
Form 4557 is the IRS's shorthand name for Publication 4557, Safeguarding Taxpayer Data, the agency's guidance on the data security measures tax preparers must put in place. If you prepare federal returns for compensation, Form 4557 applies to your practice whether you file 11 returns a year or 11,000.
The publication isn't a fillable form. It's a compliance roadmap built on three federal authorities: the Gramm-Leach-Bliley Act (GLBA), the FTC Safeguards Rule (16 CFR Part 314), and IRS Revenue Procedure 2007-40. Together they establish that tax preparers are financial institutions under federal law and must maintain a written, enforced information security program or risk suspension from the IRS e-file program.
Quick Answer
Form 4557 (IRS Publication 4557, Safeguarding Taxpayer Data) requires every paid tax preparer to maintain a written information security plan (WISP), multi-factor authentication on all systems that touch taxpayer data, encryption at rest and in transit, and a tested incident response plan. The requirement comes from the FTC Safeguards Rule and the Gramm-Leach-Bliley Act, and the IRS treats violations as grounds to suspend e-file authorization under Revenue Procedure 2007-40. There is no exemption for firm size or return volume.
Key Takeaway
- Form 4557 applies to every paid tax preparer, regardless of firm size or return volume.
- A written WISP, MFA, and encryption are baseline legal requirements under the 2023 FTC Safeguards Rule amendments.
- The IRS treats Safeguards Rule violations as violations of Revenue Procedure 2007-40, which can mean e-file suspension.
- Annual review of your WISP and controls is the compliance floor, not the ceiling.
- A documented, tested incident response plan is required, not optional.
Tax Data Security By The Numbers
The Gramm-Leach-Bliley Act (GLBA) is a federal law that classifies tax preparers as financial institutions because they collect Social Security numbers, bank account data, and income records as part of a financial service. That classification triggers mandatory data protection obligations.
The FTC Safeguards Rule (16 CFR Part 314) is a Federal Trade Commission regulation requiring covered financial institutions to develop, implement, and maintain a written information security program. The 2023 amendments added mandatory requirements for multi-factor authentication, encryption of data in transit and at rest, and annual risk assessments. See the control-by-control breakdown in our FTC Safeguards Rule checklist.
IRS Revenue Procedure 2007-40 governs every Authorized e-file Provider. The IRS has stated that a violation of the FTC Safeguards Rule is also a violation of Revenue Procedure 2007-40, so non-compliance can end with removal from the e-file program. See what that looks like in our guide to non-compliance consequences.
E-File Suspension Risk
Non-compliance with Form 4557 is not just a fine risk. The IRS treats violations of the FTC Safeguards Rule as violations of Revenue Procedure 2007-40, and the stated consequence is suspension from the IRS e-file program, which would end your ability to file returns electronically during tax season.
A Written Information Security Plan (WISP) is a documented, firm-specific plan describing the safeguards you use to protect taxpayer data, and it's the foundation of Form 4557 compliance. Every paid preparer must create, maintain, and actually follow one.
Publication 4557 points to NIST IR 7621 Revision 1, Small Business Information Security: The Fundamentals, as the recommended framework for building a WISP. Our guide to building a written information security plan walks through the structure in more detail.
A Compliant WISP Must Address
- The scope of taxpayer data your firm collects, processes, and stores
- Formal risk assessment procedures and a review schedule
- Technical, physical, and administrative safeguards in place
- Employee roles, responsibilities, and security training requirements
- Incident response and breach notification procedures
- Vendor and third-party service provider oversight
Form 4557 requires restricting taxpayer data to authorized personnel only, with unique user IDs, strong password policies, and multi-factor authentication (MFA) on every system that stores or transmits taxpayer information. The IRS recommends passwords of at least 12 characters mixing uppercase, lowercase, numbers, and symbols, with 8 characters documented as the floor.
Password managers are specifically recommended for tracking unique credentials across tax software, email, and financial portals. For IRS online accounts, see our walkthrough of setting up MFA on your IRS Tax Pro Account, and our broader guide to two-factor authentication for tax practices.
How to Build a Form 4557-Compliant Security Program
Conduct a Risk Assessment
Identify every location where taxpayer data is stored, processed, or transmitted, including laptops, cloud storage, and email, and document the likelihood of each risk.
Draft Your WISP
Using Publication 4557 and NIST IR 7621r1 as guides, write a plan covering every required control area and designate a security coordinator responsible for annual review.
Implement Technical Safeguards
Deploy MFA on all tax software and email accounts, enable full-disk encryption, and keep patches and anti-virus definitions current.
Secure Your Network
Configure Wi-Fi with WPA-2/AES encryption, use a non-identifying SSID, and segment tax workstations from guest or personal devices.
Train Your Staff
Give every employee with data access security awareness training, including phishing simulations, as required under the 2023 Safeguards Rule amendments.
Test and Update Annually
Review the WISP and test controls at least once a year, or after any material change to systems, staffing, or services, and document the review.
All taxpayer data must be encrypted both at rest and in transit. Full-disk encryption, such as Microsoft BitLocker on Windows workstations, protects stored data if a device is lost or stolen, and Transport Layer Security (TLS) 1.2 or higher is the required standard for data moving between systems. Unencrypted email is not an acceptable way to send tax documents under Form 4557.
According to Verizon's 2024 Data Breach Investigations Report, vulnerability exploitation was among the top initial access techniques used against small businesses, which is why patch management carries the same weight as anti-virus coverage.
Technical Safeguards Checklist
- Full-disk encryption (such as BitLocker) on every workstation
- TLS 1.2 or higher for any taxpayer data sent between systems
- Actively updated anti-virus and anti-malware software on every device
- Current security patches applied on a regular schedule
- WPA-2 with AES encryption on your Wi-Fi network
- A non-identifying SSID with broadcast disabled where feasible
- Guest and personal devices segmented onto a separate network from tax workstations
Form 4557 requires a documented incident response plan, not just preventive controls. Under GLBA and the FTC Safeguards Rule, a breach of taxpayer data triggers notification obligations to affected clients, the IRS, and in most states, state regulators, and delayed notification compounds both legal exposure and client trust damage.
Our guides to building an incident response plan and responding to a tax practice data breach cover the process in more detail.
IRS Steps After a Confirmed or Suspected Breach
Isolate Affected Systems
Disconnect compromised devices immediately to stop further data exfiltration.
Contact Your Security Team
Loop in your cybersecurity provider or Managed Security Service Provider (MSSP) to begin containment.
Report to Your IRS Stakeholder Liaison
Contact information for your liaison is listed directly in Publication 4557.
File IRS Form 14039-B
Submit the Business Identity Theft Affidavit if tax-related identity theft is confirmed.
Notify Affected Clients
Follow applicable state breach notification laws, many of which require notice within 30 to 90 days of discovery.
Document and Update Your WISP
Record every response action and update the plan to address the root cause.
Form 4557 Security Implementation Levels
Written Security Plan (WISP)
- Required (Floor)
- Required
- Enhanced
- Annual review
- Advanced
- Quarterly review + tabletop exercises
Multi-Factor Authentication
- Required (Floor)
- All tax systems
- Enhanced
- All systems + email
- Advanced
- All systems + phishing-resistant MFA
Encryption at Rest
- Required (Floor)
- Required
- Enhanced
- Full-disk (BitLocker)
- Advanced
- Full-disk + file-level encryption
Wireless Security
- Required (Floor)
- WPA-2 / AES
- Enhanced
- WPA-2 + segmented network
- Advanced
- Zero trust network access
Incident Response Plan
- Required (Floor)
- Required
- Enhanced
- Documented + tested
- Advanced
- Tested + MSSP-supported response
Staff Security Training
- Required (Floor)
- Required
- Enhanced
- Annual
- Advanced
- Annual + phishing simulations
| Feature | Required (Floor) | Enhanced | Advanced |
|---|---|---|---|
| Written Security Plan (WISP) | Required | Annual review | Quarterly review + tabletop exercises |
| Multi-Factor Authentication | All tax systems | All systems + email | All systems + phishing-resistant MFA |
| Encryption at Rest | Required | Full-disk (BitLocker) | Full-disk + file-level encryption |
| Wireless Security | WPA-2 / AES | WPA-2 + segmented network | Zero trust network access |
| Incident Response Plan | Required | Documented + tested | Tested + MSSP-supported response |
| Staff Security Training | Required | Annual | Annual + phishing simulations |
Book a Free Tax Cybersecurity Assessment
Bellator Cyber Guard will review your current controls against Form 4557 requirements and identify the gaps that put your e-file authorization at risk.
Frequently Asked Questions
Any tax professional who prepares federal tax returns for compensation must comply with Form 4557. This includes sole practitioners, small accounting firms, enrolled agents, and tax preparation franchises. The Gramm-Leach-Bliley Act classifies these professionals as financial institutions, which triggers mandatory data protection obligations regardless of firm size or return volume.
Yes, they refer to the same document. IRS Publication 4557, titled Safeguarding Taxpayer Data, is commonly called Form 4557 in everyday use. It is a guidance publication rather than a fillable tax form, and it outlines the data security requirements and best practices tax professionals must follow to protect client information and maintain e-file authorization.
The IRS treats violations of the FTC Safeguards Rule as violations of Revenue Procedure 2007-40. This can result in suspension from the IRS e-file program, which would prevent you from filing returns electronically on behalf of clients. GLBA violations can also expose a firm to FTC enforcement and civil penalties under applicable state laws.
Yes. A Written Information Security Plan (WISP) is a formal requirement under the FTC Safeguards Rule for all covered financial institutions, including tax preparers. Publication 4557 references the WISP requirement directly and provides guidance on what it must cover.
Yes. The 2023 updates to the FTC Safeguards Rule made MFA a mandatory control for all covered financial institutions, including tax preparers, and Publication 4557 reflects this requirement. MFA must be implemented on every system that stores or provides access to taxpayer data, including tax software, email, and remote access platforms.
Isolate affected systems immediately, then contact your IRS Stakeholder Liaison using the contact information listed in Publication 4557, file IRS Form 14039-B if identity theft is confirmed, and notify affected clients. Most states require breach notification within 30 to 90 days of discovery, and every action should be documented and used to update the WISP.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



