Tax preparers in 2026 sit under two overlapping mandates. The IRS requires every professional preparer to maintain a Written Information Security Plan, spelled out in Publications 4557 and 5708, with the Security Six as the technical baseline. The FTC Safeguards Rule (16 CFR Part 314) adds enforced controls on top: MFA, encryption, vendor oversight, an incident response plan, and a 30-day breach notification duty.
Key takeaways
Every paid preparer must keep a WISP; IRS Publication 5708 states it is required by law.
The IRS Security Six set the technical floor: antivirus, firewall, MFA, backup, drive encryption, VPN.
The FTC Safeguards Rule (16 CFR 314) adds a qualified individual, risk assessment, encryption, vendor oversight, and training.
Breaches of unencrypted data affecting 500 or more consumers must reach the FTC within 30 days.
Requirements are proven with dated documents, not intentions.
Table of Contents
What does the IRS actually require from tax preparers?
IRS Publication 4557 directs every professional tax preparer to safeguard taxpayer data, and IRS Publication 5708 states plainly that tax professionals are required by law to maintain a Written Information Security Plan. The obligation attaches to the PTIN: Form W-12 has you attest to your data security responsibilities under penalty of perjury.
Publication 4557, Safeguarding Taxpayer Data, is the IRS’s core security document for preparers. It covers access controls, encryption, secure remote work, data disposal, and breach response, and it points preparers to the FTC Safeguards Rule by name. Publication 5708 is the companion piece: a plain-language guide to creating the WISP itself, with a template you can start from.
Neither Publication 4557 nor Publication 5708 is a suggestion. Line 11 of Form W-12, the PTIN application and renewal form, is a data security responsibilities checkbox confirming you’re aware of the requirement to safeguard taxpayer data, and the form’s signature block is signed under penalty of perjury. Checking that box each renewal without a plan on file creates a gap between what you certified and what exists in your practice, and that gap puts the PTIN at risk. No PTIN means no paid return preparation.
So the IRS layer comes down to one deliverable: a written, dated, current WISP that reflects how your firm actually works.
What are the IRS Security Six?
The Security Six are the IRS’s baseline technical controls for tax professionals: antivirus software, firewalls, multi-factor authentication, backup software or services, drive encryption, and a VPN. They come from the IRS Tax Security 2.0 checklist and cover every device that touches client data, office or home.
The IRS publishes the list in its Taxes-Security-Together checklist, built with state tax agencies and the tax industry through the Security Summit. In practice:
Antivirus software, kept current and set to scan automatically
Firewalls between your network and the internet
Multi-factor authentication on tax software, email, and anything holding client data
Backup software or services, so client files survive ransomware or a dead drive
Drive encryption, so a stolen laptop holds ciphertext instead of client SSNs
A VPN for any staff member connecting from outside the office
The FTC Safeguards Rule, 16 CFR Part 314, treats professional tax preparers as financial institutions and adds specific mandates on top of the IRS baseline: a qualified individual, a written risk assessment, MFA, encryption in transit and at rest, vendor oversight, employee training, and a written incident response plan.
The rule, codified at 16 CFR Part 314, lists tax preparation firms among its covered examples at 16 CFR 314.2(h). Where Publication 4557 describes good practice, the Safeguards Rule assigns duties:
A qualified individual designated to oversee the security program (314.4(a))
A written risk assessment covering the data you hold and the threats to it (314.4(b))
Technical safeguards, including access controls, MFA, and encryption of customer information in transit and at rest (314.4(c))
Employee training so staff can carry out the program (314.4(e))
Service provider oversight: selecting capable vendors and requiring safeguards by contract (314.4(f))
A written incident response plan (314.4(h))
The FTC’s compliance guide walks through each element in plain terms. The practical read for a tax firm: your hosting provider’s certifications don’t replace your obligations. Vendor due diligence is a section of your plan, not a substitute for it. Verito’s full walkthrough of the rule is in how to comply with the FTC Safeguards Rule.
Do these rules apply to a three-person firm?
Yes. The 2021 amendments to 16 CFR Part 314 did not exempt small firms from the rule itself, and IRS Publication 5708 says a WISP scales with the size, scope, and complexity of the practice. A solo preparer’s plan can be short. It still has to exist.
Coverage turns on the data you handle, not your headcount. If your firm holds SSNs, bank and routing numbers, payroll records, or prior-year returns, the obligations apply, whether that’s one preparer or forty. What changes with size is proportion: Publication 5708 is explicit that the plan should match the firm’s size, scope of activities, complexity, and the sensitivity of the customer data it handles. A two-page WISP that accurately describes a solo practice beats a 40-page template nobody follows, because the accurate one is defensible when someone asks for it. Three parties can ask: the IRS after an incident, the FTC after a reported breach, and, most often in practice, your cyber insurance carrier at renewal.
When does a breach have to be reported?
Since May 13, 2024, firms must notify the FTC no later than 30 days after discovering a security event involving the unencrypted information of at least 500 consumers. Unauthorized access to unencrypted data is presumed to be acquisition, and the IRS separately asks breached preparers to contact their Stakeholder Liaison.
The notification requirement has three moving parts worth fixing in memory. The clock is 30 days from discovery, not from the end of your investigation. The threshold is 500 consumers, not 500 clients; a single 1040 file usually covers spouses and dependents, so a few hundred households can cross the line. And the trigger is unencrypted data: if the information was encrypted and the key stayed protected, the event doesn’t meet the rule’s definition of a notification event, which makes encryption the one control that changes what a bad day costs.
The IRS runs its own track. Its data theft page for tax professionals asks breached firms to contact their IRS Stakeholder Liaison right away, so fraudulent returns can be flagged before refunds go out, and to notify the state tax agencies where they file. One filing never satisfies another: telling the FTC does not tell the IRS, and neither notifies your state.
Which requirements apply, and what counts as evidence?
Every requirement resolves to a document someone can hand over: a dated WISP, a written risk assessment, MFA enforced everywhere client data lives, encrypted systems, training records, vendor contracts, and an incident response plan with names in it. The table maps each mandate to its source and the evidence that satisfies it.
Requirement
Where the mandate comes from
What evidence looks like
Written Information Security Plan (WISP)
IRS Pub 4557 and Pub 5708; 16 CFR 314.3
A dated, signed plan naming your security coordinator, reviewed at least annually
Named person responsible for security
16 CFR 314.4(a)
The qualified individual named in the WISP, with the duty in writing
Risk assessment
16 CFR 314.4(b); Pub 4557
A written document listing the data you hold, the threats to it, and the date you last revisited it
Multi-factor authentication
16 CFR 314.4(c); IRS Security Six
MFA enforced on every system holding client data, visible in each system’s security settings
Encryption in transit and at rest
16 CFR 314.4(c); IRS Security Six
Encrypted drives and servers, with the configuration documented in the WISP
Employee security training
16 CFR 314.4(e); Pub 4557
Training dates and staff sign-offs on file
Vendor oversight
16 CFR 314.4(f)
Contracts requiring safeguards, plus each vendor’s SOC 2 report on file
Incident response plan
16 CFR 314.4(h)
A written plan with names, steps, and a notification tree
FTC breach notification
Safeguards Rule amendment, effective May 13, 2024
A procedure for filing with the FTC within 30 days of discovery
The Security Six controls
IRS Tax Security 2.0 checklist
Antivirus, firewall, MFA, backup, drive encryption, and VPN active on every device
The pattern across every row: regulators and insurance carriers accept paper, dates, and settings. They don’t accept “our IT person handles it.” If a control can’t produce evidence, treat it as not implemented and fix the documentation first.
Where do firms usually fall short?
Most gaps come from scattered responsibility, not missing tools. Hosting enforces MFA while email doesn’t, backups exist but nobody has tested a restore, and former staff keep working logins. The FTC’s vendor oversight duty at 16 CFR 314.4(f) makes those gaps the firm’s problem, not the vendors’.
A typical small firm splits its environment across a hosting provider, an IT freelancer, a standalone antivirus tool, and a separate email host, with no one seeing the whole picture. Each vendor secures their piece. The breach happens in the seams: the hosting platform requires MFA but the email account doesn’t, so a phishing click hands over the inbox, and the inbox resets every other password. Backups exist but the first restore attempt happens after ransomware, which is the worst possible time to learn they’re broken. An account for someone who left in March still works in November.
The Safeguards Rule anticipates exactly this. The vendor oversight duty means your firm, not the vendor, answers for the whole chain, and your WISP is where the chain gets documented: which provider covers which control, and what you’ve verified. Firms whose hosting, devices, and monitoring are handled by the same people close the seams by architecture instead of by memo.
“Downtime is rare, support services (when needed) are quick, my WISP is in place, my data is backed up and secure, and updates are seamless.”
Jennifer C., Owner, J T Clark CPA LLC · G2, Aug 2025
How does Verito cover these requirements?
VeritShield WISP delivers a custom written plan designed to support IRS Pub 4557 and FTC Safeguards requirements for $999 per year with unlimited revisions. VeritGuard covers devices from $79 per device per month, and VeritComplete bundles hosting plus managed IT from $129 per user per month with the WISP included.
Start where the regulators start, with the plan. VeritShield WISP is a $999-per-year subscription: a 30-minute scoping call, then a plan built around your firm’s size, software, and workflow, delivered in 5 business days, with unlimited revisions as your firm changes through the year. You don’t need to be a Verito hosting customer to buy it.
The technical controls map to the other two products. VeritGuard is managed IT priced per device ($79, $149, or $199 per device per month) with antivirus and EDR on every tier, security training and the full WISP included from the Pro tier up, an annual FTC Safeguards audit on Pro and a bi-annual one on Elite, plus 24/7 SOC and dark web monitoring on Elite. VeritSpace hosting puts your tax software and QuickBooks on a dedicated private server with 256-bit encryption, MFA, and backups 4x daily, on infrastructure that is SOC 2 Type II and ISO 27001 certified, from $69 per user per month. VeritComplete bundles hosting and managed IT from $129 per user per month with the full WISP included on every tier.
Sponsored by Verito
Verito hosts Drake, Lacerte, UltraTax, and QuickBooks on private dedicated servers — with 24/7 support from techs who actually know tax software. Used by 1,000+ accounting firms.
See plans from $69/user →
Behind the products: 1,000+ tax and accounting firms, 100% uptime since 2016, a 4.9/5 rating across 170+ G2 reviews, and a team that answers in under 60 seconds. If you want to know where your firm stands before touching any product, a free 30-minute security assessment maps your current posture against the IRS and FTC requirements in this article.
“I value the robust firewall that Verito provides, helping me maintain compliance with WISP and ensuring the protection of client data.”
Carrol G., Owner, Gatlin Tax, Ltd · G2, Nov 2025
If the IRS, the FTC, or your insurance carrier asks, you have an answer. That’s the whole standard these requirements set, and it’s reachable for a firm of any size.
Camren Majors is co-founder and Chief Revenue Officer of Verito Technologies, a cloud hosting and managed IT company built exclusively for tax and accounting firms. He is the co-author of Beyond Best Practices: Modernizing the Successful Accounting Firm (2026). His work has been featured in NATP TAXPRO Magazine and he has presented for NATP, NAEA, and NSA.