Short answer: The 2023 amendments to the FTC Safeguards Rule replaced vague "reasonable security" language with specific, checkable requirements — a named Qualified Individual, mandatory encryption, mandatory multi-factor authentication, a written incident response plan, and periodic reporting to leadership. If your dealership's compliance program hasn't been updated since before 2023, it almost certainly doesn't meet the current standard, even if it met the old one.
Why the update happened
The original Safeguards Rule (dating back to 2003) told financial institutions to maintain "reasonable" security measures — a standard that was easy to claim and hard to enforce. After a string of data breaches at auto dealerships and other non-bank financial institutions, the FTC rewrote the rule in 2023 to close that gap. The new version reads less like a suggestion and more like a checklist an examiner can actually score you against.
The specific things that changed
A Qualified Individual is now mandatory, by name. Before, "someone" was responsible for security in a general sense. Now the rule requires one specifically designated person accountable for the program — and that name needs to be documented, not just understood internally.
Encryption is no longer optional or vague. The old rule allowed for general "appropriate" safeguards. The updated rule specifically calls for encryption of customer information, both at rest and in transit — meaning your DMS, F&I platform, and email need to actually meet that bar, not just claim to be "secure."
Multi-factor authentication is now required, not recommended. Any system that touches customer financial data needs MFA. This is one of the most commonly missed requirements among independent dealers, because it's easy to assume a strong password is enough. It isn't, under the current rule.
A written incident response plan is now required, in advance. You need a documented plan for what happens during a breach — before one happens. Improvising a response after the fact, even a good one, doesn't satisfy this requirement.
Periodic reporting to leadership is now required. Even a single-owner dealership needs a documented, dated report on the state of its security program — not just an owner's general awareness that "things are handled."
The definition of who's covered got clearer, and broader. The amendments made explicit that dealerships extending credit, arranging leases, or facilitating financing — even through a third-party lender — fall under the rule's definition of "financial institution."
What this means if your program predates 2023
A lot of independent dealers have some version of a security policy sitting in a drawer from years ago — maybe drafted when they got their dealer license, maybe copied from a template. Under the amended rule, that document almost certainly falls short, because it wasn't built to satisfy requirements that didn't exist yet. Having something in writing was closer to sufficient under the old rule. It isn't anymore.
How to check where you stand today
The fastest way to see whether your current program meets the amended requirements — not the 2003 version — is a risk assessment built around the current rule. Sterling Safeguard's free assessment checks your dealership against the actual 2023 requirements and shows you exactly which ones are missing.