FTC Safeguards Rule Requirements for 10 to 50 Employee CPA Firms in Houston
A Houston CPA Firm Guide To Safeguards Rule Compliance – Building A Safeguards Rule Program At A Small CPA Firm
The Regulation Says So in Writing.
What the FTC Safeguards Rule requires of Houston accounting firms, and the exemption most of them qualify for.
Most CPA firm owners hear "financial institution" and picture a bank. The regulation does not. It names accountants directly, and it has been enforceable since June 2023.
The text is not ambiguous. Under 16 CFR 314.2, the definitions section of the FTC Safeguards Rule: "An accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution because tax preparation services is a financial activity." There is no headcount floor and no revenue threshold. A solo practitioner with a PTIN is covered the same way a 40-person firm is.
What follows is what the rule actually requires, written from the regulation rather than from summaries of it. CinchOps builds and maintains Safeguards Rule compliance programs for CPA and accounting firms across Houston and Katy, at a flat monthly rate per endpoint, with a help desk that answers in under 15 minutes. The good news is buried in section 314.6, and most firms have never been told about it.
Does the FTC Safeguards Rule Apply to a CPA Firm?
Yes, and the regulation says so by name rather than by implication.
The FTC Safeguards Rule applies to businesses the regulation calls financial institutions, and 16 CFR 314.2 lists an accountant or tax preparation service as an example. Size does not change coverage.
The rule comes out of the Gramm-Leach-Bliley Act and was substantially rewritten in 2021, with full enforcement beginning June 9, 2023. The definition of a covered business is broader than the phrase suggests, and the regulation removes any doubt about accountants by naming them in the examples.
Two definitions decide how the rest of the rule applies to you, and both are worth reading closely:
- Customer information means "any record containing nonpublic personal information about a customer of a financial institution, whether in paper, electronic, or other form." Paper counts. The filing cabinet behind the front desk is in scope.
- Consumer means an individual who obtains a financial product or service "to be used primarily for personal, family, or household purposes." That wording matters more than it looks, and it comes back in the exemption below.
Look at what coverage does not depend on: your revenue, your staff count, whether you have an IT department, or whether you consider yourself a technology business. A 3-person practice in Katy preparing individual returns is covered by the same rule as a national firm.
What the Safeguards Rule Actually Requires
Nine areas, spelled out in 16 CFR 314.4. Here they are in plain terms.
The rule requires a written information security program built on a risk assessment, run by a named individual, with specific technical safeguards including multi-factor authentication and encryption of customer information in transit and at rest.
The regulation is prescriptive in a way most privacy rules are not. It does not say "use reasonable security." It names controls. Each item below maps to a lettered paragraph of section 314.4, so you can point your attorney or your insurer at the source.
- Designate a Qualified Individual. One named person "responsible for overseeing and implementing your information security program." It can be an employee or a third party, but it has to be someone specific, not a committee and not a vague assignment.
- Base the program on a risk assessment. Identify reasonably foreseeable internal and external risks, and describe how each will be mitigated or accepted. Reassess periodically.
- Implement access controls. Authenticate users and permit access "only to authorized users," reviewed periodically. In a CPA firm this usually means the seasonal preparer does not still have access in November.
- Inventory your data and systems. Know what data you hold, where it lives, and which devices and systems touch it. You cannot protect an asset you have not written down.
- Encrypt customer information "both in transit over external networks and at rest." This one has a second benefit that shows up in the breach section below.
- Require multi-factor authentication for "any individual accessing any information system," unless your Qualified Individual approves an equivalent control in writing. The written-approval escape hatch is narrow and rarely worth using.
- Dispose of customer information securely no later than 2 years after the last date it was used, unless you have a business or legal reason to keep it. Most firms fail this one simply by never deleting anything.
- Monitor and log authorized user activity and detect unauthorized access. Plus change management procedures for your systems.
- Train your people and vet your vendors. Security awareness training kept current, and service providers selected, contractually required to maintain safeguards, and periodically reassessed.
Beyond those, the rule requires testing: either continuous monitoring, or annual penetration testing plus vulnerability assessments at least every 6 months. It also requires a written incident response plan and an annual written report from the Qualified Individual to your governing body. Those last 3 are exactly where the exemption comes in.
The Exemption Most Houston Firms Qualify For
Section 314.6 removes 4 requirements for smaller firms. It is the least-discussed paragraph in the rule.
Under 16 CFR 314.6, a financial institution that maintains customer information concerning fewer than 5,000 consumers is exempt from 4 specific requirements: the written risk assessment, penetration testing and vulnerability assessments, the written incident response plan, and the annual report to the governing body.
The regulatory text is one sentence: "Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers." Translated, that is:
- 314.4(b)(1) the requirement that your risk assessment be written and formatted to specific criteria. You still base the program on risk. You do not owe the formal written document.
- 314.4(d)(2) annual penetration testing plus vulnerability assessments every 6 months. This is the single most expensive line item in the rule for a small firm.
- 314.4(h) the written incident response plan.
- 314.4(i) the Qualified Individual's annual written report to the board or governing body.
Two things to be careful about before you rely on it. First, the threshold counts consumers, and the rule defines a consumer as someone obtaining a service "primarily for personal, family, or household purposes." A firm doing mostly business returns may count very differently from a firm doing mostly individual ones, which is a question worth putting to your attorney rather than guessing at. Second, everything else in the rule still applies in full: the Qualified Individual, encryption, multi-factor authentication, access controls, disposal, training, vendor oversight, and the breach notification duty.
Here is the honest read from someone who sells IT services. In 30 years doing this, the pattern we see is that small firms get sold enterprise compliance packages built for the unexempted version of the rule, complete with annual penetration tests they were never required to buy. Knowing which paragraph you are exempt from is worth real money. And I would rather tell you that than sell you the test.
What Happens If Your Firm Has a Breach
A federal reporting duty took effect in May 2024, and encryption changes whether it applies.
Under 16 CFR 314.4(j), effective May 13, 2024, a covered firm must notify the Federal Trade Commission no later than 30 days after discovering a notification event affecting at least 500 consumers.
The notice must identify your firm, describe the types of information involved, give the date or date range of the event, state the number of consumers affected, and describe what happened. This duty is separate from and additional to Texas breach notification law, which carries its own deadlines. A single incident can trigger both.
Now the detail worth building your whole security budget around. The rule defines a notification event as the "acquisition of unencrypted customer information without the authorization of the individual to which the information pertains." Read that word again: unencrypted. Encryption is not only requirement number 5 on the checklist, it is the line between an incident you manage privately and a federal filing with your firm's name on it.
- Threshold: 500 or more consumers affected.
- Deadline: 30 days from discovery, not from the breach itself.
- Trigger: acquisition of unencrypted customer information without authorization.
- Not a substitute: Texas notification duties still run on their own clock, and your professional liability carrier likely has a notice requirement of its own.
If an incident is live right now, the sequencing matters more than the reading. Our guide on building an incident response plan covers who decides, who to call, and what to write down while it is happening.
Read section 314.4 and look at the verb. It says you shall, then lists nine things. A CPA firm holds Social Security numbers, bank details, and a year of someone's financial life. Nine requirements is not an excessive ask of a firm holding client data.
Compliance Is a Program, Not a Purchase
Multi-factor authentication, encryption, access reviews, logging, and vendor oversight are not one-time projects. They are settings that drift the moment nobody is watching them. CinchOps runs them continuously as part of managed cybersecurity for Houston CPA firms.
Explore CinchOps Cybersecurity →How CinchOps Can Help Your CPA Firm Comply
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.
- Through managed cybersecurity, CinchOps implements and maintains the technical safeguards the rule names: multi-factor authentication, encryption in transit and at rest, access controls, logging, and secure disposal on the 2-year cycle.
- Through CTO and CIO services, CinchOps can serve as or support your Qualified Individual, run the risk assessment, and keep vendor oversight documented rather than assumed.
- Through managed IT support, security awareness training and the ongoing controls are included at a flat monthly rate per endpoint, with no contracts, no hidden fees, and no cancellation penalties.
- CinchOps supports CPA firms across Houston, Katy, and Sugar Land, including practices running CCH Axcess, UltraTax, Lacerte, Drake, ProSeries, and QuickBooks, where filing-season uptime is not negotiable.
If nobody at your firm can name your Qualified Individual, you do not have a program yet, you have an intention. The fastest way to find out where you stand is to walk the checklist above against what is actually configured in your systems, which takes an afternoon and usually surprises people. When you want a second set of eyes on it, talk to CinchOps.
Frequently Asked Questions
Does the FTC Safeguards Rule apply to small CPA firms?
Yes. The regulation names an accountant or tax preparation service as an example of a covered financial institution, with no minimum size, revenue, or client count. A solo practitioner with a PTIN is covered the same as a large firm, though smaller firms qualify for a partial exemption under section 314.6.
What is the fewer-than-5,000-consumers exemption?
Section 314.6 exempts firms maintaining customer information on fewer than 5,000 consumers from four requirements: the written risk assessment, annual penetration testing and semi-annual vulnerability assessments, the written incident response plan, and the annual report to the governing body. Everything else, including encryption and multi-factor authentication, still applies in full.
When must a CPA firm report a breach to the FTC?
Within 30 days of discovering a notification event affecting at least 500 consumers, under 16 CFR 314.4(j), effective May 13, 2024. A notification event means acquisition of unencrypted customer information without authorization, so properly encrypted data may not trigger the duty at all. Texas notification law applies separately.
What does Safeguards Rule compliance cost for a Houston CPA firm?
Standalone compliance projects are usually quoted as a fixed engagement plus recurring testing. CinchOps includes the technical safeguards, training, and vendor documentation in its managed IT service at a flat monthly rate per endpoint, so a 12-person Katy firm pays a predictable monthly amount rather than a project fee plus surprises.
Who can be our Qualified Individual?
The rule requires one named person responsible for overseeing and implementing the program. It can be an employee, a partner, or a qualified third party such as your managed IT provider. What it cannot be is unassigned or spread across a committee, and using an outside firm does not transfer your firm's responsibility for the outcome.
Discover More
Resource
Sources
- 16 CFR 314.2 - Definitions, including accountants and tax preparation services as financial institutions
- 16 CFR 314.4 - Required elements of the information security program
- 16 CFR 314.6 - Exceptions for firms with fewer than 5,000 consumers
- 16 CFR 314.5 - Effective date of the notification requirement, May 13, 2024
- Federal Trade Commission - FTC Safeguards Rule: What Your Business Needs to Know