Skip to content
16 CFR Part 314

Safeguards Rule proof,
before anyone asks for it.

Thirteen of the requirements for non-bank financial institutions. The platform evidences six — and we name the other seven.

Request an initial conversation
Qualified Individual Risk assessment Access controls Inventory Encryption Multi-factor authentication Monitoring and testing Training Service providers Evaluate and adjust Incident response plan Report to the board FTC notification

Thirteen of the requirements in 16 CFR 314.4 — what this page walks through, one by one.

30days

To notify the FTC — as soon as possible, and no later than 30 days from the day the event is discovered. In effect since May 13, 2024.

500

Consumers affected — the threshold that triggers § 314.4(j).

5,000

Where § 314.6 draws a line: below it, parts of four requirements fall away — the written risk assessment, the testing schedule, the incident response plan, and the annual report. On which side of that line a business falls is for the FTC and for counsel to say.

ISO 9001:2015 certified by DEKRA (Germany) — a quality management certification, not a security certification. US office in Fort Lauderdale, Florida
Requirement by requirement

Six of thirteen. Not all thirteen.

Most vendors answer this with a column of checkmarks. Here is the actual split.

6/13

carried by the platform. The rest is named, not hidden.

Service

Qualified Individual

§ 314.4(a)

Platform

Risk assessment

§ 314.4(b)

Indirect

Access controls

§ 314.4(c)(1)

Platform

Inventory

§ 314.4(c)(2)

Service

Encryption

§ 314.4(c)(3)

Indirect

Multi-factor authentication

§ 314.4(c)(5)

Platform

Monitoring and testing

§ 314.4(d)

Service

Training

§ 314.4(e)

Platform

Service providers

§ 314.4(f)

Not claimed

Evaluate and adjust

§ 314.4(g)

Platform

Incident response plan

§ 314.4(h)

Not claimed

Report to the board

§ 314.4(i)

Platform

FTC notification

§ 314.4(j)

Platform — six requirements Mahoney Control continuously measures and evidences.

Service — three that no software can satisfy: a named individual, encryption in your environment, and training. How they get covered is part of that conversation.

Indirect — two the platform sees through a composite signal, not control by control. Not claimed — the annual report to the board and the periodic evaluation of the program. For the report the platform holds much of the substance; for the evaluation we make no claim. Neither is presented as satisfied.

§ 314.4(b) · (c)(2) · (d) · (f)

The evidence writes itself

  • Scored, not estimated

    A structured assessment produces a result and a risk index.

  • Current between reviews

    The inventory is fed by the stack you already run.

  • Signals become evidence

    Endpoint detection, log management, and patch status — each with an audit trail.

Mahoney Control governance center showing control mapping with status, coverage and evidence source per control
Mahoney Control governance heatmap: control domains by risk severity, with an export button

What you end up holding

Printable on the day it is asked for

  • Status, source, date

    Carried per control, as far as the platform can evaluate it — not a folder assembled the week before a review.

  • Vendors and where they sit

    Each one recorded with its data processing agreement.

  • Where the assessment stops

    The platform records whether an agreement exists. Assessing its adequacy remains legal work.

6
Measured by the platform
3
Delivered as a service
2
Visible only indirectly
2
Not claimed

How thirteen of the requirements in 16 CFR 314.4 divide in practice — what Mahoney Control measures, what Mahoney IT delivers as a service, and what neither claims. Measuring a requirement is not the same as satisfying it; whether a program meets the Rule is for an examiner and for counsel to say.

§ 314.4(j) — IN EFFECT SINCE MAY 13, 2024

Thirty days, counted from discovery

  1. The incident happens

    Nobody has to notice it yet. The event itself does not start anything.

  2. The clock starts here

    Anyone at the business knows

    An employee, officer, or agent — anyone other than the person who committed it. From this point on, the business is deemed to know.

  3. Management is told

    Often days later. The clock does not restart here — it has been running since the step before.

  4. By day 30 — notice to the FTC

    Counted from discovery, not from the day the report reached a desk — where the event meets the threshold in the Rule.

Thirty days sounds generous until the clock starts on a day nobody logged, and the count depends on an inventory nobody kept. Mahoney Control records both as they happen. The deadline is the regulation’s, not a service commitment of ours.

Bring the day you’d have to account for

A platform can hold the evidence.
It cannot decide whether the Rule reaches you.

Who carries what

Where we start, and where we stop

Mahoney IT

What you can evidence under the Rule.

Six frameworks ship with the platform: ISO 27001, NIS 2, SOC 2 Type II, NIST CSF, HIPAA and GDPR. The Safeguards Rule is not one of them — it is carried as your own rule set, loaded and scored the same way. Selecting a framework does not make anyone compliant — the product says so on the screen where you select one.

See it against your own controls

Your counsel and the FTC

Who the Rule covers in the first place.

The Rule reaches non-bank financial institutions. Whether your business is one of them is a question for your counsel and the FTC — a vendor who answers it is guessing about your business and handing you a legal conclusion at the same time.

Read the FTC’s own guidance

Mahoney Control maps client controls against these frameworks. That mapping is not a certification of Mahoney IT or of any client. Certification is issued by independent auditors against their own criteria. Mahoney IT Group Germany holds ISO 9001:2015, certified by DEKRA — a quality management certification, which says nothing about the requirements described on this page.

Questions we actually get

Questions that decide the engagement

Does Mahoney Control make your business compliant with the FTC Safeguards Rule?

No, and no software does. Compliance is an outcome an examiner or auditor confirms. Mahoney Control keeps the controls, signals, and documents that a review asks to see, scored against your rule set and exportable at any point. The requirements the platform does not cover — a named Qualified Individual, encryption inside the client environment, and training — are not product features. How they get covered is part of the initial conversation.

Is the Safeguards Rule one of the frameworks built into the platform?

No. The platform ships with six recognized frameworks: ISO 27001, NIS 2, SOC 2 Type II, NIST CSF, HIPAA, and GDPR. The Safeguards Rule is carried as your own rule set — the platform loads your written program, extracts its rules, and scores them like the built-in ones. Mapping controls against a framework is not a certification of Mahoney IT or of any client; certification is issued by independent auditors against their own criteria.

Does the platform check whether multi-factor authentication is switched on?

Not as a single reading. Where Microsoft 365 is connected, Mahoney Control reads the tenant’s overall Microsoft Secure Score, which reflects sign-in security among other factors. Confirming multi-factor authentication coverage under 16 CFR 314.4(c)(5) is a review activity carried out by people, and Mahoney IT states it that way rather than presenting a composite score as proof.

Do you have to replace your existing tools?

No. Mahoney Control reads the stack that is already in place and turns its signals into evidence. Where a control is missing entirely, that shows up as a gap rather than as a purchase order.

Start with one requirement

Bring the requirement you’re least able to evidence

Not a demo — a walk through thirteen of the requirements, checked against what your organization can produce today.

Minimum 20, maximum 2000 characters.

We offer our services to businesses only. We use your details solely to handle this inquiry. See our Privacy Policy (opens in a new tab).

You will receive an email with a confirmation link — your inquiry reaches us only after you click it, so nobody can submit an inquiry in your name. You may withdraw it at any time by emailing info@mahoney-it.com.

This page describes requirements under 16 CFR Part 314 and how Mahoney Control helps produce the evidence behind them. It is not legal advice and does not establish whether any particular business is subject to the Rule. Regulatory citations reflect the text in force on August 19, 2026.