FTC Safeguards Rule encryption and MFA requirements are among the most specific technical duties in the rule, and they are where many small financial institutions fall short. The rule, at 16 CFR part 314, requires covered businesses to protect customer information with an information security program built on a written risk assessment. Section 314.4(c) then lists safeguards that the program must include, among them encryption of customer information and multi-factor authentication for access to information systems.
This guide summarises those safeguards, the exceptions the rule allows, the related testing duties and how to record them in your written information security plan. It is general information and not legal advice. Read the regulation and confirm your obligations with counsel. Start with our guide to who the rule covers, who the FTC Safeguards Rule applies to.
Free gap assessment
Where do you actually stand against ISO 27001?
Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.
Run the free ISO 27001 gap assessment → or View premium report sample
What section 314.4(c) requires
According to the text of 16 CFR 314.4, as summarised from a legal database, the safeguards include the items in the table.
| Safeguard | What the rule says in summary |
|---|---|
| Access controls | Authenticate and permit access only to authorised users, limited to what their jobs require |
| Data inventory | Identify and manage data, personnel, devices, systems and facilities by importance to business objectives |
| Encryption | Encrypt customer information held or transmitted, in transit over external networks and at rest |
| Secure development | Use secure practices for in-house applications and evaluate external ones |
| Multi-factor authentication | Require it for any individual accessing an information system, unless the Qualified Individual approves an equivalent control |
| Data disposal | Securely dispose of customer information no later than two years after last use, with exceptions |
| Change management | Adopt formal procedures for changes |
| Monitoring and logging | Monitor and log the activity of authorised users, and detect unauthorised access |
The regulation contains detailed wording, exceptions and defined terms that this table does not capture. Use it as a map to the text and not as a substitute.
Encryption under the FTC Safeguards Rule
The rule requires encryption of all customer information held or transmitted by the institution, both in transit over external networks and at rest. If encryption is infeasible, the summary says you may use effective alternative compensating controls, but the Qualified Individual must review and approve them in writing. Treat that as a narrow exception, and record the reasons.
Turning the requirement into a checklist
- Find where the data lives. Use your data inventory to list databases, file shares, laptops, phones, backups, cloud storage and email.
- Encrypt at rest. Enable full-disk encryption on laptops and servers, and encryption in databases and cloud storage.
- Encrypt in transit. Use current TLS for websites, portals and email transport, and secure file transfer methods.
- Manage keys. Control who can access keys, and keep them separate from the data.
- Cover backups and removable media. Encrypt them, and track their location.
- Document exceptions. Where encryption is not feasible, record the compensating control and the written approval.
Multi-factor authentication under the FTC Safeguards Rule encryption and MFA duties
The rule requires multi-factor authentication for any individual accessing any information system, unless your Qualified Individual has approved in writing an equivalent or more secure access control. In practice, apply MFA to email, the customer database, remote access, cloud consoles, administrative accounts and any system that stores or lets users see customer information. Choose phishing-resistant methods where you can, such as hardware keys or authenticator apps, and avoid relying only on SMS codes for higher risk access.
Document the scope: which systems require MFA, which methods are used and who approved any exceptions. Our guide to the Qualified Individual explains who holds that role and what they must sign off.
Monitoring, logging and disposal
The rule requires you to monitor and log the activity of authorised users and detect unauthorised access, use or tampering with customer information. Turn on logging for key systems, decide who reviews logs and how often, and record how you follow up on alerts. Disposal is also specific: the summary describes secure disposal no later than two years after the last date the information is used to provide a product or service, unless it is necessary for business operations or legally required. Set a retention schedule, and record disposals.
Testing: penetration tests and vulnerability assessments
Section 314.4(d) requires regular testing. According to the summary, organizations must conduct annual penetration testing, and vulnerability assessments at least every six months, where they do not have effective continuous monitoring. Schedule these in your calendar, record the scope and results and track fixes. Where a small firm relies on a managed provider, ask the provider for reports and keep them with your WISP.
Service providers and encryption
Encryption and MFA responsibilities do not disappear when you outsource. Check that cloud and software vendors encrypt your data and support MFA, and record what you verified. Our guide to WISP service provider oversight shows how to review vendors and what to put in contracts.
Recording FTC Safeguards Rule encryption and MFA controls in your WISP
Your written plan should describe each control, the systems it covers, the owner, the evidence and the review date. Our written information security plan template guide shows a typical structure. Keep an evidence folder with configuration screenshots, MFA enrolment reports, encryption status reports, log review records and test reports. Review the plan at least annually and after significant changes.
Planning your FTC Safeguards Rule encryption and MFA rollout
Treat the work as a short project. Start with the data inventory so you know where customer information sits, then rank systems by sensitivity. Enable MFA first on email and administrator accounts, because these are the most common entry points, then extend to the customer database and remote access. Encrypt laptops and mobile devices next, since lost devices are a frequent cause of breaches, then databases, backups and cloud storage. Give each step an owner and a date, and track progress in a simple table that the Qualified Individual reviews each month.
Communicate with staff before switching controls on. Explain why MFA is needed, how to enrol, what to do if a phone is lost and who to call for help. Poor rollout leads to workarounds, such as shared accounts, that undermine the control. Run a short pilot with a few users, fix problems, and then roll out to everyone.
Evidence assessors and regulators expect
Keep records that show the controls are real: MFA enrolment reports by user, configuration screenshots showing enforced policies, encryption status reports from device management tools, key management procedures, log review records with dates and names, and penetration test and vulnerability scan reports with remediation notes. Store them in one folder with an index that matches the sections of your written plan. When the Qualified Individual reports to the board or senior management, use the same evidence to support the report. This makes FTC Safeguards Rule encryption and MFA compliance easy to demonstrate in an inquiry, and it reduces the time spent gathering material.
Keeping the controls current
Technology and threats change, so review the controls each year. Check that new systems, vendors and staff are covered, that MFA methods remain strong and that encryption settings meet current practice. When you add a new application that holds customer information, add it to the inventory and confirm its encryption and MFA before it goes live. A short onboarding checklist for new systems keeps the program current between annual reviews.
A hypothetical example
A hypothetical mortgage broker with twelve staff reviews its systems against section 314.4(c). It finds that laptops are encrypted but a shared drive of loan documents is not, and that MFA is enabled for email but not for the customer relationship system. The broker turns on encryption for the drive, enables MFA on the system, and records both changes with screenshots. One legacy application cannot support MFA, so the Qualified Individual approves in writing a compensating control that restricts access to a secure network and adds extra logging, and sets a plan to replace the application. The example is invented for illustration.
Common mistakes with FTC Safeguards Rule encryption and MFA
- Encrypting laptops but not databases, backups or shared drives.
- Applying MFA only to email and leaving business systems open.
- Exceptions granted informally, without written approval by the Qualified Individual.
- Logging turned on but nobody reviewing it.
- No scheduled penetration test or vulnerability assessment.
- Assuming vendors handle encryption without checking.
The regulation text is available at the Cornell Legal Information Institute page for 16 CFR 314.4. Also review our notes on FTC Safeguards Rule penalties and breach notification to see what is at stake.
Templates for FTC Safeguards Rule encryption and MFA
To avoid writing encryption standards, MFA policies and evidence checklists from scratch, the WISP Toolkit provides documents you can adapt. Have counsel confirm they meet your obligations.
FTC Safeguards Rule encryption and MFA FAQ
Is encryption mandatory?
The rule requires encryption of customer information in transit and at rest, with an allowance for approved compensating controls where it is infeasible.
Who approves an MFA exception?
The Qualified Individual, in writing, according to the rule’s summary. Record the control that replaces MFA.
How often must we test?
Annual penetration testing and vulnerability assessments at least every six months, where continuous monitoring is not in place.
How long can we keep customer information?
The rule describes disposal no later than two years after last use, with exceptions. Check the exact wording.
Does a small firm have to comply?
Coverage depends on the rule’s definitions and any exemptions. Check the text or ask counsel.