CFTC System Safeguards (17 CFR 37, 38, 39, 49)
The Commodity Futures Trading Commission (CFTC) System Safeguards rules establish cybersecurity and system integrity requirements for designated contract markets (DCMs), swap execution facilities (SEFs), derivatives clearing organizations (DCOs), and swap data repositories (SDRs). Requirements include cybersecurity testing, business continuity, disaster recovery, and incident response. Updated through subsequent guidance including staff advisories.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Business Continuity and Disaster Recovery
| Code | Title |
|---|---|
| 38.1051(c) | BC-DR Planning |
| 38.1051(c)(1) | Recovery Time Objectives |
| 38.1051(c)(2) | Geographic Separation of Backup |
| 38.1051(c)(3) | BC-DR Testing |
Capacity and Performance
| Code | Title |
|---|---|
| 38.1051(d) | Capacity Planning |
| 38.1051(d)(1) | Performance Monitoring |
| 38.1051(d)(2) | Scalability Requirements |
Cybersecurity Testing
| Code | Title |
|---|---|
| 38.1051(h)(1) | Vulnerability Testing |
| 38.1051(h)(2) | Penetration Testing |
| 38.1051(h)(3) | Controls Testing |
| 38.1051(h)(4) | Security Incident Response Plan Testing |
| 38.1051(h)(5) | Enterprise Technology Risk Assessment |
Information Security
VDA ISA information security requirements
| Code | Title |
|---|---|
| 37.1401(a) | General Security Requirements for SEFs |
| 38.1051(a) | General Security Requirements for DCMs |
| 39.18(a) | General Security Requirements for DCOs |
| 49.24(a) | General Security Requirements for SDRs |
| DSPF-INFO-1 | Information Classification |
| DSPF-INFO-2 | Information Handling |
| DSPF-INFO-3 | Information Access Controls |
| DSPF-INFO-4 | Security Markings |
| EIOPA-GL-10 | ICT Operations Security |
| EIOPA-GL-11 | Security Monitoring |
| EIOPA-GL-12 | Information Security Reviews, Assessment and Testing |
| EIOPA-GL-13 | Information Security Training and Awareness |
| EIOPA-GL-6 | Information Security Policy |
| EIOPA-GL-7 | Information Security Function |
| EIOPA-GL-8 | Logical Security |
| EIOPA-GL-9 | Physical Security |
| GLI33-4.1 | Information Security System Assessment |
| GLI33-4.2 | Penetration Testing |
| GLI33-4.3 | Data Protection and Encryption |
| GLI33-4.4 | Audit Trail and Logging |
| PSPF-INFO-1 | Sensitive and Classified Information |
| PSPF-INFO-2 | Security Classification System |
| PSPF-INFO-3 | Information Holdings |
| PSPF-INFO-4 | Information Disposal |
| PSPF-INFO-5 | Information Sharing |
| PSPF-INFO-6 | Security Caveated Information |
| PSPF-INFO-7 | Accountable Material |
| TISAX-IS-01 | ISMS Requirements |
| TISAX-IS-02 | Prototype Protection |
| TISAX-IS-03 | Third-Party Risk Management |
| TSSR-INFO-1 | Network Data Protection |
| TSSR-INFO-2 | Stored Communications Security |
| TSSR-INFO-3 | Lawful Interception Capability |
Systems Development and Physical Security
| Code | Title |
|---|---|
| 38.1051(e) | Systems Development and Quality Assurance |
| 38.1051(e)(1) | Change Management |
| 38.1051(f) | Physical Security Controls |
| 38.1051(g) | Systems Operations |
Maps to 641 other frameworks
Frequently Asked Questions
What is CFTC System Safeguards (17 CFR 37, 38, 39, 49)?
CFTC System Safeguards (17 CFR 37, 38, 39, 49) is a compliance framework from United States (CFTC) with 5 domains and 49 controls. The Commodity Futures Trading Commission (CFTC) System Safeguards rules establish cybersecurity and system integrity requirements for designated contract markets (DCMs), swap execution facilities (SEFs), derivatives clearing organizations (DCOs), and swap data repositories (SDRs). Requirements include cybersecurity testing, business continuity, disaster recovery, and incident response. Updated through subsequent guidance including staff advisories. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does CFTC System Safeguards (17 CFR 37, 38, 39, 49) have?
CFTC System Safeguards (17 CFR 37, 38, 39, 49) has 49 controls organised across 5 domains. The largest domains are Information Security (33 controls), Cybersecurity Testing (5 controls), Business Continuity and Disaster Recovery (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does CFTC System Safeguards (17 CFR 37, 38, 39, 49) map to?
CFTC System Safeguards (17 CFR 37, 38, 39, 49) maps to 641 other compliance frameworks. The top mapping partners are Defence Security Principles Framework (DSPF) (51% coverage), TISAX — Trusted Information Security Assessment Exchange (49% coverage), South Korea Cloud Security Assurance Program (CSAP) (49% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with CFTC System Safeguards (17 CFR 37, 38, 39, 49) compliance?
Start your CFTC System Safeguards (17 CFR 37, 38, 39, 49) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CFTC System Safeguards (17 CFR 37, 38, 39, 49) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 49 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required