Skip to content

Compliance

FTC Safeguards Rule
Penetration Testing

Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, 16 CFR Part 314

Component tests from $4,200, free retest. See all pricing →

Last reviewed

Get a fixed quote

Reply in one business day

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When you need FTC safeguards rule penetration testing

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • Your Qualified Individual’s annual report to the board is due and there is no test result to put in it.
  • You do not run continuous monitoring, so the annual penetration test and six-month vulnerability assessments are the route the Rule leaves you.
  • You added a rooftop or office, changed dealer management or tax software, or moved to the cloud: a material change that calls for a new assessment.
  • A finance partner, a lender, or a cyber insurer asked for your last penetration test and vulnerability assessment.
  • You are a tax or accounting firm updating your written information security plan before filing season.

Who is covered

Does the FTC Safeguards Rule apply to us?

The Rule covers non-bank financial institutions under FTC jurisdiction. The definition is broad: it turns on what you do, not what you call yourself.

Covered?

Auto dealers that finance or lease
Yes, most
Mortgage brokers and non-bank lenders
Yes
Tax preparers and CPA firms that complete returns
Yes
Finance companies, collectors, check cashers, wire transferors
Yes
Finders that bring buyers and sellers together
Yes
Colleges and universities in federal student aid programs
Yes
Banks and federally insured credit unions
No

Why

Auto dealers that finance or lease
The FTC treats dealers that finance, or facilitate financing, and dealers that lease for more than 90 days as financial institutions
Mortgage brokers and non-bank lenders
Brokering loans is a financial activity under 16 CFR 314.2, and the FTC names mortgage and payday lenders
Tax preparers and CPA firms that complete returns
Completing income tax returns is a financial activity under 314.2
Finance companies, collectors, check cashers, wire transferors
Named by the FTC as examples of covered institutions
Finders that bring buyers and sellers together
Added by the 2021 amendments
Colleges and universities in federal student aid programs
Taking part in federal student aid includes an agreement to comply with the Rule. EdTech vendors that sell to them are asked about testing through the HECVAT
Banks and federally insured credit unions
Covered by the Interagency Guidelines or NCUA rules instead; see banks and credit unions

Investment advisers and credit counselors are financial institutions too, but advisers registered with the SEC answer to the SEC under Regulation S-P; our page on RIA cybersecurity covers those firms. Non-bank fintech lenders usually fall under the Rule as well; see fintech penetration testing. If you are unsure, ask your counsel before you ask us.

The requirement

What 16 CFR 314.4(d)(2) requires

Option one: continuous monitoring

Effective continuous monitoring, or other systems that detect, on an ongoing basis, changes in your information systems that may create vulnerabilities. With it in place, the annual test and six-month assessments are not mandated.

Option two: test and assess

Annual penetration testing, based on the risks your risk assessment identifies, plus vulnerability assessments, including system scans for publicly known vulnerabilities, at least every six months.

Plus: after material change

A new assessment whenever your operations or business arrangements change materially, or when something happens that may materially affect your security program.

Section 314.2 defines penetration testing as a test method in which assessors attempt to circumvent or defeat the security features of an information system. A vulnerability scan alone does not meet that definition.

What we assess

What your Safeguards Rule test covers

The Rule protects customer information: credit applications, tax returns, loan files, and account data. We test the systems that hold it and the paths an attacker would take to reach it.

External Perimeter

Everything you expose to the internet: websites and online credit applications, client portals, VPN and remote access, and email.

We test for

  • Internet-facing host and service discovery
  • VPN, remote desktop, and email exposure
  • Online credit application and client portal exposure
  • Password spraying within agreed rules

Internal Network

How far one phished workstation at a store, branch, or office reaches toward customer information.

We test for

  • Active Directory attack paths
  • Lateral movement between offices or rooftops
  • Access to shares and databases holding customer information
  • Segmentation between guest Wi-Fi, office, and business systems

Controls the Rule Names

Section 314.4(c) spells out specific safeguards. We test whether they hold from the attacker’s side.

We test for

  • Multi-factor authentication for anyone accessing an information system (314.4(c)(5))
  • Encryption of customer information in transit and at rest (314.4(c)(3))
  • Logging and detection of unauthorized access (314.4(c)(8))
  • Access limited to the people who need it

Vendors & Remote Access

The dealer management provider, IT support firm, and software vendors connected to your network. Section 314.4(f) makes overseeing them your job.

We test for

  • Vendor remote-access tools and accounts
  • Shared and default vendor credentials
  • Third-party connections into the network
  • Hosted software and cloud configuration

Small institutions

The 5,000-consumer exemption in 314.6

If you maintain customer information on fewer than 5,000 consumers, 314.6 lifts four requirements: the written risk assessment requirements of 314.4(b)(1), the annual penetration test and six-month vulnerability assessments of 314.4(d)(2), the written incident response plan of 314.4(h), and the Qualified Individual’s annual report to the board under 314.4(i).

It does not lift the information security program, the safeguards in 314.4(c) such as multi-factor authentication and encryption, or the duty to regularly test or otherwise monitor your key controls. A single vulnerability assessment from $1,500 is often the right-sized way to show that.

Auto dealers

Safeguards Rule testing for auto dealers

Dealers hold exactly what identity thieves want: credit applications, Social Security numbers, and income and bank details. These are the systems a dealer test covers.

Dealer management and F&I

The DMS, the F&I menu and credit application tools, and the workstations that reach them. Most customer information sits here.

Website and online credit apps

The forms that collect applications, the CRM behind them, and the lead feeds that pass customer data between vendors.

Rooftop networks

Showroom, service drive, and office networks, and whether guest Wi-Fi and kiosks are separated from the systems that hold customer files.

Vendor remote access

The remote-support tools and accounts your DMS provider, IT firm, and other vendors use to reach your network, which 314.4(f) makes you oversee.

Tax and accounting

Tax preparers and CPA firms

Firms that complete income tax returns are financial institutions under the Rule. The IRS and the Security Summit remind tax professionals that federal law requires a written information security plan, and IRS Publication 5708 gives a template for one. The plan has to cover how you test your safeguards.

For a small practice the test is usually the client portal, remote access, email and Microsoft 365, and the office network around the tax software. Our page on penetration testing for accounting and CPA firms covers the practice side in more depth.

Fixed prices

What Safeguards Rule testing costs

Published starting prices, fixed in writing before work begins. One quote covers the year.

What it covers

External penetration test
Websites, portals, VPN, email, and everything else internet-facing
Internal penetration test
The office or rooftop network from one compromised workstation
Vulnerability assessment
Scans for publicly known vulnerabilities, each result checked by an analyst

How often

Vulnerability assessment
Every six months and after material change

Price

External penetration test
From $4,200, free retest
Internal penetration test
From $6,000, free retest
Vulnerability assessment
$1,500 up to 250 devices, $2,500 up to 1,000

The vulnerability scanning and assessment cost page explains what moves the price. Larger estates are quoted from the scope.

Board evidence

Evidence for the Qualified Individual’s board report

Section 314.4(i) requires the Qualified Individual to report in writing, at least annually, to the board or equivalent governing body, including the results of testing. The deliverables are written to drop straight into that report.

  • An executive summary in plain language: what was tested, what was found, and what was fixed.
  • The penetration test report and the two vulnerability assessment reports, dated inside the year.
  • Retest results showing remediated findings closed, not just listed.
  • An attestation letter confirming independent testing, its scope, and its dates.

Since May 2024, 314.4(j) also requires notifying the FTC as soon as possible, and no later than 30 days after discovery, when unencrypted customer information of at least 500 consumers is acquired without authorization. Testing does not replace that duty, but it lowers the odds you will need it.

Methodology

How we test

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your compliance test runs through.

  1. 01

    Scope the boundary

    The systems your framework actually covers, and nothing you would pay to test twice.

  2. 02

    Test

    The component penetration tests run to PTES and OWASP standards by senior testers.

  3. 03

    Map to controls

    Every finding tied to the requirement or control it evidences.

  4. 04

    Report for the auditor

    Evidence formatted the way your assessor, examiner, or QSA expects to read it.

  5. 05

    Fix & retest

    A free retest so the audit shows closed findings, not open ones.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope customer data

    We find the systems that hold customer information: dealer management, loan origination, tax software, portals, and the network around them.

  2. 02

    Test once a year

    External and internal penetration testing, the annual test 314.4(d)(2) requires.

  3. 03

    Assess every six months

    Validated vulnerability assessments on the six-month cadence and after material changes.

  4. 04

    Report & retest

    A report the Qualified Individual can take to the board, then a free retest of what you fix.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type.

All case studies →

Free

Retest on every penetration test

185+

Years combined experience

14

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Post-Incident Web App Assessment

Medium risk

Excessive data exposure: API responses leaked transaction metadata, including precise geolocation, enabling real-world tracking of users.

Outcome. Surfaced the exposure and hardening gaps, prioritized by how readily an attacker could chain them, and delivered fixes plus a retest to confirm closure.

8

Findings

3

Medium

Post-incident

Engagement

Read the case study

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before FTC Safeguards testing.

Still have questions? 
01Does the FTC Safeguards Rule require penetration testing?

Yes, unless you continuously monitor. Section 314.4(d)(2) requires continuous monitoring or, failing that, annual penetration testing plus vulnerability assessments at least every six months, and again after material changes to your operations or business arrangements. For dealers and firms without round-the-clock monitoring of every information system, that means the annual test and the six-month assessments.

02Does the Safeguards Rule apply to car dealerships?

To most of them. The FTC says auto dealers that finance, or facilitate the financing of, vehicles for consumers are financial institutions under the Rule, and so are dealers that lease vehicles for longer than 90 days. The FTC publishes a dealer FAQ on the Rule, and the testing requirement is the same as for any other covered institution.

03We hold data on fewer than 5,000 consumers. Are we exempt?

Partly. Section 314.6 removes four obligations for institutions that maintain customer information on fewer than 5,000 consumers: the written risk assessment requirements of 314.4(b)(1), the annual penetration test and six-month assessments of 314.4(d)(2), the written incident response plan of 314.4(h), and the annual board report of 314.4(i). The rest of the Rule still applies, including the duty to regularly test or otherwise monitor your key controls under 314.4(d)(1), so a lighter test is still worth doing.

04Do we need an outside firm, or can our IT provider do it?

The Rule does not require an outside firm. It defines a penetration test as a method in which assessors attempt to circumvent or defeat the security features of an information system. An independent tester keeps your IT provider from grading its own work, and it gives the Qualified Individual results the board can trust. We report as an independent third-party penetration test, with an attestation letter.

05How much does Safeguards Rule testing cost?

Each piece has a published starting price, fixed in writing before work begins: an external penetration test from $4,200, an internal test from $6,000, both with a free retest, and a validated vulnerability assessment at $1,500 for up to 250 devices or $2,500 for up to 1,000, run twice a year. You get one written quote for the year. Starting prices for every service are on our pricing page.

06We are a dealer group with several rooftops. How is that scoped?

By network, not by rooftop. If your stores share one dealer management system, one domain, and one network, a single internal test from one location usually reaches the shared estate, with a segmentation check between stores. Rooftops on separate networks are scoped separately. We confirm it from your network layout before we quote.

07We are a New York licensed lender. Does NYDFS apply too?

Usually, yes. A DFS license brings 23 NYCRR Part 500, which requires annual penetration testing from inside and outside your boundaries, on top of the Safeguards Rule. One external and internal test can be scoped and reported for both. See our NYDFS 23 NYCRR 500 penetration testing page.

08Does the Safeguards Rule apply to banks and credit unions?

No. Banks follow the Interagency Guidelines from their federal regulator, and federally insured credit unions follow NCUA rules. Non-federally insured credit unions are covered by the FTC Rule. Our page on penetration testing for banks and credit unions covers what examiners expect.

Ready to test your defenses?

Talk to our team about what your FTC Safeguards compliance requires.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.