Keyfactor Tech Days 2027 – Be Part of The Trust Security Conference in San Diego Register now!

GLBA Safeguards Rule:

Cryptography for Non-Bank Financial Institutions

Updated: August 24, 2026
RegionUnited States non-banking financial institutions, with parallel requirements or depository institutions
ApplicabilityFinancial Institutions under FTC jurisdiction: non-bank lenders, mortgage brokers, tax preparers, auto dealers offering financing, and other businesses meeting GLBA’s “financial activity” test Qualified Individual: the designated person responsible for overseeing and implementing the information security program Service Providers: contractually required to maintain appropriate safeguards for the customer information they handle
Relevant sections16 CFR §314.4(c)(3): Encryption of customer information at rest and in transit §314.4(a): Designation of a Qualified Individual §314.2(m) / §314.5: Breach notification to the FTC for events affecting 500 or more consumers

Overview

The FTC’s Safeguards Rule implements GLBA Section 501(b) for financial institutions under FTC jurisdiction. The Final Rule updating the Safeguards Rule took effect June 9, 2023, replacing a principles-based approach with nine prescriptive program elements, one of which is an explicit encryption mandate. A further amendment adding breach notification to the FTC took effect May 13, 2024.

Section 314.4(c)(3) requires encryption of customer information both at rest and in transit. Where encryption is not feasible, the Qualified Individual must approve, in writing, effective alternative controls. This is one of the few Safeguards Rule provisions with almost no interpretive flexibility: the default expectation is encryption, and any departure from it must be documented and justified.

Why it matters 

Civil penalties reach $100,000 per violation for the institution, and officers and directors can be personally fined up to $10,000. The 2024 breach-notification amendment ties directly to encryption status: a “notification event” is defined as the unauthorized acquisition of unencrypted customer information involving 500 or more consumers, reportable to the FTC within 30 days.

That definition means encryption status is not just a security control, it is the determining factor in whether an incident triggers a federal reporting obligation at all. An organization that can demonstrate its exposed data was encrypted may have a materially different disclosure posture than one that cannot.

How this maps to cryptography 

GLBA Safeguards Rule addresses cryptography through several interlocking control areas. The key areas with direct cryptographic implications are:

SectionFunctionWhat it saysSupporting Products
§314.4(c)(3)Encryption of Customer InformationEncryption of customer information at rest and in transit, with Qualified-Individual-approved and documented compensating controls where encryption is infeasible.EJBCA
§314.4(c)(5)Multi-Factor AuthenticationMFA for anyone accessing customer information systems, with certificate-based options available for stronger assurance.EJBCA
§314.4(a)Qualified Individual OversightCentralized reporting on cryptographic control status feeding the Qualified Individual’s oversight responsibilities and required annual report to the board.Keyfactor Command
§314.4(f)Vendor and Service Provider AssuranceCryptographic due-diligence evidence supporting service-provider contract requirements for organizations handling customer information.AgileSec
§314.2(m) / §314.5Breach Notification DeterminationA documented process for determining whether exposed customer information was encrypted, which directly determines the 30-day FTC notification obligation.EJBCA
§314.4(c)(4)Secure Application DevelopmentCode-signing and secure development practices for in-house applications that access or transmit customer information.SignServer

Audit readiness

Assessments and examinations, whether self-conducted, performed by a regulator, or reviewed by an independent assessor, focus on demonstrated evidence rather than policy statements alone. Key areas that examiners and assessors commonly probe:

  • Encryption Coverage Evidence:  Can the institution demonstrate encryption of customer information at rest and in transit across its systems?
  • Qualified-Individual-Approved Compensating Controls:  Where encryption is not used, is there a written, QI-approved justification and description of the alternative control?
  • MFA Deployment Evidence:  Is MFA enforced for all access to systems containing customer information?
  • Service Provider Contract Language:  Do contracts with service providers require appropriate safeguards, including encryption, for customer information they handle?
  • Breach Notification Readiness:  Is there a documented process for determining, within the required timeframe, whether an incident involved unencrypted customer information?
  • Annual Board Reporting Package:  Does the Qualified Individual’s required report to the board include the status of encryption and other technical safeguards?