CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT Services
    • Cybersecurity
    • Business Continuity & Disaster Recovery (BCDR)
    • Virtual CTO & CIO Services
    • Cloud Services
    • Software Defined Wide Area Networks (SD-WAN)
    • Voice Over IP (VoIP)
    • Business Process Automation
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise IT Services & Support in Houston, TX
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Law Firms
    • Manufacturing
    • Oil & Gas Services
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Reviews
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Contact
I Need IT Support Now
A teal and orange shield enclosing a tax return document on a desk in an accounting office, representing FTC Safeguards Rule data protection duties for Houston CPA firms
Shane Stevens
Shane Stevens August 25th, 2026

FTC Safeguards Rule Requirements for 10 to 50 Employee CPA Firms in Houston

A Houston CPA Firm Guide To Safeguards Rule Compliance – Building A Safeguards Rule Program At A Small CPA Firm

CPA Firm Compliance Guide
Your CPA Firm Is a Financial Institution Under Federal Law.
The Regulation Says So in Writing.

What the FTC Safeguards Rule requires of Houston accounting firms, and the exemption most of them qualify for.

TL;DR
The FTC Safeguards Rule names tax preparers as financial institutions, so it covers CPA firms of every size. Firms holding data on fewer than 5,000 consumers are exempt from 4 of the heaviest requirements. Most Houston firms qualify and do not know it.
⚖️ Who Is Covered 📋 The Requirements 🎯 The 5,000 Exemption 🚨 If There Is a Breach 🚀 How CinchOps Helps

Most CPA firm owners hear "financial institution" and picture a bank. The regulation does not. It names accountants directly, and it has been enforceable since June 2023.

The text is not ambiguous. Under 16 CFR 314.2, the definitions section of the FTC Safeguards Rule: "An accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution because tax preparation services is a financial activity." There is no headcount floor and no revenue threshold. A solo practitioner with a PTIN is covered the same way a 40-person firm is.

What follows is what the rule actually requires, written from the regulation rather than from summaries of it. CinchOps builds and maintains Safeguards Rule compliance programs for CPA and accounting firms across Houston and Katy, at a flat monthly rate per endpoint, with a help desk that answers in under 15 minutes. The good news is buried in section 314.6, and most firms have never been told about it.

SAFEGUARDS RULE AT A GLANCEThe Four Numbers That Decide What You Owe9Requirement areasin 16 CFR 314.44Lifted below5,000 consumers500Consumers triggersan FTC filing30Days from discoveryto notify the FTCCinchOps · cinchops.com
The short version: you are covered, the requirements are specific, and if your firm holds data on fewer than 5,000 consumers you are exempt from 4 of them. Security compliance is where this work lives.
One caveat: this guide is a general reference, not legal advice. It quotes the regulation, but how it applies to your specific practice is a question for your attorney and your professional liability carrier. Bring them in before you rely on any interpretation, including this one.

Does the FTC Safeguards Rule Apply to a CPA Firm?

Yes, and the regulation says so by name rather than by implication.

The FTC Safeguards Rule applies to businesses the regulation calls financial institutions, and 16 CFR 314.2 lists an accountant or tax preparation service as an example. Size does not change coverage.

The rule comes out of the Gramm-Leach-Bliley Act and was substantially rewritten in 2021, with full enforcement beginning June 9, 2023. The definition of a covered business is broader than the phrase suggests, and the regulation removes any doubt about accountants by naming them in the examples.

WHY CPA FIRMS ARE COVEREDThree Lines of Regulation, One Conclusion1Preparing tax returnsis a financial activity12 CFR 225.28(b)(6)(vi)2That makes the firm afinancial institution16 CFR 314.23Financial institutionsmust follow the Rule16 CFR 314.4Your CPA firm is a financial institution under federal lawNo employee minimum. No revenue floor. A solo practitioner with a PTIN is covered.Source: 16 CFR 314.2, quoting 12 CFR 225.28(b)(6)(vi).CinchOps · cinchops.com

Two definitions decide how the rest of the rule applies to you, and both are worth reading closely:

  • Customer information means "any record containing nonpublic personal information about a customer of a financial institution, whether in paper, electronic, or other form." Paper counts. The filing cabinet behind the front desk is in scope.
  • Consumer means an individual who obtains a financial product or service "to be used primarily for personal, family, or household purposes." That wording matters more than it looks, and it comes back in the exemption below.

Look at what coverage does not depend on: your revenue, your staff count, whether you have an IT department, or whether you consider yourself a technology business. A 3-person practice in Katy preparing individual returns is covered by the same rule as a national firm.

What the Safeguards Rule Actually Requires

Nine areas, spelled out in 16 CFR 314.4. Here they are in plain terms.

The rule requires a written information security program built on a risk assessment, run by a named individual, with specific technical safeguards including multi-factor authentication and encryption of customer information in transit and at rest.

The regulation is prescriptive in a way most privacy rules are not. It does not say "use reasonable security." It names controls. Each item below maps to a lettered paragraph of section 314.4, so you can point your attorney or your insurer at the source.

  • Designate a Qualified Individual. One named person "responsible for overseeing and implementing your information security program." It can be an employee or a third party, but it has to be someone specific, not a committee and not a vague assignment.
  • Base the program on a risk assessment. Identify reasonably foreseeable internal and external risks, and describe how each will be mitigated or accepted. Reassess periodically.
  • Implement access controls. Authenticate users and permit access "only to authorized users," reviewed periodically. In a CPA firm this usually means the seasonal preparer does not still have access in November.
  • Inventory your data and systems. Know what data you hold, where it lives, and which devices and systems touch it. You cannot protect an asset you have not written down.
  • Encrypt customer information "both in transit over external networks and at rest." This one has a second benefit that shows up in the breach section below.
  • Require multi-factor authentication for "any individual accessing any information system," unless your Qualified Individual approves an equivalent control in writing. The written-approval escape hatch is narrow and rarely worth using.
  • Dispose of customer information securely no later than 2 years after the last date it was used, unless you have a business or legal reason to keep it. Most firms fail this one simply by never deleting anything.
  • Monitor and log authorized user activity and detect unauthorized access. Plus change management procedures for your systems.
  • Train your people and vet your vendors. Security awareness training kept current, and service providers selected, contractually required to maintain safeguards, and periodically reassessed.

Beyond those, the rule requires testing: either continuous monitoring, or annual penetration testing plus vulnerability assessments at least every 6 months. It also requires a written incident response plan and an annual written report from the Qualified Individual to your governing body. Those last 3 are exactly where the exemption comes in.

FTC SAFEGUARDS RULE CHECKLISTWhat Every Covered CPA Firm Must Do 1Name a Qualified IndividualOne person accountable for the whole program 2Run a risk assessmentIdentify risks, then mitigate or accept each one 3Encrypt data in transit and at restAlso your best protection against breach notice 4Turn on multi-factor authenticationRequired for anyone touching any system 5Dispose of client data after 2 yearsUnless a business or legal reason to keep it 6Train staff and vet your vendorsContracts must require safeguards, then verify Source: 16 CFR 314.4. Enforceable since June 9, 2023. CinchOps · cinchops.com

The Exemption Most Houston Firms Qualify For

Section 314.6 removes 4 requirements for smaller firms. It is the least-discussed paragraph in the rule.

Under 16 CFR 314.6, a financial institution that maintains customer information concerning fewer than 5,000 consumers is exempt from 4 specific requirements: the written risk assessment, penetration testing and vulnerability assessments, the written incident response plan, and the annual report to the governing body.

The regulatory text is one sentence: "Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers." Translated, that is:

  • 314.4(b)(1) the requirement that your risk assessment be written and formatted to specific criteria. You still base the program on risk. You do not owe the formal written document.
  • 314.4(d)(2) annual penetration testing plus vulnerability assessments every 6 months. This is the single most expensive line item in the rule for a small firm.
  • 314.4(h) the written incident response plan.
  • 314.4(i) the Qualified Individual's annual written report to the board or governing body.
SECTION 314.6 EXEMPTIONWhat Drops Off Below 5,000 ConsumersFewer Than 5,000 ConsumersThese 4 requirements do not applyWritten risk assessment314.4(b)(1) liftedPenetration test + vuln scans314.4(d)(2) liftedWritten incident response plan314.4(h) liftedAnnual report to governing body314.4(i) lifted5,000 or More ConsumersAll 9 areas apply in fullWritten risk assessment314.4(b)(1) requiredPenetration test + vuln scans314.4(d)(2) requiredWritten incident response plan314.4(h) requiredAnnual report to governing body314.4(i) requiredEverything else still applies in fullQualified Individual, encryption, MFA, access controls, disposal, training, vendor oversightSource: 16 CFR 314.6. The threshold counts consumers, not clients.CinchOps · cinchops.com

Two things to be careful about before you rely on it. First, the threshold counts consumers, and the rule defines a consumer as someone obtaining a service "primarily for personal, family, or household purposes." A firm doing mostly business returns may count very differently from a firm doing mostly individual ones, which is a question worth putting to your attorney rather than guessing at. Second, everything else in the rule still applies in full: the Qualified Individual, encryption, multi-factor authentication, access controls, disposal, training, vendor oversight, and the breach notification duty.

Here is the honest read from someone who sells IT services. In 30 years doing this, the pattern we see is that small firms get sold enterprise compliance packages built for the unexempted version of the rule, complete with annual penetration tests they were never required to buy. Knowing which paragraph you are exempt from is worth real money. And I would rather tell you that than sell you the test.

What Happens If Your Firm Has a Breach

A federal reporting duty took effect in May 2024, and encryption changes whether it applies.

Under 16 CFR 314.4(j), effective May 13, 2024, a covered firm must notify the Federal Trade Commission no later than 30 days after discovering a notification event affecting at least 500 consumers.

The notice must identify your firm, describe the types of information involved, give the date or date range of the event, state the number of consumers affected, and describe what happened. This duty is separate from and additional to Texas breach notification law, which carries its own deadlines. A single incident can trigger both.

BREACH NOTIFICATION DECISION PATHDo You Have to Tell the FTC?1Was the customer informationencrypted?YES - STOPNot a notification eventunder 16 CFR 314.2.If not encrypted2Does it affect 500 or moreconsumers?NO - STOPNo FTC filing. Texas law andyour carrier may still apply.If 500 or moreNotify the FTC within 30 days of discovery16 CFR 314.4(j), effective May 13, 2024. The clock starts at discovery, not at the breach.Source: 16 CFR 314.2 and 314.4(j). Encryption is why the first question comes first.CinchOps · cinchops.com

Now the detail worth building your whole security budget around. The rule defines a notification event as the "acquisition of unencrypted customer information without the authorization of the individual to which the information pertains." Read that word again: unencrypted. Encryption is not only requirement number 5 on the checklist, it is the line between an incident you manage privately and a federal filing with your firm's name on it.

  • Threshold: 500 or more consumers affected.
  • Deadline: 30 days from discovery, not from the breach itself.
  • Trigger: acquisition of unencrypted customer information without authorization.
  • Not a substitute: Texas notification duties still run on their own clock, and your professional liability carrier likely has a notice requirement of its own.

If an incident is live right now, the sequencing matters more than the reading. Our guide on building an incident response plan covers who decides, who to call, and what to write down while it is happening.

Read section 314.4 and look at the verb. It says you shall, then lists nine things. A CPA firm holds Social Security numbers, bank details, and a year of someone's financial life. Nine requirements is not an excessive ask of a firm holding client data.
Shane Stevens, CEO, CinchOps - LinkedIn

Compliance Is a Program, Not a Purchase

Multi-factor authentication, encryption, access reviews, logging, and vendor oversight are not one-time projects. They are settings that drift the moment nobody is watching them. CinchOps runs them continuously as part of managed cybersecurity for Houston CPA firms.

Explore CinchOps Cybersecurity →

How CinchOps Can Help Your CPA Firm Comply

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.

  • Through managed cybersecurity, CinchOps implements and maintains the technical safeguards the rule names: multi-factor authentication, encryption in transit and at rest, access controls, logging, and secure disposal on the 2-year cycle.
  • Through CTO and CIO services, CinchOps can serve as or support your Qualified Individual, run the risk assessment, and keep vendor oversight documented rather than assumed.
  • Through managed IT support, security awareness training and the ongoing controls are included at a flat monthly rate per endpoint, with no contracts, no hidden fees, and no cancellation penalties.
  • CinchOps supports CPA firms across Houston, Katy, and Sugar Land, including practices running CCH Axcess, UltraTax, Lacerte, Drake, ProSeries, and QuickBooks, where filing-season uptime is not negotiable.

If nobody at your firm can name your Qualified Individual, you do not have a program yet, you have an intention. The fastest way to find out where you stand is to walk the checklist above against what is actually configured in your systems, which takes an afternoon and usually surprises people. When you want a second set of eyes on it, talk to CinchOps.

100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Frequently Asked Questions

Does the FTC Safeguards Rule apply to small CPA firms?

Yes. The regulation names an accountant or tax preparation service as an example of a covered financial institution, with no minimum size, revenue, or client count. A solo practitioner with a PTIN is covered the same as a large firm, though smaller firms qualify for a partial exemption under section 314.6.

What is the fewer-than-5,000-consumers exemption?

Section 314.6 exempts firms maintaining customer information on fewer than 5,000 consumers from four requirements: the written risk assessment, annual penetration testing and semi-annual vulnerability assessments, the written incident response plan, and the annual report to the governing body. Everything else, including encryption and multi-factor authentication, still applies in full.

When must a CPA firm report a breach to the FTC?

Within 30 days of discovering a notification event affecting at least 500 consumers, under 16 CFR 314.4(j), effective May 13, 2024. A notification event means acquisition of unencrypted customer information without authorization, so properly encrypted data may not trigger the duty at all. Texas notification law applies separately.

What does Safeguards Rule compliance cost for a Houston CPA firm?

Standalone compliance projects are usually quoted as a fixed engagement plus recurring testing. CinchOps includes the technical safeguards, training, and vendor documentation in its managed IT service at a flat monthly rate per endpoint, so a 12-person Katy firm pays a predictable monthly amount rather than a project fee plus surprises.

Who can be our Qualified Individual?

The rule requires one named person responsible for overseeing and implementing the program. It can be an employee, a partner, or a qualified third party such as your managed IT provider. What it cannot be is unassigned or spread across a committee, and using an outside firm does not transfer your firm's responsibility for the outcome.

Discover More

What IT Services Should Every CPA Firm Have? (2026 Checklist)
How to Choose an IT Provider That Understands CPA Firms (2026 Guide)
How Much Does Managed IT Cost for a CPA Firm? (2026 Pricing Guide)
CinchOps Reveals Critical Security Gaps in Houston Accounting Firms Through Comprehensive Cybersecurity Audit
Does a Small Business Really Need an Incident Response Plan? (2026 Guide)
Security Compliance: What Regulations Mean for Your IT Infrastructure

Resource

Infographic: the FTC Safeguards Rule for Houston CPA firms - 9 core security requirements, enforceable since June 9 2023, the under-5,000-consumer exemption, and the 500-consumer 30-day FTC breach reporting trigger
The FTC Safeguards Rule and Your Houston CPA Firm Open Full Size

Sources

  • 16 CFR 314.2 - Definitions, including accountants and tax preparation services as financial institutions
  • 16 CFR 314.4 - Required elements of the information security program
  • 16 CFR 314.6 - Exceptions for firms with fewer than 5,000 consumers
  • 16 CFR 314.5 - Effective date of the notification requirement, May 13, 2024
  • Federal Trade Commission - FTC Safeguards Rule: What Your Business Needs to Know
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

May 15th, 2026
Cybersecurity Houston
Cybersecurity Houston: How Attackers Drained $200K From an AI Wallet With Morse Code

From Morse Code To Your Bank Account: Why AI Architecture Matters – The $200K Morse Code Heist Every Houston Business Owner Should Know About

August 6th, 2025
Managed Service Provider Houston Cybersecurity
CinchOps Warns Houston Businesses: CAPTCHAgeddon Attacks Are Replacing Traditional Malware Schemes

ClickFix: Understanding Browser-Based Social Engineering Threats – The Psychology Behind Successful CAPTCHA-Based Cyberattacks

April 6th, 2026
Managed IT Houston Construction
Your Crews Aren’t Slow – Your Construction IT Is

Why Office IT Providers Struggle with Construction Jobsite Requirements – Construction IT That Deploys Where Your Crews Actually Work

May 14th, 2026
Katy Cybersecurity
Katy Cyber Security: What Business Owners Actually Need to Know

The Defense Guide For Business Owners Who Don’t Have Time For Theory – Real Cyber Security For Cinco Ranch And Energy Corridor SMBs

June 30th, 2026
Healthcare IT
Healthcare IT Support for Houston’s Senior Surge

Houston’s 65+ Growth and the Case for Managed Healthcare IT

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT Services
  • Cybersecurity
  • Virtual CTO & CIO
  • Business Continuity & Disaster Recovery for Houston Businesses
  • Cloud Services
  • Business Process Automation for Houston Businesses
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy