Skip to content
Bellator Cyber Guard
Tax36 min readDeep Dive

VPN for Tax Professionals: Secure Remote Access Guide

Set up a compliant VPN for your tax practice: IRS Security Six requirements, AES-256 encryption, MFA enforcement, and audit-ready log retention explained.

By Bellator Cyber Guard Security Team
VPN for Tax Professionals: Secure Remote Access Guide - vpn for tax professionals

What Is a VPN for Tax Professionals?

A VPN for tax professionals is a Virtual Private Network configured to meet the encryption, authentication, and access control requirements established by the IRS Security Six framework. Under IRS Publication 4557, every tax preparer holding a Preparer Tax Identification Number (PTIN) must implement six essential cybersecurity safeguards. A properly configured VPN serves as the primary mechanism for securing remote access to client data, which includes Social Security numbers, bank account details, prior-year returns, and income records.

Tax professionals face a uniquely concentrated risk profile. The FTC Safeguards Rule requires financial institutions and tax preparers to encrypt all client data in transit when accessing it remotely. A compliant VPN creates an encrypted tunnel between remote devices and your practice network, protecting nonpublic personal information (NPPI) whether your staff connects from home offices, coffee shops, or client locations. With remote work now standard across the profession, your VPN configuration directly affects your ability to operate, pass IRS security audits, and maintain your PTIN. For a full breakdown of the Safeguards Rule obligations that apply to your practice, see our FTC Safeguards Rule guide for tax preparers.

The average data breach costs $4.88 million according to the IBM Cost of Data Breach Report 2024, while an IRS-mandated PTIN suspension can halt practice revenue entirely. This guide covers IRS VPN requirements, implementation steps, protocol selection, common compliance failures, and vendor evaluation criteria, giving tax practices a complete framework for secure, compliant remote access.

Tax Practice Cybersecurity By The Numbers

$4.88M
Avg. Cost of a Data Breach

IBM Cost of Data Breach Report 2024

80%+
Hacking Breaches Involve Compromised Credentials

Verizon 2025 Data Breach Investigations Report

277 Days
Avg. Time to Identify and Contain a Breach

IBM Cost of Data Breach Report 2024

Understanding the IRS Security Six VPN Mandate

The IRS Security Six framework establishes minimum cybersecurity standards for tax professionals through six mandatory controls designed to protect NPPI. VPN sits at the center of this framework because it directly addresses risks inherent in remote access scenarios: when tax preparers connect to office networks from external locations, access cloud-based tax software over public internet connections, or work from home offices without enterprise-grade network security.

During filing season, a single compromised remote connection can expose hundreds or thousands of client records simultaneously. The Verizon 2025 Data Breach Investigations Report found that over 80% of hacking-related breaches involve compromised or weak credentials, making VPN implementation with multi-factor authentication (MFA) essential for protecting NPPI during remote work sessions. The CISA Telework Essentials Toolkit provides additional guidance on VPN selection and hardening that supports IRS compliance efforts for tax professionals working remotely.

Your IRS cybersecurity requirements extend beyond simply deploying a VPN. The Security Six framework treats VPN as one component of a layered defense that also includes firewalls, anti-malware software, MFA, backup solutions, and employee security training. Failing to implement any single component, or implementing it without proper documentation, can result in an IRS security audit finding and potential PTIN suspension. Review the complete PTIN and WISP requirements for tax preparers to understand how VPN documentation fits into your overall compliance structure.

How to Implement a Compliant VPN for Your Tax Practice

1

Assess Your Remote Access Requirements

Inventory all staff who access NPPI remotely, including home workers, mobile preparers, and satellite office employees. Document which systems, software, and data each role needs to reach from external locations.

2

Select an Enterprise VPN Platform

Choose a business-grade solution with AES-256 encryption, native MFA integration, centralized management, and 12-month log retention. Consumer services such as NordVPN or ExpressVPN do not meet IRS audit requirements.

3

Configure MFA Enforcement

Deploy authenticator apps or hardware security keys on every user account. Disable single-factor authentication entirely. Acceptable options include Microsoft Authenticator, Google Authenticator, or YubiKey hardware tokens.

4

Define Role-Based Access Controls

Map each user role to the specific network resources they need. Preparers typically need access to tax software and shared drives, not server administration interfaces or accounting back-end systems.

5

Enable Kill Switch and Endpoint Posture Checks

Configure a kill switch to block all internet traffic if the VPN connection drops unexpectedly. Set endpoint compliance policies that verify antivirus currency, OS patch status, and Endpoint Detection and Response (EDR) agent status before granting access.

6

Document Everything in Your Written Information Security Plan

Update your WISP to include VPN configuration details, MFA requirements, log retention policy, and VPN-specific incident response procedures. Missing WISP documentation is a common IRS audit failure point even for practices with sound VPN deployments.

7

Train Staff and Schedule Annual Reviews

Conduct security awareness training before each filing season. Review and re-test VPN configuration annually. Update your WISP documentation whenever vendor software, hardware, or policy changes occur.

Remote Access vs. Site-to-Site VPNs for Tax Practices

Tax practices typically implement one of two VPN architectures based on their operational structure. Understanding the distinction helps you select the right solution that meets both IRS requirements and your practice's workflow.

Remote access VPNs allow individual users to connect from any location to your practice network or cloud resources. This is the most common implementation for tax practices with mobile employees, work-from-home preparers, or staff who visit client offices. Remote access VPNs authenticate each user individually, enforce per-user access policies, and create encrypted tunnels on demand when staff connect from home networks, coffee shops, or other external locations.

Site-to-site VPNs create permanent encrypted connections between entire networks, linking your main office to a satellite location or connecting your office infrastructure to a cloud data center. All traffic between connected locations flows through the encrypted tunnel automatically, without requiring individual authentication for each session. Multi-office tax firms often deploy a hybrid approach: remote access VPN for individual staff working from home, combined with a site-to-site connection linking physical offices.

The key consideration is ensuring your solution provides the granular logging, user authentication, and access controls required by the IRS Security Six framework. These requirements must be documented in your Written Information Security Plan. For practices using cloud-based tax software, a VPN may still be necessary when accessing client data stored on local servers, connecting to office shared drives, or when your software vendor requires connections from a trusted IP address range. Review your software vendor's specific security requirements before concluding that cloud tools eliminate the need for remote access infrastructure.

VPN Compliance Checklist for Tax Preparers

  • Deploy AES-256 encryption - the minimum standard per IRS Security Six requirements
  • Enforce multi-factor authentication on every VPN connection without exception
  • Enable a kill switch to block all internet traffic if the encrypted connection drops
  • Retain VPN connection logs for a minimum of 12 months for IRS audit documentation
  • Document VPN configuration, MFA policy, and log retention settings in your Written Information Security Plan
  • Restrict each user's VPN access to only the network resources their role requires
  • Use an enterprise VPN platform - consumer services do not satisfy IRS audit requirements
  • Run endpoint posture checks to verify antivirus status and OS patches before granting access
  • Review and re-test VPN configuration annually and before each filing season
  • Train all remote employees on VPN connection procedures and steps to take if the connection drops

Need a Compliant WISP That Documents Your VPN?

Our free 2026 WISP template includes ready-to-fill sections for VPN configuration, MFA enforcement, log retention, and all six IRS Security Six controls.

Multi-Factor Authentication: The Non-Negotiable VPN Requirement

The IRS explicitly requires MFA for all remote access to systems containing NPPI. Your VPN for tax professionals must enforce MFA before allowing any connection. Single-factor authentication using only a username and password does not meet compliance requirements, regardless of password length or complexity.

This requirement carries particular weight when preparers connect from home networks, public WiFi, or client locations where network security is outside your direct control. When a preparer connects from a coffee shop or hotel, the VPN and its MFA gate are the primary barriers between an attacker on that same network and your client records. Tax practices using VPN without MFA are not in compliance with IRS Publication 4557. PTIN suspension cases frequently trace back to IRS security audits that discovered single-factor VPN authentication.

Acceptable MFA implementations for tax practice VPNs include:

  • Authenticator apps generating time-based one-time passwords (TOTP), such as Microsoft Authenticator or Google Authenticator
  • Hardware security keys such as YubiKey, the most secure option for high-risk environments
  • Push notifications sent to registered mobile devices
  • SMS or voice codes, the weakest acceptable option and not recommended for practices handling high data volumes

Your Written Information Security Plan (WISP) must document your MFA implementation in detail: which method you use, how you provision credentials to new employees, and the procedure for handling lost or compromised authentication devices. Many tax practices fail IRS audits not because they lack MFA, but because their WISP documentation does not adequately describe the MFA policy. For remote environments, extend MFA beyond the VPN itself to your tax software applications, email systems, and cloud storage platforms. Layered authentication controls throughout the remote access chain reduce the risk that a single compromised credential opens access to all client NPPI.

2026 Filing Season Compliance Deadline

The IRS requires tax preparers to have compliant Security Six controls documented in a current Written Information Security Plan before the 2026 filing season opens. Practices without documented VPN configuration, MFA enforcement, and log retention policies face IRS security audit findings that can result in PTIN suspension. Review and update your compliance documentation now, before peak season begins.

Common VPN Implementation Mistakes Tax Practices Make

Even well-intentioned practices make configuration errors that create compliance gaps or security vulnerabilities when implementing VPN for remote access. These are the most consequential mistakes to avoid.

Using Consumer VPN Services

Services like NordVPN, ExpressVPN, or Private Internet Access are designed for individual privacy browsing, not business access control. They lack centralized user management, cannot integrate with enterprise MFA systems, do not generate the connection logs IRS audits require, and route your traffic through shared servers worldwide. An IRS auditor reviewing your security documentation will not accept a consumer VPN subscription as evidence of compliant remote access infrastructure.

Neglecting Kill Switch Configuration

A kill switch automatically blocks all internet traffic if the VPN connection drops unexpectedly. Without it, your device may continue transmitting data over an unencrypted connection without your knowledge, potentially exposing client NPPI to anyone monitoring that network segment. This risk increases when staff work from coffee shops, airports, hotels, or other shared WiFi environments. Configure kill switch policies at the client level to prevent any data transmission outside the encrypted tunnel.

Insufficient Log Retention

IRS Publication 4557 requires maintaining records that demonstrate your security controls function as documented. VPN logs must be retained for at least one year, but many default VPN configurations only keep 30 to 90 days of records. Configure extended retention periods and ensure logs are backed up before system upgrades or vendor migrations. This documentation becomes the primary evidence during an IRS security review.

Skipping Endpoint Compliance Checks

Before allowing VPN connections, verify that connecting devices have current antivirus software, OS patches applied, and Endpoint Detection and Response (EDR) agents installed and active. A valid VPN session from a malware-infected device gives attackers authenticated access to your practice network. Many enterprise VPN platforms support device posture checks that automatically block connections from non-compliant endpoints before granting network access.

VPN Performance Optimization for Tax Season

VPN connections introduce some latency due to encryption overhead and routing. Poorly optimized implementations can slow tax software to unusable levels, especially during peak filing season when multiple remote workers access practice systems simultaneously. Selecting the right VPN for tax professionals requires balancing security requirements with operational performance.

Start by calculating your concurrent user count and multiplying by the bandwidth each person needs. Most tax applications require 5 to 10 Mbps per user when uploading returns or accessing cloud-based platforms. A practice with 10 simultaneous remote users needs at least 100 Mbps of internet bandwidth at the server termination point, with additional headroom for peak season loads when all remote workers connect at once.

If you use a cloud-based VPN service, select server locations geographically close to your users. A preparer in Chicago connecting through a VPN server in California experiences significantly more latency than connecting to a Chicago-region server. Many enterprise VPN platforms offer automatic server selection based on user location, optimizing performance without manual configuration for each user.

Modern protocols like IKEv2/IPsec or WireGuard offer better performance and stronger security compared to legacy OpenVPN configurations or PPTP. If you currently run an older OpenVPN deployment and experience latency complaints during filing season, migrating to WireGuard can meaningfully reduce connection overhead without sacrificing encryption strength or IRS compliance. Most business VPN platforms include built-in dashboards displaying connection quality, bandwidth utilization, and latency metrics in real time, giving your IT support team visibility into remote access health without additional tooling.

Bottom Line

VPN is one of the six mandatory controls under the IRS Security Six framework, and it only satisfies compliance requirements when configured correctly. AES-256 encryption, enforced MFA, a functional kill switch, and 12-month log retention are not optional features. Consumer VPN services do not meet IRS audit requirements under any configuration. Budget for an enterprise platform and document every control in your WISP before the filing season begins.

Integrating Your VPN with the Other IRS Security Six Controls

Your VPN operates as one component of a layered security framework, not a standalone compliance solution. Effective tax practice cybersecurity requires integrating your VPN with the other five IRS Security Six requirements.

Firewall configuration: Your firewall should restrict VPN access to only the ports and protocols necessary for operation: typically UDP 500/4500 for IPsec-based connections or TCP 443 for SSL/TLS VPNs. Configure rules that limit what resources each VPN user can reach based on their role. Preparers do not need access to accounting systems, server administration tools, or network management interfaces from remote locations.

Endpoint protection: Your remote work security strategy must verify that remote devices meet minimum security standards before connecting. Many enterprise VPN platforms support device health checks that enforce endpoint compliance, blocking connections from machines without current patches or active antivirus, before granting network access. Pair your VPN access controls with a broader remote work security strategy for small teams to cover threats that originate from unmanaged home networks.

Employee training: Train your staff to recognize phishing attacks targeting VPN credentials. Attackers frequently send fake VPN expiration notices, security alert emails, or impersonation messages designed to capture authentication credentials from remote workers. For specific examples of the tactics used against tax practice staff, see our guide on identifying and avoiding phishing attacks. Your team remains the last line of defense against credential compromise when working from networks outside your direct security controls.

Incident response: Your incident response plan for your tax practice must include specific procedures for VPN-related security events: compromised credentials, suspicious connections from unusual geographic locations, unauthorized access attempts, and infrastructure failures during peak filing season. Document who to contact, which systems to isolate, and how to preserve logs for regulatory reporting. An untested incident response plan carries nearly the same risk as having no plan at all.

Selecting a Compliant VPN Vendor for Your Tax Practice

Not all business VPN solutions satisfy IRS Security Six requirements. When evaluating vendors for your VPN for tax professionals implementation, confirm that your chosen platform provides each of the following:

  • AES-256 encryption: non-negotiable minimum per IRS Publication 4557
  • Native MFA integration: support for Duo, Microsoft Authenticator, or FIDO2 hardware tokens
  • Centralized management console: for provisioning users, pushing policy updates, and revoking access instantly when an employee leaves
  • 12-month log retention: with tamper-evident storage formatted for IRS audit documentation
  • Role-based access controls: granular permissions restricting each user to only the resources their job requires
  • Device posture checks: automated verification that connecting endpoints meet your security baseline before granting access
  • 99.9%+ uptime SLA: with redundant infrastructure that prevents outages during peak filing periods
  • 24/7 vendor support: with documented response times for priority issues during filing season

Enterprise VPN platforms commonly deployed in tax practices include Cisco AnyConnect, Palo Alto GlobalProtect, Fortinet FortiClient, SonicWall NetExtender, and cloud-managed options like Perimeter 81 or Twingate. Budget $10 to $25 per user per month for platforms that include management, licensing, and vendor support, a fraction of the cost of a data breach or a PTIN suspension event.

When evaluating vendors, request references from other accounting or tax firms of similar size. Ask those references about behavior during peak filing season concurrent loads, support responsiveness outside normal business hours, and their experience when IRS auditors requested VPN log documentation. These conversations reveal operational realities that product demos will not surface.

Building a complete tax practice cybersecurity program means treating VPN as one element of an integrated system, not an isolated compliance checkbox. For a thorough view of how VPN fits into your overall compliance posture, review our analysis of the FTC Safeguards Rule requirements for tax preparers, including data encryption, access controls, and third-party vendor oversight obligations that extend to your VPN provider.

Secure Your Tax Practice with Compliant VPN Solutions

Our cybersecurity experts help tax professionals implement IRS-compliant VPN infrastructure that protects client data while supporting remote work productivity. Schedule a free consultation today.

Frequently Asked Questions

A compliant VPN for tax professionals must use AES-256 encryption for all data in transit, enforce multi-factor authentication on every connection, retain connection logs for a minimum of 12 months, include a kill switch that blocks traffic if the tunnel drops, and provide role-based access controls limiting each user to only the network resources their job requires. The configuration and policies governing these controls must be documented in your Written Information Security Plan (WISP). Consumer VPN services do not satisfy these requirements because they lack centralized management, enterprise MFA integration, and the audit-ready logging that IRS examiners expect.

No. Consumer VPN services such as NordVPN, ExpressVPN, or Private Internet Access are not compliant with IRS Security Six requirements. They cannot integrate with enterprise MFA systems, do not provide centralized user management or access controls, and do not generate the connection logs required for IRS audit documentation. Using a consumer VPN service and presenting it as your security control during an IRS review is likely to result in an audit finding. Budget for an enterprise-grade platform with the management and logging capabilities the IRS requires.

Enterprise VPN platforms appropriate for tax practices typically cost $10 to $25 per user per month, including management, licensing, and vendor support. A 5-person practice should expect to spend $50 to $125 per month on VPN infrastructure. Platforms commonly used in tax practices include Cisco AnyConnect, Palo Alto GlobalProtect, Fortinet FortiClient, SonicWall NetExtender, Perimeter 81, and Twingate.

Possibly, yes. Even with cloud-based tax software, you may still need a VPN for remote access to local servers hosting client records or shared drives, connections from employee home networks to office infrastructure, and situations where your software vendor requires connections from a trusted IP address range. Review your complete technology environment, not just your tax software, before concluding that a VPN is unnecessary.

Your incident response plan should include specific procedures for VPN outages during peak periods. These procedures should identify who to contact at your VPN vendor, what temporary measures allow staff to continue working without exposing NPPI, how to document the outage for your security records, and target recovery times to minimize filing season disruption. Most enterprise VPN vendors offer 99.9%+ uptime SLAs with redundant infrastructure. Verify your vendor's redundancy provisions and failover procedures before signing a contract.

Review your VPN configuration and policies at least annually, before each filing season opens, and after any significant changes: new staff, software vendor changes, office moves, or security incidents. Your WISP must reflect the current state of your VPN controls. Out-of-date WISP documentation that does not match your actual VPN configuration is itself an IRS audit finding, even if the VPN itself is configured correctly.

Personal device use requires additional controls to meet IRS Security Six requirements. Before permitting personal devices, your VPN must enforce endpoint posture checks that verify the device has current antivirus software, OS patches applied, and no known malware. You should also require mobile device management (MDM) enrollment to enforce encryption, screen lock, and remote wipe capabilities on personal devices accessing NPPI. Document your BYOD policy in your WISP, including what devices are permitted, what security requirements they must meet, and the procedure for removing access when an employee leaves.

Avoid PPTP (Point-to-Point Tunneling Protocol) entirely. Its MS-CHAPv2 encryption has been broken for years and it will fail any serious IRS security review. L2TP without IPsec is also inadequate. Acceptable protocols for tax practices include IKEv2/IPsec, WireGuard, and OpenVPN in TLS mode, all of which support AES-256 or equivalent encryption standards. If you are currently running PPTP on legacy infrastructure, migrate to a modern protocol before the next filing season begins.

The FTC Safeguards Rule, which became enforceable for non-bank financial institutions in 2023, requires tax preparers to implement a written information security program that includes encryption of all customer information in transit. A properly configured VPN satisfies the transit encryption requirement for remote access scenarios. The Safeguards Rule also requires access controls, multi-factor authentication, vendor oversight, and annual risk assessments, all of which your VPN vendor selection and configuration should support. Non-compliance can result in FTC enforcement actions and civil penalties.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Network & cloud security

Protect the connections, cloud accounts, and remote-work paths that people rely on every day.