Penetration testing for auto dealerships under the FTC Safeguards Rule

If your dealership arranges financing or leases vehicles, the FTC treats you as a financial institution. That puts you under the Safeguards Rule, which asks for a penetration test every year and a vulnerability assessment every six months. Here is what that means for a dealership, and how to get it done this week without a sales call.

Penetration testing for auto dealerships under the FTC Safeguards Rule

Why a dealership counts as a financial institution

The FTC's own guidance for dealers says that dealers who finance, or help arrange financing for, vehicles for consumers are financial institutions under the Safeguards Rule. Dealers that lease vehicles for longer than 90 days are covered as well. It does not matter that a bank or a captive lender ends up holding the loan. If your finance office collects the application, you hold the customer's information, and the rule applies to you.

What you are protecting

A single deal jacket holds almost everything a criminal needs: a credit application, a Social Security number, a driver's license copy, income and employment details, and insurance information. Multiply that by every customer still in your systems. The rule covers that information wherever it sits, including your website and lead forms, your showroom and back office network, your Wi-Fi, and the remote access your staff and vendors use.

What the rule asks for

Section 314.4(d)(2) of the rule (16 CFR Part 314) says that unless you have continuous monitoring in place, you must conduct "annual penetration testing" of your information systems and vulnerability assessments "at least every six months," and again whenever your operations change in a material way.

The rule defines a penetration test as an attempt "to circumvent or defeat the security features of an information system" from outside or inside your systems. A vulnerability scan on its own does not meet that definition. You need both.

What about your DMS and CRM vendors

The FTC's dealer guidance treats a vendor as a service provider when it receives, maintains, processes, or can access your customer information. You are expected to require those vendors to keep safeguards in place and to check on them from time to time. Ask each vendor for its most recent penetration test summary. Their test covers their platform. It does not cover your own network, your website, your Wi-Fi, or the computers in your finance office. Those are yours to test.

The small dealer exception

If you keep customer information on fewer than 5,000 consumers, section 314.6 exempts you from the fixed testing schedule above. The count is the number of consumers whose information you keep, so past customers still in your systems count too. You still have to protect customer information and regularly test your safeguards, and many smaller stores run the same tests anyway because an insurer or a lender asks for them.

Why dealers are testing now

Since 2024 the rule also requires you to notify the FTC within 30 days of discovering a security event that involves the unencrypted information of at least 500 consumers. A test that finds the open door first is far cheaper than that notice.

Both requirements, one checkout

  • Automated external penetration test, from $1,995 for a 30-day window (1 external IP or domain). You set the scope, it starts in minutes, it safely attempts real exploitation, it includes retests after you fix things, and it ends with a report you can hand to an examiner, an insurer, or your attorney.
  • Automated internal penetration test, from $2,995 for a 30-day window (up to 25 internal hosts), for the showroom, service, and finance office network.
  • External vulnerability scanning, from $595 a year (10 IPs), run on a schedule so the every-six-months assessment is covered all year.
  • Dealer groups with several stores: the Standard external test covers 10 external IPs or domains for $3,495, and annual programs start at $5,995 a year.

When you need an engineer

If your examiner, insurer, or attorney asks for a test led by a named engineer, our managed penetration testing team does that.

This page is general information, not legal advice. Ask your attorney or compliance advisor how the rule applies to your business.

Will your auditor accept it? See what is in the report.

See pen test pricing and buy online · Talk to a specialist

Related: FTC Safeguards Rule overview, tax and accounting firms, mortgage brokers and lenders, cyber insurance, penetration test cost

Ready when you are

Ready to get your pen test done this week?

Automated penetration testing from Clone Systems starts at $1,995 for an external test and $2,995 for an internal test. Buy it online, start in minutes, and retest for free within your 30-day window.