The exemption, in one sentence
If you run a small practice you have probably been told that the FTC Safeguards Rule has a carve-out for firms holding data on fewer than 5,000 consumers, and that you are therefore exempt. The first half is true. The second half is a summary that has drifted a long way from the text.
Here is the whole exemption. It is 16 CFR 314.6, and it is one sentence:
16 CFR 314.6 — Exceptions
Four paragraphs. Not the Rule. Not section 314.4, which is the section containing every substantive requirement. Four specific paragraphs of it.
Everything else in 314.4 applies to a sole practitioner exactly as it applies to a two-hundred-person firm. That includes encryption, multi-factor authentication, access controls, secure disposal, and the paragraph on overseeing the software vendors you buy from — which is the one that is almost never mentioned and is the reason I wrote this.
A note before we go further: I am not a lawyer and this is not legal advice. What follows is the regulation with its paragraph numbers, so you can go and read it yourself. That is deliberately a lower bar than advice and a higher bar than most of what is written about this.
What the four exempted paragraphs actually remove
The exemption is genuinely useful. It removes the four most administratively heavy requirements in the Rule, which are the ones that make least sense for a practice with no IT department and no board.
| Paragraph | What it requires | What the exemption means for you |
|---|---|---|
| 314.4(b)(1) | A written risk assessment identifying reasonably foreseeable internal and external risks, with criteria for evaluating and categorising threats and how each risk will be mitigated or accepted | You still need to think about risk. You do not have to produce it as a formal written document in that prescribed form |
| 314.4(d)(2) | Continuous monitoring, or annual penetration testing plus biannual vulnerability assessments | You are not expected to commission penetration tests. This is the single most expensive requirement in the Rule and it is lifted |
| 314.4(h) | A written incident response plan | No formal written plan required. Knowing what you would do is still sensible |
| 314.4(i) | An annual written report to your board or governing body | Meaningless for a sole trader, and duly removed |
If you have been putting this off because you assumed it meant penetration testing and a formal risk register, the exemption is better news than you think. What it does not do is release you from the substantive security obligations underneath.
What still applies in full
These are the parts of 314.4 that a firm under 5,000 consumers is not exempt from. The two most concrete are worth quoting directly, because the wording is more specific than most summaries suggest.
Encryption — 314.4(c)(3)
Note at rest. Not just documents in flight between you and a client — the files sitting on the laptop. Full-disk encryption is built into both Windows and macOS, it is free, and switching it on takes about ten minutes. If you do one thing off the back of this article, make it that one.
Multi-factor authentication — 314.4(c)(5)
Any individual, any information system. In practice that means MFA on your email before anything else, because your email is where the client documents actually are, whatever else you use. Then the accounting software, the payroll system, cloud storage, and the portal if you have one.
On “your Qualified Individual”: the Rule requires one to be designated. It does not require them to be a different person, or to hold a qualification. In a solo practice, that is you. Write your own name down and move on.
And the rest
Access controls, an inventory of where customer information is held, secure disposal when you no longer need it, and change management all sit in the same section and are not exempted. None of them is exotic for a small practice. Most of them amount to knowing what you have and where it is.
314.4(f): the paragraph nobody mentions
This is the one that matters most for a small practice and gets written about least, because it is not about your own security posture. It is about everybody you buy software from.
314.4(f) requires three things:
16 CFR 314.4(f) — Oversee service providers
- “Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue”
- “Requiring your service providers by contract to implement and maintain such safeguards”
- “Periodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards”
It is not in the exempted list. A sole practitioner carries it in full.
Which means every tool that touches client financial data sits inside a requirement you do not get a pass on for being small. The accounting software, the payroll system, the receipt capture app, your email provider, cloud storage, the portal, and the shared drive folder you have been using since 2019 and have not thought about since.
The reasonable reading, and the unreasonable one
The Rule says reasonable steps and periodically. It does not say audit, and it does not require you to be a security professional. A deliberate choice, a contract, and a periodic look is the standard.
What it does rule out is the thing most small practices actually do, which is to accumulate tools without ever deciding anything, and then never look again.
The one-page vendor list
Here is the practical form of 314.4(f) for a practice with no compliance function. It is a list. One page. It is the single most useful artefact in this article and it takes an afternoon.
Step one: write down everything that touches client financial data. Be uncomfortably thorough. Most practices are surprised by the length of their own list, and the surprise is the point.
- Accounting software, and any second ledger you kept for one legacy client
- Payroll
- Receipt capture
- Your email provider — do not skip this one, it holds more than anything else
- Cloud storage, including personal accounts you have used for work
- The client portal, if you have one
- Your password manager
- Backup drives, including the one in a drawer
- Anywhere a client has ever sent you something — a form tool, a file transfer service, a messaging app
Step two: four columns against each one.
| Column | What goes in it |
|---|---|
| What data it holds | Client names, bank data, tax IDs, payroll data. Be specific |
| Their published security position | A SOC 2 report, ISO 27001, or simply a security page. Note what they publish and where. “Nothing published” is a legitimate entry and a useful one |
| Contract terms | Most business software terms include data protection commitments. Note that you checked, and where |
| Date you last looked | The whole of “periodically assessing” lives in this column |
That is the artefact. Review it once a year — the same week you renew your PTIN is as good a trigger as any — and put the date on it.
The real reason it is worth an actual afternoon rather than fifteen minutes: writing the list is how you find the tool you forgot you were using. The dormant Dropbox folder, the file transfer service you used once for a big engagement, the personal email account a client still sends things to. That is your genuine exposure, far more than whether your accounting software holds the right certification.
Form W-12, question 11
If you are a paid tax preparer there is a second obligation running alongside the FTC Rule, and it has a sharper edge because it attaches to you personally rather than to your firm.
Since 2023, renewing your PTIN on Form W-12 requires you to confirm at question 11 that you have a data security plan in place. It is an affirmative attestation on a signed form, with your PTIN behind it.
There is no small-firm carve-out on that question. The FTC exemption at 314.6 removes the requirement for certain things to be written in a prescribed form; it does not remove the underlying obligation to have a security programme, and the W-12 question does not distinguish by firm size at all.
Practically, this is the reason to do the work rather than to keep meaning to. Most of the Safeguards Rule is enforced at the level of the profession and the occasional enforcement action. The PTIN attestation is a thing you personally sign every year.
Writing the WISP, using the IRS template
The IRS publishes the accounting-specific version of all this, free, and it is considerably shorter than you are expecting.
| Publication | What it is | How to use it |
|---|---|---|
| IRS Publication 4557 | Safeguarding Taxpayer Data. The profession’s playbook for the requirements, including overseeing service providers | Read once, to know what the obligations are in plain language rather than regulatory text |
| IRS Publication 5708 | Creating a Written Information Security Plan. A sample WISP with the structure already built | This is the template. Start from it rather than from a blank page — that is what it is for |
The honest description of the job: download 5708, work through it in an afternoon, attach your vendor list from the section above, and review it once a year. That is a reasonable afternoon and it discharges the great majority of what is being asked of a solo practice.
Note the useful interaction with the exemption. Because 314.4(b)(1) is lifted for you, you are not obliged to produce the formal written risk assessment in the prescribed form. But writing something is still the easiest way to be able to answer the W-12 question honestly, and 5708 makes it a fill-in-the-blanks exercise rather than a drafting one.
The whole thing as an afternoon
In order, shortest first:
- Turn on full-disk encryption on every machine with client data. BitLocker on Windows, FileVault on macOS. Ten minutes, and it addresses the “at rest” half of 314.4(c)(3), which is the half people miss.
- Turn on MFA everywhere, starting with email. 314.4(c)(5).
- Write the vendor list. Everything that touches client data, four columns, dated. 314.4(f). This is the long part and it is where the surprises are.
- Download Publication 5708 and fill it in, attaching the vendor list.
- Delete what you do not need. Secure disposal is a requirement, and the old client files in a personal cloud account are a liability with no offsetting benefit.
- Diarise a review for the week you renew your PTIN.
None of that requires a consultant. The parts that would have required one — penetration testing, the formal risk assessment, the incident response plan — are precisely the four paragraphs the exemption removes.
What I am not certain about
Three limits on the above, stated plainly, because an article about compliance that pretends to more confidence than it has is worse than useless.
- I am not a lawyer and this is not advice. Everything above is cited to a paragraph number precisely so that you can check it rather than trust me. If your situation is unusual, or you have had an incident, get proper advice.
- “SOC 2 is required” is an industry norm, not a statute. You will see it claimed that vendor vetting under these rules is evidenced by a SOC 2 Type II report. The WISP obligation and the W-12 attestation are hard requirements. The idea that a particular certification is the required evidence is a security industry reading rather than something I could verify in IRS or FTC text. Treat a vendor with no certification as a question to ask, not an automatic failure.
- This is US-only. UK and EU practices are under a different regime entirely — UK GDPR and the ICO’s processor obligations. I did not verify those and none of the above transfers.
Where to read the primary sources
16 CFR 314.4 for the requirements and 314.6 for the exemption, both on eCFR. IRS Publication 4557 and Publication 5708, free at irs.gov. Form W-12 for the PTIN attestation.
314.6 in particular is worth ten seconds of your time. It is one sentence, and reading it is faster than reading anyone’s summary of it, including this one.
Disclosure
I build document-collection software for small accounting practices, which makes me a service provider of exactly the kind 314.4(f) is about. So it is fair to note that an article encouraging you to take vendor oversight seriously is not a disinterested one.
Apply the list above to me as rigorously as to anyone else. If a vendor cannot tell you plainly where your data sits, who can reach it and what happens when you leave, that is your answer, and it does not become a better answer because their marketing is good.