FTC Safeguards Rule Requirements: The Checklist
By Cooper Kelley, Founder, Tailwater Tech · July 15, 2026
The strengthened FTC Safeguards Rule stopped being vague. Instead of “maintain reasonable safeguards,” it now spells out a specific set of elements every covered firm has to have. That is good news: it means compliance is a checklist you can actually work through, not a judgment call.
Here is that checklist in plain English, mapped to what a small tax or accounting firm actually does. None of it requires a bank’s budget. It requires that each item is genuinely in place and, for most firms, written down.
The nine required elements
The rule (16 CFR 314.4) is built around a written security program containing these components:
- 1. Designate a Qualified Individual. One named person accountable for the security program. It can be an owner, an employee, or an outside provider, but someone owns it.
- 2. Conduct a written risk assessment. Identify where client data lives and the threats to it, in writing, so the safeguards that follow are grounded in real risk.
- 3. Implement the core safeguards. Access controls, an inventory of data and systems, encryption of client data at rest and in transit, secure development or configuration, multi-factor authentication, secure disposal, change management, and logging of who accesses what.
- 4. Regularly test and monitor. Continuous monitoring, or an annual penetration test plus vulnerability scans at least twice a year, to confirm the safeguards actually work.
- 5. Train your people. Security-awareness training and phishing tests for staff, because your team is the most-targeted way in.
- 6. Oversee your service providers. Choose vendors who can protect the data, put security terms in their contracts, and keep their reports (such as SOC 2) on file.
- 7. Keep the program current. Review and update the plan as your firm, tools, and risks change, not once and forget.
- 8. Maintain a written incident response plan. A concrete plan for what to do if client data is breached, before you need it under a deadline.
- 9. Report to leadership. The Qualified Individual reports on the program to ownership or the board at least annually.
The small-firm exception
Firms holding information on fewer than 5,000 consumers get a lighter load on four items: the written risk assessment, the continuous-monitoring-or-testing requirement, the written incident response plan, and the annual written report. The underlying expectations do not vanish, and everything else on the list, including MFA, encryption, access controls, a Qualified Individual, vendor oversight, and training, still applies to every firm regardless of size.
Where firms usually fall short
In practice, the gaps cluster in a few predictable places: MFA that is on for email but not for the tax software or the remote-access tool, encryption assumed but never actually verified on every laptop, no named Qualified Individual so nothing gets owned, and no tested backup. These are also the first things an insurer’s application asks about and the first an examiner checks after a breach.
How to use this list
Work down it honestly and mark each item green, partial, or missing. The partial and missing rows are your plan. Most small firms can close the majority of gaps with tooling they either already pay for (Microsoft 365 or Google Workspace MFA and encryption) or can add without much cost. The hard part is not the technology. It is making sure each item is really done and documented, and then keeping it that way.
Want to see which items you are missing?
The Safeguards Check walks your firm through these controls in about two minutes and emails a plain-English report showing exactly which requirements are green, partial, or missing. No sales call required to get your score.
Take the free Safeguards Check →Frequently asked questions
- How many requirements does the FTC Safeguards Rule have?
- The rule is built around nine elements of a written security program: a Qualified Individual, a risk assessment, a set of core safeguards (including MFA and encryption), regular testing, staff training, service-provider oversight, keeping the program current, an incident response plan, and annual reporting to leadership.
- Is MFA actually required, or just recommended?
- Required. Multi-factor authentication is one of the specific safeguards named in the rule, and it must be in place for any system that stores client data, not just email. Its absence is one of the first things regulators and insurers flag.
- Do small firms have to do all nine?
- Firms with information on fewer than 5,000 consumers get relief on four items (written risk assessment, formal testing, written incident response plan, and annual reporting). The rest, including MFA, encryption, access controls, a Qualified Individual, vendor oversight, and training, apply to everyone.
- Can I outsource the Qualified Individual role?
- Yes. The rule allows the Qualified Individual to be a qualified outside service provider. You still retain responsibility for the program, but a managed IT or security partner can hold and run the role for you.
Keep reading