Who the rule covers
The rule applies to non-bank "financial institutions," and the FTC defines that broadly. Its own examples include:
- Automobile dealerships that lease vehicles or arrange financing
- Tax preparers and accountants who prepare income tax returns
- Mortgage brokers and lenders
- Payday lenders and finance companies
- Collection agencies
- Check cashers and wire transfer businesses
- Credit counselors and some financial advisors
- Real estate settlement services
What the rule says
Section 314.4(d)(2) of the rule (16 CFR Part 314) says that unless you have continuous monitoring in place, you must conduct "annual penetration testing" of your information systems and vulnerability assessments "at least every six months," and again whenever your operations change in a material way.
The rule defines a penetration test as an attempt "to circumvent or defeat the security features of an information system" from outside or inside your systems. A vulnerability scan on its own does not meet that definition. You need both.
The small business exception
If you keep customer information on fewer than 5,000 consumers, section 314.6 exempts you from the specific testing schedule above. You still have to protect customer information and regularly test your safeguards, and many small firms run the same tests anyway because an insurer, a lender, or a software partner asks for them.
Both requirements, one checkout
- Automated external penetration test, from $1,995 for a 30-day window (1 external IP or domain). It starts the same day, safely attempts real exploitation, includes retests after you fix things, and ends with a report you can hand to an examiner.
- Automated internal penetration test, from $2,995 for a 30-day window (up to 25 internal hosts), for your office network.
- External vulnerability scanning, from $595 a year (10 IPs), run on a schedule so the every-six-months assessment is covered all year.
When you need an engineer
If your examiner, insurer, or attorney asks for a test led by a named engineer, our managed penetration testing team does that.
This page is general information, not legal advice. Ask your attorney or compliance advisor how the rule applies to your business.
See pen test pricing and buy online · Talk to a specialist
Related: SOC 2, HIPAA, ISO 27001, PCI DSS 11.4, penetration test cost
