Nacha: ACH Supplemental Security Requirements for Data at Rest
Blog post from Basis Theory
Nacha’s updated ACH security rules require organizations that store bank account numbers electronically to make them unreadable at rest, responding to the growing scale of ACH transfers and the risks associated with account-number fraud. ACH is a U.S. bank-transfer network that processed nearly 27 billion payments worth almost $62 trillion in 2020, and its transactions rely on routing and account numbers to direct funds between financial institutions. The requirement was introduced in phases, applying from June 30, 2021 to ACH originators and third parties initiating more than 6 million annual payments, and from June 30, 2022 to those exceeding 2 million, with totals assessed across financial partners. It covers 5-to-17-digit deposit account numbers, including numbers visible in scanned checks or authorization forms, but does not currently extend to names, amounts, or routing numbers; actively used account data may remain readable under appropriate access controls. The discussion notes that companies are pursuing approaches such as encryption, tokenization, aliasing, and masking to comply while limiting operational disruption, and suggests many are voluntarily securing additional transaction data in anticipation of broader future requirements.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.