Small Firms Think the FTC Safeguards Rule Doesn't Apply to Them.

April 14, 2026

When business owners hear “FTC Safeguards Rule,” the first thought is usually banks. Big financial institutions. Wall Street. Not a two-person CPA office in Lady Lake or an independent insurance agency in The Villages.

That assumption has left a lot of small businesses out of compliance since June 2023, often without knowing it.

What the FTC Safeguards Rule actually covers

The rule was written to cover any business “significantly engaged” in financial activities. That language is broad on purpose.

The FTC’s own guidance lists covered businesses, and the list includes:

  • Accountants and tax preparation services
  • Mortgage brokers and lenders
  • Vehicle dealerships that offer leases or arrange financing, which is nearly every dealership
  • Investment advisors not required to register with the SEC
  • Real estate settlement providers
  • Collection agencies, check cashing services, and wire transfer services

If you prepare tax returns, you are on that list. If you help car buyers get a loan, you are on that list. The size of your firm is not a factor. A solo CPA and a regional accounting firm are both covered.

The test is your activities, not your label. A retail store that just accepts credit cards generally isn’t covered. Doctors and lawyers typically aren’t either, because HIPAA and bar rules govern them instead.

The FTC published a guide specifically for small businesses: FTC Safeguards Rule: What Your Business Needs to Know

What compliance actually requires

The rule requires a written information security program, called a WISP, built around nine elements. In plain terms:

  1. A Qualified Individual. One named person responsible for the program. It can be an employee or an outside IT provider, but a senior person at your firm still owns the outcome.
  2. A risk assessment. A documented look at what client data you hold, where it lives, and what could go wrong.
  3. The safeguards themselves. Controls limiting who can access sensitive data, an inventory of your systems, encryption of customer information stored and in transit, multi-factor authentication for anyone accessing client data, and secure disposal of old records.
  4. Testing. Either continuous monitoring, or annual penetration testing plus vulnerability scans every six months, to make sure the controls actually work.
  5. Employee training that’s kept current, not a one-time video.
  6. Vendor oversight. Contracts requiring the services that touch your client data, including IT providers, cloud storage, and tax software, to protect it.
  7. Keeping the program current as your business and the threats change.
  8. A written incident response plan: who does what when something goes wrong. A template nobody has read doesn’t count.
  9. An annual written report on the program to your owner or board.

For a small firm, this doesn’t have to be complicated. But it does have to exist, in writing. “We’re careful with client data” is not an information security program.

The exemption nobody mentions

Here’s something most write-ups skip: if your firm maintains information on fewer than 5,000 consumers, you’re exempt from four of the nine elements: the formal written risk assessment, the annual penetration testing requirement, the written incident response plan, and the annual report.

What you’re not exempt from: the written program itself, the Qualified Individual, MFA, encryption, access controls, training, and vendor oversight. The exemption trims paperwork. It doesn’t excuse the actual security.

And be careful with the count: it’s consumers whose data you’ve ever maintained, not active clients. A tax office that’s been open ten years crosses 5,000 faster than you’d think.

The deadline has already passed

The mandatory compliance date was June 9, 2023, more than three years ago. Businesses that were unaware of the rule haven’t been exempt from it. They’ve been out of compliance.

The penalties are significant: FTC civil penalties can run to more than $50,000 per violation, per day, and corporate officers can be held personally liable. The exact figures adjust annually. The FTC’s guide linked above carries the current numbers.

There’s also a newer requirement with teeth of a different kind: since May 2024, a breach involving the information of 500 or more consumers must be reported to the FTC within 30 days, and that report becomes public record. Your clients, your competitors, and the local paper can look it up.

Most small firms haven’t been audited. But the risk isn’t only regulatory. If client financial records are leaked and you can’t demonstrate you had a security program in place, the liability conversation gets much harder, and a Safeguards failure can void your cyber insurance claim on top of it.

What this looks like for CPA firms and tax preparers

Your clients trust you with Social Security numbers, tax returns, business financials, and years of personal financial history. That data is exactly what the Safeguards Rule is designed to protect.

If you renew a PTIN, you’ve already attested to this: Question 11 on the IRS W-12 renewal form asks whether you’re aware of your obligation to have a data security plan. Checking that box without a written plan behind it is exactly the gap the rule targets.

For most small CPA practices, compliance means:

  • Documented procedures for how client data is stored and accessed
  • MFA on email and anywhere client data lives. Email is where W-2 fraud and phishing hit accounting firms hardest.
  • Backups that are tested and offsite
  • A written security plan you can point to if a client or regulator asks

This also ties directly into cyber insurance renewals. Carriers are asking for the same evidence at renewal time. Getting your security program in order handles both requirements at once.

What this looks like for insurance agencies

For insurance agencies, the enforcement path is slightly different: GLBA’s safeguards obligations for insurance are handled by state insurance regulators rather than the FTC, but the substance is the same, and your carriers demand it regardless. Agencies hold personal information across large client rosters: dates of birth, financial details, sometimes health information.

For independent agencies and small brokerages, the requirements mirror the FTC’s list: a written security plan, access controls, MFA, tested backups, and someone accountable for the program. Carrier appointment agreements and E&O renewals increasingly ask for proof of all of it.

What this looks like for dealerships

If your dealership arranges financing or leasing, you’re squarely covered. The FTC has said so explicitly and publishes compliance FAQs for auto dealers specifically. Credit applications, and the personal financial data on them, are the core of what the rule protects. The nine elements above apply, and the under-5,000-consumer exemption is unlikely to help a dealership of any real volume.

The practical path forward

The good news is that for a small firm, building a compliant information security program is not a months-long project. Most of the pieces are practical IT practices that a managed IT plan already covers: monitored systems, MFA, tested backups, access controls, and documentation.

What you get with a monthly IT plan, beyond the day-to-day support, is a paper trail. When your cyber insurance carrier asks at renewal, when a client asks how their data is protected, or if the FTC ever asks at all, you have real answers, in writing, with dates on them. Proof of compliance is the standard now, not intent.

If you’re not sure whether your firm is covered, where you stand against the nine elements, or whether the 5,000-consumer exemption applies to you, that’s worth finding out before a problem surfaces. The coverage question usually takes about five minutes to answer.

Who helps small firms in Lake County, FL comply?

Intermachine Systems builds and maintains Safeguards compliance programs, including the written plan, MFA, encryption, backups, and documentation, for CPA firms, tax preparers, insurance agencies, and dealerships across Lake, Marion, and Sumter Counties.

Give us a call at 352-561-8106 or email hello@intermachine.io. We work with CPA firms, tax preparers, insurance agencies, and dealerships in Lady Lake, The Villages, Leesburg, and surrounding communities.

No pressure, no jargon, just a straight answer about where you stand.

Frequently asked questions

Does the FTC Safeguards Rule apply to my business?

If your business is ‘significantly engaged’ in financial activities, including tax preparation firms, CPAs, mortgage brokers, auto dealers that arrange financing or leasing, collection agencies, and financial advisors not registered with the SEC, you are a financial institution under the Gramm-Leach-Bliley Act and the rule applies, regardless of your size.

What does the FTC Safeguards Rule require?

A written information security program with nine elements, including a designated Qualified Individual, access controls, encryption of customer data, multi-factor authentication, employee training, vendor oversight, and regular testing or monitoring of your safeguards.

Is there a small business exemption to the FTC Safeguards Rule?

Partially. Businesses maintaining information on fewer than 5,000 consumers are exempt from the formal written risk assessment, annual penetration testing, the written incident response plan, and annual board reporting, but still must maintain a written security program, MFA, encryption, access controls, training, and vendor oversight.

What are the penalties for violating the FTC Safeguards Rule?

FTC civil penalties can exceed $50,000 per violation per day, and corporate officers can face personal liability. Since May 2024, breaches affecting 500 or more consumers must also be reported to the FTC within 30 days, and that report becomes public record.

Who helps small firms in Lake County, FL comply with the FTC Safeguards Rule?

Intermachine Systems builds and maintains Safeguards compliance programs, including the written plan, MFA, encryption, backups, and documentation, for CPA firms, tax preparers, insurance agencies, and dealerships across Lake, Marion, and Sumter Counties.

Schedule Free Consultation

Free phone consultation, you select date and time

Schedule Now

Contact Intermachine

Call text or send an email.

Contact Us