The rules that apply to you, checked.

Every rule we track for the industries we serve, in plain English: what it asks of your IT, the dates that matter, where it stands today and a link to the regulator’s own words.

Last checked

Every rule we track

Pick your industry. Each entry says what the rule asks of your IT, the dates that matter and where it stands, with a link to the source.

Showing all 16 rules.

  • SEC Regulation S-P

    Securities and Exchange Commission

    Status: In force

    Keep a written incident response program, notify affected clients no later than 30 days after you learn of a breach, and oversee your service providers so they tell you within 72 hours.

    1. Amendments took effect
    2. Larger firms must comply (advisers: $1.5 billion or more)
    3. Smaller firms must comply
    4. Last checked

    Applies to Investment advisers registered with the SEC, broker-dealers, investment companies and transfer agents

    • A written incident response program that detects, contains and recovers from unauthorized access to customer information.
    • Notices to affected clients that say what happened and how they can protect themselves.
    • Written policies for due diligence on, and monitoring of, every service provider that handles client data.
    • Written records showing you follow the safeguards and disposal rules.

    Sources: SEC compliance guide, SEC final rule page

  • SEC cybersecurity rule for advisers

    Securities and Exchange Commission

    Status: Withdrawn

    This 2022 proposal will not become a rule; the SEC said it would propose again if it returns to the subject.

    1. Proposed
    2. Withdrawn

    Applies to Investment advisers and funds

    • For registered advisers, Regulation S-P is where the SEC’s incident response and breach notice duties now live.

    Source: Federal Register withdrawal notice

  • FTC Safeguards Rule

    Federal Trade Commission

    Status: In force

    Run a written security program under a named Qualified Individual, with multi-factor authentication, encryption and oversight of your vendors, and report a breach of 500 or more people’s unencrypted data to the FTC within 30 days.

    1. Updated requirements took effect
    2. FTC breach notice took effect
    3. Last checked

    Applies to Financial firms the FTC oversees, including tax preparation firms, mortgage brokers and investment advisers not required to register with the SEC

    • A Qualified Individual who runs the program and reports on it in writing at least once a year.
    • A written risk assessment, multi-factor authentication for anyone who reaches customer information, and encryption on your systems and in transit.
    • Continuous monitoring, or a yearly penetration test and vulnerability scans every six months.
    • A written incident response plan, and oversight of your service providers.
    • Firms with information on fewer than 5,000 consumers are exempt from a few parts, including the written risk assessment and the written incident response plan.

    Sources: FTC guide to the Safeguards Rule, FTC, May 14, 2024, Federal Register, 16 CFR 314 (2021)

  • IRS written information security plan

    Internal Revenue Service

    Status: In force

    Create and keep a written information security plan to protect taxpayer data, and acknowledge that duty each year when you renew your PTIN.

    1. IRS reminder, IR-2026-92
    2. Last checked
    3. PTIN renewals open
    4. Every PTIN expires

    Applies to Paid tax return preparers and their firms

    • IRS Publication 5708 is the IRS’s own template for the plan.
    • Line 11 of Form W-12 asks you to acknowledge the duty when you apply for or renew a PTIN.
    • After a data theft, the IRS asks tax pros to contact their IRS Stakeholder Liaison.

    Sources: IRS news release IR-2026-92, Form W-12 instructions, line 11, IRS Publication 5708, IRS PTIN renewal FAQ

  • HIPAA Security Rule

    Department of Health and Human Services

    Status: In force

    Run an accurate, thorough risk analysis, put safeguards in place that answer it, and have a business associate agreement with every vendor that handles your electronic patient records.

    1. Published. Stays in force while HHS’s update is pending.

    Applies to Medical and dental practices, health plans, clearinghouses and their business associates. HHS names managed service providers, and CPA firms and attorneys whose work involves patient information, as business associates.

    • An accurate and thorough risk analysis, and risk management that answers it.
    • A written business associate agreement before any vendor creates, receives, keeps or sends electronic patient records for you.
    • In August 2025 HHS settled with a New York CPA firm for $175,000 after ransomware, finding no thorough risk analysis. It was the 10th case in HHS’s Risk Analysis Initiative.

    Sources: HHS summary of the Security Rule, HHS on business associates, HHS press release, Aug 18, 2025

  • HIPAA Security Rule update

    Department of Health and Human Services

    Status: Proposed

    Would require multi-factor authentication, encryption, an asset inventory and network map, a yearly compliance audit and a plan to restore key systems within 72 hours.

    1. Proposed
    2. Comment period closed
    3. Last checked
    4. Final rule projected by HHS

    Applies to The same practices, plans, clearinghouses and business associates, if it becomes final

    • Every safeguard would become required, ending the split between required and addressable steps.
    • Vulnerability scans every six months and a penetration test every year.
    • Business associates would confirm their safeguards in writing every year, and report activating a contingency plan within 24 hours.
    • HHS’s current regulatory agenda lists it as a long-term action. The current rule stays in force meanwhile.

    Sources: HHS fact sheet, HHS regulatory agenda, Federal Register, 90 FR 898

  • HIPAA Breach Notification Rule

    Department of Health and Human Services

    Status: In force

    Tell affected patients no later than 60 days after you discover a breach of unsecured health information; HHS hears within 60 days too when 500 or more people are affected, or in a yearly report when fewer are.

    1. Published, updated in 2013

    Applies to Practices and plans, with business associates telling them within the same 60 days

    • Breaches affecting more than 500 residents of a state also go to prominent local media.
    • A business associate must tell you no later than 60 days after discovering a breach.
    • Data encrypted the way HHS guidance specifies isn’t “unsecured,” so losing it doesn’t trigger these notices.

    Source: HHS Breach Notification Rule

  • CMMC

    Department of Defense

    Status: Paused

    When a defense contract calls for it, self-assess against the 15 basic controls (Level 1) or the 110 requirements of NIST SP 800-171 Rev 2 (Level 2), post the results in SPRS and affirm them every year.

    1. Program rule took effect
    2. Phase 1: self-assessments begin
    3. Phase 2 suspended
    4. Contract terms cut to self-assessments
    5. Last checked
    6. Phase 2 was due. Paused.

    Applies to Defense contractors and subcontractors whose systems handle federal contract information or controlled unclassified information (CUI)

    • Level 1: a yearly self-assessment of the 15 basic safeguards in FAR 52.204-21, with no open items allowed.
    • Level 2: a self-assessment against the 110 requirements of NIST SP 800-171 Rev 2 every three years, affirmed every year; open items must close within 180 days.
    • Results go into the Supplier Performance Risk System (SPRS).
    • The Defense Department says the pause does not lift DFARS 252.204-7012.

    Sources: DoD CIO: About CMMC, Class deviation 2026-O0025, Rev. 3, Federal Register, 32 CFR 170, Federal Register, DFARS CMMC rule

  • DFARS 252.204-7012

    Department of Defense

    Status: In force

    Protect covered defense information to NIST SP 800-171, report cyber incidents to the Defense Department within 72 hours, and keep images of affected systems for 90 days.

    1. NIST SP 800-171 deadline. Unchanged by the CMMC pause.

    Applies to Defense contractors whose systems hold covered defense information

    • Reports go to the Defense Department’s DIBNet portal, which needs a medium assurance certificate, so get one before you need it.
    • Images of affected systems and the relevant monitoring data must be kept for at least 90 days after the report.

    Sources: DFARS 252.204-7012, DoD CIO: About CMMC

  • FAR 52.204-21

    Federal Acquisition Regulation

    Status: In force

    Apply 15 basic safeguards, from limiting access to authorized users to keeping malware protection current, on any system that holds federal contract information.

    1. Took effect

    Applies to Federal contractors whose systems hold federal contract information

    • The 15 include limiting access to authorized users, authenticating users, wiping media before disposal, limiting physical access, and scanning for malicious code.
    • They are the same 15 that a CMMC Level 1 self-assessment covers.

    Sources: FAR 52.204-21, Federal Register, 81 FR 30439

  • Florida Bar Rule 4-1.6(e)

    The Florida Bar and the Supreme Court of Florida

    Status: In force

    Make reasonable efforts to prevent unauthorized access to, or disclosure of, client information; the rule’s comment now names generative AI as a confidentiality risk.

    1. Comment naming generative AI took effect

    Applies to Every Florida lawyer

    • What counts as reasonable turns on how sensitive the information is, how likely a disclosure is, and the cost and difficulty of more safeguards.
    • The comment to Rule 4-1.1 on competence names generative AI too, among the technology a lawyer should understand.

    Source: Rules Regulating The Florida Bar

  • Florida Bar Ethics Opinion 24-1

    The Florida Bar

    Status: Guidance

    Research an AI tool’s data retention, data sharing and self-learning policies before you use it; the Bar recommends client consent before confidential information goes in, and client-facing chatbots must say they are AI.

    1. Issued

    Applies to Florida lawyers using generative AI

    • Lawyers may use generative AI but must protect confidentiality, work competently, avoid improper billing and follow the advertising rules.
    • Tell clients, preferably in writing, before charging them the actual cost of an AI tool.
    • Advisory ethics opinions are not binding, but they show how the Bar reads its rules.

    Source: Florida Bar Ethics Opinion 24-1

  • Florida Bar technology CLE

    The Florida Bar

    Status: In force

    Complete at least 3 of your 30 continuing legal education hours in approved technology courses in every 3-year cycle.

    1. Technology hours first required

    Applies to Every Florida lawyer

    • The 3 technology hours count toward the 30, not on top of them.

    Sources: Florida Bar CLE requirements, Rules Regulating The Florida Bar

  • ABA Formal Opinion 512

    American Bar Association

    Status: Guidance

    Lawyers using generative AI must weigh their duties of competence, confidentiality, communication with clients and reasonable fees.

    1. Issued

    Applies to Lawyers anywhere, as guidance on the ABA Model Rules

    • Lawyers may bill for the time spent entering information and checking an AI draft, but in most cases not for learning the tool.

    Source: ABA news release, Jul 29, 2024

  • PCI DSS v4.0.1

    PCI Security Standards Council

    Status: In force

    If you take card payments, your card processor can hold you to PCI DSS, and every requirement in the current version has applied since March 31, 2025.

    1. Version 4.0.1 published
    2. Version 4.0 retired
    3. Future-dated requirements took effect
    4. Last checked

    Applies to Merchants and anyone else that stores, processes or transmits cardholder data, including organizations that take gifts by card

    • Whether you must comply, and how you prove it, is up to the card brands and your processor.
    • Version 4.0.1 was a limited revision: no requirements added or removed.

    Sources: PCI Security Standards Council, PCI DSS at the Council

  • Florida Information Protection Act

    Florida Legislature

    Status: In force

    Protect Floridians’ personal information with reasonable measures, and notify those affected within 30 days of a breach (and the Attorney General’s office at 500 or more); vendors that hold the data for you must tell you within 10 days.

    1. Took effect. Checked against the 2026 statutes.

    Applies to Businesses and associations that keep Floridians’ personal information, and the vendors that hold it for them

    • Personal information includes Social Security, license and passport numbers, financial account numbers with their codes, medical and health insurance details, biometric data, geolocation, and a username or email with its password.
    • The Attorney General’s office can allow 15 more days for good cause, asked for in writing.
    • Notifying more than 1,000 people at once means telling the national credit reporting agencies too.
    • Missed notices can cost up to $500,000 in civil penalties.
    • Nonprofits: the law is written for businesses and associations; ask your counsel whether it covers your organization.

    Sources: Florida Statutes s. 501.171 (2026), Florida Senate, SB 1524 (2014)

What changed in the last year

Newest first. Each change links to the rule it touches.

  1. CMMC. The current Defense Department class deviation tells contracting officers to cut CMMC terms in new and existing contracts back to self-assessments. See the rule

  2. IRS. The IRS and the Security Summit reminded tax pros that federal law requires a written information security plan. See the rule

  3. CMMC. Phase 2, the third-party assessments due November 10, 2026, was suspended. Phase 1 self-assessments stay. See the rule

  4. SEC Regulation S-P. Smaller firms, including advisers with less than $1.5 billion under management, had to comply. See the rule

  5. SEC Regulation S-P. Larger firms, including advisers with $1.5 billion or more under management, had to comply. See the rule

  6. CMMC. Phase 1 began: defense contracts can require Level 1 and Level 2 self-assessments. See the rule

What we hand you

So when an examiner, an auditor or your insurer asks, the answer is already on paper. Pick an industry above and this list follows.

Ask for the file

  • A 72-hour breach notice, in writing If a breach touches a system we run for you, we tell you within 72 hours of learning of it: the term Reg S-P asks advisers to require, and faster than the 10 days Florida law gives us.
  • Answers for any questionnaire A completed security questionnaire, SIG Lite included, and a written summary of how we protect your data, for a regulator’s file, a prime contractor or a big customer.
  • An incident response plan to adopt A written plan for spotting, containing and recovering from an incident, with our part in it spelled out.
  • Evidence, kept all year MFA, encryption, access review, backup test and training records, current whenever an examiner, an auditor, a board or a funder asks.
  • A signed Business Associate Agreement HHS counts IT providers that support systems holding patient records as business associates. We sign the agreement before we start.
  • Your risk analysis, written down We run the security risk analysis with you, record what we find and keep it current as your systems change.
  • Proof of encryption Reports showing laptops, phones and backups are encrypted. Under HHS guidance, properly encrypted data isn’t “unsecured,” so a lost laptop doesn’t trigger breach notices.
  • Help writing your WISP We draft the technical sections of your written information security plan from IRS Publication 5708. You own the plan.
  • A data theft checklist Who to call, in order, including your IRS Stakeholder Liaison, the call the IRS asks tax pros to make.
  • An AI tool review We read the retention, sharing and training terms of the AI tools you’re weighing, the research Opinion 24-1 describes, and write up what we find.
  • An approved-tools list A short written list of the AI and file-sharing tools your firm allows, and the account settings to match.
  • A NIST SP 800-171 gap assessment Scored for your SPRS entry, with a plan of action for anything still open.
  • Your CMMC self-assessment, ready The evidence behind your Level 1 or Level 2 self-assessment and the yearly affirmation in SPRS, kept current.
  • Help with a 72-hour incident report If an incident touches covered defense information, we help you investigate, preserve images for 90 days and gather what the report needs.
  • The 15 basic safeguards, in place Set up on the systems that hold federal contract information, with records you can show a contracting officer.
  • Answers for your insurer MFA, backup and training evidence for your cyber insurance renewal questionnaire.
  • Card data kept off your systems We check that online gifts run through your processor’s hosted payment page, so card numbers don’t pass through your systems, and help with the questionnaire your processor asks for.

How we keep this current

We read each rule where it lives: the regulator’s own site, the Federal Register, the statute or the Bar’s rulebook, not someone’s summary of it. Every entry links to that source.

We check every entry again at least once a month, and the same week an agency announces a change. The date at the top moves only when every entry has been checked.

Outside Florida? Every state has its own breach law. If you have staff or clients in other states, ask and we’ll pull the ones that reach you.

This page is our plain-English reading of public rules, not legal advice. Your attorney, CPA or compliance officer has the final word on what applies to you.

Need the file for an exam or a renewal?

Tell us what you’re being asked for. We’ll send what we have, go through your questionnaire with you and tell you plainly what’s missing.

Call Ask for the file