First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/FTC Safeguards Rule (GLBA) Readiness Assessment
AssessmentCompliance

FTC Safeguards Rule (GLBA) Readiness Assessment

The FTC Safeguards Rule (16 CFR Part 314, issued under the Gramm-Leach-Bliley Act) reaches the non-bank businesses the FTC calls financial institutions — auto dealers that arrange financing, mortgage brokers and lenders, finance companies, tax-preparation and accounting firms, collection agencies, credit counselors and investment advisers not registered with the SEC — and since its 2023 amendments it names the controls: a designated Qualified Individual, a written risk assessment, eight specific safeguards including multi-factor authentication and encryption, testing, training, service-provider oversight, a written incident response plan, an annual report to the board and, since 13 May 2024, notice to the FTC within 30 days when unencrypted information on 500 or more consumers is taken. This is a fixed-price, three-week readiness assessment that reviews each of those program elements against what your business actually has, maps the technical safeguards to the Microsoft 365 controls you already license — Microsoft Entra MFA and Conditional Access, Purview data inventory, DLP and sensitivity labels, encryption in transit and at rest including encrypted email, Intune, audit logging, retention and disposal — and hands you a gap report and roadmap, a written information security program (WISP) outline, a service-provider oversight checklist, an incident-response and FTC-notification procedure, and a board-report template. $3,950 fixed for one Microsoft 365 tenant and one information security program. We are Microsoft 365 engineers, not a law firm: whether the rule covers you and what a notice must say are your counsel's calls, and this engagement is built to hand them evidence. You keep the Qualified Individual designation, and nothing here certifies or guarantees compliance — no assessment from anyone can.

Timeline 3 weeksService owner Dan ApplebyMicrosoft 365Microsoft Entra IDMicrosoft Purview

What this engagement is

The Safeguards Rule used to ask for 'reasonable' safeguards and leave the rest to you. The amended rule, in force since June 2023, names them: a Qualified Individual who owns the program, a written risk assessment, eight specific safeguards in 16 CFR 314.4(c) — access controls, a data and systems inventory, encryption of customer information in transit over external networks and at rest, secure development practices, multi-factor authentication for anyone accessing any information system, secure disposal, change management, and logging of user activity — plus testing or continuous monitoring, staff training, oversight of service providers, a program that is kept current, a written incident response plan and an annual written report to your board or senior officer. In November 2023 the FTC added a notification duty that took effect on 13 May 2024: when unencrypted customer information on 500 or more consumers is acquired without authorization, the FTC is told as soon as possible and no later than 30 days after discovery. In June 2025 the FTC published FAQs for auto dealers that, among other things, make clear that a vendor you were required to use by your manufacturer is still your service provider to oversee. The businesses in scope are mostly 10-500 seat organizations with no security team — dealerships and dealer groups, mortgage and finance companies, tax and accounting firms, collection agencies, advisers — running Microsoft 365, with the customer information that matters living in a dealer management system, a tax or CRM platform and, more than anyone admits, in email, shared mailboxes, OneDrive and Teams. This assessment starts with coverage, because everything else depends on it: with your counsel's input we record why the business is (or is not) a financial institution under the rule's definition, roughly how many consumers' information you hold — the rule's 314.6 exceptions relieve institutions holding information on fewer than 5,000 consumers of the written risk assessment, the penetration-testing cadence, the written incident response plan and the annual report, but not of MFA, encryption or the other safeguards — and which systems hold customer information. Then we review all nine program elements by interview and by document: who the Qualified Individual is and whether the designation is written down, whether a risk assessment exists and says what the rule wants it to say, what training has happened, which vendors have access and what their contracts require, what the incident plan says, and when the board last received a report. The technical safeguards get the deep treatment, read-only, in your tenant: MFA coverage for every identity including administrators, shared mailboxes and service accounts, Conditional Access and legacy-authentication exposure, privileged roles, Purview's data classification against the sensitive information types that define this data — Social Security numbers, bank account and card numbers, driver's license numbers — DLP and sensitivity labels, encryption in transit and at rest including Purview Message Encryption for mail to consumers, BitLocker and device compliance through Intune, Purview audit logging and its retention period, retention and deletion policies against the rule's disposal expectation, external sharing and guest access, and what Defender is watching. Each of the eight safeguards ends up in a control map that names the setting, the workload and the evidence — the exhibit an examiner, a carrier or a manufacturer audit actually asks for. What you receive is built to be used, not filed. The gap report ties every finding to the paragraph of 314.4 it serves and ranks it by exposure and effort. The roadmap names the setting, the workload and the owner for each item and separates what your own staff can do next week from what needs an engagement — commonly MFA for every user, DLP policies for the data types the rule protects, encrypted email, security awareness training and phishing simulation for the training element, and managed detection and response where the Qualified Individual chooses continuous monitoring over annual penetration testing. The WISP outline gives your program the structure the rule expects, with the client-specific content marked for you and counsel to complete. The service-provider oversight checklist and vendor register turn 314.4(f) into a list with names on it. The incident-response and FTC-notification procedure puts the 500-consumer, 30-day trigger and the contents of the notice into a page your team can follow at 2 a.m. The board-report template covers what 314.4(i) says the annual report must address. When the assessment is done, the Compliance Evidence and Audit Readiness Retainer can keep the evidence current month by month, and the Virtual CISO retainer can support the person you designate as Qualified Individual. Three things we say plainly because the market does not. We are Microsoft 365 engineers, not a law firm, a CPA firm or a certification body: the coverage determination, the reading of any state breach law and the wording of a notice belong with your counsel, and our regulatory summaries are our engineering reading of the public rule text and the FTC's business guidance as of September 2026. The Qualified Individual is yours — the rule lets a service provider's employee hold the role, but only if you retain responsibility for compliance, designate a senior member of your own staff to direct and oversee that person, and require the provider to keep its own information security program; this engagement does not take the designation, and it says so in the report. And nothing certifies FTC Safeguards compliance — there is no certificate, and a vendor selling one is telling you something about themselves. What exists is a documented program with evidence behind it, and that is what this assessment produces for the Microsoft 365 part of your business.

Success criteria

01The coverage position is documented: the business's own determination, made with its counsel, of financial-institution status under 16 CFR 314.2, the approximate number of consumers whose information it holds, and whether the 314.6 exceptions apply — recorded as a decision with its reasoning, not assumed.
02Each of the nine program elements has a written finding — in place, partially in place, or absent — tied to the paragraph of 314.4 it serves and to the evidence (or the absence of evidence) behind it.
03Each of the eight 314.4(c) safeguards is mapped to the Microsoft 365 controls as configured on the assessment date, naming the setting, the workload and the evidence, with the gap between the setting and the rule's wording stated.
04MFA status is stated for every identity in the tenant — users, administrators, shared mailboxes and service accounts — and every non-Microsoft system holding customer information is listed with its MFA status as you report it and marked for the Qualified Individual's attention where it is off.
05Every service provider with access to customer information is in a register with an oversight status: contract security clause present or absent, security evidence held or not, and whether the vendor was manufacturer-mandated.
06The client holds a WISP outline, a service-provider oversight checklist, an incident-response and FTC-notification procedure, and a board-report template, each mapped to its rule paragraph and marked where counsel's input is needed.
07The remediation roadmap is ranked by exposure and effort, and each item names the setting, the workload, the owner and whether it is client-executable or engagement-scale.
08The owner or senior leadership and the Qualified Individual have received the readout, and the report states in writing what was assessed, what was not, and why.

What you receive

Coverage and scope memo — the business's working determination of financial-institution status under 314.2 (recorded with counsel's input, not made by us), the consumer-count band, the 314.6 exception position, the legal entities and locations sharing the tenant and the program, and the systems holding customer information.
Nine-element gap report — Qualified Individual, written risk assessment, the eight safeguards, testing and monitoring, training, service-provider oversight, program updates, incident response plan and annual board report, each with a finding, a 314.4 citation, the evidence reviewed and the exposure rating.
Microsoft 365 control map — for each 314.4(c) safeguard, the Entra ID, Purview, Exchange Online, SharePoint and OneDrive, Teams, Intune and Defender settings as found, with the evidence exported: MFA and Conditional Access coverage, privileged roles, data classification results for the sensitive information types the rule protects, DLP and label coverage, transport and at-rest encryption position, encrypted-email configuration, device encryption and compliance, audit-log status and retention period, retention and deletion policies, external sharing and guest access.
Evidence index — every exhibit filed in your own SharePoint with the control it supports, the date captured and the source, so the file outlives the engagement and the report.
Prioritized remediation roadmap — each item tied to a finding and a citation, with the setting, workload and owner named, an effort class, and a client-executable or engagement-scale marker.
Written information security program (WISP) outline — the document structure the rule expects, section by section, with the Microsoft 365 findings pre-filled where they belong and the business-specific and legal content marked for you and counsel to complete.
Service-provider oversight checklist and vendor register — every vendor with access to customer information, including manufacturer-mandated platforms, with what to require by contract, what evidence to ask for and how often to reassess; Microsoft's own published audit reports and Product Terms noted for the Microsoft side.
Incident-response and FTC-notification procedure — roles, decision points, the 500-consumer and 30-day trigger, what the FTC notice must contain, where state breach laws enter the picture as a question for counsel, and the post-incident review, drafted as a procedure your team can follow and counsel can adapt.
Annual board-report template — the status of the program and the material matters 314.4(i) expects the report to address, laid out so the Qualified Individual can complete it in an afternoon.
Readout session for the owner or senior leadership and the Qualified Individual, delivered live with the written report and roadmap.

How the work unfolds

Week 1, days 1-2 — Kickoff, coverage and scope

We record your coverage position with counsel's input, the consumer-count band that decides the 314.6 exceptions, the entities and locations that share the tenant and the program, and the systems that hold customer information. Read-oriented, time-bound access to Microsoft 365, Entra ID, Purview, Intune and Defender is granted for the engagement window, and the documents that exist — WISP, risk assessment, incident plan, training records, vendor contracts, last board report — are collected. Absence is a finding, not a blocker.

Week 1, days 2-5 — Program-element interviews

Structured interviews with the Qualified Individual or the person you intend to designate, the owner or controller, and whoever runs IT: how the program is run today, who decides, what has been written down, what training has happened, which vendors touch customer information and under what contract, what happens when something goes wrong. Each of the nine elements gets a draft finding.

Weeks 1-2 — Microsoft 365 control mapping

Read-only review of the tenant against the eight 314.4(c) safeguards: MFA and Conditional Access for every identity, legacy authentication, privileged roles, Purview data classification for Social Security, bank account, card and driver's license numbers across Exchange, SharePoint, OneDrive and Teams, DLP and sensitivity labels, encryption in transit and at rest and encrypted email, BitLocker and device compliance in Intune, Purview audit status and retention, retention and deletion policies, external sharing and guest access, Defender coverage. Evidence is exported to your SharePoint as it is gathered.

Week 2 — Service-provider register and oversight

Every vendor with access to customer information — dealer management system, CRM, tax or practice software, lender and finance portals, e-signature, document storage, payroll, your IT provider, and any platform your manufacturer requires — is registered with the contract security language you supply, the evidence you hold, and a reassessment cadence. Microsoft's side is documented from its published Product Terms and audit reports.

Weeks 2-3 — Findings, roadmap and program documents

Findings are validated with your stakeholders, ranked by exposure and effort, and assembled into the gap report and roadmap. The WISP outline, the service-provider oversight checklist, the incident-response and FTC-notification procedure and the board-report template are drafted from the findings, with counsel's items marked.

Week 3 — Readout and handover

The report, roadmap and program documents are presented to the owner or senior leadership and the Qualified Individual. We walk the priority items, agree what your own staff execute from the roadmap and what, if anything, is scoped as separate fixed-price work, and remove our access.

Prerequisites

An active Microsoft 365 tenant — Business Premium, E3, E5 or a mix. We verify what your plan actually includes rather than assume it; a control your licensing does not carry is reported as a licensing gap, not a configuration failure.
A named Qualified Individual, or the person you intend to designate, available for interviews and the readout — and the owner, controller or senior officer who will receive the annual report.
Your working position on coverage: whether you regard the business as a financial institution under the rule. We record it and the reasoning; the determination itself is yours and your counsel's.
A rough count of consumers whose information you hold — customers, applicants and former customers — because the rule's 314.6 exceptions turn on whether that number is below 5,000.
A list of the systems that hold customer information — dealer management system, CRM, tax or practice-management software, lender and finance portals, e-signature, document storage, payroll — with the vendor, who has access, and whether MFA is enabled as far as you know.
Existing documents where they exist: written information security program, risk assessment, incident response plan, training records, vendor contracts or security addenda, and the last report to the board. Their absence is itself a finding.
Administrative access sufficient for read-oriented review of Microsoft 365, Entra ID, Purview, Intune and Defender for the engagement window, granted through a time-bound, least-privilege relationship you approve.
Availability of your IT contact for configuration questions in weeks 1-2 and of your stakeholders for findings validation in week 3.
The fixed fee covers one Microsoft 365 tenant and one information security program; a group with several locations or affiliated entities sharing both is one engagement. Separate tenants, or separate programs for separately regulated entities, are scoped and quoted in writing before anything starts.

Who does what

IT Partner

  • Record the coverage position and the scope with the reasoning written down, and state in the report what was and was not assessed.
  • Review all nine program elements by interview and by document, and document a finding for each with its 314.4 citation and evidence.
  • Review the Microsoft 365 tenant read-only against the eight 314.4(c) safeguards and export the evidence to your SharePoint as it is gathered.
  • Build the service-provider register and oversight checklist from the vendor list and contracts you supply.
  • Rank the gaps by exposure and effort and produce the roadmap with settings, workloads and owners named.
  • Draft the WISP outline, the incident-response and FTC-notification procedure and the board-report template from the findings, marking every item that needs counsel's or the business's input.
  • Deliver the readout in plain language, answer the Qualified Individual's platform questions, and remove our access at the end.

Your team

  • Own the determination of whether the rule applies to the business, made with counsel, and the reading of any state breach-notification law.
  • Designate and retain the Qualified Individual; where a service provider's employee holds the role, retain responsibility for compliance, designate a senior member of your staff to direct and oversee that person, and require the provider to maintain its own information security program.
  • Provide access, stakeholders, the vendor list, contracts and existing documents on the agreed schedule.
  • Report the MFA and security status of non-Microsoft systems as you understand it; we list them, we do not test them.
  • Validate draft findings for factual accuracy within the review window.
  • Decide remediation priorities and own the risk acceptance for gaps deliberately left open.
  • Complete the WISP, the procedure and the board report from the outlines with counsel's input, execute the roadmap internally or scope follow-on work separately, and maintain the program over time — a point-in-time report ages as the tenant changes.

What's not included

Acting as your Qualified Individual. The designation and the legal responsibility stay with you; this engagement assesses the program, it does not run it. The rule permits a service provider's employee to hold the role under conditions the client's responsibilities above spell out — if you want ongoing support for the person you designate, that is the Virtual CISO retainer, scoped separately.
Legal advice of any kind: whether the rule covers your business, how the 314.6 exceptions apply to you, whether an event is a notification event, what a notice to the FTC or to consumers must say, state breach-notification and privacy laws, the FTC Privacy Rule and its notices, or representation in any inquiry. The report is written so counsel can use it.
Attestations, certifications, letters of compliance or any statement that your business is 'FTC Safeguards compliant' — no such certificate exists, no engagement from anyone can honestly issue one, and no deliverable here will use the phrase except to say this.
Penetration testing and vulnerability scanning. The rule's testing element gives the Qualified Individual a choice between continuous monitoring and an annual penetration test with vulnerability assessments at least every six months; we document which path you are on and what evidence it needs, and we do not perform the tests.
Remediation implementation — every roadmap item is executable as separately quoted, fixed-price work: MFA for all users, Conditional Access policies, DLP policies, encrypted email, Intune device management, Purview retention and lifecycle management and sensitivity labeling.
Review of non-Microsoft systems — the dealer management system, CRM, tax or practice software, lender and finance portals, e-signature and document platforms, and any manufacturer-mandated tool. They are listed in the service-provider register with the MFA and security status you report, as items for your oversight; their configuration is not assessed.
Writing the full written information security program, the risk assessment or the policies. The WISP outline gives the structure and pre-fills the Microsoft 365 findings; completing it with the business-specific and legal content is yours and counsel's, with the vCISO retainer available if you want help doing it.
Delivery of staff training — the training element is a finding and a roadmap item here; the recurring program is Managed Security Awareness Training and Phishing Simulation.
Ongoing monitoring, detection and response — where the Qualified Individual chooses continuous monitoring, Managed Detection and Response is a separate recurring service; this assessment documents what the choice requires.
Ongoing evidence maintenance and periodic re-assessment — the Compliance Evidence and Audit Readiness Retainer keeps the control evidence current month by month; a re-assessment can be scheduled as its own engagement.
Microsoft licensing purchases, including any plan or add-on the report identifies as genuinely required — for example longer audit-log retention. Microsoft's subscription and metered charges are yours.
Physical safeguards beyond what tenant and device configuration evidences — paper deal jackets, key boxes, office access and media destruction are in the WISP outline as headings for you to complete, not assessed on site.

Limitations & technical notes

!This page and the engagement contain no legal advice. The regulatory summaries are our engineering reading of the public text of 16 CFR Part 314 and the FTC's business guidance as of September 2026; the rule, its thresholds and the FTC's interpretations change, and your counsel decides what applies to you. Confirm any date or threshold against the FTC's current text before relying on it.
!There is no 'FTC Safeguards certification'. The FTC recognizes no certifying body and issues no certificate; this engagement produces a documented program with evidence behind it, which is what actually exists.
!The coverage determination is yours and your counsel's. We record it and the reasoning; if your position changes, the findings still stand as a description of your Microsoft 365 controls, but their regulatory weight is for counsel to reassess.
!This is a point-in-time assessment. Configuration drift, new workloads, licensing changes and staff turnover all age the findings; the report is dated and says so.
!Findings depend on the access and information provided. Systems outside the tenant, undisclosed data locations and shadow IT are outside what this assessment can see, and non-Microsoft systems are listed on the strength of what you report about them.
!A well-configured Microsoft 365 tenant is necessary but not sufficient. The Qualified Individual, the risk assessment, training, vendor oversight, the incident plan and the board report are organizational duties that no platform setting discharges, and most of the customer information the rule protects also lives in systems we do not assess.
!Available controls vary by licensing. Microsoft 365 Business Premium already carries Entra ID P1 for Conditional Access, Intune and Defender for Business; longer audit-log retention, privileged identity management and access reviews depend on higher plans or add-ons. The report distinguishes gaps fixable by configuration from gaps that genuinely require a licensing change, and will not recommend an upgrade a configuration change can cover.
!The engagement reviews configuration and evidence; it does not read, copy or export customer records, and customer information stays in your tenant and your systems.
!$3,950 covers one Microsoft 365 tenant and one information security program. Separate tenants, or separately regulated entities that need separate programs, receive a fixed written quote before work starts.

Frequently asked questions

Does the FTC Safeguards Rule apply to our business?

If you are significantly engaged in providing financial products or services to consumers and no other federal regulator has enforcement authority over you, the FTC's reading is that you are a financial institution under its rule. The FTC's own examples include mortgage lenders and brokers, payday lenders, finance companies, account servicers, check cashers, wire transferors, collection agencies, credit counselors and other financial advisers, tax-preparation firms, non-federally insured credit unions, investment advisers not required to register with the SEC, and — through their financing activity — automobile dealers. That is our reading of the rule's definitions and the FTC's guidance, not a legal opinion; the determination is yours and your counsel's, and the first deliverable records it with its reasoning.

What does the rule actually require?

Nine things, as we read 16 CFR 314.4: designate a Qualified Individual to own the program; base the program on a written risk assessment; implement eight named safeguards — access controls, a data and systems inventory, encryption in transit and at rest, secure development practices for in-house applications, multi-factor authentication, secure disposal, change management, and logging and monitoring of user activity; test or continuously monitor; train staff; oversee service providers; keep the program current; maintain a written incident response plan; and report in writing to the board or a senior officer at least annually. Since 13 May 2024 there is a tenth duty: notify the FTC within 30 days of discovering that unencrypted customer information on 500 or more consumers was acquired without authorization.

We hold information on fewer than 5,000 consumers. Are we exempt?

Partly, and not from the parts that bite. As we read 314.6, an institution holding customer information on fewer than 5,000 consumers is relieved of the written risk assessment, the penetration-testing and vulnerability-assessment cadence, the written incident response plan and the annual board report. It still needs a Qualified Individual, a risk assessment on which the program is based, all eight safeguards including MFA and encryption, training, service-provider oversight and the FTC notification duty. Counting is also less obvious than it sounds — applicants and former customers count, and a dealership that has been financing cars for a decade usually crosses the line. We record the band you are in and counsel confirms the position.

Does the rule really require MFA on everything — even the dealer management system?

As written, 314.4(c)(5) requires multi-factor authentication for any individual accessing any information system, unless your Qualified Individual approves in writing reasonably equivalent or more secure access controls. That reaches the DMS, the CRM, lender portals, remote access and email alike. In Microsoft 365 we verify MFA and Conditional Access coverage for every identity — users, administrators, shared mailboxes, service accounts — and whether legacy authentication is still letting passwords through the back door. For the non-Microsoft systems we list what you report and flag every 'off' for the Qualified Individual's attention; where a vendor genuinely cannot do MFA, the written exception is theirs to approve and document, and we say so.

We are on Microsoft 365. Does that make us compliant?

No — but it gives you most of the technical safeguards without buying anything. Microsoft 365 Business Premium, for example, already carries Conditional Access for MFA, Purview data classification and DLP, service-side encryption at rest and TLS in transit, encrypted email, Intune for device encryption and compliance, retention policies for disposal, audit logging and Defender for Business. Whether those controls are switched on, cover everyone and are evidenced is the question, and default settings are tuned for collaboration, not for 314.4(c). Measuring that gap, setting by setting, is what the control map does. The organizational elements — Qualified Individual, risk assessment, training, vendor oversight, incident plan, board report — no platform can do for you.

What is the FTC notification requirement?

Since 13 May 2024, as we read 314.4(j), a notification event — unencrypted customer information on at least 500 consumers acquired without authorization — must be reported to the FTC as soon as possible and no later than 30 days after discovery, using the FTC's reporting form. The notice covers who you are, the types of information involved, the date or date range if you can determine it, the number of consumers affected and a general description of what happened. Information counts as unencrypted if the encryption key was also taken. This is separate from the state breach-notification laws that govern notice to the consumers themselves, which is where counsel comes in. Our procedure puts the trigger, the decision points and the contents on one page; the decision to file is counsel's.

Can you be our Qualified Individual?

Not in this engagement, and we think you should be careful about anyone who offers it as a line item. The rule allows the Qualified Individual to be employed by a service provider, but only if you retain responsibility for compliance, designate a senior member of your own staff to direct and oversee that person, and require the provider to maintain its own information security program. The designation, in other words, never really leaves your building. What we offer is support for the person you designate — the Virtual CISO retainer gives them a security program, policy governance and reporting cadence — while the role and the accountability stay with you.

Is this a penetration test?

No. The rule's testing element, 314.4(d), gives the Qualified Individual a choice: continuous monitoring, or an annual penetration test plus vulnerability assessments at least every six months and whenever the environment materially changes. This assessment documents which path you are on and what evidence it needs. For many Microsoft 365 organizations the practical answer is continuous monitoring — Defender's vulnerability management and a managed detection service watching the tenant and endpoints — and we say when that is the better fit. Whether it satisfies the rule for you is the Qualified Individual's documented decision; a penetration test, if you choose that path, is separate work from a testing provider.

What is a WISP and do you write it for us?

A written information security program is the document the rule expects your program to live in — who the Qualified Individual is, what the risk assessment found, what safeguards you run, how you test, train, oversee vendors, respond to incidents and report to the board. We deliver the outline: the structure section by section, with the Microsoft 365 findings already in the places they belong and the business-specific and legal content clearly marked. You and counsel complete it, or the vCISO retainer helps you do so. Tax and accounting firms should note that the IRS separately expects paid preparers to maintain a written information security plan and points at the same Safeguards Rule; the same document does double duty.

We are a dealership. What about the DMS, the OEM tools and the lender portals?

They are where most of your customer information actually lives, and the rule treats every one of those vendors as a service provider you must select carefully, bind by contract and periodically reassess. The FTC's June 2025 FAQs for auto dealers make the point that a platform your manufacturer requires you to use is still your service provider to oversee — being mandated is not an exemption. We do not assess those systems' configuration; we put every one of them in the vendor register with the MFA and security status you report, the contract language you hold, and what to ask for, so your oversight has names and dates on it. The Microsoft 365 side — where deal documents get emailed, scanned to OneDrive and shared in Teams — we assess in depth.

We are a tax or accounting firm. Anything different for us?

The platform mechanics are the same, but the data is denser — Social Security numbers, bank account numbers and full returns arrive by email and portal every day, and the seasonal rhythm means staff, devices and shared mailboxes change fast. Purview's data classification usually shows returns and W-2s sitting in mailboxes and OneDrive well beyond the season, which is exactly what the disposal safeguard is about, and encrypted email for outbound client documents is the single most common gap. The IRS's own expectations for tax professionals point at the same rule, so the WISP outline serves both.

What does the remediation roadmap look like, and can you do the work?

A ranked list, not a lecture: each item names the finding it closes, the 314.4 paragraph it serves, the setting and workload, an effort class, and whether your own team can do it from the report. Quick wins — MFA gaps, legacy authentication, anonymous-link settings, audit logging — are separated from projects such as a DLP rollout for the data types the rule protects, encrypted email, or retention design. Yes, we can execute any of it as separately quoted, fixed-price work, and deliberately not as part of the assessment, so the findings stay honest and you keep the choice of who fixes what. Many clients do the quick wins themselves, which we consider a good outcome.

How much of our staff's time does this take?

A handful of hours. The technical review is read-only work in admin portals — no configuration changes, no agents, no downtime, no access to customer records. The human load is the interviews in week one (the Qualified Individual or the person you intend to designate, the owner or controller, whoever runs IT), assembling the vendor list and any existing documents, a validation pass in week three and the readout. If your IT is outsourced, your provider joins the technical questions; they are usually a vendor in the register too.

Why is the price fixed at $3,950, and what does it cover?

Because the scope is fixed: one Microsoft 365 tenant, one information security program, the nine-element review, the eight-safeguard control map, the program documents and three weeks. A dealer group or firm with several locations or affiliated entities sharing one tenant and one program is one engagement. Separate tenants, or separately regulated entities that need their own programs, are quoted in writing before anything starts. The price is quoted in writing before work begins and you pay after you approve delivery; if the scoping call shows the fit is wrong, we say so then, not mid-project.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$3,950 per project
3 weeks
Book the Safeguards assessment