Insights · Compliance

The FTC Safeguards Rule Checklist, Annotated, With Real Costs

All nine required elements of 16 CFR 314.4 in one table: what actually satisfies each at a five-seat firm and a fifty-seat firm, what it honestly costs, and the evidence an underwriter or investigator will ask to see.

An annotated compliance checklist and cost worksheet on a desk beside a laptop

The FTC Safeguards Rule (16 CFR Part 314) requires any business that handles customer financial information, including tax preparers, accountants, insurance agents, auto dealers, mortgage brokers and collection agencies, to run a documented information security program built on nine required elements, from a written risk assessment to an incident response plan. There is no small-business exemption, multi-factor authentication and encryption in transit and at rest have been mandatory since June 9, 2023, and civil penalties can reach $53,088 per violation.

Most checklists for this rule are either a list of the nine element headings with no annotation, or a sales page for a product that covers two of them. This one is different. For each element we set out what the regulation literally requires, what satisfies it at a five-person firm versus a fifty-person firm, what it honestly costs, and what evidence you should be able to produce when someone asks. That last column matters more than most firms realise: an insurance underwriter, an auditor or an FTC investigator does not ask whether you are secure. They ask for documents.

One thing up front: we are technologists, not lawyers. This article explains the rule as operators who implement it. Whether a given program is legally sufficient for your firm is a question for your counsel.

Does this rule apply to me?

Almost certainly yes, if you are reading this. The Safeguards Rule applies to financial institutions under FTC jurisdiction, and the definition is far broader than the name suggests. It reaches any business that handles customer financial information: Social Security numbers and ITINs, bank and routing numbers, payroll data. That includes tax preparers, accountants and bookkeepers; insurance agents; auto dealers; mortgage brokers; collection agencies; and many other businesses that would never describe themselves as financial institutions.

There is no small-business exemption. In the 2021 rulemaking (86 Fed. Reg. 70272, December 9, 2021), the FTC addressed this directly and held that being a sole operator is not determinative. Some requirements scale down with headcount, and the table below shows how, but none of the nine elements disappear because your firm is small.

If you are a tax firm you may already have IRS Publication 5708 on file, the written information security plan template most tax practices download. Keep it. But understand what it is: a starting document, not a compliance program. The rule requires a program that runs, and the difference between the two is exactly what the following table describes.

The nine required elements of 16 CFR 314.4, annotated

Each row is one of the nine elements the rule requires, in the order the regulation lists them. Costs are honest: several rows genuinely cost nothing but time, because the controls are configuration of software you already own. Where money is required we give ranges and say so, because pricing varies widely by vendor and scope.

ElementWhat it literally saysAt 5 seatsAt 50 seatsTypical costEvidence to keep
Designate a qualified individual
314.4(a)
Name one person responsible for implementing and overseeing the program.One principal, named in writing. The role can be outsourced, but the firm keeps responsibility and a senior person must oversee the provider.A named senior manager, or an outsourced Qualified Individual with a defined reporting line to the partners.$0 in-house. Outsourced retainers typically $500 to $2,500 a month; scope drives it.A dated designation memo, and the individual’s written reports.
Written risk assessment
314.4(b)
Write down where customer information lives, what threatens it, and how you evaluate and address those risks.A genuine working document: where the data is, who touches it, what could go wrong, what you plan to do about each risk.The same, with a stated methodology, a full asset and data-flow inventory, and a scheduled annual refresh.$0 plus one to two working days in-house. Outsourced assessments typically $1,500 to $7,500.The dated assessment, with revision history showing it gets reviewed rather than filed.
Design and implement safeguards
314.4(c)
Put controls in place for the risks you identified, including access controls, MFA, and encryption in transit and at rest. Mandatory since June 9, 2023.MFA on email, tax or practice software, and remote access. Disk encryption, built into Windows and macOS. Least-privilege access. Secure disposal of old drives and paper.All of that, plus single sign-on or conditional access, EDR on every endpoint, MDM for laptops and phones, and centralised logging.At 5 seats, mostly $0: settings in software you already pay for. At 50 seats, EDR roughly $3–8 per endpoint per month, MDM $2–6 per device per month.MFA enrollment reports, encryption status reports, access-review records, disposal logs or shredding receipts.
Regularly test or monitor
314.4(d)
Verify the safeguards actually work, through continuous monitoring or periodic testing.Scheduled vulnerability scans with someone actually reading the reports and fixing findings. Many IT providers bundle this.Continuous monitoring or an MDR service, plus an annual penetration test.Scanning often $0 to $100 a month through an existing provider. Penetration tests $5,000 to $25,000 by scope. MDR roughly $10–25 per endpoint per month.Dated scan reports, remediation notes, the penetration test report and evidence of follow-up.
Personnel policies: training and access
314.4(e)
Implement policies and procedures for your people: security awareness training and access controls.Annual security awareness training, documented. Access granted by role and removed the day someone leaves.A training platform with phishing simulation, onboarding and offboarding checklists, and quarterly access reviews.Nearly free at 5 seats. Training platforms roughly $10 to $30 per user per year.Training completion records with names and dates, access-review sign-offs, offboarding checklists.
Oversee service providers
314.4(f)
Choose providers that can protect the data, require it by contract, and periodically reassess them.A one-page vendor list — tax software, cloud storage, IT provider, e-signature, payroll — with a contract or data protection agreement on file for each.The same, plus vendors tiered by risk and reassessed on a schedule.$0, plus a few hours.The vendor inventory, the contract clauses, notes from periodic reassessments.
Evaluate and adjust the program
314.4(g)
Update the program when your risks, your business or your test results change.An annual review meeting with brief notes, plus an update after any incident or major change.The same discipline, tied into the Qualified Individual’s reporting cycle.$0, plus a few hours a year.Dated review notes and the resulting document revisions.
Written incident response plan
314.4(h)
Write down, in advance, who does what when something goes wrong.A short plan naming roles and contact numbers — insurer, counsel, IT provider — and the steps, including the FTC’s 30-day notification requirement. Walk through it once.A fuller plan with defined severity levels and an annual tabletop exercise.$0 plus a few hours to write. Facilitated tabletops $1,500 to $5,000 if outsourced.The dated plan, tabletop notes, post-incident reports if you have ever used it.
Regular written reports
314.4(i)
The qualified individual reports in writing, regularly, to the board or the senior person in charge.A short annual written report. In an owner-led firm this feels odd, because you are reporting to yourself. Write it and file it anyway; it is the document that proves the program ran.An annual or more frequent written report to the partners or board, on the agenda and in the minutes.$0, plus an hour or two.The dated reports themselves.

What it actually costs

A five-seat firm. First year: roughly 30 to 50 hours of principal and staff time, plus somewhere between $0 and $2,000 in actual spend, typically a training platform and vulnerability scanning if your IT provider does not already include it. The large majority of the work is configuration of software you already own and documents you write once. Ongoing: 15 to 25 hours a year and a similar small spend. If you outsource the qualified individual role, add the retainer.

A fifty-seat firm. First year: typically $20,000 to $60,000 all in, once you add EDR across every endpoint, MDM, a training platform, an annual penetration test and possibly a retained security lead, plus meaningful internal time. Ongoing: roughly $15,000 to $40,000 a year. These are ranges, and where you land depends heavily on what your existing IT stack already covers.

The pattern worth noticing: at small scale, the Safeguards Rule is mostly a time problem, not a money problem. The firms that struggle are not the ones that cannot afford it. They are the ones that downloaded a template, signed it, and never built the running program behind it.

Penalties and the notification clock

Two numbers, stated flatly. Civil penalties can reach $53,088 per violation, as of January 2025. And where a security event involves unencrypted customer information of 500 or more consumers, the firm must notify the FTC within 30 days.

The 30-day clock is worth sitting with, not because it is frightening but because of what it implies operationally. Thirty days is not much time to discover what happened, determine how many consumers were affected and determine whether the information was encrypted, all while running your firm and handling the incident itself. That determination is far easier if encryption at rest was actually enabled and you have the status reports to prove it, and if your incident response plan already names who makes the notification call and who your counsel is. The elements in the table are not independent boxes. The ones you did in the quiet months are what make the 30 days survivable.

The real deadline is your insurance renewal

In our experience the forcing function for most small firms is not the FTC. It is the cyber liability application. Carriers now require documented controls as a binding condition of coverage, and they can deny a claim if no plan existed at the time of the breach. Firms are being non-renewed, or declined outright, over the MFA and backup questions on the application.

This changes the economics of the whole exercise. A signed application that overstates your controls is worse than no coverage, because you are paying premiums for a policy that may not respond. And the evidence column in the table above is precisely what an underwriter or a claims adjuster will ask for. If your renewal is in the next six months, that is your deadline, and it is a harder one than anything in the regulation.

One 2026 addition: put AI tools in the risk assessment

The risk assessment element requires you to assess where customer information goes, and in 2026 that includes AI tools your staff may be pasting client data into. IBM and Ponemon’s Cost of a Data Breach 2026 report, published in July 2026 and covering 602 breached organizations across 17 industries and 16 countries, found that 68% of breached organizations lacked governance over AI tools, and that where attackers targeted AI systems directly, 92% of those organizations had failed to control access to them. The same report puts the average US breach at $11.5 million, and finds one in four malicious breaches were AI-enabled, averaging around $6 million against a $4.99 million global average.

You do not need an AI policy the size of a phone book. You need a paragraph in the risk assessment naming which tools are approved, which data may not enter them, and who checked. That is the whole addition, and it costs nothing but the conversation.

Questions we get asked

Does the Safeguards Rule apply to a one-person tax practice?

Yes. There is no small-business exemption, and in the 2021 rulemaking the FTC held that being a sole operator is not determinative. If you handle SSNs, bank account numbers or payroll data for clients, the rule applies. The requirements scale down in practice, as the five-seat column above shows, but none of the nine elements go away.

Is IRS Publication 5708 enough?

No. It is a reasonable starting outline for the written plan, and most tax firms should keep using it as one. But a template on file is not a compliance program. The rule requires implemented controls, testing, training records, vendor oversight and written reporting, with evidence behind each.

What are the penalties?

Civil penalties can reach $53,088 per violation as of January 2025, and a security event involving unencrypted information of 500 or more consumers must be reported to the FTC within 30 days. For most small firms the more immediate consequence is on the insurance side: a denied claim or a non-renewal.

Do I need to hire a CISO to satisfy the Qualified Individual requirement?

No. You need to designate one person, and at a small firm that is usually a principal, named in a dated memo. The role can be outsourced, and for many firms that is the sensible path, but the firm retains responsibility and a senior person internally must oversee the provider.

Does having cyber insurance make me compliant?

No, and the dependency runs the other way. Insurance satisfies none of the nine elements, but carriers increasingly require the same controls the rule does as a binding condition of coverage. The program gets you the policy. The policy does not get you the program.

We are not attorneys, and nothing here is legal advice. This article describes how we implement the Safeguards Rule as an operating program. Whether a given program is legally sufficient for your firm is a determination for your firm’s counsel.

Matthew Firth is the founder and Technology Lead of NexSpark Solutions. He has run security and compliance programs against NIST, SOC 2, ISO 27001, PCI DSS and SOX, and leads the technology side of every engagement personally.

Keep reading

Find out where you actually stand

We run a Safeguards gap assessment against all nine elements: what you already satisfy, what needs configuring, and what the evidence file is missing. For firms that want the role handled, we also serve as an outsourced Qualified Individual. One conversation tells you whether it is worth going further.

Get in touch