Compliance · 16 CFR Part 314
What does the FTC Safeguards Rule require for vulnerability testing and vendor oversight?
The FTC Safeguards Rule (16 CFR Part 314) requires covered financial institutions to monitor their information systems continuously or, failing that, to run a penetration test every year and vulnerability assessments at least every six months. It also requires them to choose capable service providers, bind them by contract to safeguards and assess them periodically.
Who it covers
Non-bank financial institutions under the FTC’s jurisdiction. The rule’s own examples include mortgage lenders and brokers, payday lenders, finance companies, account servicers, check cashers, wire transferors, collection agencies, credit counselors and other financial advisors, tax preparation firms, non-federally insured credit unions, and investment advisors that aren’t required to register with the SEC.
Firms that hold customer information on fewer than 5,000 consumers are exempt from some requirements, including the testing in §314.4(d)(2). The service provider requirements still apply to them.
What it requires for testing
Section 314.4(d)(2) gives two routes. The first is effective continuous monitoring. Without it, a firm needs:
- A penetration test of its information systems every year, based on the risks in its risk assessment.
- Vulnerability assessments, including scans for publicly known vulnerabilities, at least every six months, and whenever its operations or business arrangements change materially.
What it requires for service providers
Section 314.4(f) requires a firm to take reasonable steps to select and retain service providers that can safeguard customer information, to require those safeguards by contract, and to assess each provider periodically, based on the risk it presents and whether its safeguards are still adequate.
Other duties worth knowing
- A Qualified Individual must oversee the information security program (§314.4(a)).
- Since May 2024, a firm must notify the FTC within 30 days of discovering a security breach involving the unencrypted information of at least 500 consumers (§314.4(j)).
How an MSP evidences it with Outerwall
- External vulnerability evidence. Continuous checks of the internet-facing assets your client approved, each finding dated and backed by its evidence, toward §314.4(d)(2). Internal systems and the annual penetration test need other tools or a qualified tester.
- Supplier oversight. Your client’s suppliers, found from public sources and confirmed by your client, with alerts when one is breached, toward the periodic assessment in §314.4(f).
- A record of fixes. Tickets in your PSA show what was found, when, and when the fix was confirmed.
- Evidence packs mapped to the rule are on the roadmap.
Not legal advice. This page summarizes the rule for MSPs. Your client’s counsel or compliance lead decides what it requires of them. Outerwall’s output supports a client’s compliance evidence. It does not, by itself, make a client compliant.
Sources
Give your clients the evidence.
Design partners shape the evidence packs mapped to the FTC Safeguards Rule.