Skip to content
Bellator Cyber Guard
Tax17 min readDeep Dive

IRS Security Six Checklist for Tax Professionals (2026)

The IRS Security Six checklist for tax professionals covers antivirus, firewalls, MFA, backups, encryption, and VPNs, see what to put in place.

By Bellator Cyber Guard Security Team

What the IRS Security Six Checklist Covers

The IRS Security Six is a list of six baseline safeguards the Internal Revenue Service recommends every tax professional put in place to protect taxpayer data: anti-virus software, a firewall, multi-factor authentication (MFA), backup software or services, drive encryption, and a virtual private network (VPN). The IRS publishes this list through its Security Summit "Protect Your Clients; Protect Yourself" campaign and in Publication 4557, Safeguarding Taxpayer Data, as the minimum technical controls a preparer's office should have running before it handles a single tax return.

If you prepare returns, hold an Electronic Filing Identification Number (EFIN), or store client Social Security numbers and financial records, this checklist applies to you, whether you're a solo preparer or run a multi-location firm. Below is what each item means in practice, how it fits into your legal obligations under the FTC Safeguards Rule, and how to roll it out without disrupting tax season.

Quick Answer

The IRS Security Six is a set of six baseline security tools the IRS recommends for every tax professional: anti-virus/anti-malware software, a firewall, multi-factor authentication, data backup, drive encryption, and a VPN. It comes from IRS Publication 4557 and the Security Summit's annual awareness campaign. These six controls are the minimum starting point, not a complete Written Information Security Plan (WISP), but implementing them is a practical first step toward meeting FTC Safeguards Rule obligations.

IRS Security Six Action Checklist

  • Install and actively maintain anti-virus/anti-malware software on every device that touches client data
  • Deploy a network firewall and keep each workstation's built-in firewall enabled
  • Turn on multi-factor authentication for email, tax software, and any client portal
  • Back up client data automatically with at least one copy stored off-site or in the cloud
  • Encrypt hard drives on every laptop and desktop that stores or accesses taxpayer data
  • Require a VPN for any remote access to office systems or files

Why the IRS Publishes This List

Tax professionals are a high-value target for identity thieves because a single compromised preparer account can expose hundreds or thousands of Social Security numbers, wage records, and bank routing details in one incident. The IRS created the Security Summit, a partnership between the IRS, state tax agencies, and the tax industry, after stolen preparer credentials and phishing attacks on tax professionals contributed to a rise in fraudulent returns filed with real client data. The Security Six checklist is the Summit's answer to a common problem: many small firms didn't know where to start.

Publication 4557 also ties directly to your obligations under the Gramm-Leach-Bliley Act, enforced for tax preparers through the FTC Safeguards Rule. That rule requires a documented, risk-based information security program, the Security Six is a practical starting inventory of controls, not the full program itself.

1. Anti-Virus and Anti-Malware Software

Anti-virus and anti-malware software scans files, downloads, and email attachments for known malicious code and blocks it before it runs. For a tax office, this is your first line of defense against malware delivered through fake IRS notices, e-file rejection emails, and infected PDF attachments. Traditional signature-based anti-virus is no longer enough on its own, most managed security providers now recommend endpoint detection and response (EDR), which watches for suspicious behavior instead of just matching known virus signatures. See our overview of endpoint detection and response for how the two differ.

2. Firewalls

A firewall filters network traffic in and out of your office, blocking connections from known malicious sources and unauthorized inbound access to your systems. Every tax office needs both a network-level firewall (built into your router or a dedicated appliance) and the software firewall built into each workstation's operating system. If you're setting one up for the first time or replacing consumer-grade equipment left over from a prior IT vendor, see our walkthrough on firewall setup for a tax office.

3. Multi-Factor Authentication (MFA)

Multi-factor authentication requires a second proof of identity, a code from an app, a hardware key, or a push notification, in addition to a password before granting account access. MFA stops the largest share of account takeover attempts, because a stolen or guessed password alone is no longer enough to log in. Enable it on your email, your tax preparation software, your client portal, and any cloud storage that holds return data. If you haven't rolled this out yet, walk through our step-by-step guide to set up two-factor authentication across your firm's accounts.

4. Backup Software or Services

Backups protect your practice from ransomware, hardware failure, and human error, a corrupted drive or an accidentally deleted client file shouldn't cost you the return. The IRS recommends automated, regular backups with at least one copy stored off-site or in the cloud, separate from your primary network, so a single incident can't destroy both your live data and your backup at once. Test restores periodically; a backup you've never restored from is not one you can rely on during an actual incident.

5. Drive Encryption

Drive encryption scrambles the data stored on a hard drive so it's unreadable without the correct decryption key, even if the physical device is removed. This matters most for laptops: a stolen or lost laptop with an unencrypted drive hands a thief direct access to every client file on it. Windows (BitLocker) and macOS (FileVault) both include encryption tools at no extra cost, the most common gap is that they're simply never turned on.

6. Virtual Private Network (VPN)

A VPN encrypts the connection between a device and your office network or cloud systems, which matters any time a preparer works from home, a client's office, or public Wi-Fi. Without one, credentials and client data can be intercepted on unsecured networks. See our overview of VPN security for what to look for in a business-grade VPN versus a free consumer app.

Beyond the Security Six: What Else the IRS and FTC Expect

The Security Six is a starting toolkit, not a complete compliance program. Tax professionals are also expected to maintain a Written Information Security Plan (WISP) that documents your risk assessment, access controls, employee training, and incident response procedures, a requirement under the FTC Safeguards Rule and referenced directly in Publication 4557. If you don't have one yet, our tax safeguard compliance 4557 guide walks through what the plan needs to cover, and you can start from our free WISP template built for tax practices.

You should also have a documented incident response plan. If a breach does happen, the IRS expects preparers to report data theft promptly, and firms often need to file Form 14039-B data theft reporting on behalf of affected clients. Structuring your response ahead of time using a recognized framework like the NIST incident response framework means you're not making decisions for the first time during an active breach.

Security Six Is a Floor, Not a Ceiling

Publication 4557 describes the Security Six as a baseline. Meeting all six items does not by itself satisfy the FTC Safeguards Rule's requirement for a documented, risk-based security program, you still need a WISP, employee training, and periodic risk assessments. Confirm your specific obligations with a qualified compliance advisor or attorney.

How to Roll Out the Security Six in Your Practice

1

Inventory your current tools

List every device, account, and cloud service that touches client tax data, and note which of the six controls is already in place for each.

2

Close the gaps first, then formalize

Turn on MFA and drive encryption before tax season crunch, these take minutes per account and close the highest-risk gaps fastest.

3

Document what you implement

Record dates, settings, and responsible staff for each control; this documentation becomes evidence for your WISP and any regulator or insurer review.

4

Review annually and after any change

Reassess the checklist whenever you add software, hire staff, or open a new office, and at minimum once a year before filing season.

Key Takeaway

The Security Six covers the technical basics, anti-virus, firewall, MFA, backups, encryption, and VPN, but a defensible security program also needs a written plan, staff training, and a tested incident response process.

Book a Free Tax Cybersecurity Assessment

Get plain-language help checking your firm's Security Six controls and WISP against what the IRS and FTC expect. No pressure.

Frequently Asked Questions

The Security Six itself is IRS guidance, not a standalone law. Tax professionals are legally required to maintain reasonable data security under the FTC Safeguards Rule, and the Security Six represents the IRS's recommended minimum controls for working toward that standard. Legal questions about your specific obligations should go to counsel.

The Security Six is a list of technical tools. A Written Information Security Plan (WISP) is the documented program required by the FTC Safeguards Rule covering risk assessment, access controls, vendor management, employee training, and incident response, the Security Six tools feed into that plan, they don't replace it.

Yes. The IRS doesn't mandate specific brands or products, it describes the categories of protection needed. What matters is that each function, malware protection, network filtering, strong authentication, backup, encryption, and secure remote access, is actually in place and maintained.

Review at least once a year before filing season starts, and any time you add new software, open a new office location, or bring on new staff, since each change can introduce new gaps.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.