
EFIN Security Requirements: What Every Tax Preparer Must Know in 2026
If you hold an Electronic Filing Identification Number (EFIN), the IRS holds you directly responsible for the security of every return you process electronically. Failing to meet the standards in IRS Publication 4557, "Safeguarding Taxpayer Data", puts your EFIN at risk of suspension or permanent revocation, which ends your ability to e-file for clients entirely.
This tax preparer EFIN security compliance checklist for 2026 breaks down every requirement across the three safeguard categories the IRS evaluates: administrative, physical, and technical. The rules apply equally to solo practitioners and multi-staff firms. Any preparer handling 11 or more individual returns annually must have a documented Written Information Security Plan (WISP) in place. That threshold has not changed, but the IRS has intensified its scrutiny of implementation quality, not just whether a document exists.
The data breach exposure is real. According to the IBM Cost of Data Breach Report 2024, the average breach now costs $4.88 million per incident. Tax preparation businesses are attractive targets because client files contain Social Security numbers, income data, financial account details, and prior-year return history, all in one place.
The 2026 filing season brings heightened IRS focus on third-party vendor security, remote access controls, and multi-factor authentication (MFA). Preparers who last updated their WISP in 2023 or early 2024 likely have gaps that need attention before the season opens.
Tax Preparer Security By The Numbers
IBM Cost of Data Breach Report 2024, per-incident average across all industries
IBM 2024: average time to identify and contain a breach once it begins
Any preparer filing 11 or more returns annually must maintain a compliant WISP under IRS Publication 4557
IRS Publication 4557 and the FTC Safeguards Rule: Layered Obligations
Publication 4557 draws from three sources: the Gramm-Leach-Bliley Act (GLBA), the FTC Safeguards Rule, and IRS-specific requirements for authorized e-file providers. Together, they create a security framework that covers Federal Tax Information (FTI) across your entire practice, from how you store files to how you train staff.
The WISP you build under Publication 4557 must address four operational areas: who is responsible for security (administrative), how you physically protect your office and equipment (physical), what technical controls you deploy (technical), and how you detect and respond to security events (monitoring and incident response). Each area requires specific documentation, not just informal practice.
The FTC Safeguards Rule, which took full effect in June 2023, adds compliance requirements beyond Publication 4557 alone. Tax preparers qualify as "financial institutions" under the GLBA, which means the Rule applies to your practice. It mandates annual risk assessments, multi-factor authentication for all remote system access, encryption of customer data at rest and in transit, and specific employee training obligations. Our guide to the FTC Safeguards Rule for tax preparers covers these layered requirements in detail.
EFIN holders who have not revisited their compliance program since before June 2023 should treat this filing season as a reset. The gap between a pre-Safeguards-Rule WISP and current requirements is now large enough to create meaningful exposure during an IRS compliance review.
2026 Filing Season Compliance Requirement
All authorized IRS e-file providers must have an updated, implemented Written Information Security Plan in place before the 2026 filing season begins. An existing WISP from prior years must be reviewed and revised to reflect personnel changes, new software, and any security incidents from the previous year. Providers who cannot produce a current, functional WISP during an IRS compliance review face EFIN suspension.
EFIN Security Compliance: Step-by-Step Implementation Roadmap
Designate Your Information Security Officer
Name a specific person responsible for your WISP and ongoing security oversight. This individual must have the authority to enforce policies, allocate budget for remediation, and coordinate incident response. Solo practitioners can designate themselves, but the designation must appear in the WISP document by name.
Conduct a Documented Risk Assessment
Inventory every system, device, and process that touches Federal Tax Information. Identify threats, vulnerabilities, and the likelihood of harm for each. Document your findings in writing. The FTC Safeguards Rule requires this assessment annually, and the results should drive every other control in your WISP.
Build or Update Your Written Information Security Plan
Create or revise your WISP to cover all three safeguard categories. Use IRS Publication 5708's sample WISP as a starting baseline, then customize it to reflect your actual software, office setup, and staffing. A WISP that describes a practice other than your own will not hold up during a review.
Deploy Required Technical Controls
Enable multi-factor authentication on every system touching client data, configure automatic screen locks (10-minute maximum), activate encrypted storage and transmission, and install current endpoint protection on all devices used for tax preparation work. Document the configuration details for each control.
Train All Staff Before Filing Season Opens
Conduct annual security awareness training covering phishing recognition, password practices, FTI handling procedures, and how to report a suspected incident. Document completion with dates and employee names. New hires must complete training before they are granted access to any system containing client data.
Test Your Incident Response Procedures
Run a tabletop exercise simulating a data breach or ransomware attack before the season begins. Verify that staff know how to report an incident internally, who contacts the IRS Stakeholder Liaison, and how to notify affected clients within required timeframes. Update your procedures based on what the exercise reveals.
Administrative Safeguards: The Policies and Accountability the IRS Expects
Administrative safeguards are the policies, procedures, and oversight structures that govern how your practice manages security responsibilities. The IRS treats these as the backbone of your compliance program because even the best technical controls fail without the right human processes behind them.
Your WISP must name a specific security coordinator. Assigning responsibility to "management" or "the IT department" does not satisfy the requirement. That individual must have documented authority to make security decisions, enforce policies with staff, and spend money on remediation when needed. This is true even for a one-person practice.
Access control documentation is an area where tax preparers frequently fall short. You must be able to produce a current list of every person with access to systems containing FTI, explain the business reason for each person's access level, and show when access was last reviewed. When an employee leaves or changes roles, access revocation must happen immediately and be logged. Our walkthrough of IRS WISP requirements includes the specific documentation structure that satisfies this expectation.
Employee training records matter just as much as the training itself. Sending staff a link to a generic cybersecurity video does not meet the standard. Training must be annual, documented with completion dates and employee names, and specific to IRS data handling requirements, not just general internet security hygiene. If an IRS reviewer asks to see your training documentation during a compliance review, you need more than an email receipt from an online course provider.
Administrative Safeguards Checklist
- Designate a named Information Security Officer with written authority documented in the WISP
- Maintain a current inventory of all systems that store or process Federal Tax Information
- Document all user access grants, role changes, and terminations with dates and approvals
- Conduct annual security awareness training specific to IRS data handling requirements
- Maintain signed confidentiality agreements from all employees and contractors with FTI access
- Write and test an incident response plan that includes IRS Stakeholder Liaison contact information
- Assess all third-party vendors who access, store, or transmit client tax data
- Complete and document a risk assessment before each filing season
- Review and update your WISP annually and after any personnel change, software addition, or security incident
Technical Safeguards: Specific Controls the IRS Will Verify
Technical safeguards are the system-level controls that directly protect Federal Tax Information from unauthorized access, theft, and disclosure. The IRS expects specific, documented implementations. "We have antivirus software" is not a sufficient answer during a compliance review.
Multi-factor authentication is required for every system that handles client tax data, including tax preparation software, email platforms, cloud storage, and any remote access tool. Under the FTC Safeguards Rule, MFA for remote system access has been mandatory since June 2023. If your practice uses remote desktop, VPN, or cloud-based tax software accessed from outside the office network, MFA must be active on all those connections. Our guide on choosing a VPN for secure remote access to client data includes specific recommendations for tax environments.
Encryption requirements cover both data in transit and data at rest. Client files stored on local drives, external storage, or cloud services must be encrypted. Data transmitted to clients, the IRS, or between office locations must travel over encrypted connections using Transport Layer Security (TLS) 1.2 or higher. Preparers using unencrypted USB drives or legacy email systems to move client documents have significant exposure here.
Endpoint Detection and Response (EDR) software provides a meaningful upgrade over standard antivirus for tax preparation environments. Unlike traditional antivirus, EDR monitors for behavioral indicators of compromise, detects fileless malware and ransomware before encryption can complete, and generates the audit logs that satisfy IRS documentation requirements. Our comparison of EDR, MDR, and XDR solutions explains which tier fits different practice sizes and risk profiles. All endpoint security software must be kept current, with updates applied within 30 days of release.
Physical Security: The Requirements Most Tax Preparers Overlook
Physical safeguards protect your computing equipment and the data stored on it from direct, in-person compromise. These requirements get less attention than technical controls, but they are equally enforceable and equally important to an IRS reviewer.
Workstation positioning is a specific, documented requirement under Publication 4557. Computer screens must not be visible to clients, visitors, or any person not authorized to view Federal Tax Information. In a shared office or reception area, this typically means angling monitors away from common spaces or installing privacy screen filters. Automatic screen locks must engage after no more than 10 minutes of inactivity. Staff must also lock their screens manually when stepping away, even briefly.
Server rooms, network equipment closets, and filing cabinets containing tax records must be kept locked. Access should be limited to specific named individuals, and entry should be logged. For home-based practitioners, this means a locked office or locked file storage for paper documents, backup drives, and any portable media containing client data. The IRS does not require a separate locked room in all cases, but the principle of limiting physical access to FTI applies regardless of where you practice.
Media disposal creates significant risk for tax preparers who do not have a formal process. Hard drives from retired computers, backup tapes, USB drives, and even office copiers with internal storage can retain readable client data long after devices leave your possession. The IRS expects certified data destruction for any media that stored FTI. Use a qualified destruction service and maintain the destruction certificate indefinitely. Our resource on responding after a data breach covers what happens when media disposal fails and client FTI is exposed.
The Takeaway
An EFIN is not just an authorization number. It carries legal obligations for data security that flow directly from IRS Publication 4557, the FTC Safeguards Rule, and applicable state privacy laws. If your WISP is more than 12 months old and has not been updated after personnel changes or security incidents, it is out of compliance now, regardless of what the document says.
Annual Compliance Maintenance: Keeping Your EFIN in Good Standing Year-Round
Compliance is not a one-time project. EFIN holders must demonstrate ongoing security program management, which means scheduled activities throughout the calendar year, not just a documentation effort before each filing season.
The most important annual activity is a full WISP review conducted before the busy season begins, typically between October and December. This review should examine every named individual in the document (roles change), every system listed as containing FTI (new software may have been adopted during the year), and every security incident from the prior year (lessons learned must feed back into documented procedures). A WISP that has not changed in two years almost certainly no longer reflects your actual practice.
Third-party vendor management has grown in importance as tax practices adopt more cloud-based tools. Every service provider that accesses, stores, or transmits Federal Tax Information must be assessed for security adequacy. That means reviewing current SOC 2 Type II reports, confirming encryption standards, and verifying that your contracts include security obligations and breach notification timeframes. Our analysis of security for tax client portals covers what to look for when evaluating the platforms you use to share documents with clients.
Patch management must be documented and followed as a scheduled process. Unpatched systems running outdated software are among the most common findings in IRS compliance reviews. Your policy should specify who applies patches, how quickly after release, and how exceptions are tracked when a system cannot be immediately updated. "We update when we remember" is not a patch management policy.
Common EFIN Compliance Pitfalls and How to Close the Gaps
Most EFIN compliance failures trace back to a small set of recurring mistakes. Knowing what they are lets you audit your own program before an IRS review finds them.
The most common problem is a WISP that exists on paper but does not reflect actual practice. Preparers download a template, fill in their firm name, and file it away. Two years later, they have new employees, new software, and a different office configuration, but the WISP still describes their 2023 setup. An IRS reviewer who asks to see your incident response contact list and finds numbers for former employees will not treat that as a minor documentation gap.
Incomplete MFA deployment is the second major failure area. Many preparers implement multi-factor authentication on their primary tax software but leave email, cloud storage, and remote desktop tools unprotected. All of those paths can reach client data. The FTC Safeguards Rule requires MFA on all remote access to systems containing customer financial information, not just the tax application itself.
Inadequate training documentation is the third recurring gap. Sending staff a link to a generic cybersecurity awareness video does not satisfy annual training requirements. Documentation must include specific dates, employee names, and a description of what the training covered. The content must address FTI handling specifically, including how to recognize a phishing email targeting tax preparers, what to do with a suspicious attachment, and how to report an incident internally.
Remote work security is often the most significant blind spot. Remote access to systems containing FTI requires the same controls as in-office access, plus additional protections for the home network environment. Your WISP must explicitly address remote work as a documented policy, not an informal arrangement. Our practical guide on remote work security for small teams includes a checklist specific to tax practice environments.
Free 2026 WISP Template for Tax Preparers
Get a compliant Written Information Security Plan template built specifically for tax professionals. Pre-formatted to meet IRS Publication 4557 and FTC Safeguards Rule requirements for the 2026 filing season.
Software and Cloud Service Requirements for EFIN Compliance
Tax preparation software used by EFIN holders must meet specific security standards. Choosing software that meets those standards is only part of the obligation. You must also configure it correctly, maintain current updates, and use it in an environment that supports its security features.
When evaluating any tax software platform, verify that it provides automatic session timeout, encrypted local data storage, role-based user access controls with the ability to limit what each user can see and do, and complete audit logging of all user activity. Software that lacks audit logging creates a documentation gap when the IRS asks you to demonstrate who accessed which client files and when.
Cloud-based tax platforms require additional scrutiny. Confirm that your vendor maintains SOC 2 Type II certification, uses current encryption standards for data at rest and in transit, and has a documented breach notification process that meets IRS and state requirements. Request updated security documentation from cloud vendors annually as part of your vendor management review. A vendor that cannot provide current SOC 2 documentation or declines to share their security practices represents a compliance risk that flows directly back to your EFIN.
The IRS authorized e-file provider program includes ongoing obligations to maintain software security standards throughout the provider relationship. Our tax security solutions include managed compliance services for tax preparation practices, covering vendor assessments, technical control deployment, and ongoing WISP maintenance.
Bottom Line
EFIN security compliance is a scheduled maintenance program, not a one-time project. Build a calendar: WISP review before filing season, monthly patch checks, quarterly access audits, and annual employee training. Practices that treat compliance as an ongoing operational commitment are far less likely to face an EFIN suspension than those who scramble before an audit or incident forces the issue.
Book a Free EFIN Security Compliance Assessment
Our tax cybersecurity specialists will evaluate your current WISP, technical controls, and training program against 2026 IRS and FTC requirements, then provide a specific remediation roadmap for your practice.
Frequently Asked Questions
Operating as an authorized e-file provider without a compliant WISP violates IRS Publication 4557 requirements and the FTC Safeguards Rule. The most immediate consequence is EFIN suspension or revocation if the IRS identifies the gap during a compliance review, a data breach investigation, or a routine audit. Without an active EFIN, you cannot electronically file tax returns for clients. The FTC can also assess civil penalties against tax preparers who fail to maintain adequate data security programs under the Gramm-Leach-Bliley Act. Get started with our WISP template for tax preparers or explore our IRS Publication 4557 compliance services.
Your Written Information Security Plan must be reviewed and updated at least annually, and the IRS expects that review to occur before each filing season. Beyond the annual review, your WISP must be updated whenever material changes occur: when employees join or leave, when you adopt new software or change cloud vendors, after any security incident, or when IRS or FTC guidance changes. A WISP is a living document that must reflect how your practice actually operates today, not how it was set up when you first created it.
The IRS does not mandate third-party penetration testing or external audits as a universal requirement for all EFIN holders. However, both Publication 4557 and the FTC Safeguards Rule require regular risk assessments. For practices with more than a handful of employees or that operate complex technology environments, a third-party assessment is often the most reliable way to document that requirement. Larger tax firms qualifying as "financial institutions" under the expanded Safeguards Rule face more specific requirements for independent security testing. Our Publication 4557 compliance services include risk assessment support appropriate for practices of all sizes.
Annual security awareness training is required for all employees and contractors who handle Federal Tax Information. Training must cover phishing recognition, password security practices, proper handling and disposal of client data, and how to report a suspected security incident. Generic online courses may not satisfy the requirement if they do not address IRS-specific data handling obligations. Documentation of training completion, including dates and employee names, must be maintained and available for IRS review. New employees must complete training before they receive access to any system containing FTI.
Yes, cloud storage is permissible for client tax documents, but your cloud provider must meet specific security standards. The provider must encrypt data both at rest and in transit, maintain SOC 2 Type II certification or equivalent, and provide contractual commitments covering security practices and breach notification. You must verify these standards annually as part of your vendor management program and document that verification in your WISP. Free or consumer-grade cloud services, such as a personal Dropbox account or an unmanaged Google Drive, generally do not meet the requirements for storing Federal Tax Information.
A reportable security incident includes any unauthorized access to, disclosure of, or acquisition of Federal Tax Information or client personally identifiable information. This covers ransomware infections that encrypt files containing tax data, phishing attacks where an employee's credentials are compromised, loss or theft of a device containing unencrypted client data, and unauthorized access to your tax software or client portal. When an incident occurs, you must notify the IRS Stakeholder Liaison in your area, notify affected clients, and report to your state data breach notification authority if required by state law. Your incident response plan should document these notification procedures before any incident happens. See our incident response planning guide for tax practices for step-by-step procedures.
Remote work does not reduce your EFIN security obligations. Every device used to access Federal Tax Information from outside your primary office must meet the same security standards as in-office equipment. This means multi-factor authentication on all remote access connections, a VPN or secure remote desktop solution using current encryption, automatic screen locks, up-to-date endpoint protection software, and a prohibition on accessing client data over shared or public Wi-Fi without an active VPN. Home networks used for tax preparation work must use WPA2 or WPA3 encryption. Your WISP should explicitly address remote work as a documented policy with specific controls listed, not as an informal arrangement left to individual employees to manage on their own.
IRS Publication 4557 requires that tax preparers maintain secure backups of all data and programs used in their e-file operations. Backups must be encrypted, stored in a location physically separate from your primary systems, and tested regularly to verify successful restoration. A backup you have never tested is not a reliable backup. Best practice for active tax practices is daily incremental backups during filing season, with monthly full backups year-round. Backup media is subject to the same physical security and disposal requirements as your primary storage. When a backup drive is retired, it must be securely destroyed and you must maintain the destruction certificate for your records.
Penalties depend on the nature and severity of the violation and which regulatory body takes action. The IRS can suspend or revoke your EFIN, ending your ability to e-file returns. The FTC can assess civil penalties under the Gramm-Leach-Bliley Act for failures to maintain required safeguards. State attorneys general can bring actions under state data breach notification and privacy laws, with penalty ranges that vary by state. In cases involving intentional misconduct or willful disregard for security requirements, criminal referrals are possible. A data breach affecting client FTI also creates civil liability exposure to affected clients. Maintaining a documented, implemented compliance program is your most effective protection against all of these outcomes.
The IRS does not specify a single universal retention period for all security documentation. As a practical standard: retain your WISP and all prior versions for at least five years; employee training records for three to five years; incident response records for significant incidents indefinitely; and vendor security assessments and contracts for the duration of the vendor relationship plus three years. Some states impose longer retention requirements for records related to data breaches or privacy compliance. Build a documented retention schedule into your WISP so practices are consistent across your firm and do not depend on individual employees to remember what to keep.
Schedule
Need help with IRS compliance?
Our tax cybersecurity specialists can review your security posture and help you get compliant.


