
Cybersecurity for tax professionals is a legal requirement, not an optional best practice. Every tax preparer, CPA, and accounting firm that handles taxpayer data must comply with three overlapping federal frameworks: IRS Publication 4557, "Safeguarding Taxpayer Data," the FTC Safeguards Rule under the Gramm-Leach-Bliley Act (GLBA), and IRS Publication 1075 for firms that handle federal tax information. Together, these rules require a signed Written Information Security Plan (WISP), the IRS Security Six technical controls, an annual risk assessment, and documented incident response, backed by FTC civil penalties of up to $100,000 per violation and IRS authority to suspend a Preparer Tax Identification Number (PTIN).
The stakes are rising heading into the 2026 filing season. The IRS Security Summit, a coalition of the IRS, state tax agencies, and tax industry groups, reports that ransomware attacks against tax firms increased 87% year over year, with average ransom demands reaching $287,000 at mid-sized practices. This guide covers what the 2026 rules actually require and how to build a compliance program that holds up under audit.
Quick Answer
Tax professionals must comply with three federal frameworks: IRS Publication 4557, the FTC Safeguards Rule (16 CFR Part 314), and IRS Publication 1075 for firms handling federal tax information. In practice, that means a signed WISP, the IRS Security Six controls (anti-malware, firewalls, MFA, encrypted backups, drive encryption, and VPN), an annual written risk assessment, and documented vendor oversight and incident response. Preparers filing 11 or more returns a year must keep a current WISP on file before filing season starts, and the FTC Safeguards Rule applies even to sole practitioners, with civil penalties of up to $100,000 per violation.
Tax Practice Cybersecurity, By the Numbers
Three Federal Frameworks Set the 2026 Compliance Baseline
IRS Publication 4557, "Safeguarding Taxpayer Data," outlines the security measures every preparer acknowledges when applying for or renewing a PTIN. Non-compliance can lead to PTIN suspension, which ends a preparer's ability to file returns on clients' behalf.
Publication 4557 works alongside the FTC Safeguards Rule, which classifies tax preparers as "financial institutions" under the GLBA. That classification brings FTC enforcement authority to your practice, with civil penalties up to $100,000 per violation. The rule was amended effective June 2023 to add specific technical mandates beyond the original general guidance: continuous monitoring, annual penetration testing, defined encryption standards, and documented incident response, each with written evidence. Our guide to the FTC Safeguards Rule's Qualified Individual requirement covers who at your firm needs to own this responsibility.
IRS Publication 1075 sets detailed security guidelines for federal tax information (FTI). It targets federal, state, and local tax administrators directly, but its technical standards, AES-256 encryption for data at rest and TLS 1.2 or higher in transit, along with defined authentication and monitoring controls, are a useful reference for any practitioner handling taxpayer data. For a consolidated reference across all three frameworks, see our IRS compliance white paper. Questions about how these rules apply to your specific practice structure are best directed to your attorney or compliance counsel.
The IRS Security Six
- Anti-malware and EDR that detects ransomware behavior, not just known virus signatures
- Next-generation firewalls with network segmentation around systems that store taxpayer data
- Multi-factor authentication on tax software, email, cloud storage, and remote access
- Encrypted, offline backups following the 3-2-1 rule, with restoration tested monthly
- Full-disk encryption using FIPS 140-2 validated cryptographic modules on every device
- VPN required for all remote access, with split-tunneling disabled
These six categories, set by the IRS Security Summit, are the baseline the IRS expects every practice to meet. For a full walkthrough of each control with configuration guidance, see our IRS Security Six checklist for tax professionals, our multi-factor authentication setup guide, our VPN selection guide, and our backup guide for tax practices.
2026 Filing Season Requirement
The IRS requires every tax preparer filing 11 or more returns annually to maintain a current, signed WISP before filing season opens. The FTC Safeguards Rule applies to sole practitioners too, there is no size exemption. Firms without a compliant plan risk PTIN suspension under Publication 4557 and FTC civil penalties up to $100,000 per violation.
Your WISP Is the Foundation of Compliance
The Written Information Security Plan (WISP) is the central document that shows the IRS, FTC, and state regulators you have taken data security seriously. It must be signed by a responsible party and updated at least annually, or whenever your technology environment changes materially.
The IRS published IRS Publication 5708, which includes a sample WISP template for small tax practices. That template is a starting point, not a finished plan, it needs customization to reflect your actual systems, vendors, and risk profile. A generic template that does not match your technology stack will raise questions during an audit. For a customizable starting point built for tax practices, see our free WISP template. Your WISP must name who is responsible for security, what systems are in scope, how you assess risk, what technical controls are in place, how you train employees, how you manage vendors, and how you respond to incidents.
Regulators treat unsigned or undated WISPs as if no plan exists. A version-controlled document with annual review dates is what provides an evidentiary record if your firm is ever audited or investigated.
How to Build a Compliant WISP in 6 Steps
Designate a Security Coordinator
Name one person who owns the WISP, coordinates annual reviews, and serves as the point of contact for breach response.
Inventory Systems and Data
Catalog every device, application, and third-party service that stores, processes, or transmits taxpayer data.
Conduct a Written Risk Assessment
Evaluate human, technical, and third-party risks using a structured methodology such as NIST SP 800-30. Document vulnerabilities and remediation priorities.
Document Your Security Controls
Record each Security Six control in place, with vendor names, configuration standards, and testing schedules.
Build Incident Response Procedures
Define who to notify, how to contain an incident, when to involve law enforcement, and how to notify affected clients.
Schedule Annual Review and Training
Set a calendar date to review the WISP each year, and document employee security awareness training with attendance logs.
Get a Custom WISP Built for Your Practice
Bellator builds a Written Information Security Plan matched to your actual systems and vendors, starting at $749 for up to 5 users, with a custom quote for larger practices. A properly scoped WISP typically saves a practice 20 to 40 billable hours compared to building one from scratch.
Risk Assessment: Human, Technical, and Vendor Risk
The FTC Safeguards Rule requires a written risk assessment annually, and Publication 4557 expects you to identify threats to taxpayer data confidentiality. NIST Special Publication 800-30, published by the National Institute of Standards and Technology (NIST), provides a structured framework that scales to practices of any size, covering three dimensions: human factors, technical vulnerabilities, and third-party risk.
According to Stanford University research, employee errors account for 88% of data breaches, so the assessment should cover password practices, phishing susceptibility, and remote work habits. Phishing simulations give a more accurate measure of real susceptibility than self-reported surveys. See our analysis of AI-driven phishing tactics for how these campaigns are evolving.
On the technical side, vulnerability scanning flags unpatched software and weak configurations, and the Common Vulnerability Scoring System (CVSS) sets remediation timelines: high-severity findings (CVSS 9.0 to 10.0) within 24 hours, moderate findings (CVSS 7.0 to 8.9) within 7 days. Annual penetration testing, now required under the amended FTC Safeguards Rule, confirms which vulnerabilities are actually exploitable rather than relying on scores alone.
Every vendor with access to client data, cloud storage providers, tax software companies, IT support firms, payroll processors, adds risk to your environment. The FTC Safeguards Rule requires ongoing oversight of service providers through written contracts and monitoring, not a one-time questionnaire.
Ransomware and Business Email Compromise Peak During Filing Season
The FBI's Internet Crime Complaint Center (IC3) ranks tax professionals among the most targeted industries, and attackers time campaigns to filing season when practices are under the most pressure. Modern ransomware operations use double extortion, encrypting data while threatening to publish stolen client information even if you can restore from backup. Layered defenses limit the damage when one control fails: email security gateways that sandbox unknown attachments, EDR with behavioral detection that flags rapid file encryption and shadow copy deletion, network segmentation that isolates taxpayer data systems, and immutable write-once-read-many (WORM) backups that ransomware cannot encrypt or delete. Practices that want continuous monitoring without building an internal security team can compare managed detection and response options on our protection plans page.
Business email compromise (BEC) cost businesses $2.7 billion in 2023, according to FBI IC3 reporting. Criminals impersonate clients requesting refund deposit changes, partners requesting W-2 data, or vendors requesting wire transfers, attacks that exploit trust and time pressure during filing season. DMARC (Domain-based Message Authentication, Reporting and Conformance), DKIM (DomainKeys Identified Mail), and SPF (Sender Policy Framework) authenticate outbound email and help flag spoofed domains. On the process side, require verbal verification, a call to a known phone number, before acting on any request to change financial account information or payment instructions, regardless of how legitimate the email looks. Document this policy in your WISP and train every staff member who handles client communications.
Key Takeaway
No tax practice is too small to be targeted. Criminals prioritize firms based on the value of the data they hold, not headcount, a sole practitioner with 50 clients holds 50 complete financial profiles. Layered security controls, a current WISP, and documented annual training are what separate a practice that survives a breach from one that doesn't.
Documentation Regulators Actually Check
Meeting security requirements is one challenge. Proving it is another. During an IRS audit, FTC investigation, or breach inquiry, the completeness of your documentation often determines whether you face maximum penalties or can demonstrate good-faith compliance that regulators weigh in mitigation. The FTC expects retention of compliance records for a minimum of seven years, consistent with IRS Publication 1075 guidance.
Keep, at minimum: a version-controlled WISP with annual review dates and a signature, annual risk assessment reports documenting vulnerabilities and remediation status, vendor security assessments including SOC 2 Type II reports and signed contracts, training records with attendance logs and assessment scores, and incident logs covering every security event, including minor ones, with detection timestamps and response actions. Practices with well-maintained records consistently see better outcomes in enforcement proceedings than those reconstructing events after the fact.
Vendor Oversight and Cyber Insurance
The FTC Safeguards Rule requires ongoing evaluation of service providers, not just at onboarding. Before sharing taxpayer data with a vendor, collect a SOC 2 Type II report, a completed security questionnaire, proof of cyber liability insurance with at least $2 million in coverage, and a 24-hour breach notification commitment. Service agreements should spell out encryption standards, access controls, breach notification timelines, audit rights, and data destruction procedures at contract end. A vendor relationship without these written provisions can create a documentation gap during an audit even when the vendor's actual security practices are strong.
A WISP and technical controls reduce breach risk; cyber insurance addresses what remains. A breach can trigger forensic investigation, notification costs, regulatory defense, and client credit monitoring, expenses that can reach six figures even for a small practice. Confirm your policy covers regulatory defense costs, not only first-party response, and check that it applies to the data types your practice handles. Most underwriters now require evidence of security controls before binding coverage, so a current WISP and training records support better underwriting terms.
2026 Compliance Checklist
- Maintain a current, signed WISP reviewed within the last 12 months
- Complete an annual written risk assessment
- Deploy EDR on every device that stores or processes taxpayer data
- Require MFA on tax software, email, cloud storage, and remote access
- Encrypt devices with FIPS 140-2 validated full-disk encryption
- Maintain WORM backups and test restoration monthly
- Deploy DMARC, DKIM, and SPF email authentication
- Complete annual penetration testing and document vendor security assessments
Talk with a cybersecurity expert
Get a practical review of where your practice stands against IRS and FTC requirements before filing season.
Frequently Asked Questions
Yes. IRS guidance applies to preparers filing 11 or more returns a year, and the FTC Safeguards Rule applies to any practitioner handling consumer financial information, including a solo preparer with a handful of clients. There is no size exemption under either framework.
Non-compliance can lead to PTIN suspension under IRS Publication 4557 and FTC civil penalties of up to $100,000 per violation under the Safeguards Rule. Documented, good-faith compliance efforts are typically weighed favorably if a firm is investigated.
At least once a year, and any time your technology, vendors, or staff responsibilities change in a way that affects how taxpayer data is stored or accessed.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



