Back to Frameworks

CFTC System Safeguards (17 CFR 37, 38, 39, 49)

United States (CFTC)
v17 CFR 37.1401, 38.1051, 39.18 and 49.24 as in force 2026-08-17
5 domains
39 controls

The Commodity Futures Trading Commission (CFTC) System Safeguards rules (17 CFR Parts 37, 38, 39, and 49) establish comprehensive cybersecurity, business continuity, incident reporting, system integrity, and risk management requirements for designated contract markets (DCMs), swap execution facilities (SEFs), derivatives clearing organizations (DCOs), and swap data repositories (SDRs).

Verified

CFTC System Safeguards (17 CFR 37, 38, 39, 49) is a compliance framework from United States (CFTC) with 5 domains and 39 controls that map to 27 other frameworks. The largest domains are CFTC System Safeguards: Business Continuity and Disaster Recovery (12 controls), CFTC System Safeguards: Cybersecurity Testing (10 controls), CFTC System Safeguards: Risk Analysis and Oversight Program (10 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

CFTC System Safeguards: Business Continuity and Disaster Recovery

12 controls
Controls in the CFTC System Safeguards: Business Continuity and Disaster Recovery domain of CFTC System Safeguards (17 CFR 37, 38, 39, 49)12 controls
CodeTitle
CFTC-SS-10Geographic Dispersal of Backup Infrastructure and Personnel
CFTC-SS-11Testing and Review of Business Continuity and Disaster Recovery Capabilities
CFTC-SS-24Periodic Update of the Recovery Plan and Emergency Procedures
CFTC-SS-25Same Day Recovery Time Objective for Critical Entities
CFTC-SS-26Own Resources or Contractual Arrangements to Meet the Recovery Objective
CFTC-SS-27Coordination of the Recovery Plan with Members and Market Participants
CFTC-SS-28Synchronised Testing with Members and Market Participants
CFTC-SS-29Recovery Plan Accounts for Essential Service Providers
CFTC-SS-30Outsourcing with Retention of Complete Responsibility
CFTC-SS-31Testing Covers Outsourced Resources and Tester Independence from Providers
CFTC-SS-8Business Continuity and Disaster Recovery Plan and Resources
CFTC-SS-9Next Business Day Recovery Time Objective

CFTC System Safeguards: Cybersecurity Testing

10 controls
Controls in the CFTC System Safeguards: Cybersecurity Testing domain of CFTC System Safeguards (17 CFR 37, 38, 39, 49)10 controls
CodeTitle
CFTC-SS-13Vulnerability Testing
CFTC-SS-14External Penetration Testing
CFTC-SS-15Controls Testing
CFTC-SS-16Security Incident Response Plan and Testing
CFTC-SS-17Enterprise Technology Risk Assessment
CFTC-SS-18Independence of Testers
CFTC-SS-33Regular Periodic Objective Testing and Review of Automated Systems
CFTC-SS-34Internal Penetration Testing
CFTC-SS-35Scope of Testing and Assessment
CFTC-SS-36Internal Reporting and Review by Senior Management and the Board

CFTC System Safeguards: Notification, Records and Remediation

4 controls
Controls in the CFTC System Safeguards: Notification, Records and Remediation domain of CFTC System Safeguards (17 CFR 37, 38, 39, 49)4 controls
CodeTitle
CFTC-SS-19Prompt Notification to the Commission
CFTC-SS-20Production of System Safeguards Books and Records
CFTC-SS-21Remediation of Vulnerabilities and Deficiencies
CFTC-SS-32Timely Advance Notice of Material Planned Changes

CFTC System Safeguards: Registrant Specific Requirements

3 controls
Controls in the CFTC System Safeguards: Registrant Specific Requirements domain of CFTC System Safeguards (17 CFR 37, 38, 39, 49)3 controls
CodeTitle
CFTC-SS-37Protection of Swap Data Repository Data
CFTC-SS-38Production of Annual Total Trading Volume
CFTC-SS-39Critical Financial Market Designation Obligations

CFTC System Safeguards: Risk Analysis and Oversight Program

10 controls
Controls in the CFTC System Safeguards: Risk Analysis and Oversight Program domain of CFTC System Safeguards (17 CFR 37, 38, 39, 49)10 controls
CodeTitle
CFTC-SS-1Program of Risk Analysis and Oversight
CFTC-SS-12Capacity and Performance Planning Category
CFTC-SS-2Enterprise Risk Management and Governance Category
CFTC-SS-22Business Continuity and Disaster Recovery Planning Category
CFTC-SS-23Resources Sufficient to Fulfil Obligations
CFTC-SS-3Information Security Category
CFTC-SS-4Systems Operations Category
CFTC-SS-5Systems Development and Quality Assurance Category
CFTC-SS-6Physical Security and Environmental Controls Category
CFTC-SS-7Generally Accepted Standards and Best Practices

Your Compliance Coverage

If you comply with CFTC System Safeguards (17 CFR 37, 38, 39, 49), you already cover:

Maps to 27 other frameworks

39 total controls
FedRAMP High
39 source controls mapped|98 target controls covered
100%
FedRAMP Moderate
39 source controls mapped|99 target controls covered
100%
NIST SP 800-53 Revision 5.1 HIGH
38 source controls mapped|92 target controls covered
97%
C5 (Germany)
38 source controls mapped|38 target controls covered
97%
NIST SP 800-161 Rev 1
38 source controls mapped|55 target controls covered
97%
NIST Cybersecurity Framework 2.0
38 source controls mapped|82 target controls covered
97%
NIST SP 800-53 Rev 5 MODERATE
36 source controls mapped|91 target controls covered
92%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
36 source controls mapped|85 target controls covered
92%
NIST SP 800-53 Rev 5
35 source controls mapped|91 target controls covered
90%
DORA
35 source controls mapped|17 target controls covered
90%
SOC 2
33 source controls mapped|34 target controls covered
85%
HIPAA Security Rule
31 source controls mapped|44 target controls covered
79%
NIST SP 800-53 Rev 5 LOW
30 source controls mapped|64 target controls covered
77%
NIST SP 800-66 Rev 2
29 source controls mapped|38 target controls covered
74%
PCI DSS 4.0
26 source controls mapped|60 target controls covered
67%
APRA CPS 230 Operational Risk Management
26 source controls mapped|40 target controls covered
67%
ISO 22301:2019
23 source controls mapped|39 target controls covered
59%
ISO 27002:2022
23 source controls mapped|59 target controls covered
59%
ISO 27001:2022
23 source controls mapped|59 target controls covered
59%
NIST SP 800-171 Rev 3
22 source controls mapped|48 target controls covered
56%
Azure Security Benchmark
21 source controls mapped|46 target controls covered
54%
CIS Controls v8
21 source controls mapped|52 target controls covered
54%
CMMC 2.0
14 source controls mapped|39 target controls covered
36%
ISO 27005:2022
1 source controls mapped|3 target controls covered
3%
ISO 27018:2019
1 source controls mapped|2 target controls covered
3%
ISO 27017:2015
1 source controls mapped|3 target controls covered
3%
ISO 27701:2019
1 source controls mapped|5 target controls covered
3%

What is CFTC System Safeguards (17 CFR 37, 38, 39, 49) and who does it apply to?

CFTC System Safeguards (17 CFR 37, 38, 39, 49) is a compliance framework from United States (CFTC) with 5 domains and 39 controls. The Commodity Futures Trading Commission (CFTC) System Safeguards rules (17 CFR Parts 37, 38, 39, and 49) establish comprehensive cybersecurity, business continuity, incident reporting, system integrity, and risk management requirements for designated contract markets (DCMs), swap execution facilities (SEFs), derivatives clearing organizations (DCOs), and swap data repositories (SDRs). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does CFTC System Safeguards (17 CFR 37, 38, 39, 49) actually require?

CFTC System Safeguards (17 CFR 37, 38, 39, 49) has 39 controls organised across 5 domains. The largest domains are CFTC System Safeguards: Business Continuity and Disaster Recovery (12 controls), CFTC System Safeguards: Cybersecurity Testing (10 controls), CFTC System Safeguards: Risk Analysis and Oversight Program (10 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of CFTC System Safeguards (17 CFR 37, 38, 39, 49) do I already cover?

CFTC System Safeguards (17 CFR 37, 38, 39, 49) maps to 27 other compliance frameworks. The top mapping partners are FedRAMP High (100% coverage), FedRAMP Moderate (100% coverage), NIST SP 800-53 Revision 5.1 HIGH (97% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement CFTC System Safeguards (17 CFR 37, 38, 39, 49)?

Start your CFTC System Safeguards (17 CFR 37, 38, 39, 49) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CFTC System Safeguards (17 CFR 37, 38, 39, 49) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 39 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required