
The best cloud hosting for tax professionals combines the tax preparation software your staff already uses with security controls that satisfy IRS Publication 4557, the IRS's guide to safeguarding taxpayer dataIRS Publication 1075, the federal standard for systems that handle Federal Tax Information (FTI), and the FTC Safeguards Rule, the Federal Trade Commission's data security regulation for financial institutions that include tax preparers. For the 2026 filing season, that means a provider running SOC 2 Type II certified data centers, AES-256 encryption for stored data, TLS 1.2 or higher for data in transit, mandatory multi-factor authentication (MFA), and a signed contract guaranteeing that FTI stays on U.S. servers.
According to IBM's 2024 Cost of a Data Breach Report, the average data breach now costs $4.88 million. The FTC can also assess civil penalties up to $46,517 per violation of the Safeguards Rule. A cloud vendor that cuts corners on security puts more than client data at risk. It can jeopardize your firm's Electronic Filing Identification Number (EFIN) and its ability to e-file returns at all.
Quick Answer
The best cloud hosting for tax professionals is a SOC 2 Type II certified platform, either a browser-based SaaS tax program or a hosted virtual desktop for software like Intuit ProSeries, Thomson Reuters UltraTax, or Drake Tax, that enforces MFA, encrypts data with AES-256 and TLS 1.2 or higher, and contractually guarantees U.S.-only data residency for Federal Tax Information. Before signing, confirm the vendor can demonstrate IRS Publication 1075 compliance and a documented incident response process, and plan to update your Written Information Security Plan (WISP) to reflect the new vendor relationship.
SaaS or Hosted Desktop: Which Model Fits Your Firm
Most small and mid-sized practices choose between two hosting models. Software as a Service (SaaS) platforms run entirely in a browser with no local install, are typically billed per return or per preparer seat, and push security updates automatically. Infrastructure as a Service (IaaS) hosting, offered by providers such as Rightworks, Ace Cloud Hosting, Summit Hosting, and Verito, puts your existing desktop software, ProSeries, CCH Axcess Tax, UltraTax, or Drake, on a hosted virtual machine you access remotely, typically priced $40 to $120 per user per month on top of your existing software license. Platform as a Service (PaaS) options exist for firms building custom system integrations, but they rarely make sense outside larger, multi-system practices.
Whichever model you choose, the vendor contract must state that FTI stays on U.S. servers. Offshore storage of FTI is a compliance failure that can trigger suspension of your e-filing privileges. For a broader look at securing any small business's cloud environment, see our cloud security guide for small businesses.
Cloud Provider Evaluation Checklist
- Verify a current SOC 2 Type II attestation covering security and confidentiality
- Confirm a contractual guarantee of U.S.-only data residency for Federal Tax Information
- Validate IRS Publication 1075 compliance through a completed security questionnaire
- Confirm AES-256 encryption at rest and TLS 1.2 or higher in transit
- Require multi-factor authentication on every account with no exceptions
- Confirm backup retention of at least 30 days with tested point-in-time recovery
- Review breach notification timelines and incident response procedures before signing
- Confirm an uptime SLA of 99.9% or better with financial remedies for outages
MFA Is a Requirement, Not a Preference
Multi-factor authentication (MFA) is a security control that requires two or more independent proofs of identity before granting access, such as a password plus a code from an authenticator app. IRS Publication 5293, the IRS's data security resource guide for tax professionals, and the FTC Safeguards Rule both require MFA for any system that holds taxpayer or customer financial data. Phishing-resistant options, FIDO2/WebAuthn security keys or authenticator apps, hold up better than SMS text codes, which remain vulnerable to SIM-swapping attacks.
See our guide to setting up MFA on your IRS Tax Pro Account for step-by-step setup instructions. For the full list of federal security obligations tied to your cloud environment, see our IRS Publication 4557 compliance guide and our IRS WISP requirements guide.
Update Your WISP Before You Migrate
Every cloud vendor, data flow, and access control tied to tax data has to be documented in your Written Information Security Plan. A custom WISP starts at $749 for practices with up to 5 users, with larger practices quoted separately.
Talk with a cybersecurity expert
Bellator Cyber Guard helps tax practices evaluate cloud providers, configure MFA and access controls, and keep WISP documentation current.
Frequently Asked Questions
IRS Publication 1075 does not name SOC 2 specifically, but SOC 2 Type II attestation is the standard way vendors document the physical and logical security controls Publication 1075 requires. Ask any cloud provider for their current SOC 2 Type II report before signing a contract.
General-purpose file storage services are not built to meet IRS Publication 1075 or FTC Safeguards Rule requirements on their own. Tax practices need a dedicated client portal or encrypted document exchange tool backed by a signed data processing agreement covering Federal Tax Information.
SaaS tax platforms are usually billed per return or per preparer seat. Hosted desktop software, such as ProSeries, UltraTax, or Drake, through an IaaS provider typically runs $40 to $120 per user per month, in addition to your existing software license.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.


