• SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Call us today! 844-OCD-TECH

Find our Location
OCD TechOCD Tech
  • SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us
FTC Safeguards Rule

FTC Safeguards Rule Published in Federal Register: Effective Date 1/10/2022

December 14, 2021 Posted by Kate Upton IT Security

The FTC’s Final Rule to amend the Standards for Safeguarding Customer Information has been published to the Federal Register. The effective date for the rule is January 10, 2022.

This means that starting January 10, 2022 organizations will begin to be required to implement the provisions within the FTC Safeguards Rule. 
 
As part of this Final Rule, the deadline for complying with the provisions that organizations were originally given 6 months to meet has been extended to one year. This means that the following requirements in the Rule will need to be met by December 9, 2022:
 
– 314.4(a) the appointment of a Qualified Individual 
– 314.4 (b)(1) conducting a written risk assessment 
– 314(c)(1) through (8) setting forth the new elements of the information security program
– 314.4(d)(2) requiring continuous monitoring or annual penetration test
– 314.4(e) requiring training for personnel
– 314.4(f)(3) requiring periodic assessment of service providers
– 314.4(h) requiring a written incident response plan 
– 314.4(i) requiring an annual written report from the Qualified Individual. 
 
This encompasses all major requirements of the rule, meaning that organizations now have one year to build their compliance program, implement any new technologies, and to hire a Qualified Individual. 
 
If your organization needs assistance complying with the FTC Safeguards Rule, please reach out to Kate Upton or Michael Hammond here at OCD-Tech. OCD-Tech has a tailored program to help organizations meet each requirement and can fit this program to each organization’s unique needs. 
 
Share
0
Kate Upton

About Kate Upton

Kate Upton is the IT Government Compliance Team Lead at OCD-Tech. Kate has been with the firm since May 2019. Before joining the firm, Kate received her Bachelor’s degree in Political Science & Legal Studies from the University of Maine and went on to earn a Master’s degree from Northeastern University in Strategic Intelligence. She dedicates her time at the firm to meeting the unique compliance needs of clients in the Defense Industrial Base with projects including CMMC, NIST 800-171, NIST 800-53, and DFARS rules. Kate lives in Portland, Maine with her dog Lucy.

You also might be interested in

OCD TECH NIST UPDATE

NIST Framework update

Aug 16, 2023

The National Institute of Standards and Technology (NIST) has recently[...]

Penetration Testing

Penetration Testing  

Apr 9, 2024

Don’t Get Hacked, Safeguard Your Business  Imagine a world where[...]

You only have $10,000 to spend on IT security, where do you spend it?

You only have $10,000 to spend on IT security, where do you spend it?

Jan 17, 2023

Spending money on your business is always a difficult decision,[...]

Find us on

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Send Message
OCD Tech logo Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

  • OCD Tech
  • 25 BHOP, Suite 407, Braintree MA, 02184
  • 844-623-8324
  • https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®

IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review

IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO

Industries

  • Financial Services
  • Government
  • Enterprise
  • Auto Dealerships

© 2025 — OCD Tech: IT Audit - Cybersecurity - IT Assurance

  • OCD Tech
  • About Us
  • Contact Us
Prev Next