By Joseph Boyd, MBA, Founder and Principal Advisor at Infosec CheckLast updated
Direct answer
Tax and accounting professionals that prepare income tax returns are treated as financial institutions under the FTC Safeguards Rule and must develop, implement and maintain a written information security program. IRS publications commonly call this a Written Information Security Plan, or WISP.
The core requirements include assigning a Qualified Individual, assessing risk, implementing administrative, technical and physical safeguards, using multi-factor authentication, protecting customer information, training personnel, overseeing service providers, testing safeguards and updating the program. Some detailed requirements are limited for financial institutions that maintain customer information concerning fewer than 5,000 consumers, but that exception does not eliminate the WISP or the core information-security program.
Authorized IRS e-file Providers may have additional requirements under IRS Publication 1345. The first five security, privacy and business standards primarily apply to Online Providers, while security-incident reporting applies to all Authorized IRS e-file Providers covered by that publication.
Written by Joseph Boyd, MBA, Founder and Principal Advisor at Infosec Check
Published · Last reviewed
Scope: Cybersecurity and taxpayer-data safeguards for United States tax preparation and accounting practices · Jurisdiction: United States
This page provides general educational and risk-management information. It is not legal advice, an audit, a certification or a determination that a particular requirement applies to a specific firm. Requirements depend on the services performed, information maintained, e-file role, customer count, contracts, state law and other facts.
What are “IRS cybersecurity requirements”?
Short answer: The phrase is useful search language, but the obligations do not come from one IRS cybersecurity rule.
Three sources are often grouped together:
- The FTC Safeguards Rule is the core federal regulation. The Rule is codified at 16 CFR Part 314. It treats an accountant or tax preparation service that is in the business of completing income tax returns as a financial institution and requires a comprehensive information security program.
- IRS Publications 4557 and 5708 explain taxpayer-data protection and WISP development. IRS Publication 4557 provides safeguarding guidance. IRS Publication 5708 provides a WISP outline and sample template for tax and accounting practices.
- IRS Publication 1345 adds rules for Authorized IRS e-file Providers. Publication 1345 addresses participation in IRS e-file and includes additional security, privacy, business and incident-reporting standards.
The distinction matters. IRS publications explain responsibilities and, in the case of Publication 1345, establish participation rules for IRS e-file. The FTC Safeguards Rule supplies the enforceable information-security program requirements discussed throughout the IRS materials.
Are tax preparers required to have a Written Information Security Plan?
Short answer: Yes. The IRS states that federal law requires tax and accounting professionals to create and maintain a WISP.
In its August 18, 2026 reminder, the IRS and Security Summit said tax professionals are legally required to maintain a written, accessible plan and should review, test and update it regularly.
The requirement is not satisfied merely by owning antivirus software, using tax-preparation software or hiring an IT provider. A WISP is the written governance structure that connects risks, responsibilities, safeguards, training, vendors, testing, incident procedures and supporting evidence.
The information security program must be appropriate to the size and complexity of the practice, the nature and scope of its work, and the sensitivity of the customer information involved. A sole practitioner may have a shorter and simpler WISP than a large regional accounting firm, but small size does not eliminate the WISP requirement.
Who is covered?
The Safeguards Rule expressly identifies an accountant or tax preparation service that is in the business of completing income tax returns as a financial institution. IRS Publication 5708 describes tax and accounting professionals as financial institutions regardless of size.
Coverage should still be evaluated against the firm's actual activities. A business that prepares returns, stores taxpayer records, operates an online tax platform, transmits returns as an Authorized IRS e-file Provider or performs several financial activities may have overlapping responsibilities.
Important distinctions include:
- A professional tax preparer may be subject to the Safeguards Rule and WISP requirement.
- An Authorized IRS e-file Provider must also review the current IRS e-file participation rules.
- An Online Provider may be subject to the first five additional security, privacy and business standards in Publication 1345.
- An Electronic Return Originator, or ERO, may have specific IRS incident-reporting instructions.
- A firm may also have duties under state breach-notification laws, customer contracts, software agreements and cyber insurance representations.
Do not assume that every requirement described for an Online Provider applies to every neighborhood tax office. Do not assume that using a third-party tax platform transfers all responsibility away from the practice either.
What does the FTC Safeguards Rule require from a tax practice?
The following requirements form the core of an effective information security program. The exact implementation must be based on the practice's facts and risk assessment.
1. Maintain a written information security program
The firm must develop, implement and maintain a comprehensive program containing administrative, technical and physical safeguards. The program should be written in one or more readily accessible parts and should reflect how the firm actually operates.
2. Designate a Qualified Individual
A Qualified Individual must oversee, implement and enforce the information security program. The person may be an employee, affiliate or service provider. No particular job title or certification is automatically required, but the individual must have knowledge suited to the firm's circumstances.
If an outside provider serves as the Qualified Individual, the firm retains responsibility and must designate a senior member of its own personnel to supervise that relationship.
3. Assess risks to customer information
The program must be based on an assessment of reasonably foreseeable internal and external risks. That means identifying the taxpayer and customer information the firm handles, where it is stored, who can access it, how it moves, which vendors touch it, and how it could be disclosed, misused, altered, destroyed or otherwise compromised.
Risk assessment is not a one-time exercise. It should be revisited when systems, personnel, vendors, locations, services or threats change.
4. Implement safeguards based on the risks
Required safeguards can include:
- Access controls that limit customer information to authorized users with a legitimate need
- An inventory of data, personnel, devices, systems and facilities
- Encryption of customer information in transit and at rest, or documented compensating controls when encryption is infeasible
- Procedures for assessing the security of applications that handle customer information
- Multi-factor authentication for individuals accessing information systems, unless the Qualified Individual approves a reasonably equivalent or stronger control in writing
- Secure data-retention and disposal procedures
- Change-management procedures
- Logging and monitoring designed to detect unauthorized access, use or tampering
A policy stating that a safeguard exists is not the same as evidence that it is configured, operating, monitored and reviewed.
5. Test or monitor safeguard effectiveness
The firm must regularly test or otherwise monitor the effectiveness of key controls, systems and procedures, including controls intended to detect attacks and intrusions.
The Rule contains more prescriptive testing provisions for firms that maintain customer information concerning 5,000 or more consumers. Smaller firms are excepted from that specific subsection, but not from the general requirement to test or monitor safeguards.
6. Provide cybersecurity awareness training
Personnel must receive security awareness training that is updated as necessary to reflect the risks identified by the risk assessment. This is a direct program element, not an optional extra.
Training should address the decisions people actually make, including phishing, false login pages, malicious attachments, social engineering, altered payment or refund instructions, unsafe document exchange, account recovery, suspicious remote-access requests and reporting potential incidents.
The IRS also emphasizes that professional and administrative personnel have roles in protecting taxpayer information.
7. Oversee service providers
The firm must take reasonable steps to select capable service providers, require appropriate safeguards by contract and periodically assess providers based on the risks they present.
Relevant providers may include tax software companies, hosted platforms, cloud storage providers, managed IT services, payroll vendors, document portals, shredding companies and contractors with access to customer information.
Vendor assurance is not the same as vendor oversight. The practice should know what the contract requires, what information the vendor can reach and what evidence supports the vendor's safeguards.
8. Evaluate and adjust the program
The information security program must change when testing, risk assessments, business operations, vendor relationships or other circumstances reveal a material issue. A WISP with an old date and no change record is difficult to defend as an operating program.
9. Prepare for security incidents
Firms maintaining customer information concerning 5,000 or more consumers are subject to the Rule's detailed written incident-response-plan provision. Smaller firms are excepted from that particular subsection, but the IRS strongly recommends that tax professionals develop a data-theft response plan.
Regardless of size, a firm should know who can isolate systems, preserve evidence, contact the IRS, reach its insurer and counsel, communicate with clients, coordinate with vendors and evaluate state or federal notification duties.
10. Report program status to leadership
For firms maintaining customer information concerning 5,000 or more consumers, the Qualified Individual must report in writing at least annually to the board or equivalent governing body. If the firm has no board, the report goes to the senior officer responsible for the program.
The report addresses the program's status, risk decisions, service providers, testing results, security events and recommended changes.
Does the fewer-than-5,000-consumers exception eliminate the WISP requirement?
Short answer: No. It narrows four specific provisions. It is not a blanket exemption from the Safeguards Rule.
The threshold concerns customer information maintained for fewer than 5,000 consumers. It is not an employee-count test, a revenue test or simply the number of returns prepared during the current year.
| Safeguards Rule element | Fewer than 5,000 consumers | 5,000 or more consumers |
|---|---|---|
| Written information security program | Required | Required |
| Qualified Individual | Required | Required |
| Risk assessment | Program must still be based on risk assessment; the detailed written requirements in section 314.4(b)(1) are excepted | Detailed written risk assessment requirements apply |
| Access controls, encryption, MFA, disposal, change management and logging | Required as applicable under the Rule | Required as applicable under the Rule |
| Regular testing or monitoring | Required | Required |
| Prescribed continuous monitoring or annual penetration testing and vulnerability-assessment cadence | Section 314.4(d)(2) is excepted | Applies |
| Security awareness training | Required | Required |
| Service-provider oversight | Required | Required |
| Written incident response plan under section 314.4(h) | Excepted, although IRS guidance recommends a response plan | Required |
| Annual written Qualified Individual report under section 314.4(i) | Excepted | Required |
| FTC notification for a qualifying event involving at least 500 consumers | Applies when the reporting trigger is met | Applies when the reporting trigger is met |
Because consumer counting and information scope can be fact-specific, firms should confirm how the threshold applies to their records and retention practices.
What additional IRS e-file cybersecurity requirements may apply?
IRS Publication 1345 separates general tax-professional safeguards from additional standards for Authorized IRS e-file Providers.
The first five standards continue to apply to Online Providers of individual income tax returns:
- An Extended Validation SSL certificate using the specified TLS and cryptographic standards
- Weekly external vulnerability scans performed by a qualifying independent scanning vendor
- A written information privacy and safeguards policy with the required statement and acceptable privacy-seal certification
- Protection against bulk filing of fraudulent returns
- Public domain-name registration meeting the IRS requirements
The sixth standard, reporting security incidents, applies to all Authorized IRS e-file Providers covered by Publication 1345. The publication states that a confirmed reportable security incident must be reported as soon as possible and no later than the next business day. EROs-only are directed to contact their local IRS Stakeholder Liaison using the IRS data-theft instructions.
These e-file standards should not be copied onto every tax practice without first identifying the firm's IRS e-file role. Publication 1345 refers readers to IRS Publication 3112 for the definition of Online Provider.
What are the cybersecurity incident-reporting deadlines?
Different authorities can create different reporting duties. One incident may trigger more than one timeline.
| Reporting channel | General trigger described by the source | Timing described by the source |
|---|---|---|
| IRS, under Publication 1345 | Confirmed reportable security incident affecting an Authorized IRS e-file Provider | As soon as possible, no later than the next business day |
| Federal Trade Commission | Notification event involving the information of at least 500 consumers | As soon as possible, no later than 30 days after discovery |
| State agencies and affected individuals | Depends on applicable state law, residency, information involved and incident facts | Varies by state and circumstance |
| Cyber insurance carrier | Depends on the policy's notice, consent and cooperation provisions | Follow the actual policy and carrier instructions |
These deadlines are not interchangeable. Contacting an IT provider does not necessarily satisfy notice to the IRS, FTC, state authorities, affected individuals or an insurer.
The IRS advises tax professionals to contact their IRS Stakeholder Liaison when taxpayer data is stolen or compromised. A firm facing an active incident should promptly coordinate technical response, evidence preservation, insurance notice and qualified legal guidance.
Is the IRS Publication 5708 WISP template enough by itself?
Short answer: No. Publication 5708 says its sample is not exhaustive and is not a substitute for a plan based on the specific needs and requirements of the business.
The template is a useful starting structure. It does not automatically establish that the firm assessed its own risks, configured safeguards, trained personnel, reviewed vendor contracts, tested controls or kept the program current.
A defensible WISP should connect each written statement to an owner and supporting evidence. Examples include:
- The approved WISP version and review history
- A current inventory of hardware, software, data locations and authorized users
- Risk-assessment records and risk-treatment decisions
- MFA and encryption configuration evidence
- Access reviews and employee offboarding records
- Security awareness training records
- Vendor contracts, reviews and follow-up decisions
- Vulnerability, monitoring or testing reports appropriate to the firm
- Incident-response contacts, procedures and exercise records
- Management review and approval records
The objective is not a larger binder. The objective is a program whose statements can be shown to be true.
An IRS cybersecurity readiness checklist for tax practices
Use this list as an executive screening tool, not as a substitute for an applicability review or legal advice.
- Confirm whether the firm prepares income tax returns and which IRS e-file roles it holds.
- Confirm the number of consumers whose customer information the firm maintains.
- Name the Qualified Individual and document leadership oversight.
- Maintain a current, accessible WISP that reflects actual operations.
- Inventory taxpayer information, systems, devices, applications, locations, users and vendors.
- Complete and update the firm's risk assessment.
- Verify MFA, encryption, access controls, logging, retention and secure disposal.
- Train personnel on current threats and the firm's procedures.
- Review service-provider contracts and evidence of safeguards.
- Test or monitor key safeguards and document results.
- Maintain incident contacts and procedures appropriate to the firm's size and obligations.
- Verify IRS, FTC, state and insurance reporting routes before an incident.
- Review the program after operational changes, test findings, vendor changes or security events.
Start with the people who handle taxpayer information
Technology cannot prevent every unsafe click, deceptive call, false login page or altered instruction. Infosec Check starts with Ante Up cybersecurity awareness training, a live monthly learning program that helps owners and employees recognize common threats, slow down, verify unusual requests and report concerns.
Ante Up is general education. Participation alone does not certify compliance with the Safeguards Rule, IRS guidance, a contract, an insurance requirement or any other framework.
From that foundation, a tax or accounting practice can add the compliance or IT guidance it actually needs. Infosec Check can help leadership examine regulatory applicability, WISP structure, risk assessment, vendor oversight, safeguard evidence, incident readiness and cyber insurance representations. Technical implementation can then be assigned to the firm's IT provider or another appropriate specialist with defined responsibilities and evidence requirements.
Frequently asked questions
Does the IRS require tax preparers to have a WISP?
The IRS states that federal law requires tax and accounting professionals to create and maintain a Written Information Security Plan. The underlying federal information-security requirements are primarily found in the FTC Safeguards Rule, while IRS Publications 4557 and 5708 explain taxpayer-data safeguards and WISP development for tax practices.
Does a sole tax preparer need a Written Information Security Plan?
Yes. Small size does not eliminate the WISP requirement. The plan may be shorter and less complex than the program of a large accounting firm, but it must be appropriate to the practice's activities and the sensitivity of the customer information it maintains.
Are firms with fewer than 5,000 customers exempt from the Safeguards Rule?
No. The Rule excepts firms maintaining customer information concerning fewer than 5,000 consumers from four specific provisions. The exception does not eliminate the written information security program, Qualified Individual, core safeguards, security awareness training, service-provider oversight or general testing and monitoring requirements.
Is multi-factor authentication required for tax preparers?
The Safeguards Rule requires multi-factor authentication for individuals accessing information systems unless the Qualified Individual approves in writing the use of reasonably equivalent or more secure access controls. IRS Publication 1345 also identifies MFA requirements affecting access to taxpayer information and online accounts.
Is cybersecurity awareness training required for a tax practice?
Yes. The Safeguards Rule requires security awareness training for personnel, updated as necessary to reflect risks identified by the firm's risk assessment. Training should be connected to the firm's actual threats, policies and reporting procedures.
Can an IT provider serve as the Qualified Individual?
Potentially. The Qualified Individual may work for a service provider, but the tax practice retains responsibility. The firm must designate a senior member of its own personnel to direct and oversee the outside Qualified Individual, and the service provider must maintain an information security program that protects the firm as required by the Rule.
Does using professional tax software make a firm compliant?
No. Secure tax software may support the program, but it does not replace the firm's responsibility for risk assessment, access, devices, email, employees, vendors, policies, training, incident response, testing and evidence.
How often should a tax practice update its WISP?
The program should be evaluated and adjusted when risk assessments, testing, operational changes, vendor changes or other circumstances may materially affect security. IRS Publication 5708 describes the WISP as an evergreen document and recommends reviewing it at least annually or when material business practices change.
When must a tax professional report a cybersecurity incident to the IRS?
IRS Publication 1345 states that Authorized IRS e-file Providers must report a confirmed reportable security incident as soon as possible and no later than the next business day. EROs-only are directed to contact their local IRS Stakeholder Liaison using the IRS data-theft instructions.
Does a WISP template prove compliance?
No. A template can help organize the plan, but it does not prove that the firm's risks were assessed, safeguards were implemented, personnel were trained, vendors were overseen, controls were tested or the program was updated.
Authoritative sources
- 16 CFR Part 314, Standards for Safeguarding Customer Information
Issuer: Electronic Code of Federal Regulations
Supports: The binding Safeguards Rule text, covered tax-preparation activity, required program elements, limited exceptions and FTC notification requirement.
- FTC Safeguards Rule: What Your Business Needs to Know
Issuer: Federal Trade Commission
Supports: Plain-language FTC explanation of information-security program requirements.
- IRS Publication 4557, Safeguarding Taxpayer Data
Issuer: Internal Revenue Service
Supports: Taxpayer-data safeguards, threat awareness, response guidance and the relationship to the FTC Safeguards Rule.
- IRS Publication 5708, Creating a Written Information Security Plan for Your Tax and Accounting Practice
Issuer: Internal Revenue Service
Supports: WISP requirements, planning structure, sample template and tax-practice implementation considerations.
- IRS Publication 1345, Authorized IRS e-file Providers of Individual Income Tax Returns
Issuer: Internal Revenue Service
Supports: Current IRS e-file participation standards, Online Provider requirements and security-incident reporting.
- IRS and Security Summit WISP reminder, August 18, 2026
Issuer: Internal Revenue Service
Supports: Current IRS statement that tax and accounting professionals must create and maintain a WISP and should review, test and update it.
Primary sources are cited for the specific point noted. They do not determine how a rule, contract, or policy applies to a particular organization.
Know what applies. Prove what is true. Fix what is not.
If your tax or accounting practice is uncertain whether its WISP, training, safeguards, vendor records and incident procedures match its responsibilities, Infosec Check can help leadership clarify the position and define the next step.
Call (855) 624-6262 or contact Infosec Check.
