
IRS Publication 5293, Data Security Resource Guide for Tax Professionals, is a free directory published by the Internal Revenue Service (IRS) that gathers data security guidance from several federal agencies into one reference document for tax preparers. It does not create a new standalone security standard. Instead, it links you to the specific requirements and tools that already apply to your practice: the Security Six safeguards from Publication 4557, the sample Written Information Security Plan (WISP) in Publication 5708, Federal Trade Commission (FTC) Safeguards Rule obligations, and steps for reporting a suspected data breach.
If you're a paid tax preparer, an accounting firm owner, or an office manager responsible for client data, Pub 5293 is worth downloading, but only as a starting index. This guide covers what's actually inside it, how the pieces connect to the compliance obligations that carry real consequences, and what to do with the checklist once you've read it in 2026.
Quick Answer
IRS Publication 5293 is a compilation of links and contacts, not a standalone checklist. It directs tax preparers to Publication 4557 (Safeguarding Taxpayer Data), the Security Six controls, the sample Written Information Security Plan in Publication 5708, Federal Trade Commission (FTC) Safeguards Rule requirements, and breach-reporting contacts. Use it as a map to find the document you need, then implement the underlying requirement, most preparers still need a written, practice-specific WISP and the technical controls it describes.
What's Inside IRS Publication 5293
Publication 5293 is organized as a resource index rather than a single checklist. Reading through it, the material falls into roughly four categories:
- Baseline security guidance: links to Publication 4557 and the IRS Security Six checklist, covering antivirus software, firewalls, multi-factor authentication, backup software, drive encryption, and a virtual private network (VPN).
- Planning tools: a pointer to Publication 5708, the IRS's sample Written Information Security Plan template, and small-business guidance from the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
- Threat awareness: links to IRS Identity Theft Central and warnings about phishing attacks on tax professionals, since compromised preparer credentials remain a common way client data is stolen.
- Incident response contacts: who to call if you suspect a breach, including your local IRS Stakeholder Liaison, your state tax agency, and federal law enforcement.
None of these sections are exclusive to Pub 5293. Every document it links to already exists on its own; the guide's value is saving you the time of hunting for each one separately across IRS.gov, FTC.gov, and NIST.gov.
How to Use IRS Publication 5293 in Your Practice
Download the guide and confirm your practice type
Get the current-year PDF from IRS.gov and note that it's a resource index, not a checklist you fill in directly.
Work through the Security Six first
Publication 4557's baseline controls, antivirus, firewall, multi-factor authentication, backup software, drive encryption, and a VPN, are the foundation everything else builds on.
Build or benchmark your WISP
Use the Publication 5708 template as a starting point, then fill in your actual vendors, access controls, and staff roles.
Map your FTC Safeguards Rule obligations
Determine whether your practice qualifies as a covered financial institution under the Gramm-Leach-Bliley Act, and confirm who holds the required qualified individual role.
Save your breach reporting contacts now
Write down your IRS Stakeholder Liaison, state tax agency contact, and local law enforcement details before you need them under pressure.
Pub 5293 vs. Pub 4557 vs. Pub 5708
Pub. 5293
- What It Covers
- A directory of links to IRS, FTC, and NIST security resources
- How To Use It
- Start here to find the exact document you need
Pub. 4557
- What It Covers
- Safeguarding Taxpayer Data: baseline security recommendations for preparers
- How To Use It
- Read this for the core Security Six controls
Pub. 5708
- What It Covers
- Sample Written Information Security Plan (WISP) template
- How To Use It
- Use this to draft or benchmark your own written plan
| Feature | What It Covers | How To Use It |
|---|---|---|
| Pub. 5293 | A directory of links to IRS, FTC, and NIST security resources | Start here to find the exact document you need |
| Pub. 4557 | Safeguarding Taxpayer Data: baseline security recommendations for preparers | Read this for the core Security Six controls |
| Pub. 5708 | Sample Written Information Security Plan (WISP) template | Use this to draft or benchmark your own written plan |
Action Checklist From Pub 5293's Resource List
- Confirm your practice has a written WISP that names a qualified individual
- Verify antivirus, firewall, and multi-factor authentication are active on every device (the Security Six)
- Encrypt taxpayer data at rest and in transit
- Train staff at least once a year on phishing and social engineering
- Save your IRS Stakeholder Liaison and state tax agency contact information before an incident happens
- Review your WISP and vendor list at least annually
Why the Resource List Points Back to the FTC Safeguards Rule
Most of Publication 5293's links exist because of one requirement: the FTC Safeguards Rule, issued under the Gramm-Leach-Bliley Act (GLBA), a federal law that regulates how financial institutions handle customer information. Tax preparation businesses have been treated as covered financial institutions under the amended rule since its compliance deadline of June 9, 2023, according to the FTC. The rule requires a written information security program, a designated qualified individual to run it, and specific technical controls; our guide to the FTC Safeguards Rule qualified individual requirement covers who can hold that role at a small practice.
That's also why Pub 5293 links to the Publication 5708 WISP template instead of including a finished plan. A WISP is practice-specific: the IRS can point you to a starting template, but it can't fill in your vendor list, your access controls, or your incident response contacts for you. Our breakdowns of the IRS WISP template and the WISP template for sole proprietors walk through what each section needs to say. Multi-factor authentication (MFA) on your IRS accounts is one of the specific controls examiners look for first; see our walkthrough of IRS Tax Pro Account MFA setup if you haven't enabled it yet.
Report Suspected Breaches Promptly
IRS guidance directs tax professionals to contact their local IRS Stakeholder Liaison as soon as they suspect a data loss, along with their state tax agency (most states are listed through the Federation of Tax Administrators) and, for identity theft affecting individual clientsIRS Identity Theft Central. Waiting to confirm the full scope of an incident before reporting can delay protective filing measures for your clients.
A Resource List Isn't a Finished Security Program
Publication 5293 tells you which documents to read. It doesn't encrypt your files, patch your software, or write your WISP for you. Most practices that download the guide still need to convert its checklist items into a dated, practice-specific plan and working technical controls, and skipping that step carries real consequences; see our overview of non-compliance consequences for tax preparers who stop at the reading stage.
Bellator Cyber Guard builds a custom Written Information Security Plan starting at $749 for practices with up to five users, with larger firms quoted separately (see WISP pricing and details). A properly built WISP commonly replaces 20 to 40 hours of billable staff time otherwise spent researching templates and cross-referencing IRS and FTC requirements. If you also need the underlying technical controls the Security Six describes, monitored antivirus, patching, and backup, compare managed options on the protection plans page. Solid tax data management habits, like limiting who can access client files and logging when records are opened, close gaps that Pub 5293 assumes your practice has already handled.
Get Help Turning Publication 5293 Into a Working Plan
Talk through what your practice actually needs beyond the resource list. No pressure, no obligation.
Frequently Asked Questions
No single document is itself the legal requirement. The underlying obligations, such as the FTC Safeguards Rule for paid preparers and Publication 4557's baseline recommendations, are what apply to your practice. Pub 5293 is a navigation aid to those requirements, not a substitute for meeting them. Confirm specific legal obligations with your attorney or compliance advisor.
Publication 4557, Safeguarding Taxpayer Data, describes the actual security controls the IRS recommends, including the Security Six. Publication 5293 is a shorter index that links out to 4557 and several other agencies' resources so preparers don't have to search for each one separately.
No. Pub 5293 links to Publication 5708, the IRS's sample Written Information Security Plan, rather than containing the template itself.
The guide points to your local IRS Stakeholder Liaison, your state tax agency, and, for identity theft affecting individual clients, IRS Identity Theft Central. Many practices also need to notify affected clients directly; check your state's specific notification rules with counsel.
The IRS periodically refreshes its resource guides as agency contacts and requirements change. Confirm you're using the current-year version posted on IRS.gov before relying on the contact information inside it.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



