Skip to content
Bellator Cyber Guard
Tax18 min readDeep Dive

IRS Security Six Checklist for Tax Professionals (2026)

The IRS Security Six requirements cover antivirus, firewalls, MFA, backups, encryption, and VPNs. See what tax professionals need in place for 2026.

By Bellator Cyber Guard Security Team
IRS Security Six Checklist for Tax Professionals (2026) - irs security six checklist for tax professionals

What the IRS Security Six Checklist Requires

The IRS Security Six requirements are six baseline security controls the Internal Revenue Service expects every tax professional to have in place before handling a single return: anti-virus/anti-malware software, a firewall, multi-factor authentication (MFA), data backup, drive encryption, and a virtual private network (VPN). The IRS lists these controls in Publication 4557, Safeguarding Taxpayer Data, and promotes them through the Security Summit's "Protect Your Clients; Protect Yourself" campaign, a joint effort between the IRS, state tax agencies, and the tax industry.

If you prepare returns, hold an Electronic Filing Identification Number (EFIN), or store client Social Security numbers and financial records, the Security Six applies to your office, whether you work solo or run a multi-location firm. The sections below explain what each control does, how it connects to your legal obligations under the FTC Safeguards Rule, and how to roll it out without disrupting filing season.

Quick Answer

The IRS Security Six requirements cover six tools every tax practice should run: anti-virus/anti-malware software, a firewall, multi-factor authentication, automated data backup, drive encryption, and a VPN. The list comes from IRS Publication 4557 and the Security Summit's annual awareness campaign. These six controls are a starting point, not a complete Written Information Security Plan (WISP), but putting them in place is a practical first step toward meeting FTC Safeguards Rule obligations.

IRS Security Six Action Checklist

  • Install and actively maintain anti-virus or anti-malware software on every device that touches client data
  • Deploy a network firewall and keep each workstation's built-in firewall enabled
  • Turn on multi-factor authentication for email, tax software, and any client portal
  • Back up client data automatically with at least one copy stored off-site or in the cloud
  • Encrypt hard drives on every laptop and desktop that stores or accesses taxpayer data
  • Require a VPN for any remote access to office systems or files

Why the IRS Publishes This List

Tax professionals are a high-value target for identity thieves. A single compromised preparer account can expose hundreds or thousands of Social Security numbers, wage records, and bank routing numbers in one incident. The IRS created the Security Summit, a partnership between the IRS, state tax agencies, and tax industry groups, after stolen preparer credentials and phishing attacks on tax professionals contributed to a rise in fraudulent returns filed using real client data.

IRS Publication 4557 also ties directly to your obligations under the Gramm-Leach-Bliley Act, enforced for tax preparers through the FTC Safeguards Rule. That rule requires a documented, risk-based information security program. The Security Six is a starting inventory of controls, not the full program. If you hold an EFIN, see our EFIN protection guide for the obligations tied specifically to e-file credentials.

1. Anti-Virus and Anti-Malware Software

Anti-virus and anti-malware software scans files, downloads, and email attachments for known malicious code and blocks it before it runs. For a tax office, this is the first line of defense against malware delivered through fake IRS notices, e-file rejection emails, and infected PDF attachments. Signature-based anti-virus alone is no longer enough; most managed security providers now recommend endpoint detection and response (EDR), which watches for suspicious behavior instead of only matching known virus signatures. See our comparison of EDR solutions and false-positive rates for how the two approaches differ.

2. Firewalls

A firewall filters network traffic in and out of your office, blocking connections from known malicious sources and unauthorized inbound access. Every tax office needs both a network-level firewall, built into your router or a dedicated appliance, and the software firewall built into each workstation's operating system. If you're setting one up for the first time or replacing consumer-grade equipment left by a prior IT vendor, see our firewall setup guide for tax offices.

3. Multi-Factor Authentication (MFA)

Multi-factor authentication requires a second proof of identity, a code from an app, a hardware key, or a push notification, in addition to a password, before granting account access. MFA stops the large majority of account takeover attempts because a stolen or guessed password alone is no longer enough to log in. Enable it on your email, your tax preparation software, your client portal, and any cloud storage that holds return data. If you haven't rolled this out, our IRS Tax Pro Account MFA setup guide walks through the steps.

Important

The IRS Security Summit points to stolen preparer credentials and phishing as recurring causes of fraudulent returns filed with real client data. MFA directly blocks that attack path, which is one reason the IRS treats it as a baseline control rather than an optional upgrade.

4. Backup Software or Services

Backups protect your practice from ransomware, hardware failure, and human error. A corrupted drive or an accidentally deleted client file shouldn't cost you the return. The IRS recommends automated, regular backups with at least one copy stored off-site or in the cloud, separate from your primary network, so a single incident can't destroy both your live data and your backup at once. Test restores periodically; a backup you've never restored from is not one you can rely on during an actual incident.

5. Drive Encryption

Drive encryption scrambles the data stored on a hard drive so it's unreadable without the correct decryption key, even if the physical device is removed. This matters most for laptops: a stolen or lost laptop with an unencrypted drive hands a thief direct access to every client file on it. Windows (BitLocker) and macOS (FileVault) both include encryption tools at no extra cost. The most common gap is that they're never turned on.

6. Virtual Private Network (VPN)

A VPN encrypts the connection between a device and your office network or cloud systems, which matters any time a preparer works from home, a client's office, or public Wi-Fi. Without one, credentials and client data can be intercepted on unsecured networks. Look for a business-grade VPN with centralized management rather than a free consumer app, which typically lacks the logging and administrative controls a firm needs for compliance documentation.

Beyond the Security Six: What Else the IRS and FTC Expect

The Security Six is a starting toolkit, not a complete compliance program. Tax professionals are also expected to maintain a Written Information Security Plan (WISP) that documents your risk assessment, access controls, employee training, and incident response procedures, a requirement under the FTC Safeguards Rule and referenced directly in Publication 4557. Our WISP guide for tax practices covers what the plan needs to include.

You should also have a documented incident response plan. If a breach happens, the IRS expects preparers to report data theft promptly, and firms often need to file Form 14039-B, Business Identity Theft Affidavit, on behalf of affected clients. Structuring your response ahead of time using a recognized framework like NIST Special Publication 800-61, the federal incident handling guide, means you're not making decisions for the first time during an active incident. See our tax professional data breach response guide for the reporting steps, and our overview of non-compliance consequences for what regulators and insurers look for afterward.

Need a WISP, not just a checklist?

Bellator builds a custom Written Information Security Plan starting at $749 for practices with up to 5 users, with larger practices quoted separately. A documented WISP typically saves a firm 20 to 40 billable hours compared to drafting one from scratch.

Security Six Is a Floor, Not a Ceiling

Publication 4557 describes the Security Six as a baseline. Meeting all six items does not by itself satisfy the FTC Safeguards Rule's requirement for a documented, risk-based security program; you still need a WISP, employee training, and periodic risk assessments. Confirm your specific obligations with a qualified compliance advisor or attorney.

How to Roll Out the Security Six in Your Practice

1

Inventory your current tools

List every device, account, and cloud service that touches client tax data, and note which of the six controls is already in place for each.

2

Close the gaps first, then formalize

Turn on MFA and drive encryption before tax season crunch; both take minutes per account and close the highest-risk gaps fastest.

3

Document what you implement

Record dates, settings, and responsible staff for each control. This documentation becomes evidence for your WISP and for any regulator or insurer review.

4

Review annually and after any change

Reassess the checklist whenever you add software, hire staff, or open a new office, and at minimum once a year before filing season.

Key Takeaway

The Security Six covers the technical basics: anti-virus, firewall, MFA, backups, encryption, and a VPN. A defensible security program also needs a written plan, staff training, and a tested incident response process.

Talk with a cybersecurity expert

Get a plain-language review of your firm's Security Six controls and WISP against what the IRS and FTC expect.

Frequently Asked Questions

The Security Six itself is IRS guidance, not a standalone law. Tax professionals are legally required to maintain reasonable data security under the FTC Safeguards Rule, and the Security Six represents the IRS's recommended minimum controls for working toward that standard. Legal questions about your specific obligations should go to counsel.

The Security Six is a list of technical tools. A Written Information Security Plan (WISP) is the documented program required by the FTC Safeguards Rule, covering risk assessment, access controls, vendor management, employee training, and incident response. The Security Six tools feed into that plan; they don't replace it.

Yes. The IRS doesn't mandate specific brands or products; it describes the categories of protection needed. What matters is that each function, malware protection, network filtering, strong authentication, backup, encryption, and secure remote access, is actually in place and maintained.

Review at least once a year before filing season starts, and any time you add new software, open a new office location, or bring on new staff, since each change can introduce new gaps.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.