The 72-Hour Clause
Amended SEC Regulation S-P does not regulate TPAs. It regulates the advisers, broker-dealers, and fund companies TPAs work alongside — and it requires them to make sure their service providers report a breach within 72 hours.
The short answer: since June 3, 2026, every broker-dealer, investment company, SEC-registered investment adviser, and registered transfer agent has had to comply with amended Regulation S-P. Part of that obligation is written oversight of service providers, including making sure those providers report a qualifying breach within 72 hours. A TPA that holds customer information for one of those firms is, for this purpose, their service provider. The clause is already showing up in contracts; the question is whether your incident process can actually meet it.
Covered institutions must ensure service providers “provide notification to the covered institution as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred.” Source: SEC, Regulation S-P Small Entity Compliance Guide (opens in new tab)
Who the Rule Actually Covers
The SEC adopted the amendments on May 16, 2024. They apply to what the rule calls covered institutions: brokers and dealers, funding portals, investment companies, investment advisers registered with the SEC, and registered transfer agents. Larger entities had to comply by December 3, 2025; smaller entities by June 3, 2026. As of today, the rule is fully in force.
For those firms, the amendments require a written incident response program, notice to affected individuals as soon as practicable and no later than 30 days after becoming aware of unauthorized access to sensitive customer information (with limited exceptions), recordkeeping, and — the part that matters here — written policies requiring oversight of service providers.
How It Reaches a TPA
A TPA is usually not a covered institution. But the service-provider requirement follows the data, not the org chart. If your systems store, process, or transmit customer information on behalf of a covered institution, you are likely inside its oversight program whether or not anyone has told you yet.
In retirement plan work, the common paths are:
- Adviser-affiliated TPAs — firms under common ownership with, or operating alongside, an SEC-registered investment adviser that shares client data
- Recordkeeping and platform relationships where the recordkeeper, custodian, or platform is itself a broker-dealer, investment company complex, or transfer agent
- Advisory partners whose client records flow into your administration systems for plan design, testing, or reporting
Whether a specific relationship triggers the rule depends on the entity types involved and on whose customer information sits in which system. That is a question for the covered institution’s compliance team and your counsel — but it is a question you should expect to be asked, and the integration register is how you answer it.
Three Clocks, One Incident
The 72-hour requirement does not replace anything; it stacks. A single incident at a TPA can start several timelines at once, each owed to a different party:
| Owed to | Timeline | Source |
|---|---|---|
| A covered institution you serve | As soon as possible, no later than 72 hours after becoming aware | Regulation S-P, flowed down by contract |
| Affected individuals (by the covered institution, or by you under a written agreement) | As soon as practicable, no later than 30 days | Regulation S-P |
| ERISA plan sponsors and participants | “Without unreasonable delay” | DOL Cybersecurity Program Best Practices (opens in new tab), and your service agreements |
| The FTC, if your firm is a covered financial institution and at least 500 consumers are affected | As soon as possible, no later than 30 days after discovery | FTC Safeguards Rule, effective May 13, 2024 (opens in new tab) |
| Individuals and state regulators | Varies by state of residence | State breach-notification statutes |
| Your cyber insurer | Per policy — often prompt notice as a condition of coverage | Your policy |
On the FTC row: the Safeguards Rule applies to “financial institutions” under FTC jurisdiction, and the FTC’s own list includes account servicers and financial advisers who are not SEC-registered. Whether it reaches a particular TPA depends on what the firm actually does; get counsel’s view rather than assuming either way.
Why 72 Hours Is Harder Than It Sounds
The clock starts at awareness, not at certainty. Forensic investigations take weeks. The contractual obligation arrives long before you know the scope, which means the first notice will be incomplete by design. Decide in advance what a preliminary notice contains.
Someone has to be aware. An alert that fires at 2 a.m. on a Saturday and is read on Monday has already consumed most of the window. 24/7 monitoring is what turns “72 hours” from a legal fiction into something achievable.
You have to know whose data it was. The notice goes to the covered institution whose customer information was affected. If you cannot map systems to clients quickly, you cannot notify the right party on time.
Contracts will not agree with each other. One adviser asks for 72 hours, a recordkeeper for 48, a plan sponsor for 24. Your process has to meet the shortest commitment you have signed, which is a good reason to know what that is before the incident. The DOL’s best practices already expect contracts with service providers to address notification protocol; see continuous monitoring and third-party risk.
What to Have Ready
- A contract inventory listing every signed notification window, shortest first
- A client-to-system map so an affected system can be translated into affected clients in minutes
- A named decision-maker with authority to declare awareness and trigger notice, plus a deputy
- A preliminary notice template that states what is known, what is not, and when the next update will come
- 24/7 detection and escalation that reaches a human who can act
- A tabletop exercise that runs the 72-hour clock end to end at least annually — the same evidence DOL expects under its business-resiliency practice
None of this is specific to Regulation S-P. It is ordinary incident readiness, measured against a harder deadline. Firms that already meet the DOL practices covered in our DOL compliance guide are most of the way there.
Not sure which of these clocks apply to your firm? The free TPA Cyber Rules Navigator maps them from five questions.
Frequently Asked Questions
Does SEC Regulation S-P apply directly to TPAs?
Generally not. The amended rule applies to broker-dealers, funding portals, investment companies, SEC-registered investment advisers, and registered transfer agents, which the SEC calls covered institutions. A TPA that is not one of those is outside the rule itself. It reaches TPAs indirectly: covered institutions must maintain written policies requiring oversight of their service providers, including ensuring those providers notify them of a qualifying breach within 72 hours. If a TPA maintains customer information for a covered institution, expect that requirement to appear in the contract.
When does the 72-hour clock start?
Under the SEC's summary of the rule, the service provider must notify the covered institution as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the service provider. The clock runs from awareness of the breach, not from completion of a forensic investigation, which is why detection capability and a clear internal escalation path matter more than the notice template.
Can a TPA send breach notices to individuals on behalf of an adviser or broker-dealer?
The amended rule permits a covered institution to enter into a written agreement with its service provider to notify affected individuals on its behalf, but the ultimate responsibility for the notice stays with the covered institution. Covered institutions must notify affected individuals as soon as practicable and no later than 30 days after becoming aware of the incident, subject to limited exceptions. A TPA agreeing to send notices should make sure its incident process can support that timeline.
Could You Notify Within 72 Hours?
A free assessment tests your detection, escalation, and notification path against the shortest window you have signed.
Book Free IT & Cyber Assessment (opens in new tab)