CFTC System Safeguards (17 CFR 37, 38, 39, 49)
The Commodity Futures Trading Commission (CFTC) System Safeguards rules (17 CFR Parts 37, 38, 39, and 49) establish comprehensive cybersecurity, business continuity, incident reporting, system integrity, and risk management requirements for designated contract markets (DCMs), swap execution facilities (SEFs), derivatives clearing organizations (DCOs), and swap data repositories (SDRs).
CFTC System Safeguards (17 CFR 37, 38, 39, 49) is a compliance framework from United States (CFTC) with 5 domains and 39 controls that map to 27 other frameworks. The largest domains are CFTC System Safeguards: Business Continuity and Disaster Recovery (12 controls), CFTC System Safeguards: Cybersecurity Testing (10 controls), CFTC System Safeguards: Risk Analysis and Oversight Program (10 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
CFTC System Safeguards: Business Continuity and Disaster Recovery
| Code | Title |
|---|---|
| CFTC-SS-10 | Geographic Dispersal of Backup Infrastructure and Personnel |
| CFTC-SS-11 | Testing and Review of Business Continuity and Disaster Recovery Capabilities |
| CFTC-SS-24 | Periodic Update of the Recovery Plan and Emergency Procedures |
| CFTC-SS-25 | Same Day Recovery Time Objective for Critical Entities |
| CFTC-SS-26 | Own Resources or Contractual Arrangements to Meet the Recovery Objective |
| CFTC-SS-27 | Coordination of the Recovery Plan with Members and Market Participants |
| CFTC-SS-28 | Synchronised Testing with Members and Market Participants |
| CFTC-SS-29 | Recovery Plan Accounts for Essential Service Providers |
| CFTC-SS-30 | Outsourcing with Retention of Complete Responsibility |
| CFTC-SS-31 | Testing Covers Outsourced Resources and Tester Independence from Providers |
| CFTC-SS-8 | Business Continuity and Disaster Recovery Plan and Resources |
| CFTC-SS-9 | Next Business Day Recovery Time Objective |
CFTC System Safeguards: Cybersecurity Testing
| Code | Title |
|---|---|
| CFTC-SS-13 | Vulnerability Testing |
| CFTC-SS-14 | External Penetration Testing |
| CFTC-SS-15 | Controls Testing |
| CFTC-SS-16 | Security Incident Response Plan and Testing |
| CFTC-SS-17 | Enterprise Technology Risk Assessment |
| CFTC-SS-18 | Independence of Testers |
| CFTC-SS-33 | Regular Periodic Objective Testing and Review of Automated Systems |
| CFTC-SS-34 | Internal Penetration Testing |
| CFTC-SS-35 | Scope of Testing and Assessment |
| CFTC-SS-36 | Internal Reporting and Review by Senior Management and the Board |
CFTC System Safeguards: Notification, Records and Remediation
| Code | Title |
|---|---|
| CFTC-SS-19 | Prompt Notification to the Commission |
| CFTC-SS-20 | Production of System Safeguards Books and Records |
| CFTC-SS-21 | Remediation of Vulnerabilities and Deficiencies |
| CFTC-SS-32 | Timely Advance Notice of Material Planned Changes |
CFTC System Safeguards: Registrant Specific Requirements
| Code | Title |
|---|---|
| CFTC-SS-37 | Protection of Swap Data Repository Data |
| CFTC-SS-38 | Production of Annual Total Trading Volume |
| CFTC-SS-39 | Critical Financial Market Designation Obligations |
CFTC System Safeguards: Risk Analysis and Oversight Program
| Code | Title |
|---|---|
| CFTC-SS-1 | Program of Risk Analysis and Oversight |
| CFTC-SS-12 | Capacity and Performance Planning Category |
| CFTC-SS-2 | Enterprise Risk Management and Governance Category |
| CFTC-SS-22 | Business Continuity and Disaster Recovery Planning Category |
| CFTC-SS-23 | Resources Sufficient to Fulfil Obligations |
| CFTC-SS-3 | Information Security Category |
| CFTC-SS-4 | Systems Operations Category |
| CFTC-SS-5 | Systems Development and Quality Assurance Category |
| CFTC-SS-6 | Physical Security and Environmental Controls Category |
| CFTC-SS-7 | Generally Accepted Standards and Best Practices |
Your Compliance Coverage
If you comply with CFTC System Safeguards (17 CFR 37, 38, 39, 49), you already cover:
FedRAMP High
100%
39 controls mapped
Compare →FedRAMP Moderate
100%
39 controls mapped
Compare →NIST SP 800-53 Revision 5.1 HIGH
97%
38 controls mapped
Compare →+ 24 more: C5 (Germany) (97%), NIST SP 800-161 Rev 1 (97%)
See all 27 mapped frameworks ↓Maps to 27 other frameworks
What is CFTC System Safeguards (17 CFR 37, 38, 39, 49) and who does it apply to?
CFTC System Safeguards (17 CFR 37, 38, 39, 49) is a compliance framework from United States (CFTC) with 5 domains and 39 controls. The Commodity Futures Trading Commission (CFTC) System Safeguards rules (17 CFR Parts 37, 38, 39, and 49) establish comprehensive cybersecurity, business continuity, incident reporting, system integrity, and risk management requirements for designated contract markets (DCMs), swap execution facilities (SEFs), derivatives clearing organizations (DCOs), and swap data repositories (SDRs). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does CFTC System Safeguards (17 CFR 37, 38, 39, 49) actually require?
CFTC System Safeguards (17 CFR 37, 38, 39, 49) has 39 controls organised across 5 domains. The largest domains are CFTC System Safeguards: Business Continuity and Disaster Recovery (12 controls), CFTC System Safeguards: Cybersecurity Testing (10 controls), CFTC System Safeguards: Risk Analysis and Oversight Program (10 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of CFTC System Safeguards (17 CFR 37, 38, 39, 49) do I already cover?
CFTC System Safeguards (17 CFR 37, 38, 39, 49) maps to 27 other compliance frameworks. The top mapping partners are FedRAMP High (100% coverage), FedRAMP Moderate (100% coverage), NIST SP 800-53 Revision 5.1 HIGH (97% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement CFTC System Safeguards (17 CFR 37, 38, 39, 49)?
Start your CFTC System Safeguards (17 CFR 37, 38, 39, 49) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CFTC System Safeguards (17 CFR 37, 38, 39, 49) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 39 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required