Non-bank financial institutions sent about 163 breach notifications to the Federal Trade Commission in 2025, the first full calendar year of the Safeguards Rule's notice requirement, according to the FTC's August 2026 Paperwork Reduction Act notice. That is roughly 42 percent more than the 115 a year FTC staff estimated in the final rule published in November 2023. The same rule, 16 CFR Part 314, is one of the few US regulations that names penetration testing, defines it and sets a frequency for it.
Section 314.4(d)(2) has required annual penetration testing and vulnerability assessments at least every six months since 9 June 2023, unless the institution runs effective continuous monitoring. It reaches auto dealers that finance or lease, mortgage lenders, brokers and servicers, tax preparers, payday lenders, finance companies, collection agencies and colleges that take part in federal student aid. Every statement below was read from the regulation text on eCFR, the Federal Register, FTC business guidance and Federal Student Aid's own announcements on 1 October 2026. It explains the rule; it is not legal advice.
Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, founded in Toronto in 2021 with a London office. Every human-led engagement is staffed by two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications, and its testers hold bug bounty Hall of Fame listings at the US Department of Defense and the US Federal Reserve. For a Safeguards Rule program that means a test built to the rule's definition: the perimeter from outside, the internal network and Active Directory from inside, credit application and customer portals across every role, multi-factor authentication on every sign-in path, and phishing and vishing against the help desk and the staff who move money, which the FTC has said fall within its definition of penetration testing. It runs as a one-time annual engagement on the 314.4(d)(2) calendar or as a continuous program, with retesting and an attestation letter included. Published pricing covers one web application and its APIs (pricing); network, Active Directory and social engineering scopes are quoted.
Quick answer: what does the FTC Safeguards Rule require for penetration testing?
Unless a covered institution has effective continuous monitoring, 16 CFR 314.4(d)(2) requires annual penetration testing of its information systems, scoped each year from its written risk assessment, and vulnerability assessments at least every six months, plus whenever operations or business arrangements materially change or other circumstances may materially affect the program. The rule defines penetration testing at 314.2(n) as a test in which assessors attempt to circumvent or defeat security features "from outside or inside your information systems." Institutions holding customer information on fewer than 5,000 consumers are exempt from the clause under 314.6. The Qualified Individual must report to the board in writing at least annually under 314.4(i), in a report which must address material matters such as "results of testing." Since 13 May 2024, a breach of unencrypted information on 500 or more consumers must be reported to the FTC within 30 days of discovery under 314.4(j).

What 16 CFR 314.4(d)(2) says, word for word
Paragraph (d) has two parts. Paragraph (d)(1) applies to every covered institution and requires it to "regularly test or otherwise monitor the effectiveness of the safeguards' key controls, systems, and procedures, including those to detect actual and attempted attacks on, or intrusions into, information systems." Paragraph (d)(2) then sets the floor for information systems. The current text on eCFR, up to date as of 29 September 2026, reads:
(2) For information systems, the monitoring and testing shall include continuous monitoring or periodic penetration testing and vulnerability assessments. Absent effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities, you shall conduct:
(i) Annual penetration testing of your information systems determined each given year based on relevant identified risks in accordance with the risk assessment; and
(ii) Vulnerability assessments, including any systemic scans or reviews of information systems reasonably designed to identify publicly known security vulnerabilities in your information systems based on the risk assessment, at least every six months; and whenever there are material changes to your operations or business arrangements; and whenever there are circumstances you know or have reason to know may have a material impact on your information security program.
Four phrases decide what a buyer has to purchase.
"Your information systems." The definition at 314.2(j) covers systems that contain customer information or are "connected to a system containing customer information," and it names "telephone switching and private branch exchange systems" and environmental controls among them. The Commission explained why connected systems are in: "a common source of data breaches is a vulnerability in a connected system that an attacker exploits to gain access to the company's network and move within the network to obtain access to the system containing sensitive information" (86 FR 70277). A test confined to the server that stores loan files skips the route an attacker would take to reach it.
"Determined each given year based on relevant identified risks." The rule does not fix the scope. It must follow the written risk assessment required by 314.4(b)(1), and it can change from year to year as the assessment does. A test with no line back to the risk assessment is hard to defend as scoped "in accordance with the risk assessment."
"From outside or inside." The definition at 314.2(n) reads in full: "Penetration testing means a test methodology in which assessors attempt to circumvent or defeat the security features of an information system by attempting penetration of databases or controls from outside or inside your information systems." A vulnerability scan does not meet it, from either side of the perimeter.
"At least every six months; and whenever there are material changes." Vulnerability assessments run on three triggers: the calendar, material changes to operations or business arrangements, and other circumstances that may materially affect the program. The Commission added the event-driven triggers to the final rule because it "agrees biannual vulnerability testing may not be sufficient to detect new threats" (86 FR 70293). A new integration into the dealer management system, a move to a new loan origination platform or a campus system migration are the kinds of change a risk assessment should treat as material.
Paragraph (d)(2) covers information systems only. The Commission said the general testing duty in (d)(1) "should apply to physical safeguards (e.g., testing effectiveness of physical locks)," while the monitoring, vulnerability assessment and penetration testing in (d)(2) "is not relevant to information in physical form" (86 FR 70293).
Social engineering is inside the definition
During the rulemaking, the Money Services Round Table argued that the penetration tests required by 314.4(d)(2) would not have to test "potential human vulnerabilities" such as social engineering or phishing. The Commission disagreed: "The fact that the testing involves employees with access to the information system, rather than just the system itself, does not exclude such tests from the definition of 'penetration testing.' Attempted social engineering and phishing are important parts of testing the security of information systems and would not be excluded by this definition" (86 FR 70277). For a dealership help desk that resets passwords by phone, a lender's closing team that receives wire instructions or a tax practice in filing season, that passage is the reason to put social engineering in the scope the risk assessment sets.
The continuous monitoring option, and what it takes to rely on it
The clause offers a choice: "continuous monitoring or periodic penetration testing and vulnerability assessments." The annual test and the six-month assessments apply only "absent effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities." The Commission was plain about it in 2021: "the Rule requires one, not both," adding that "many financial institutions may choose to use both" (86 FR 70293).
The rule does not define continuous monitoring. The closest the Commission came is its account of the 2019 proposal, which "explained continuous monitoring is any system that allows real-time, ongoing monitoring of an information system's security, including monitoring for security threats, misconfigured systems, and other vulnerabilities" (86 FR 70293). It added that such a system "will include some form of vulnerability assessment," and that institutions choosing it "would also be satisfying" the logging and monitoring safeguard in 314.4(c)(8). FTC staff guidance leans the same way. The small entity compliance guide says testing "can be accomplished through continuous monitoring of your system," and the June 2025 dealer FAQ tells dealers: "You should continuously monitor information systems. If you cannot continuously monitor, then you must conduct annual penetration testing and vulnerability assessments at least every six months."
Three points weigh on that choice.
The operative word is "effective." The monitoring has to detect, on an ongoing basis, the changes that create vulnerabilities across every information system in scope, connected systems included. An institution relying on it should be able to show that it does, system by system. A tool that covers only part of the estate is hard to defend as meeting that description for the systems it misses.
Monitoring does not retire the rest of paragraph (d). Paragraph (d)(1) still requires testing or monitoring of the controls that detect attacks, and 314.4(c)(4) still requires procedures for "evaluating, assessing, or testing the security of externally developed applications." A penetration test is the direct way to show that detection fires and that a licensed portal enforces its own access rules.
The model the FTC borrowed from has dropped the option. The FTC said its 2019 proposal was "based primarily on the cybersecurity regulations issued by the New York Department of Financial Services, 23 NYCRR 500," together with the NAIC's insurance data security model law (84 FR 13163), and its continuous monitoring wording is nearly identical to text New York has since deleted. The second amendment to Part 500, adopted in November 2023, struck the monitoring alternative and now requires covered entities to "conduct, at a minimum" penetration testing "from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually." Outside Part 500's own small-entity exemption at 500.19(a), a lender or servicer operating under a New York Banking Law license has no monitoring route in that rule. Our NYDFS guide covers it.
Who the Safeguards Rule covers
The rule applies to "financial institutions" over which the FTC has jurisdiction: any business significantly engaged in an activity that is financial in nature under section 4(k) of the Bank Holding Company Act, unless another regulator enforces the Gramm-Leach-Bliley Act against it. Section 314.1(b) lists the familiar cases:
More specifically, those entities include, but are not limited to, mortgage lenders, "pay day" lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, travel agencies operated in connection with financial services, collection agencies, credit counselors and other financial advisors, tax preparation firms, non-federally insured credit unions, investment advisors that are not required to register with the Securities and Exchange Commission, and entities acting as finders.
The statute decides who is left out. Under 15 U.S.C. 6805(a), banks answer to the federal banking agencies, federally insured credit unions to the NCUA, broker-dealers, investment companies and SEC-registered advisers to the SEC, and insurers to state insurance authorities. The FTC takes "any other financial institution." The Consumer Financial Protection Bureau enforces the Act's privacy provisions "but not with respect to the standards under section 6801," which are the safeguards standards. The rule also follows the data: it "applies to all customer information in your possession," including information about the customers of other financial institutions that provided it to you.
Business | Where coverage comes from | Systems usually in scope |
|---|---|---|
Auto dealers that finance or lease | FTC staff dealer FAQ (June 2025); 314.2(h)(2)(ii) leasing; 314.2(e)(2)(i)(E) arranging vehicle credit | Dealer management system, credit application and F&I tools, CRM, OEM portals, dealership networks |
Mortgage lenders, brokers and servicers | 314.1(b); 314.2(h)(2)(xi) brokers; 314.2(e)(2)(i)(L) servicing rights | Loan origination system, borrower portal and document upload, servicing platform, email |
Tax preparers and accounting firms | 314.2(h)(2)(viii); IRS Publication 5708 | Client portal, tax software, Microsoft 365, file shares |
Colleges in federal student aid | Program Participation Agreement; FSA GENERAL-23-09; OMB Compliance Supplement | Student information and financial aid systems, student portals, identity provider |
Payday lenders and finance companies | 314.1(b); 314.2(b)(2)(i) credit applicants | Online application and underwriting, payments, collections tools |
Collection agencies and debt buyers | 314.1(b); 314.2(e)(2)(i)(J) purchased accounts | Collections platform, payment portal, call recording, data feeds |
Finders | 314.2(h)(2)(xiii), added in 2021 | Marketplace platform and the data it brokers |
Data processors serving these businesses | FTC's DealerBuilt complaint: data processing, 12 CFR 225.28(b)(14) | Hosted platforms that hold clients' customer data |
Auto dealers
The FTC's June 2025 staff FAQ for dealers says the rule "applies to financial institutions subject to the FTC's authority. That includes most automobile dealers who finance or lease automobiles." Dealers "who finance (or facilitate the financing of) automobiles for consumers are financial institutions," and leasing for longer than 90 days qualifies on its own. Arranging the loan is enough even when the dealer does not keep the contract: "If your dealership arranges or brokers a loan for a consumer, then you are in a 'continuing relationship' with that consumer," and the dealer must keep protecting that information "for as long as you have that customer information in your possession." The FAQ also reaches the network around the data: "unless you maintain two separate networks that are not connected, the protections that you need to provide for customer information on your network will also protect other information on your network." Our ranking of penetration testing companies for auto dealerships covers dealer management systems, F&I tools and dealer-group scopes.
Mortgage lenders, brokers and servicers
Mortgage lenders and brokers are named in 314.1(b), and 314.2(h)(2)(xi) makes a mortgage broker a financial institution "because brokering loans is a financial activity." Servicing creates the relationship as well. An individual whose consumer loan you own or service is your consumer "even if you hold those rights in conjunction with one or more other institutions" (314.2(b)(2)(iv)), and having "a loan for which you own the servicing rights" is a continuing relationship (314.2(e)(2)(i)(L)). A lender or servicer operating under a New York Banking Law license also answers to Part 500. The mortgage lender and servicer ranking maps loan origination, borrower portals and wire fraud exposure.
Tax preparers and accounting firms
Section 314.2(h)(2)(viii) is explicit: "An accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution." The IRS repeats it in Publication 5708 (Rev. 8-2024): "Under the GLBA and Safeguards Rule, tax and accounting professionals are considered financial institutions, regardless of size." Size still matters for the test itself through the 314.6 exemption below. The accounting and CPA firm ranking covers the IRS publications, SQMS No. 1 and the Canadian rules.
Colleges and universities
Federal Student Aid treats the rule as a condition of Title IV participation. Its February 2023 announcement GENERAL-23-09 states that each participating institution "has agreed in its Program Participation Agreement (PPA) to comply with the GLBA Safeguards Rule under 16 C.F.R. Part 314," and defines customer information for schools as "information obtained as a result of providing a financial service to a student (past or present)." OMB's 2025 Compliance Supplement tells single auditors that the FTC "considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as 'financial institutions'" and that "If an institution has not designated a Qualified Individual, it is not in compliance with the GLBA requirements." The higher education ranking covers student information systems, research networks and campus identity.
Payday lenders, finance companies, collection agencies and finders
All four appear by name in 314.1(b). Consumer status starts at the application: an individual who applies for personal credit is a consumer "regardless of whether the credit is extended" (314.2(b)(2)(i)). A debt buyer has a continuing relationship with anyone obligated on an account it purchases, "unless you do not locate the consumer or attempt to collect any amount from the consumer on the account" (314.2(e)(2)(i)(J)). Finders, businesses that bring together buyers and sellers who negotiate and close the transaction themselves, were added by the 2021 amendments.
The 5,000-consumer exemption in 314.6
The exemption is one sentence in 314.6: "Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers." Four obligations fall away below the line: the written risk assessment, the annual penetration test and six-month vulnerability assessments, the written incident response plan and the Qualified Individual's annual report to the board.
Everything else stays. A small institution still needs a Qualified Individual, a risk assessment (without the written criteria 314.4(b)(1) prescribes), the eight safeguards in 314.4(c) including encryption and multi-factor authentication, regular testing or monitoring of key controls under (d)(1), training, service provider oversight, program updates and the 30-day FTC breach notice. The Commission said exempted institutions "will still need to conduct risk assessments, design and implement a written information security program with the required elements, utilize qualified information security personnel and train employees, monitor activity of authorized users, oversee service providers, and evaluate and adjust their information security program" (86 FR 70304).
Counting decides which side of the line an institution is on. A consumer is an individual who obtains a financial product or service "primarily for personal, family, or household purposes" (314.2(b)(1)), so business customers do not count. The Commission said the exemption counts "all individual consumers about which a financial institution maintains customer information, including both current and former customers," and counts people rather than transactions, so "a financial institution that had 100 transactions with a single customer would count only a single consumer" (86 FR 70301). Information "anonymized or otherwise transformed so it is no longer reasonably linkable to a customer" does not count, but a dealer that keeps only a financing customer's "name, phone number, address, and VIN" still holds customer information (86 FR 70300). By contrast, the FTC's 2025 dealer FAQ says names and addresses collected from every buyer, with nothing showing who financed or leased, are not customer information.
Because former customers count, the line is easier to cross than an active-customer count suggests. The disposal safeguard at 314.4(c)(6) requires disposal no later than two years after information was last used to serve the customer, unless business, legal or feasibility exceptions apply, and the Commission noted the incentive directly: "A financial institution may choose to dispose of information so it holds information on few enough consumers to qualify for exemption" (86 FR 70301). Federal Student Aid uses the same 5,000 threshold, but its own summary drops only the incident response plan and the board report ("are only required to address the first seven elements"), and single auditors test whether the written program addresses those seven elements.
The program the test sits inside
The penetration test is one element of a written information security program. Each other element either sets the test's scope or consumes its results.
Element | Section | What the rule requires | What the penetration test feeds |
|---|---|---|---|
Qualified Individual | 314.4(a) | One qualified individual oversees, implements and enforces the program; may work for an affiliate or service provider | Owns the scope decision and receives the findings |
Written risk assessment | 314.4(b)(1) | Written criteria for rating risks, assessing controls and mitigating or accepting risk | Sets this year's test scope; results update it |
Access controls | 314.4(c)(1) | Authorized users only; customers limited to their own information | Authorization testing across roles and accounts |
Encryption | 314.4(c)(3) | Customer information encrypted in transit over external networks and at rest; where encryption is infeasible, effective compensating controls reviewed and approved by the Qualified Individual | Finds clear-text transport and exposed data stores |
Secure development and external apps | 314.4(c)(4) | Secure development for in-house apps; procedures for testing externally developed apps | Application testing of portals and licensed platforms |
Multi-factor authentication | 314.4(c)(5) | For "any individual accessing any information system," unless the Qualified Individual approves an equivalent in writing | Tests every sign-in path, legacy protocols and exceptions |
Change management | 314.4(c)(7) | Procedures for change management | Retesting after material change |
Logging and monitoring | 314.4(c)(8) | Monitor and log authorized users; detect unauthorized access | Shows whether the test's own activity was seen |
Testing or monitoring | 314.4(d) | Key controls under (d)(1); absent effective continuous monitoring, the annual test and six-month assessments under (d)(2) | The test itself |
Training | 314.4(e) | Awareness training updated for the risks the assessment identifies | Phishing and vishing results feed the training |
Service providers | 314.4(f) | Select capable providers, require safeguards by contract, assess them periodically | Tests vendor access paths; vendor test evidence |
Evaluate and adjust | 314.4(g) | Adjust the program in light of testing and monitoring results | The remediation plan |
Incident response plan | 314.4(h) | Written plan, including remediation of identified weaknesses | Exercises detection and response |
Board report | 314.4(i) | Written, at least annually, addressing material matters such as "results of testing" | The summary the board reads |
FTC notice | 314.4(j) | Within 30 days of discovery, 500 or more consumers | Logs that show what was or was not acquired |
The Qualified Individual
The rule asks for one person. Section 314.4(a) requires a Qualified Individual "responsible for overseeing and implementing your information security program and enforcing your information security program," who may be employed by you, an affiliate or a service provider. If the role is outsourced, the institution must retain responsibility for compliance, designate "a senior member of your personnel" to direct and oversee the Qualified Individual, and require the provider to maintain a program that protects the institution. The Commission set no credential: "No particular level of education, experience, or certification is prescribed by the Rule" (86 FR 70280). FTC staff say the same in plain terms: "The person doesn't need a particular degree or title. What matters is real-world know-how suited to your circumstances."
The annual report to the board
Section 314.4(i) requires the Qualified Individual to "report in writing, regularly and at least annually" to the board of directors or equivalent governing body, or, where none exists, to a senior officer responsible for the program. The report must cover "the overall status of the information security program and your compliance with this part" and material matters "such as risk assessment, risk management and control decisions, service provider arrangements, results of testing, security events or violations and management's responses thereto, and recommendations for changes in the information security program." For institutions above the 5,000-consumer line, test results will ordinarily be among the material matters the board sees each year. A test report built for that use, with severity counts, remediation status and retest results the Qualified Individual can lift directly, saves a rewrite.
The FTC breach notice: 314.4(j), in force since 13 May 2024
The Commission approved the notice requirement on 27 October 2023 by a 3-0 vote, published it at 88 FR 77499 on 13 November 2023 and made it effective on 13 May 2024. Its supplemental proposal had used a 1,000-consumer threshold; the final rule set 500. The rule now provides:
Trigger: a "notification event," meaning "acquisition of unencrypted customer information without the authorization of the individual to which the information pertains." Information counts as unencrypted "if the encryption key was accessed by an unauthorized person."
Presumption: "Unauthorized acquisition will be presumed to include unauthorized access to unencrypted customer information unless you have reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of such information."
Threshold and clock: at least 500 consumers; notice "as soon as possible, and no later than 30 days after discovery of the event," made electronically on the FTC's form.
Discovery: the first day the event is known to you, and it is known once it is known to "any person, other than the person committing the breach, who is your employee, officer, or other agent."
Contents: the institution's name and contact details, the types of information involved, the date or date range if it can be determined, the number of consumers affected or potentially affected, a general description, and whether law enforcement has determined in writing that public notice would impede a criminal investigation or harm national security; the official can then ask for public disclosure to be delayed up to 30 days after the filing, extendable by up to 60 days in writing. The 30-day filing deadline does not move.
Publicity: FTC staff warn that "Your report may be made public," for example in "a public listing of breach notifications or in response to a Freedom of Information Act request."
The 314.6 exemption does not reach paragraph (j). An institution holding customer information on 3,000 consumers that loses unencrypted records on 600 of them still files. The presumption is where testing and logging meet: an institution that cannot show what an intruder touched is presumed to have lost it. A penetration test that checks whether the logging required by 314.4(c)(8) captures each access path tells the Qualified Individual, before an incident, whether that evidence will exist.
The numbers are now public. FTC staff estimated in 2023 that about 115 institutions a year would file (88 FR 77506). In its August 2026 notice, the Commission said it "received approximately 163 breach notifications" in 2025 and estimated each report takes about five hours to prepare (91 FR 54873).

How the requirement arrived, 2003 to 2026
The original rule required a program, a risk assessment and regular testing or monitoring of key controls, but named no penetration test. The 2021 amendments added the specific elements and the testing cadence, and a 2022 delay moved the new elements to 9 June 2023.
Date | What happened | Source |
|---|---|---|
23 May 2003 | Original Safeguards Rule takes effect | 67 FR 36484; 91 FR 54872 |
4 April 2019 | FTC proposes detailed program elements "based primarily" on New York's Part 500 and the NAIC insurance data security model law | 84 FR 13158 |
9 December 2021 | Amended rule published, effective 10 January 2022, with the testing clause and other new elements set for 9 December 2022 | 86 FR 70272 |
23 November 2022 | Those elements delayed to 9 June 2023, citing "a reported shortage of qualified personnel" and supply chain issues | 87 FR 71509 |
9 June 2023 | Qualified Individual, written risk assessment, safeguards (c)(1) to (8), the 314.4(d)(2) testing clause, training, service provider assessments, incident response plan and board report apply | 87 FR 71510 |
13 May 2024 | FTC breach notice at 314.4(j) takes effect | 88 FR 77499 |
16 June 2025 | FTC publishes its automobile dealer FAQ | FTC press release |
25 August 2026 | FTC reports about 163 breach notifications received in 2025 and seeks to renew the reporting clearance, which expires 31 December 2026 | 91 FR 54872 |
What enforcement looks like
Two FTC cases: DealerBuilt and Ascension
Two FTC Safeguards Rule cases sit closest to the readers of this guide. Both were brought under the original rule, before the 2021 amendments named the test, and both turned on gaps the amended rule now spells out.
DealerBuilt (2019). LightYear Dealer Technologies, doing business as DealerBuilt, sold dealer management system software and data processing to auto dealers. The FTC treated it as a financial institution in its own right because it was "significantly engaged in data processing for its customers, auto dealerships that extend credit to consumers" (complaint). A storage device attached to its backup network left an open port for about 18 months, during which the company did not "perform any vulnerability scanning, penetration testing, or other diagnostics to detect the open port." A hacker reached the unencrypted personal information of about 12.5 million consumers stored by 130 dealer customers and downloaded that of more than 69,000, and DealerBuilt learned of the breach from one of its dealer customers (FTC, 12 June 2019). The final order, issued 3 September 2019, requires penetration testing of its network "at least once every twelve (12) months" and vulnerability testing "once every four months," with biennial third-party assessments for 20 years.
Ascension Data & Analytics (2021). A mortgage industry analytics firm sent documents on about 37,000 mortgages, covering 60,593 consumers, to an OCR vendor without assessing the vendor's security, although its own policy required it to. The vendor misconfigured its cloud storage, leaving the information exposed "to anyone on the internet for a year, beginning in January 2018," and about 52 unauthorized IP addresses accessed it (complaint). The final order, issued 22 December 2021, requires the company to have each vendor that stores covered information document "vulnerability scanning" and "penetration testing" at least once every twelve months and promptly after an incident, and to keep that documentation for five years. For a 314.4(f) file, that order is a template for what to ask of service providers.
Federal Student Aid
For colleges, the enforcing hand is the Department of Education. GENERAL-23-09 says GLBA findings from a compliance audit "or any other means" are resolved "as part of the Department's final determination of an institution's administrative capability" and "will have the same effect on an institution's participation in the Title IV programs as any other determination of non-compliance." An institution found out of compliance without a breach must submit a corrective action plan, and "Repeated non-compliance by an institution or a servicer may result in an administrative action taken by the Department, which could impact the institution's or servicer's participation in the Title IV programs." FSA's 2020 enforcement announcement adds that its Cybersecurity Team "may temporarily or permanently disable the institution or servicer's access to the Department's information systems" where an institution poses substantial risk to student information.
Breaches carry their own consequences. The 2026-2027 FSA Handbook says the Department "considers any breach in the security of student records and information to be a demonstration of a potential lack of administrative capability," and FSA's April 2024 announcement GENERAL-24-46 reminds institutions to "immediately report breaches within 24 hours after the incident is known or identified." In single audits, OMB's 2025 Compliance Supplement directs auditors to "Verify that the institution has designated a Qualified Individual" and that the written program addresses the required elements.
What a Safeguards Rule penetration test should cover
The rule does not list targets. It points the test at information systems, attempted from outside or inside, as the risk assessment selects them, and the safeguards in 314.4(c) say what each part of the test should prove.

Area | Rule hook | What to test |
|---|---|---|
External perimeter | 314.2(n): "from outside" | Internet-facing hosts, VPN and remote access, exposed administration interfaces, email security |
Internal network and Active Directory | 314.2(n): "inside"; 314.2(j) connected systems | Lateral movement from one workstation, Kerberos and delegation paths, segmentation between systems that hold customer information and those connected to them |
Customer portals and APIs | 314.4(c)(1)(ii): customers limited to their own information | Authorization across roles and accounts, IDOR on application and document identifiers, session handling |
Externally developed applications | 314.4(c)(4) | Licensed platforms and their integrations, tested within what the vendor permits in writing |
Multi-factor authentication | 314.4(c)(5): "any individual accessing any information system" | Every sign-in path, legacy protocols, conditional access exclusions, service and vendor accounts |
Phone systems and people | 314.2(j) names PBX systems; 86 FR 70277 on social engineering | Phishing, vishing, help desk reset pretexts and payment-change requests |
Service provider access | 314.4(f); FTC dealer FAQ on vendor MFA | Remote support tools, integration accounts and direct network connections |
Logging and detection | 314.4(c)(8); 314.4(d)(1) | Whether the test's own activity was logged and detected, and how quickly |
On vendor access, the FTC's dealer FAQ is specific: "If you are giving a service provider direct access to your network, they should be required to use multi-factor authentication for that access because they are individuals accessing your information systems." A test that checks the remote support and integration accounts vendors use answers that question with evidence. The internal and perimeter work maps to internal and external network penetration testing; portals and their APIs to web application penetration testing.
Penetration test or vulnerability assessment?
Absent effective continuous monitoring, the rule asks for both, on different clocks, and describes them differently. Vulnerability assessments are "systemic scans or reviews of information systems reasonably designed to identify publicly known security vulnerabilities," run at least every six months. The penetration test is an attempt to "circumvent or defeat the security features of an information system," run annually. A scan finds a missing patch. It does not show that one borrower can open another borrower's documents, or that the help desk will reset a password for a caller who knows a date of birth. Our comparison of penetration testing and vulnerability assessment sets out how other frameworks draw the same line.
The evidence to keep
The rule sets no retention period for program records. It requires five things in writing: the information security program itself (314.3(a)), the risk assessment (314.4(b)(1)), any approval by the Qualified Individual of an alternative to multi-factor authentication (314.4(c)(5)), the incident response plan (314.4(h)) and the Qualified Individual's report (314.4(i)). The testing file should let anyone reading those documents follow a line from the risk assessment to the scope, the findings, the fixes and the board.
Evidence | Why the rule needs it | Produced by |
|---|---|---|
Risk assessment version that set this year's scope | 314.4(b)(1); 314.4(d)(2)(i) scope "in accordance with the risk assessment" | Qualified Individual |
Decision between continuous monitoring and annual testing | 314.4(d)(2); if relying on monitoring, proof it detects vulnerability-creating changes "on an ongoing basis" | Qualified Individual |
Scope statement and signed authorization | 314.2(n): which systems are tested from outside and which from inside | Institution and tester |
Tester contract and service provider file | 314.2(r) and 314.4(f), where testers can reach customer information | Institution |
Penetration test report | 314.4(d)(2)(i): method, findings, severity and proof | Tester |
Vulnerability assessment reports | 314.4(d)(2)(ii): every six months, after material change and when other circumstances may materially affect the program | Internal team or provider |
Remediation record and retest results | 314.4(g); 314.4(h)(5) remediation of identified weaknesses | Institution and tester |
Qualified Individual's written report | 314.4(i)(2): material matters such as "results of testing" | Qualified Individual |
Written approvals of MFA alternatives (314.4(c)(5)) and a record of any Qualified Individual approval of compensating controls for encryption (314.4(c)(3)) | 314.4(c)(5) requires the approval in writing; 314.4(c)(3) applies only where encryption is infeasible | Qualified Individual |
Consumer count, if relying on the exemption | 314.6, counting current and former customers | Institution |
Logs that show what was and was not acquired | 314.2(m) presumption; 314.4(c)(8); 314.4(j) | Institution |
Colleges have a reader for this file every year: OMB's Supplement records ED's expectation that the Qualified Individual "would be able to provide the written information security program" to the auditors. For any covered institution, a short report or completion letter serves a lender, OEM or client that asks for proof of testing, but the full report and retest record belong in the program file.
Safeguards Rule testing checklist
Ten steps take a covered institution through one testing year.
Confirm coverage and count consumers. Check your activities against 314.1(b) and the examples in 314.2(h), then count every individual, current or former, about whom you hold customer information to see whether 314.6 applies.
Name the Qualified Individual. Designate one person under 314.4(a) and, if that person works for an affiliate or service provider, a senior member of your own staff to oversee them.
Update the written risk assessment. Record the criteria 314.4(b)(1) requires and list the information systems in scope, including systems connected to those that hold customer information.
Decide in writing how you will meet 314.4(d)(2). Choose effective continuous monitoring or annual penetration testing with vulnerability assessments every six months, and record the evidence that supports the choice.
Scope the annual test from the risk assessment. Cover the perimeter from outside, the internal network and directory from inside, customer portals, externally developed applications, multi-factor authentication and the people the risk assessment names.
Contract the tester as a service provider. Where testers may reach customer information, select them, bind them by contract and assess them under 314.4(f).
Run vulnerability assessments on every trigger. Scan at least every six months, after material changes to operations or business arrangements, and when other circumstances may materially affect the program.
Fix, retest and adjust the program. Track each finding to closure, retest it and update the program under 314.4(g).
Report results of testing to the board. Put the test and scan results, open risks and recommendations into the Qualified Individual's written report under 314.4(i).
Rehearse the FTC notice. Test the incident response plan against the 30-day clock in 314.4(j), including whether your logs can show what was and was not acquired.
If you also operate in Canada
The Safeguards Rule is a US rule, and Canadian dealers, lenders, tax practices and colleges work under different statutes. PIPEDA's Principle 4.7 requires that personal information "be protected by security safeguards appropriate to the sensitivity of the information" (Justice Laws) and does not name a penetration test. The dealership and mortgage rankings in this series set out the Canadian rules for those sectors.
What it costs with Stingrai
Stingrai publishes prices for two packages. An Autonomous Pentest, in which Snipe tests alone with no penetration testers, is at US$3,000 per assessment or US$650 per month on a 12-month continuous plan. A Hybrid Pentest, in which Stingrai's penetration testers and Snipe test together throughout, is at US$6,800 per assessment or US$1,275 per month on a 12-month continuous plan. Both cover exactly one web application and its APIs, which for a covered institution is usually the credit application, borrower or client portal. The "No High or Critical Finding = Don't Pay" guarantee applies to the Autonomous tier only.
The rest of a Safeguards Rule scope, including the external perimeter, the internal network, Active Directory, Microsoft 365, more applications and social engineering, is quoted through get a quote. Current figures are on the pricing page, and our penetration testing cost guide shows how scope moves market prices.
How Stingrai supports a Safeguards Rule program
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
For a covered institution, that translates into a test built to 314.4(d)(2) and the 314.2(n) definition. Network testing runs from the internet-facing perimeter and from inside, through lateral movement and segmentation between systems that hold customer information and the systems connected to them, with Active Directory assessed for ACL abuse and Kerberos and delegation paths to domain admin. Credit application, borrower, client and student portals are tested authenticated across every role, hunting IDOR and broken authorization. Microsoft 365 and Entra ID are tested for consent grants and Conditional Access gaps, where exceptions to multi-factor authentication are configured. Phishing and vishing aimed at the help desk and the staff who release payments test the people the FTC placed inside the definition.
Two named penetration testers staff every human-led engagement, reviewed by the team lead and an engagement partner, and the team holds 18 published CVEs. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept and prioritized remediation guidance, with live chat to the testers and Jira and Slack integration. Retesting is included, every human-led and hybrid report ships with an attestation letter, and Enterprise engagements add high-level management and post-remediation executive reports. Engagements run as a one-time annual test on the 314.4(d)(2) calendar or as a continuous program across the year. On the one web application in the published packages, Snipe, Stingrai's autonomous AI agent for web applications and their APIs, tests alone on the Autonomous tier; on a Hybrid engagement, Snipe and the penetration testers test together throughout, with the testers directing where it digs. The firm-level accreditation is listed on the CREST Marketplace. Stingrai's penetration testing supports your Safeguards Rule program by producing the testing evidence that paragraphs (d), (g) and (i) refer to.
Frequently Asked Questions
Does the FTC Safeguards Rule require penetration testing?
Yes, unless the institution has effective continuous monitoring. 16 CFR 314.4(d)(2) requires annual penetration testing of the institution's information systems, scoped each year from its written risk assessment, and vulnerability assessments at least every six months, after material changes and when other circumstances may materially affect the program, "absent effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities." The clause has applied since 9 June 2023. Institutions holding customer information on fewer than 5,000 consumers are exempt from it under 314.6.
How often does the Safeguards Rule require vulnerability assessments?
Unless the institution has effective continuous monitoring: at least every six months, plus whenever there are material changes to operations or business arrangements and whenever there are circumstances the institution knows or has reason to know may have a material impact on its information security program. The rule describes vulnerability assessments as including "any systemic scans or reviews of information systems reasonably designed to identify publicly known security vulnerabilities." The penetration test is a separate annual requirement.
What counts as continuous monitoring under the Safeguards Rule?
The rule does not define it. It refers to "effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities." In 2021 the FTC recalled that its proposal described continuous monitoring as "any system that allows real-time, ongoing monitoring of an information system's security, including monitoring for security threats, misconfigured systems, and other vulnerabilities," and said the rule "requires one, not both." An institution relying on monitoring should be able to show that it covers every information system in scope, and the paragraph (d)(1) duty to test or monitor key controls still applies.
Who is exempt from the Safeguards Rule penetration testing requirement?
Financial institutions that maintain customer information concerning fewer than 5,000 consumers. Section 314.6 exempts them from the written risk assessment, the annual penetration test and six-month vulnerability assessments, the written incident response plan and the Qualified Individual's annual board report. The FTC counts current and former customers, and counts people rather than transactions. Multi-factor authentication, encryption, the other safeguards and the 30-day FTC breach notice still apply.
Does the FTC Safeguards Rule apply to car dealerships?
Yes, to most dealers that finance or lease. The FTC's June 2025 staff FAQ says the rule applies to "most automobile dealers who finance or lease automobiles," that dealers who finance or facilitate financing are financial institutions, and that leasing for longer than 90 days also qualifies. A dealer that arranges a loan and does not keep the contract must still protect the customer information for as long as it has it.
Do colleges and universities have to comply with the Safeguards Rule?
Yes, if they take part in federal student aid. Each institution agrees in its Program Participation Agreement to comply with 16 CFR Part 314, and Federal Student Aid resolves GLBA findings as part of its determination of administrative capability, with corrective action plans and possible administrative action for repeated non-compliance. Single auditors check that the institution has designated a Qualified Individual and has a written program that addresses the required elements.
When must a financial institution notify the FTC of a breach?
As soon as possible and no later than 30 days after discovering a notification event involving the information of at least 500 consumers. A notification event is the acquisition of unencrypted customer information without authorization, and unauthorized access is presumed to be acquisition unless the institution has reliable evidence otherwise. The requirement in 314.4(j) took effect on 13 May 2024 and applies to institutions of every size. The FTC received about 163 such notices in 2025.
What penetration testing evidence should a Qualified Individual keep?
The rule sets no retention period, so keep the chain that connects risk to result: the written risk assessment that set the year's scope, the decision between continuous monitoring and annual testing, the signed scope and authorization, the penetration test report, vulnerability assessment reports from every six-month cycle and every other triggered assessment, the remediation and retest record, the service provider file for the tester, and the Qualified Individual's written report to the board, which must address material matters such as "results of testing" under 314.4(i).
Does social engineering count as penetration testing under the Safeguards Rule?
Yes. When a commenter argued that the definition left out human vulnerabilities, the FTC answered that testing employees with access to an information system does not take a test outside the definition, and that "Attempted social engineering and phishing are important parts of testing the security of information systems and would not be excluded by this definition." Whether phishing and vishing belong in a given year's test is a scoping decision the risk assessment should drive.
Related reading
Best Penetration Testing Companies for Auto Dealerships (2026)
Best Penetration Testing Companies for Mortgage Lenders and Servicers (2026)
Best Penetration Testing Companies for Accounting and CPA Firms (2026)
References
Electronic Code of Federal Regulations. 16 CFR Part 314, Standards for Safeguarding Customer Information. Title 16 up to date as of 29 September 2026. https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314. Source of every rule quotation, including 314.1(b), 314.2, 314.4(d)(2), 314.4(i), 314.4(j), 314.5 and 314.6.
Federal Trade Commission. Standards for Safeguarding Customer Information, final rule. 86 FR 70272, 9 December 2021. https://www.federalregister.gov/documents/2021/12/09/2021-25736/standards-for-safeguarding-customer-information. Commission explanations of continuous monitoring, social engineering, connected systems, the Qualified Individual and the exemption count.
Federal Trade Commission. Standards for Safeguarding Customer Information, delay of effectiveness. 87 FR 71509, 23 November 2022. https://www.federalregister.gov/documents/2022/11/23/2022-25201/standards-for-safeguarding-customer-information.
Federal Trade Commission. Standards for Safeguarding Customer Information, breach notification final rule. 88 FR 77499, 13 November 2023, effective 13 May 2024. https://www.federalregister.gov/documents/2023/11/13/2023-24412/standards-for-safeguarding-customer-information.
Federal Trade Commission. Standards for Safeguarding Customer Information, notice of proposed rulemaking. 84 FR 13158, 4 April 2019. https://www.federalregister.gov/documents/2019/04/04/2019-04981/standards-for-safeguarding-customer-information.
Federal Trade Commission. Agency Information Collection Activities; Proposed Collection; Comment Request; Extension. 91 FR 54872, 25 August 2026. https://www.federalregister.gov/documents/2026/08/25/2026-17331/agency-information-collection-activities-proposed-collection-comment-request-extension. Source of the 2025 breach notification count.
Federal Trade Commission. FTC Safeguards Rule: What Your Business Needs to Know. December 2024. https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know.
Federal Trade Commission. Automobile Dealers and the FTC's Safeguards Rule Frequently Asked Questions. June 2025. https://www.ftc.gov/business-guidance/resources/automobile-dealers-ftcs-safeguards-rule-frequently-asked-questions.
Federal Trade Commission. FTC Amends Safeguards Rule to Require Non-Banking Financial Institutions to Report Data Security Breaches. 27 October 2023. https://www.ftc.gov/news-events/news/press-releases/2023/10/ftc-amends-safeguards-rule-require-non-banking-financial-institutions-report-data-security-breaches.
Federal Trade Commission. FTC Provides Guidance on Updated Safeguards Rule. 16 June 2025. https://www.ftc.gov/news-events/news/press-releases/2025/06/ftc-provides-guidance-updated-safeguards-rule.
Federal Trade Commission. In the Matter of LightYear Dealer Technologies, LLC (DealerBuilt), complaint and decision and order, Docket C-4687. Order issued 3 September 2019. https://www.ftc.gov/system/files/documents/cases/172_3051_c-4687_dealerbuilt_decision_order.pdf.
Federal Trade Commission. Auto Dealer Software Provider Settles FTC Data Security Allegations. 12 June 2019. https://www.ftc.gov/news-events/news/press-releases/2019/06/auto-dealer-software-provider-settles-ftc-data-security-allegations.
Federal Trade Commission. In the Matter of Ascension Data & Analytics, LLC, complaint and decision and order, Docket C-4758. Order issued 22 December 2021. https://www.ftc.gov/system/files/documents/cases/1923126c4758ascensionorder.pdf.
Federal Student Aid. GENERAL-23-09: Updates to the Gramm-Leach-Bliley Act Cybersecurity Requirements. 9 February 2023. https://fsapartners.ed.gov/knowledge-center/library/electronic-announcements/2023-02-09/updates-gramm-leach-bliley-act-cybersecurity-requirements.
Federal Student Aid. Enforcement of Cybersecurity Requirements under the Gramm-Leach-Bliley Act. 28 February 2020. https://fsapartners.ed.gov/knowledge-center/library/electronic-announcements/2020-02-28/enforcement-cybersecurity-requirements-under-gramm-leach-bliley-act.
Federal Student Aid. GENERAL-24-46: Service Provider Relationships for GLBA Compliance. 24 April 2024. https://fsapartners.ed.gov/knowledge-center/library/electronic-announcements/2024-04-24/service-provider-relationships-glba-compliance.
Federal Student Aid. 2026-2027 Federal Student Aid Handbook, Volume 2, Chapter 7. Last modified 29 August 2026. https://fsapartners.ed.gov/knowledge-center/fsa-handbook/2026-2027/vol2/ch7-record-keeping-privacy-electronic-processes.
Office of Management and Budget. 2025 Compliance Supplement, Part 5, Student Financial Assistance Cluster, Special Tests and Provisions 10. https://www.whitehouse.gov/wp-content/uploads/2025/05/Part-5-Cluster-of-Programs.pdf.
US Code. 15 U.S.C. 6805, Enforcement. 2023 edition, govinfo. https://www.govinfo.gov/content/pkg/USCODE-2023-title15/html/USCODE-2023-title15-chap94-subchapI-sec6805.htm.
New York State Department of Financial Services. Second Amendment to 23 NYCRR 500, adopted text. November 2023. https://www.dfs.ny.gov/system/files/documents/2023/10/rf_fs_2amend23NYCRR500_text_20231101.pdf.
Internal Revenue Service. Publication 5708, Creating a Written Information Security Plan for your Tax and Accounting Practice. Rev. 8-2024. https://www.irs.gov/pub/irs-pdf/p5708.pdf.
Justice Laws Website. Personal Information Protection and Electronic Documents Act, Schedule 1, Principle 4.7. https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html.
Stingrai. Pricing. https://www.stingrai.io/pricing. Published one-time and continuous package prices for one web application and its APIs.
Ready to scope a Safeguards Rule penetration test?
Section 314.4(d)(2) is specific in a way most regulations are not: absent effective continuous monitoring, an annual penetration test of information systems scoped from the written risk assessment and vulnerability assessments every six months and after material change, with results of testing reported to the board in writing under 314.4(i). Stingrai's penetration testing supports your Safeguards Rule program with two named penetration testers on every human-led engagement, retesting and an attestation letter, as a one-time annual engagement or as continuous coverage across the year. Book a free scoping call, get a quote for a full perimeter, internal, application and social engineering scope, or read the published package prices on the pricing page.



