← Notes
July 25, 2026 · 7 min read

The FTC Safeguards Rule, in plain English

The Safeguards Rule reaches far more small firms than the phrase “financial institution” suggests — tax preparers, bookkeepers, advisers and firms that arrange financing. What it asks for, and what changes if you hold fewer than 5,000 consumers’ records.

Most small firms that fall under the FTC’s Safeguards Rule have never heard of it, because the phrase it turns on — “financial institution” — sounds like it means banks. It does not. The definition covers businesses significantly engaged in activities that are financial in nature, and that sweeps in a lot of firms with no vault and no tellers.

Who it tends to reach

Firms that are commonly inside the definition include tax preparers, bookkeepers and accountants doing tax work, investment advisers, mortgage brokers and lenders, businesses that arrange financing or leases for customers, collection agencies, and real estate appraisers. The common thread is handling customers’ financial information as a meaningful part of what you do.

Whether the Rule reaches your particular business is a legal determination, and it is worth getting an actual answer from counsel rather than inferring one from a list. The cost of being wrong runs in both directions: unnecessary work if you are outside it, an unmet federal obligation if you are inside it and assumed otherwise.

What it asks for

The Rule asks for a written information security program, and then sets out the elements that program is expected to contain. In plain terms:

  • A named individual responsible for the program — the Rule calls this the Qualified Individual. In a small firm this is usually the owner, and naming them in writing is the point.
  • A written risk assessment: what customer information you hold, where it lives, and what could go wrong with it.
  • Access controls and a record of where customer information actually is. You cannot protect what nobody has written down.
  • Encryption of customer information in transit and at rest.
  • Multi-factor authentication for anyone accessing a system holding customer information — unless the Qualified Individual approves an equivalent control in writing.
  • Secure disposal of customer information within two years of the last time it was needed for business.
  • Staff training.
  • Written oversight of service providers — the vendors who touch your customers’ information on your behalf.
  • A written incident response plan.
  • A written report to the owner or board at least annually.

The part small firms usually miss

The Rule scales with size, and this matters enormously for a business of one to fifty people. A firm holding information on fewer than 5,000 consumers is relieved of several of the elements above: the written risk assessment, the continuous monitoring or annual penetration testing requirement, the written incident response plan, and the annual written report.

What that relief does not do is exempt you from the Rule. The program itself, the Qualified Individual, the access controls, the encryption, and the multi-factor authentication all still apply. Firms tend to make one of two opposite mistakes here — assuming the threshold exempts them entirely, or budgeting for a penetration test they do not need. Establishing which side of the threshold you are on is a five-minute question with a large consequence.

The 30-day reporting deadline

Since 2024 the Rule has also carried its own breach-reporting duty. A security event involving the unencrypted customer information of 500 or more consumers has to be reported to the FTC through its online form as soon as possible, and no later than 30 days after discovery.

That deadline is shorter than most state breach-notification deadlines, and it runs independently of them. Meeting a state’s 60-day limit does not satisfy it. If you are inside the Rule, this is the clock most worth writing into your incident response plan, because it is the one most likely to be missed while everyone is busy dealing with the incident itself.

Where documentation actually gets you

Holding a written program is a requirement of the Rule, not a substitute for the rest of it. Documentation does not encrypt anything, does not turn on multi-factor authentication, and does not conduct your risk assessment. What a good program does is state plainly which of those things are in place today, name who owns the ones that are not, and put a date on them.

That is the shape Coverwright generates: your program names the Qualified Individual, records the elements the Rule asks for, and — where your answers say a control is not in place — states a remediation commitment rather than a claim. It also tells you where the boundary is, because the determination of whether the Rule applies to you stays with you and your counsel, not with a document generator.