CFTC System Safeguards (17 CFR 37, 38, 39, 49)
The Commodity Futures Trading Commission (CFTC) System Safeguards rules establish cybersecurity and system integrity requirements for designated contract markets (DCMs), swap execution facilities (SEFs), derivatives clearing organizations (DCOs), and swap data repositories (SDRs). Requirements include cybersecurity testing, business continuity, disaster recovery, and incident response. Updated through subsequent guidance including staff advisories.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (17)
Business Continuity and Disaster Recovery
| Code | Title |
|---|---|
| 38.1051(c) | BC-DR Planning |
| 38.1051(c)(1) | Recovery Time Objectives |
| 38.1051(c)(2) | Geographic Separation of Backup |
| 38.1051(c)(3) | BC-DR Testing |
Capacity and Performance
| Code | Title |
|---|---|
| 38.1051(d) | Capacity Planning |
| 38.1051(d)(1) | Performance Monitoring |
| 38.1051(d)(2) | Scalability Requirements |
Cybersecurity Testing
| Code | Title |
|---|---|
| 38.1051(h)(1) | Vulnerability Testing |
| 38.1051(h)(2) | Penetration Testing |
| 38.1051(h)(3) | Controls Testing |
| 38.1051(h)(4) | Security Incident Response Plan Testing |
| 38.1051(h)(5) | Enterprise Technology Risk Assessment |
Governance
| Code | Title |
|---|---|
| CFTC-SS-1 | Information Security Program |
| CFTC-SS-21 | Annual Program Review |
| CFTC-SS-9 | Internal Reporting and Review |
Incident Response
| Code | Title |
|---|---|
| CFTC-SS-7 | Security Incident Response Plan |
Information Security
VDA ISA information security requirements
| Code | Title |
|---|---|
| 37.1401(a) | General Security Requirements for SEFs |
| 38.1051(a) | General Security Requirements for DCMs |
| 39.18(a) | General Security Requirements for DCOs |
| 49.24(a) | General Security Requirements for SDRs |
| DSPF-INFO-1 | Information Classification |
| DSPF-INFO-2 | Information Handling |
| DSPF-INFO-3 | Information Access Controls |
| DSPF-INFO-4 | Security Markings |
| EIOPA-GL-10 | ICT Operations Security |
| EIOPA-GL-11 | Security Monitoring |
| EIOPA-GL-12 | Information Security Reviews, Assessment and Testing |
| EIOPA-GL-13 | Information Security Training and Awareness |
| EIOPA-GL-6 | Information Security Policy |
| EIOPA-GL-7 | Information Security Function |
| EIOPA-GL-8 | Logical Security |
| EIOPA-GL-9 | Physical Security |
| GLI33-4.1 | Information Security System Assessment |
| GLI33-4.2 | Penetration Testing |
| GLI33-4.3 | Data Protection and Encryption |
| GLI33-4.4 | Audit Trail and Logging |
| PSPF-INFO-1 | Sensitive and Classified Information |
| PSPF-INFO-2 | Security Classification System |
| PSPF-INFO-3 | Information Holdings |
| PSPF-INFO-4 | Information Disposal |
| PSPF-INFO-5 | Information Sharing |
| PSPF-INFO-6 | Security Caveated Information |
| PSPF-INFO-7 | Accountable Material |
| TISAX-IS-01 | Information Security Policy and Organisation |
| TISAX-IS-02 | Information Security Risk Management |
| TISAX-IS-03 | Third-Party Risk Management |
| TSSR-INFO-1 | Network Data Protection |
| TSSR-INFO-2 | Stored Communications Security |
| TSSR-INFO-3 | Lawful Interception Capability |
Operations
| Code | Title |
|---|---|
| CFTC-SS-14 | Capacity and Performance |
| CFTC-SS-15 | Change Management |
People
| Code | Title |
|---|---|
| CFTC-SS-19 | Training |
Records
| Code | Title |
|---|---|
| CFTC-SS-20 | Records Retention |
Reporting
| Code | Title |
|---|---|
| CFTC-SS-13 | Notification to CFTC |
Resilience
| Code | Title |
|---|---|
| CFTC-SS-10 | Business Continuity and Disaster Recovery |
| CFTC-SS-11 | Geographic Diversity |
Risk
| Code | Title |
|---|---|
| CFTC-SS-2 | Risk Analysis and Oversight |
| CFTC-SS-8 | Enterprise Technology Risk Assessment |
Security
| Code | Title |
|---|---|
| CFTC-SS-16 | Access Control |
| CFTC-SS-17 | Logging and Monitoring |
| CFTC-SS-18 | Encryption |
Standards
| Code | Title |
|---|---|
| CFTC-SS-3 | Generally Accepted Standards Alignment |
Systems Development and Physical Security
| Code | Title |
|---|---|
| 38.1051(e) | Systems Development and Quality Assurance |
| 38.1051(e)(1) | Change Management |
| 38.1051(f) | Physical Security Controls |
| 38.1051(g) | Systems Operations |
Testing
| Code | Title |
|---|---|
| CFTC-SS-4 | Vulnerability Testing |
| CFTC-SS-5 | Penetration Testing |
| CFTC-SS-6 | Controls Testing |
Third Party
| Code | Title |
|---|---|
| CFTC-SS-12 | Third Party Service Providers |
Your Compliance Coverage
If you comply with CFTC System Safeguards (17 CFR 37, 38, 39, 49), you already cover:
Defence Security Principles Framework (DSPF)
36%
25 controls mapped
Compare →TISAX — Trusted Information Security Assessment Exchange
34%
24 controls mapped
Compare →South Korea Cloud Security Assurance Program (CSAP)
34%
24 controls mapped
Compare →+ 659 more: Protective Security Policy Framework (PSPF) Release 2024 (34%), CSA CCM v4 (33%)
See all 662 mapped frameworks ↓Maps to 662 other frameworks
Frequently Asked Questions
What is CFTC System Safeguards (17 CFR 37, 38, 39, 49)?
CFTC System Safeguards (17 CFR 37, 38, 39, 49) is a compliance framework from United States (CFTC) with 17 domains and 70 controls. The Commodity Futures Trading Commission (CFTC) System Safeguards rules establish cybersecurity and system integrity requirements for designated contract markets (DCMs), swap execution facilities (SEFs), derivatives clearing organizations (DCOs), and swap data repositories (SDRs). Requirements include cybersecurity testing, business continuity, disaster recovery, and incident response. Updated through subsequent guidance including staff advisories. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does CFTC System Safeguards (17 CFR 37, 38, 39, 49) have?
CFTC System Safeguards (17 CFR 37, 38, 39, 49) has 70 controls organised across 17 domains. The largest domains are Information Security (33 controls), Cybersecurity Testing (5 controls), Business Continuity and Disaster Recovery (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does CFTC System Safeguards (17 CFR 37, 38, 39, 49) map to?
CFTC System Safeguards (17 CFR 37, 38, 39, 49) maps to 662 other compliance frameworks. The top mapping partners are Defence Security Principles Framework (DSPF) (36% coverage), TISAX — Trusted Information Security Assessment Exchange (34% coverage), South Korea Cloud Security Assurance Program (CSAP) (34% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with CFTC System Safeguards (17 CFR 37, 38, 39, 49) compliance?
Start your CFTC System Safeguards (17 CFR 37, 38, 39, 49) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CFTC System Safeguards (17 CFR 37, 38, 39, 49) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 70 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required