Does the under-5,000-consumer exemption apply to us?
It might apply to specific elements. Collection agencies maintaining customer information concerning fewer than 5,000 consumers are exempt from four requirements.
Those are the written risk assessment, penetration testing and the twice-yearly vulnerability assessment, the written incident response plan, and the annual board report. They must still maintain a written information security program and the other safeguards.
Those include access controls and MFA, encryption, audit logging of access to customer information, secure disposal, and training. The FTC 30-day breach-notification duty still applies.
We confirm your consumer count during onboarding and scope the program to what actually applies to you.
How long does it take to get a collection agency compliant?
It depends on your current posture. A program built from scratch typically takes 60 to 120 days to establish. The work starts with the gap analysis and risk assessment, then moves through control implementation and documentation.
We scope every engagement to what your environment actually needs rather than to a fixed package.