Skip to content
Bellator Cyber Guard
Tax42 min readDeep Dive

Tax Preparer Cybersecurity Compliance 2025: What Changed

IRS PTIN and FTC Safeguards Rule requirements, WISP development, and penalties for tax preparers. Your complete 2026 compliance guide. Protect your practice.

By Bellator Cyber Guard Security Team
Tax Preparer Cybersecurity Compliance 2025: What Changed - tax preparer cybersecurity compliance 2025

What Tax Preparers Are Now Required to Do for Cybersecurity Compliance in 2026

Tax preparer cybersecurity compliance requirements that took shape in 2025 are now fully enforced mandates for the 2026 filing season, and the consequences for non-compliance extend directly to your ability to practice. The IRS ties your Preparer Tax Identification Number (PTIN) and Electronic Filing Identification Number (EFIN) to security compliance, meaning a failure to implement required controls is a threat to your license to prepare returns.

The regulatory urgency is grounded in real numbers. Tax-related identity theft resulted in over $2.3 billion in fraudulent refunds in 2024, with compromised tax professional credentials accounting for 34% of those incidents according to the IRS Criminal Investigation Division. Tax professionals handle more sensitive financial data per client than most financial institutions, including Social Security numbers, investment records, bank account details, and personally identifiable information, making them targets for sophisticated attacks designed to file fraudulent returns before your clients know they have been compromised.

Three federal frameworks govern what you must do: IRS Publication 4557, the FTC Safeguards Rule under 16 CFR § 314, and applicable state data breach notification laws. Together they require a Written Information Security Plan (WISP), specific technical controls including multi-factor authentication (MFA) and encryption, a designated Qualified Individual responsible for your security program, and documented employee training.

This guide walks through each requirement with the specificity needed to build a defensible compliance posture before the 2026 filing season closes.

Tax Cybersecurity By the Numbers

$2.3B
Fraudulent Refunds in 2024

IRS Criminal Investigation Division

34%
Breaches Via Compromised Tax Pro Credentials

IRS Criminal Investigation Division, 2024

$4.88M
Average Data Breach Cost

IBM Cost of Data Breach Report 2025

The Federal Regulatory Framework: Three Overlapping Mandates

Tax preparer cybersecurity compliance sits at the intersection of IRS credential requirements, FTC financial privacy law, and state breach notification statutes. Understanding how these frameworks overlap, and where they diverge, helps you avoid the gaps that regulators and forensic investigators look for after an incident.

IRS Publication 4557: The Security Six Foundation

IRS Publication 4557, titled "Safeguarding Taxpayer Data," establishes six baseline controls that apply to all return preparers who handle taxpayer information. These represent the minimum security posture the IRS expects before issuing or renewing PTIN and EFIN credentials:

  • Anti-virus and endpoint protection on every device that accesses tax systems
  • Firewalls preventing unauthorized inbound and outbound network access
  • Two-factor authentication on tax software, email, and cloud storage
  • Drive encryption protecting data at rest on laptops, desktops, and external drives
  • Backup procedures using offline or cloud-based storage with tested restoration
  • Software updates applied promptly to patch known vulnerabilities

The IRS can suspend or revoke PTIN and EFIN credentials for practitioners who fail to implement these controls. For a detailed breakdown of how credential requirements intersect with security documentation, see our guide to PTIN and WISP requirements for tax preparers.

FTC Safeguards Rule: Program-Level Security Requirements

The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule under 16 CFR § 314, enforced by the Federal Trade Commission, requires financial institutions to develop, implement, and maintain information security programs. Tax preparation firms qualify as financial institutions under GLBA. The June 2023 amendments removed prior size-based exemptions entirely, meaning solo practitioners and two-person offices face the same requirements as regional accounting firms.

The rule mandates designation of a Qualified Individual responsible for overseeing, implementing, and enforcing the security program. This person must have the authority and resources to implement controls and must report program status to the board or senior management at least annually. For solo practitioners, the tax professional typically serves as their own Qualified Individual. For the full scope of FTC requirements, our FTC Safeguards Rule guide for tax preparers covers each of the 16 program elements the rule specifies.

State breach notification laws add a third layer. All 50 states have notification statutes with varying timelines, scope thresholds, and agency reporting requirements. A breach affecting clients in multiple states may simultaneously trigger obligations in each jurisdiction where those clients reside, regardless of where your practice is located.

2026 Filing Season Compliance Deadline

The IRS and FTC expect all tax preparers to have an updated Written Information Security Plan in place before the 2026 filing season. Practitioners without a compliant plan risk PTIN suspension, EFIN revocation, and FTC civil penalties up to $100,000 per violation. Compliance gaps identified after a breach carry significantly higher costs than implementing controls before one occurs.

Written Information Security Plan: Your Compliance Backbone

The WISP sits at the center of both IRS and FTC compliance. IRS Publication 5708 provides a sample WISP structure the agency officially recommends, while the FTC Safeguards Rule specifies 16 program elements a compliant plan must address. A WISP that satisfies the FTC's requirements generally meets or exceeds IRS expectations at the same time.

A compliant WISP must document your risk assessment findings and remediation plans, describe the technical and administrative controls you have in place, name your Qualified Individual and define their responsibilities, outline your vendor oversight procedures, and specify your incident response and breach notification procedures.

The plan must be reviewed at minimum annually and updated whenever you add systems, change vendors, or experience a security incident. Each revision should carry a date, and prior versions should be retained for at least three years to demonstrate compliance history.

Our IRS Publication 5708 sample WISP guide explains how to use the agency's own template as your starting point, and our WISP template for tax preparers provides a ready-to-customize document aligned with both IRS Publication 4557 and the FTC Safeguards Rule. For a complete package, the all-in-one compliance package bundles templates, training resources, and review procedures into a single system.

Many practitioners download a template and file it away without customizing it to their actual environment. Regulators and forensic investigators examining a post-breach WISP will immediately identify generic language that does not reflect real controls. A document naming your specific tax software, your cloud storage provider, your MFA application, and your backup vendor is defensible under scrutiny. A generic one is not.

Tax Practice Security Implementation Roadmap

1

Designate Your Qualified Individual

Name the person responsible for your security program. For solo practitioners, this is you. Document the designation in your WISP with their contact information and defined responsibilities.

2

Complete a Written Risk Assessment

Inventory every system that stores or processes taxpayer data. Identify threats, vulnerabilities, and the likelihood and impact of each risk. Document findings and your remediation priorities.

3

Deploy Endpoint Protection

Install Endpoint Detection and Response (EDR) software on every device used for tax work. Configure automated scanning, behavioral monitoring, and real-time alerts for suspicious activity.

4

Enable Multi-Factor Authentication Everywhere

Turn on MFA for tax software, email, cloud document storage, client portals, and any remote access tools. Use an authenticator app rather than SMS for stronger protection against credential attacks.

5

Encrypt All Storage Devices

Enable BitLocker on Windows devices, FileVault on Macs, and encryption on all external drives and USB storage. Verify encryption is active before connecting devices to client systems.

6

Implement and Test Backup Procedures

Configure automated daily backups to both a local and an offsite or cloud-based destination. Run a restoration test quarterly to confirm backups are functional before you need them in an incident.

7

Train Staff and Document Completion

Deliver security awareness training to all personnel with access to taxpayer data. Collect signed attendance rosters and store completion records with assessment scores for at least three years.

8

Write and Test Your Incident Response Plan

Document response procedures for data breaches, ransomware, and business email compromise. Pre-draft notification letters. Test the plan with a tabletop exercise at least once per year.

Technical Controls: Building Defense-in-Depth Protection

Endpoint Detection and Response vs. Traditional Antivirus

IRS Publication 4557 requires anti-virus software, but signature-based antivirus no longer provides adequate protection against the threats actively targeting tax practices. Modern ransomware uses polymorphic code and fileless attack techniques that evade signature detection entirely. Endpoint Detection and Response (EDR) solutions address this through behavioral analysis, detecting suspicious activity patterns rather than waiting for a known malware signature to match.

According to the IBM Cost of Data Breach Report 2025, organizations using EDR detected breaches 220 days faster than those relying on legacy antivirus, reducing average breach costs by $1.76 million. For a tax practice handling thousands of returns containing Social Security numbers and financial account data, detection speed is the difference between a contained incident and a practice-ending breach. Our comparison of EDR vs. MDR vs. XDR solutions explains the differences and which tier fits a small tax practice.

Multi-Factor Authentication: Implementation Quality Matters

Microsoft's security research shows that MFA blocks 99.9% of automated credential attacks. Implementation quality determines how much of that protection you actually receive. SMS-based authentication provides weaker protection than app-based or hardware token methods because SIM-swapping attacks can redirect your text messages to an attacker's device before you ever see the code.

The NIST Special Publication 800-63B Digital Identity Guidelines rank authentication methods by assurance level. For tax professionals, authenticator app-based MFA using Google Authenticator, Microsoft Authenticator, or Duo provides the Level 2 assurance that satisfies both IRS and FTC requirements. Hardware security keys using FIDO2/WebAuthn provide Level 3 assurance and are increasingly supported by major tax software platforms.

MFA must be enabled on every system that stores or processes taxpayer data: your tax preparation software, email, cloud document storage, client portal, and any remote access tools. Enabling MFA on some systems while leaving others unprotected creates the gaps attackers look for first. For the specific threats facing client-facing portals, our analysis of tax client portal security covers the most common attack vectors.

Encryption: At Rest and In Transit

Full-disk encryption protects taxpayer data if a laptop is lost or stolen. BitLocker on Windows and FileVault on macOS provide native encryption at no additional cost. External drives and USB storage devices used for tax work must also be encrypted. Unencrypted portable storage is one of the most common causes of reportable breaches for small practices because it is easy to overlook and easy to lose.

Data in transit requires Transport Layer Security (TLS) 1.2 or higher for any client portal, email attachment transmission, or cloud storage access. Verify that every vendor you use for client data transmission supports current TLS standards, and avoid sending taxpayer documents via unencrypted email.

WISP and Technical Controls Compliance Checklist

  • Designate a named Qualified Individual responsible for your security program
  • Complete a written risk assessment covering all systems that store or process taxpayer data
  • Deploy EDR or managed antivirus on every device used for tax work
  • Enable MFA on tax software, email, cloud storage, and remote access tools
  • Encrypt all drives on laptops, desktops, and external storage devices
  • Implement and test an automated backup with an offline or cloud-based copy
  • Document a Written Information Security Plan with all FTC Safeguards Rule elements
  • Conduct security awareness training for all staff and document completion with signed rosters
  • Review all vendor contracts and add data protection clauses covering notification and deletion
  • Write and test an incident response plan with breach notification procedures and contact lists
  • Schedule an annual WISP review, risk assessment, and independent penetration test

Need a Ready-to-Use WISP Template?

Our free 2026 WISP template is pre-built to satisfy IRS Publication 4557 and all 16 elements of the FTC Safeguards Rule. Download and customize it for your practice in under an hour.

Employee Security Training: Turning Your Biggest Vulnerability Into a Defense Asset

The Verizon 2025 Data Breach Investigations Report attributes 82% of breaches to the human element, including phishing, credential misuse, and social engineering. For tax practices, that risk concentrates during January through April when filing volume peaks and staff process high volumes of client communications under time pressure. Attackers time their campaigns accordingly.

The FTC Safeguards Rule mandates documented security training for all personnel with access to customer information, delivered during onboarding and periodically thereafter based on role, responsibilities, and the evolving threat environment. During filing season, the threats your team needs to recognize include:

  • W-2 phishing schemes, fraudulent emails impersonating employers or clients requesting employee tax documents for supposed verification, designed to harvest credentials or deliver malware
  • IRS impersonation calls, callers posing as IRS agents demanding immediate action on supposed compliance issues, used to extract login credentials or authorize fraudulent wire transfers
  • Business email compromise (BEC), spoofed executive emails requesting urgent wire transfers or changes to direct deposit information, timed to coincide with the administrative load of filing season
  • Credential harvesting sites, fake tax software login pages distributed via phishing emails that capture credentials and relay them to attackers in real time

Training documentation requirements under the FTC Safeguards Rule include signed attendance rosters, completion certificates from your training platform, assessment scores demonstrating comprehension with an 80% passing threshold as a reasonable benchmark, and records of annual refresher sessions. The IRS Security Summit program publishes free training materials at IRS.gov each filing season that meet FTC documentation requirements when paired with sign-in sheets and completion acknowledgments.

Bottom Line on Training

The FTC Safeguards Rule requires documented security training for every employee with access to customer data. Free IRS Security Summit materials satisfy the content requirement, but documentation is what regulators examine after an incident. Collect signed rosters, save completion certificates, and store training records for at least three years.

Incident Response Planning and Breach Notification Requirements

A documented incident response plan serves two distinct purposes: it reduces breach costs by enabling faster, more organized response, and it demonstrates regulatory good faith when you are required to notify agencies and affected individuals. The IBM Cost of Data Breach Report found that organizations with documented response plans detected breaches 54 days faster and saved an average of $1.49 million compared to firms without formal plans.

The FTC Safeguards Rule mandates written incident response procedures. The NIST Computer Security Incident Handling Guide (Special Publication 800-61) provides the standard four-phase framework that regulators recognize: Preparation, Detection and Analysis, Containment and Eradication and Recovery, and Post-Incident Activity. Your tax practice incident response plan should follow this structure and include specific contact lists, escalation procedures, pre-drafted notification templates, and a tested restoration procedure for your backup systems. Our incident response plan guide for tax practices walks through each phase with templates you can adapt.

Breach Notification: Who You Must Notify and When

Notification timelines run from the date of discovery, defined as when you have reasonable belief that unauthorized access occurred, not from the actual breach date, which may be weeks earlier. Multi-layered notification requirements mean you may simultaneously report to federal agencies, state regulators, and affected clients:

  • IRS notification, report immediately through the IRS Data Theft Information Reporting System when PTIN, EFIN, or e-Services credentials are compromised; also contact your local IRS stakeholder liaison directly
  • FTC notification, required under GLBA Safeguards Rule for breaches affecting consumer financial information that trigger state notification thresholds
  • State notification, all 50 states have breach notification laws with varying timelines, typically 30 to 90 days; some require notification to the state attorney general in addition to affected individuals
  • FBI IC3 reporting, submit a complaint at ic3.gov for cybercrime incidents including ransomware and business email compromise; this assists federal investigations and supports cyber liability insurance claims

Pre-drafting notification letters and maintaining a current client contact list is part of incident preparation, not something to build during an active breach. Build these materials into your WISP and test them before you need them.

Vendor Oversight, Ongoing Monitoring, and PTIN Documentation

Third-Party Risk Management

Tax practices rely on cloud-based tax software, document management portals, payroll services, and IT support providers, all of which handle or can access client data. The FTC Safeguards Rule explicitly requires tax professionals to exercise due diligence when selecting service providers and to include contractual data protection obligations in vendor agreements.

Before engaging any vendor with access to taxpayer data, verify their security posture by reviewing their SOC 2 Type II report, ISO 27001:2022 certification, or equivalent independent security attestation. Request a completed security questionnaire covering encryption standards, access controls, breach notification timelines, and their own vendor oversight practices.

Your vendor contracts must include encryption requirements for data in transit and at rest, defined access controls limiting which personnel can reach your client data, a notification obligation requiring the vendor to alert you within a defined window of discovering a breach, audit rights allowing periodic security reviews, and a data deletion procedure specifying how your information is destroyed when the contract ends.

PTIN Renewal: What the IRS Wants to See

The IRS increasingly scrutinizes security practices during PTIN renewal, with examiners requesting evidence of implemented controls and documented policies. Be prepared to produce the following when renewing for the 2026 filing season and beyond:

  • Screenshots showing active EDR or antivirus protection on all devices used for tax work
  • Firewall configuration documentation demonstrating network perimeter controls
  • MFA enabled on tax software and email, with settings screenshots as documentation
  • Drive encryption verification -- BitLocker on Windows, FileVault on Mac
  • Backup procedure documentation including schedules and restoration test results
  • Your Written Information Security Plan with a current-year revision date
  • Employee training records with signed rosters, completion certificates, and assessment scores
  • Vendor contracts with data protection clauses for all service providers
  • Your incident response plan with tested notification procedures and pre-drafted letters
  • Annual risk assessment results documenting current threats and control effectiveness

Organize these documents in labeled electronic folders with version control and a backup copy. A well-organized compliance folder takes minutes to produce under examination; a disorganized one takes days and creates a poor first impression with investigators. For ongoing managed compliance support, our IRS Publication 4557 compliance services and tax practice security solutions provide options sized for solo practices and small firms alike.

What This Means for Your Practice

The 2026 filing season is the enforcement baseline. IRS examiners can request security documentation during PTIN renewal, and FTC civil penalties for Safeguards Rule violations can reach $100,000 per violation with additional exposure under state law. Implementing required controls costs a fraction of what a breach or enforcement action costs to remediate.

Get a Free Tax Practice Security Assessment

Our cybersecurity experts will evaluate your current compliance posture against IRS Publication 4557 and the FTC Safeguards Rule and provide actionable recommendations for the 2026 filing season.

Frequently Asked Questions

Tax preparers must meet three overlapping sets of requirements: IRS Publication 4557's Security Six controls covering endpoint protection, firewalls, MFA, encryption, backups, and software updates; the FTC Safeguards Rule under 16 CFR § 314 requiring a 16-element written information security program with a designated Qualified Individual; and applicable state breach notification laws. All three apply regardless of firm size, and there is no minimum client or revenue threshold that creates an exemption.

Yes. The IRS ties PTIN and EFIN credentials to security compliance under IRS Publication 4557. Examiners can request documentation of implemented controls during PTIN renewal, and failure to demonstrate adequate security posture can result in suspension or revocation of your credentials. Without a valid PTIN or EFIN, you cannot prepare or electronically file returns.

Yes. The June 2023 amendments to the FTC Safeguards Rule removed all size-based exemptions. Solo practitioners, two-person offices, and firms of any size that handle consumer financial information, which includes tax return data, are covered by the rule. There is no minimum client threshold or revenue floor that creates an exemption from the Safeguards Rule requirements.

A Qualified Individual is the person you designate to oversee, implement, and enforce your information security program. They must have sufficient authority and resources to implement required controls and must report program status to ownership or senior management at least annually. For solo practitioners, the tax professional typically serves as their own Qualified Individual. The designation must be documented in your WISP with the person's name, title, and defined responsibilities.

Your WISP must be reviewed at minimum once per year. You must also update it whenever you add new systems or software, change vendors who handle taxpayer data, experience a security incident, or identify significant new risks in your annual risk assessment. Each revision should carry a date, and prior versions should be retained for at least three years to demonstrate a compliance history during any regulatory examination.

The IRS may request screenshots confirming active endpoint protection, firewall configuration records, MFA settings on tax software and email, drive encryption verification, backup schedules and restoration test results, your current WISP with a revision date, employee training records with signed rosters and completion certificates, vendor contracts with data protection clauses, your incident response plan, and annual risk assessment results. Keep these in organized, labeled electronic folders with a backup copy so you can produce them quickly under examination.

Yes. The FTC can seek civil penalties up to $100,000 per violation of the Safeguards Rule, plus additional penalties under Section 5 of the FTC Act for unfair or deceptive practices. State breach notification laws carry separate penalties that vary by state and can include fines calculated per affected individual. PTIN or EFIN revocation would prevent you from preparing returns entirely, which represents a practice-ending outcome for most tax professionals.

The FTC Safeguards Rule requires training for all personnel with access to customer information, delivered at onboarding and periodically thereafter based on role and responsibilities. Adequate documentation includes signed attendance rosters, completion certificates from your training platform, assessment scores demonstrating comprehension, and records of annual refresher sessions. An 80% passing threshold on written assessments is a reasonable benchmark. The IRS Security Summit publishes free training materials each filing season that satisfy the content requirement when paired with proper documentation.

Isolate affected systems immediately to prevent further spread. Contact the IRS through the IRS Data Theft Information Reporting System and your local IRS stakeholder liaison if PTIN or EFIN credentials are involved. File a complaint with the FBI Internet Crime Complaint Center at ic3.gov. Engage a cybersecurity incident response provider to contain and investigate the breach. Begin breach notification procedures under applicable state laws, which typically require notification within 30 to 90 days of discovery. Notify your cyber liability insurer as early as possible to preserve coverage and access pre-approved response vendors.

SMS-based authentication satisfies the basic two-factor authentication requirement in IRS Publication 4557, but it provides weaker protection than app-based or hardware token methods. NIST SP 800-63B rates SMS authentication at a lower assurance level because SIM-swapping attacks can intercept codes. The FTC Safeguards Rule does not specify an MFA method, but it requires controls commensurate with the risks you face. For most tax practices, an authenticator app such as Google Authenticator, Microsoft Authenticator, or Duo represents the minimum defensible implementation for protecting taxpayer data.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.