201 CMR 17.00 Compliance Checklist for Massachusetts Businesses

201 CMR 17.00 is the Massachusetts data security regulation. It requires any business that owns or licenses personal information about even one Massachusetts resident to maintain a written information security program, called a WISP, with specific administrative and technical safeguards. The Attorney General enforces it under Chapter 93A, with penalties up to $5,000 per violation plus litigation costs. This checklist walks through every requirement and how to close the gaps.

Who has to comply with 201 CMR 17.00?

The scope is wider than most owners assume. The regulation, formally titled Standards for the Protection of Personal Information of Residents of the Commonwealth, applies to every person or business that receives, stores, maintains, processes, or otherwise has access to personal information about a Massachusetts resident. Not "companies based in Massachusetts." Not "companies above a certain size." Anyone holding the data.

In practice that means:

There is no small business exemption. The regulation instead applies a risk-based standard: safeguards must be appropriate to your size, scope, resources, and the sensitivity of the data. That flexibility helps a 15-person firm, but it does not excuse one.

What counts as personal information under the regulation?

Personal information is a Massachusetts resident's first name or initial and last name combined with any of the following: Social Security number, driver's license or state ID number, or a financial account or payment card number that permits access to the account. If you run payroll, take payments, extend credit, or keep scanned IDs on file, you hold personal information.

What does the 201 CMR 17.00 compliance checklist require?

The state publishes its own compliance checklist on Mass.gov, and it is worth reading in full. Here is each requirement, translated into what you actually have to do.

  1. Written information security program (WISP). A living document, in writing, that describes how you protect personal information. Not a template you downloaded and never opened again. The whole regulation hangs off this document, and it is the first thing a regulator or insurer asks for.
  2. A designated employee. Someone must be named as responsible for the program. Title matters less than accountability. In companies without a security hire, this is exactly the role a fractional CISO fills.
  3. Risk assessment. Identify where personal information lives, how it moves, and what could reasonably go wrong: paper files, laptops, cloud apps, email, vendor systems. Document the risks and the safeguards you chose. Repeat at least annually.
  4. Access controls. Restrict personal information to employees who need it for their jobs. Terminate access immediately when someone leaves. Unique logins, no shared accounts, and strong authentication on anything reachable from the internet.
  5. Encryption of transmitted and portable data. Personal information must be encrypted when it travels across public networks or wireless, and when it sits on laptops and other portable devices. An unencrypted laptop in a stolen car is the classic Massachusetts breach report.
  6. Vendor oversight. If third parties handle personal information for you, you must take reasonable steps to select vendors capable of protecting it and require those protections by contract. Payroll providers, IT firms, marketing platforms, and now AI tools all count.
  7. Monitoring. The program must include ongoing monitoring to detect unauthorized access or use, and an annual review of the program's effectiveness. Firewalls, malware protection, and patching are expected as baseline technical measures.
  8. Employee training. Everyone who touches personal information needs training on the WISP and on the discipline that follows violations. Once at hire and refreshed periodically. Untrained employees are how most of these incidents start.
  9. Incident documentation. When something goes wrong, you must document the response and review what happened, then adjust the program. Massachusetts also has a separate breach notification law, Chapter 93H, that requires notifying affected residents and the state.

What does enforcement actually look like?

The Attorney General enforces 201 CMR 17.00 through Chapter 93A, the state consumer protection statute, with civil penalties up to $5,000 per violation. Per violation matters: a breach affecting 1,000 residents is not one violation. Massachusetts AG settlements over data security failures have run from tens of thousands to millions of dollars, and they routinely require years of third-party audits on top of the fine. The predictable pattern in these cases: the company had no WISP, or had one it never followed.

How does 201 CMR 17.00 interact with cyber insurance?

More directly every year. Cyber insurance applications have become evidence-based audits, and the questions map almost one to one onto this checklist: written program, named owner, MFA, encryption, vendor management, training. A current WISP with documentation behind it does three things for you at renewal:

Treat the WISP as one artifact serving three audiences: the regulator, the insurer, and the enterprise customers who send security questionnaires.

Where do AI tools fit into your WISP?

This is the newest gap we find in Massachusetts programs. The regulation's vendor oversight and risk assessment requirements were written long before generative AI, but they cover it cleanly: an AI tool that touches personal information is a third-party service provider, full stop. If an employee pastes payroll data into a personal ChatGPT account, personal information has moved to a vendor you never assessed, under terms you never reviewed, outside every safeguard your WISP describes.

Practically, that means three additions to a 2026-era program: include AI tools in your annual risk assessment, name the approved tools and prohibited data types in policy, and verify that any approved AI vendor offers no-training commitments and retention controls in writing. If your WISP has not been touched since ChatGPT launched, it is describing a company that no longer exists. We cover the employee side of this in our shadow AI guide.

Key takeaway: If you hold personal information on a single Massachusetts resident, you are required to have a written, current, actually-followed information security program. The nine items above are the whole test. Most mid-sized companies can close every gap in one quarter, and the same work cuts insurance friction and speeds up sales questionnaires.

Frequently asked questions

Does 201 CMR 17.00 apply to companies outside Massachusetts?

Yes. The regulation follows the data, not the company. If your business owns or licenses personal information about even one Massachusetts resident, an employee or a customer, 201 CMR 17.00 applies regardless of where you are headquartered. A New Hampshire firm with two Massachusetts employees is covered.

Is there a small business exemption to 201 CMR 17.00?

No. There is no headcount or revenue exemption. The regulation applies a risk-based standard instead: your safeguards should match your size, resources, the amount of data you hold, and the sensitivity of that data. A 10-person firm needs a real WISP, but a simpler one than a hospital.

How often should we update our WISP?

Review it at least annually, and any time there is a material change in your business practices: new systems, new vendors, a merger, remote work changes, or AI tools that touch personal information. The regulation also requires a post-incident review after any breach. Most companies pair the annual WISP review with their cyber insurance renewal.

Next step

If you need a WISP built or brought up to date, our cybersecurity consulting practice runs the risk assessment and delivers the program in writing. If you need someone to own it year round, including the annual review, insurance renewal, and training calendar, that is what our vCISO service does every month.

Want a quick read on where you stand first? The free Business AI Maturity Assessment scores you across six dimensions, including governance and security.

Is your WISP real, or a PDF nobody has opened since 2019?

Get a scored baseline in ten minutes, or talk to us about building a program that satisfies the regulator, the insurer, and your biggest customer.

Take the free AI Assessment