Skip to content
Bellator Cyber Guard
Tax7 min readStandard

IRS Form 4557 Requirements: Safeguarding Taxpayer Data

By Bellator Cyber Guard Security Team
IRS Form 4557 Requirements: Safeguarding Taxpayer Data, form 4557

Form 4557 is the IRS's shorthand name for Publication 4557, Safeguarding Taxpayer Data, the agency's guidance on the data security measures tax preparers must put in place. If you prepare federal returns for compensation, Form 4557 applies to your practice whether you file 11 returns a year or 11,000.

The publication isn't a fillable form. It's a compliance roadmap built on three federal authorities: the Gramm-Leach-Bliley Act (GLBA), the FTC Safeguards Rule (16 CFR Part 314), and IRS Revenue Procedure 2007-40. Together they establish that tax preparers are financial institutions under federal law and must maintain a written, enforced information security program or risk suspension from the IRS e-file program.

Quick Answer

Form 4557 (IRS Publication 4557, Safeguarding Taxpayer Data) requires every paid tax preparer to maintain a written information security plan (WISP), multi-factor authentication on all systems that touch taxpayer data, encryption at rest and in transit, and a tested incident response plan. The requirement comes from the FTC Safeguards Rule and the Gramm-Leach-Bliley Act, and the IRS treats violations as grounds to suspend e-file authorization under Revenue Procedure 2007-40. There is no exemption for firm size or return volume.

Key Takeaway

  • Form 4557 applies to every paid tax preparer, regardless of firm size or return volume.
  • A written WISP, MFA, and encryption are baseline legal requirements under the 2023 FTC Safeguards Rule amendments.
  • The IRS treats Safeguards Rule violations as violations of Revenue Procedure 2007-40, which can mean e-file suspension.
  • Annual review of your WISP and controls is the compliance floor, not the ceiling.
  • A documented, tested incident response plan is required, not optional.

Tax Data Security By The Numbers

$4.88M
Average cost of a data breach in 2024
399,000+
Tax-related identity theft affidavits filed
68%
Breaches involving a human element

The Gramm-Leach-Bliley Act (GLBA) is a federal law that classifies tax preparers as financial institutions because they collect Social Security numbers, bank account data, and income records as part of a financial service. That classification triggers mandatory data protection obligations.

The FTC Safeguards Rule (16 CFR Part 314) is a Federal Trade Commission regulation requiring covered financial institutions to develop, implement, and maintain a written information security program. The 2023 amendments added mandatory requirements for multi-factor authentication, encryption of data in transit and at rest, and annual risk assessments. See the control-by-control breakdown in our FTC Safeguards Rule checklist.

IRS Revenue Procedure 2007-40 governs every Authorized e-file Provider. The IRS has stated that a violation of the FTC Safeguards Rule is also a violation of Revenue Procedure 2007-40, so non-compliance can end with removal from the e-file program. See what that looks like in our guide to non-compliance consequences.

E-File Suspension Risk

Non-compliance with Form 4557 is not just a fine risk. The IRS treats violations of the FTC Safeguards Rule as violations of Revenue Procedure 2007-40, and the stated consequence is suspension from the IRS e-file program, which would end your ability to file returns electronically during tax season.

A Written Information Security Plan (WISP) is a documented, firm-specific plan describing the safeguards you use to protect taxpayer data, and it's the foundation of Form 4557 compliance. Every paid preparer must create, maintain, and actually follow one.

Publication 4557 points to NIST IR 7621 Revision 1, Small Business Information Security: The Fundamentals, as the recommended framework for building a WISP. Our guide to building a written information security plan walks through the structure in more detail.

A Compliant WISP Must Address

  • The scope of taxpayer data your firm collects, processes, and stores
  • Formal risk assessment procedures and a review schedule
  • Technical, physical, and administrative safeguards in place
  • Employee roles, responsibilities, and security training requirements
  • Incident response and breach notification procedures
  • Vendor and third-party service provider oversight

Form 4557 requires restricting taxpayer data to authorized personnel only, with unique user IDs, strong password policies, and multi-factor authentication (MFA) on every system that stores or transmits taxpayer information. The IRS recommends passwords of at least 12 characters mixing uppercase, lowercase, numbers, and symbols, with 8 characters documented as the floor.

Password managers are specifically recommended for tracking unique credentials across tax software, email, and financial portals. For IRS online accounts, see our walkthrough of setting up MFA on your IRS Tax Pro Account, and our broader guide to two-factor authentication for tax practices.

How to Build a Form 4557-Compliant Security Program

1

Conduct a Risk Assessment

Identify every location where taxpayer data is stored, processed, or transmitted, including laptops, cloud storage, and email, and document the likelihood of each risk.

2

Draft Your WISP

Using Publication 4557 and NIST IR 7621r1 as guides, write a plan covering every required control area and designate a security coordinator responsible for annual review.

3

Implement Technical Safeguards

Deploy MFA on all tax software and email accounts, enable full-disk encryption, and keep patches and anti-virus definitions current.

4

Secure Your Network

Configure Wi-Fi with WPA-2/AES encryption, use a non-identifying SSID, and segment tax workstations from guest or personal devices.

5

Train Your Staff

Give every employee with data access security awareness training, including phishing simulations, as required under the 2023 Safeguards Rule amendments.

6

Test and Update Annually

Review the WISP and test controls at least once a year, or after any material change to systems, staffing, or services, and document the review.

All taxpayer data must be encrypted both at rest and in transit. Full-disk encryption, such as Microsoft BitLocker on Windows workstations, protects stored data if a device is lost or stolen, and Transport Layer Security (TLS) 1.2 or higher is the required standard for data moving between systems. Unencrypted email is not an acceptable way to send tax documents under Form 4557.

According to Verizon's 2024 Data Breach Investigations Report, vulnerability exploitation was among the top initial access techniques used against small businesses, which is why patch management carries the same weight as anti-virus coverage.

Technical Safeguards Checklist

  • Full-disk encryption (such as BitLocker) on every workstation
  • TLS 1.2 or higher for any taxpayer data sent between systems
  • Actively updated anti-virus and anti-malware software on every device
  • Current security patches applied on a regular schedule
  • WPA-2 with AES encryption on your Wi-Fi network
  • A non-identifying SSID with broadcast disabled where feasible
  • Guest and personal devices segmented onto a separate network from tax workstations

Form 4557 requires a documented incident response plan, not just preventive controls. Under GLBA and the FTC Safeguards Rule, a breach of taxpayer data triggers notification obligations to affected clients, the IRS, and in most states, state regulators, and delayed notification compounds both legal exposure and client trust damage.

Our guides to building an incident response plan and responding to a tax practice data breach cover the process in more detail.

IRS Steps After a Confirmed or Suspected Breach

1

Isolate Affected Systems

Disconnect compromised devices immediately to stop further data exfiltration.

2

Contact Your Security Team

Loop in your cybersecurity provider or Managed Security Service Provider (MSSP) to begin containment.

3

Report to Your IRS Stakeholder Liaison

Contact information for your liaison is listed directly in Publication 4557.

4

File IRS Form 14039-B

Submit the Business Identity Theft Affidavit if tax-related identity theft is confirmed.

5

Notify Affected Clients

Follow applicable state breach notification laws, many of which require notice within 30 to 90 days of discovery.

6

Document and Update Your WISP

Record every response action and update the plan to address the root cause.

Form 4557 Security Implementation Levels

Written Security Plan (WISP)

Required (Floor)
Required
Enhanced
Annual review
Advanced
Quarterly review + tabletop exercises

Multi-Factor Authentication

Required (Floor)
All tax systems
Enhanced
All systems + email
Advanced
All systems + phishing-resistant MFA

Encryption at Rest

Required (Floor)
Required
Enhanced
Full-disk (BitLocker)
Advanced
Full-disk + file-level encryption

Wireless Security

Required (Floor)
WPA-2 / AES
Enhanced
WPA-2 + segmented network
Advanced
Zero trust network access

Incident Response Plan

Required (Floor)
Required
Enhanced
Documented + tested
Advanced
Tested + MSSP-supported response

Staff Security Training

Required (Floor)
Required
Enhanced
Annual
Advanced
Annual + phishing simulations

Book a Free Tax Cybersecurity Assessment

Bellator Cyber Guard will review your current controls against Form 4557 requirements and identify the gaps that put your e-file authorization at risk.

Frequently Asked Questions

Any tax professional who prepares federal tax returns for compensation must comply with Form 4557. This includes sole practitioners, small accounting firms, enrolled agents, and tax preparation franchises. The Gramm-Leach-Bliley Act classifies these professionals as financial institutions, which triggers mandatory data protection obligations regardless of firm size or return volume.

Yes, they refer to the same document. IRS Publication 4557, titled Safeguarding Taxpayer Data, is commonly called Form 4557 in everyday use. It is a guidance publication rather than a fillable tax form, and it outlines the data security requirements and best practices tax professionals must follow to protect client information and maintain e-file authorization.

The IRS treats violations of the FTC Safeguards Rule as violations of Revenue Procedure 2007-40. This can result in suspension from the IRS e-file program, which would prevent you from filing returns electronically on behalf of clients. GLBA violations can also expose a firm to FTC enforcement and civil penalties under applicable state laws.

Yes. A Written Information Security Plan (WISP) is a formal requirement under the FTC Safeguards Rule for all covered financial institutions, including tax preparers. Publication 4557 references the WISP requirement directly and provides guidance on what it must cover.

Yes. The 2023 updates to the FTC Safeguards Rule made MFA a mandatory control for all covered financial institutions, including tax preparers, and Publication 4557 reflects this requirement. MFA must be implemented on every system that stores or provides access to taxpayer data, including tax software, email, and remote access platforms.

Isolate affected systems immediately, then contact your IRS Stakeholder Liaison using the contact information listed in Publication 4557, file IRS Form 14039-B if identity theft is confirmed, and notify affected clients. Most states require breach notification within 30 to 90 days of discovery, and every action should be documented and used to update the WISP.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.