The IRS Security Six are the six baseline protections the IRS expects every tax professional to have in place: antivirus software, a firewall, multi-factor authentication, backup, drive encryption, and a VPN. The list comes from the IRS Taxes-Security-Together Checklist and anchors the Security Summit’s 2026 “Protect Your Clients; Protect Yourself” campaign. Implementing the six is a firm-level project: each control needs an owner, a working configuration, and a line of evidence in your WISP.
Key takeaways
The Security Six: antivirus software, a firewall, multi-factor authentication, backup, drive encryption, and a VPN.
They anchor the 2026 five-week “Protect Your Clients; Protect Yourself” Security Summit campaign.
Each control needs an owner, a working setup, and a WISP entry naming the product and the review date.
Five of the six are VeritComplete line items from $129 per user per month; drive encryption is covered on hosted infrastructure and managed devices.
Table of Contents
What are the IRS Security Six?
The Security Six are the baseline protections the IRS asks every tax professional to put in place: antivirus software, a firewall, multi-factor authentication, backup software or services, drive encryption, and a virtual private network. They lead the IRS Taxes-Security-Together Checklist, and IRS Publication 4557 carries the same expectations for anyone with a PTIN.
The list comes from the IRS Taxes-Security-Together Checklist, published by the Security Summit, the partnership between the IRS, state tax agencies, and the private-sector tax industry. Deploying the Security Six is the checklist’s first step. Writing a data security plan, the WISP, is its second: the six controls are what you do, and the WISP is where you prove you did it. IRS Publication 4557, Safeguarding Taxpayer Data, sets out the same safeguards in detail.
The six controls:
Antivirus software that scans files for malware and updates itself automatically
A firewall between your systems and outside traffic
Multi-factor authentication as a second layer on account logins
Backup of critical files to external media or secure cloud storage
Drive encryption so a lost or stolen device holds unreadable data
A VPN for staff connecting from outside the office
None of this is exotic: it’s baseline cybersecurity work most firms already have pieces of. The gap at most small firms isn’t awareness, it’s follow-through: the antivirus that never updated, the firewall still on default settings, the backup nobody has ever restored from.
Why do the Security Six matter more in 2026?
The Security Six anchor the 2026 edition of “Protect Your Clients; Protect Yourself,” the Security Summit’s five-week summer campaign for tax professionals. The campaign is a joint effort of the IRS, state tax agencies, and the tax industry, and it points firms back at the same six controls Publication 4557 expects.
The 2026 campaign runs five weeks, and CPA Practice Advisor’s July 2026 coverage is blunt about what it means in practice: the IRS keeps repeating the same short list because that list is where preparer data losses actually start. The bar isn’t moving. A firm that works through the six controls once, and writes down what it did, is answering the same question the IRS will ask again next summer.
How do you implement each of the Security Six at a small firm?
Implementation is the same loop six times: pick the control’s owner, put it in place on every machine that touches client data, and write the evidence into your WISP. Here is what the IRS expects for each control, what the work involves at a small firm, and what to record.
1. Antivirus software
What the IRS expects: security software on every computer that scans for malware and updates automatically, per the Taxes-Security-Together Checklist.
What it involves at a small firm: one decision and one afternoon. Pick a business-grade product with EDR, the layer that watches for attack behavior instead of just known virus signatures, install it on every workstation and laptop, turn on automatic updates, and name the person who checks the alerts. The consumer antivirus that shipped with the laptop, installed once and never opened again, is the version of this control that fails quietly.
What your WISP records: the product name, the devices it covers, the automatic-update setting, and who reviews alerts.
2. Firewall
What the IRS expects: a barrier between anything holding taxpayer data and outside traffic.
What it involves at a small firm: most business routers ship with a firewall built in, so the work is confirmation, not purchase: verify it’s turned on, change the default admin password, and close the ports nothing uses. Firms on a hosted server inherit a managed firewall around the environment where client data actually lives.
What your WISP records: the firewall in use (router model or hosting provider), who manages it, and when the settings were last reviewed.
3. Multi-factor authentication
What the IRS expects: a second factor beyond the password on accounts that touch taxpayer data. The FTC Safeguards Rule sets the same expectation for information systems, so one enrollment effort covers both.
What it involves at a small firm: turning it on where it already exists. Tax software, email, cloud storage, and hosted desktops all offer MFA; the work is enrolling every employee and chasing down whoever finds it annoying. Use an authenticator app over text messages where the option exists, and do the enrollment in one sitting so it doesn’t trail off half-finished.
What your WISP records: which systems have MFA enabled, the factor type, and the enrollment date for each employee.
4. Backup
What the IRS expects: critical files backed up routinely to external media or secure cloud storage.
What it involves at a small firm: three properties, checked in order: automatic (a human clicking “back up now” is a control that stops working in March), off-site (a drive in the same office burns in the same fire), and tested. Restore one file each quarter to prove the backup is real; a backup that has never been restored from is a hope, not a control.
What your WISP records: what gets backed up, the schedule, the retention period, where copies live, and the date of the last test restore.
5. Drive encryption
What the IRS expects: full-disk encryption on devices that hold taxpayer data, so a lost or stolen machine exposes ciphertext instead of client returns.
What it involves at a small firm: Windows Pro editions include BitLocker at no extra cost. Enable it on each workstation and laptop that stores client files, and keep the recovery keys somewhere other than the laptop bag. Firms on a hosted server shrink this job: client data sits on encrypted infrastructure instead of scattered local drives, and only the machines still in play need attention.
What your WISP records: which devices are encrypted, the method, and where recovery keys are stored.
6. Virtual private network (VPN)
What the IRS expects: an encrypted connection whenever staff work over networks the firm doesn’t control.
What it involves at a small firm: for a traditional office network with remote staff, a VPN service configured on every remote laptop, set as mandatory rather than optional. Left to individual discretion, it’s off exactly when someone files from hotel Wi-Fi. On a hosted desktop model, the connection to the server is already encrypted; the VPN covers everything else staff do remotely.
What your WISP records: the VPN product, who has accounts, and when remote-access rules were last reviewed.
“I love the fact that I can work from anywhere and be absolutely (100%) productive. I also really appreciate the fact that Verito has truly invested in security to make sure no one accesses my information.”
Steven J., Owner, Jacobson Clergy Tax Service LLC · G2, Jul 2025
Which VeritComplete line items cover the Security Six?
Five of the six controls are named line items in VeritComplete, Verito’s hosting-plus-managed-IT bundle: antivirus with EDR, a managed firewall, multi-factor authentication, backup, and VPN access. Drive encryption is covered on the hosted infrastructure and on managed devices. Plans cost $129, $199, and $249 per user per month.
Control
What the IRS expects
DIY effort
VeritComplete line item
Antivirus
Security software that scans for malware and updates automatically
Pick a business-grade product, install it on every machine, watch the alerts yourself
Antivirus with EDR on every tier
Firewall
A barrier between taxpayer data and outside traffic
Configure the router firewall, change default credentials, review port rules
Managed firewall around the dedicated private server
Multi-factor authentication
A second factor on every account touching taxpayer data
Enable it per app, enroll each employee, chase the holdouts
MFA on every tier, plus identity management and 1Password Enterprise on Pro and Elite
Backup
Routine backup of critical files to external media or secure cloud
Buy backup software, schedule it, test restores quarterly
Server backups with 60-day retention (90-day on Elite), plus device backup from 250 GB to 1 TB by tier
Drive encryption
Full-disk encryption on devices holding client data
Enable BitLocker on each device, manage the recovery keys
256-bit encryption on the hosted environment; managed devices covered
VPN
An encrypted connection for remote work
Choose a provider, configure every remote laptop, keep it mandatory
VPN access on every tier (Lite on Essentials, Full on Pro and Elite)
VeritComplete puts the hosted server and the managed-IT layer under one agreement at $129, $199, or $249 per user per month, and every tier includes the full VeritShield WISP: the same $999-per-year document sold standalone, with unlimited revisions through the year. That closes the checklist’s second step, the written plan, in the same purchase. The environment itself is designed to support IRS Pub 4557 and FTC Safeguards requirements, with SOC 2 Type II and ISO 27001 certified infrastructure behind it.
Firms that want to keep their current hosting can pick up the device-security half on its own through VeritGuard, priced per device at $79, $149, or $199 per device per month. Either way, the six controls and the WISP evidence for them come from the same people, so nothing on the checklist sits waiting on a second vendor. 1,000+ tax and accounting firms already run on Verito, rated 4.9/5 across 170+ G2 reviews.
“Secure hosting platform. If there are ever any issues, I call, someone answers immediately and my problem is resolved in a few minutes or less.”
Put an owner on each control, write the evidence into your WISP, and the 2026 campaign becomes a checklist your firm has already finished. If the IRS or your insurance carrier asks, you have an answer with a date on it.Sources
Camren Majors is co-founder and Chief Revenue Officer of Verito Technologies, a cloud hosting and managed IT company built exclusively for tax and accounting firms. He is the co-author of Beyond Best Practices: Modernizing the Successful Accounting Firm (2026). His work has been featured in NATP TAXPRO Magazine and he has presented for NATP, NAEA, and NSA.
Practice management software runs your firm's clients, projects, deadlines, and time in one place. How to pick the right tool for your firm and host it securely.