressing the seven areas named in §314.4(h), including a §314.4(j) notification decision path for a security event involving the unencrypted customer information of 500 or more consumers.

05

Qualified Individual board-report template

A reusable §314.4(i) report structure covering overall program status, compliance, and material matters, with the evidence each section should cite. You run it; we do not sign it.

06

Prioritized remediation roadmap

Immediate actions and a sequenced plan balancing risk reduction, dependencies, effort, and cost, with an executive readout. Where remediation implementation is needed, it is scoped separately in writing.

Typical timebox: 2 to 4 weeks after kickoff and timely evidence access. Multi-entity, multi-brand, or high-complexity environments are scoped separately. Fees are scoped after the diagnostic and confirmed in writing before work begins. This lane rides on the same evidence method as the cybersecurity risk assessment; where you need both, we sequence them rather than bill them twice. Where remediation implementation follows the readiness cycle, it is scoped separately in writing and may be delivered by a disclosed qualified specialist from DSE's expert network. DSE remains accountable for scope, quality, and integration.

Primary sources

Every claim traces to the rule text.

We cite the regulation and the rulemaking record, not vendor explainers or blog summaries. These are the sources this page relies on.

We do not publish enforcement counts, average penalty figures, or breach statistics for this Rule. If a number cannot be traced to a primary source, it does not appear on this page.

Clear boundaries

Readiness work, not assurance.

This is a point-in-time readiness assessment of the systems, people, documentation, and evidence in the agreed scope. It is not legal advice, not an audit, not a certification, not an attestation, and not a regulatory examination. It does not guarantee compliance, an enforcement outcome, insurance coverage, a contract award, or eligibility for anything. It does not make your organization secure and does not prevent, detect, or reduce the likelihood of any security incident; it documents risk against a defined scope at a point in time. DSE does not operate a security operations center, does not provide continuous monitoring or managed detection and response, does not perform live incident response or digital forensics and incident response (DFIR), and does not run penetration tests. Where you need any of those, we help you scope the requirement and select a provider you contract directly. Remediation implementation is the one item on this list DSE will perform, and only where it is separately scoped in writing. Whether the Rule applies to you, and whether your program satisfies it, are determinations for your counsel, your Qualified Individual, and the Commission. Counsel, auditors, assessors, and carriers retain their respective roles. The Qualified Individual under 16 CFR 314.4(a) is your designation to make and your program to own. DSE does not serve as your Qualified Individual, and does not sign your §314.4(i) board report.