Skip to content
Bellator Cyber Guard
Tax19 min readDeep Dive

VPN for Tax Professionals: Secure Remote Access Guide

Set up a compliant VPN for your tax practice: IRS Security Six requirements, AES-256 encryption, MFA enforcement, and audit-ready log retention explained.

By Bellator Cyber Guard Security Team
VPN for Tax Professionals: Secure Remote Access Guide - vpn for tax professionals

A VPN for tax professionals encrypts remote connections to a practice's network or cloud systems, protecting Social Security numbers, bank account details, and prior-year returns while staff work outside the office. If you're researching VPN tax compliance requirements, the starting point is IRS Publication 4557, which requires every tax preparer holding a Preparer Tax Identification Number (PTIN) to implement six mandatory safeguards known as the IRS Security Six. A properly configured VPN is the control that secures remote access to nonpublic personal information (NPPI) under that framework.

The stakes are concrete. According to IBM's Cost of a Data Breach Report 2024, the average data breach now costs $4.88 million, and an IRS audit finding tied to inadequate remote access controls can lead to PTIN suspension, which stops a practice from filing returns. This guide covers what a compliant VPN requires, how to set one up, and where practices most often get the configuration wrong.

Quick Answer

A compliant VPN for tax professionals uses AES-256 encryption, enforces multi-factor authentication on every connection, retains logs for at least 12 months, and includes a kill switch that blocks traffic if the tunnel drops. Consumer VPN services such as NordVPN or ExpressVPN do not meet IRS Security Six requirements because they lack centralized management, enterprise MFA integration, and audit-ready logging. Business VPN platforms with these features typically cost $10 to $25 per user per month. Every control needs to be documented in your Written Information Security Plan (WISP) before the 2026 filing season opens.

Why VPN Sits at the Center of the IRS Security Six

The IRS Security Six framework sets minimum cybersecurity standards for tax professionals through six required controls: antivirus software, firewalls, multi-factor authentication, backup software, drive encryption, and a VPN. VPN addresses the risk created when preparers connect to office systems or cloud-based tax software from home networks, client offices, or public WiFi.

According to the Verizon 2025 Data Breach Investigations Report, more than 80% of hacking-related breaches involve compromised or weak credentials, which is why MFA on every VPN connection matters as much as the encrypted tunnel itself. The CISA Telework Essentials Toolkit offers additional guidance on hardening remote access that supports these IRS requirements. Review the full IRS Security Six checklist alongside your VPN setup, since missing or undocumented controls elsewhere in the framework can still produce an audit finding.

How to Implement a Compliant VPN for Your Tax Practice

1

Assess remote access needs

List every staff member who accesses NPPI remotely and what systems, software, or shared drives each role needs to reach.

2

Select an enterprise VPN platform

Choose a business-grade solution with AES-256 encryption, native MFA integration, centralized management, and 12-month log retention. Consumer services do not meet IRS audit requirements.

3

Enforce MFA on every account

Require an authenticator app or hardware security key for all VPN logins and disable single-factor authentication entirely.

4

Set role-based access controls

Limit each user to the network resources their role needs. Preparers rarely need access to server administration or accounting back-end systems.

5

Enable a kill switch and endpoint checks

Block all internet traffic automatically if the VPN drops, and verify antivirus and patch status before granting access.

6

Document it in your WISP

Record VPN configuration, MFA policy, and log retention in your Written Information Security Plan. Missing documentation is a common audit failure even when the technical setup is sound.

Remote Access vs. Site-to-Site VPNs

Most tax practices use a remote access VPN, which lets individual staff connect from any location and authenticates each user separately. This fits practices with work-from-home preparers or staff who visit client offices. A site-to-site VPN instead creates a permanent encrypted link between two networks, such as a main office and a satellite location, without requiring per-session authentication. Multi-office firms often run both: remote access VPN for individual staff, plus a site-to-site connection between physical locations.

Cloud-based tax software does not automatically eliminate the need for a VPN. You may still need one to reach local servers, office shared drives, or when a software vendor requires connections from a trusted IP range. Whichever architecture you use, document it in your WISP.

VPN Compliance Checklist for Tax Preparers

  • Deploy AES-256 encryption, the minimum standard under IRS Security Six
  • Enforce MFA on every VPN connection without exception
  • Enable a kill switch to block traffic if the connection drops
  • Retain VPN connection logs for at least 12 months
  • Document VPN configuration and MFA policy in your WISP
  • Restrict each user's access to only the resources their role requires
  • Use an enterprise VPN platform, not a consumer service
  • Run endpoint posture checks before granting access
  • Review and re-test VPN configuration before each filing season

Need a WISP That Documents Your VPN Configuration?

A custom Written Information Security Plan puts your VPN, MFA, and access control policies into the format IRS examiners expect, and typically saves a practice 20 to 40 billable hours compared to drafting one from scratch. Bellator's WISP service starts at $749 for practices with up to 5 users, with a custom quote for larger practices.

MFA Is Non-Negotiable for VPN Access

The IRS requires multi-factor authentication for all remote access to systems containing NPPI. A username and password alone does not satisfy this requirement, regardless of password complexity. When a preparer connects from a coffee shop or hotel WiFi, the VPN's MFA gate is often the only barrier between an attacker on that network and client records.

Acceptable methods include authenticator apps such as Microsoft Authenticator or Google Authenticator, hardware security keys like YubiKey, and push notifications to a registered device. SMS or voice codes are the weakest acceptable option and are not recommended for practices handling high data volumes. Your WISP needs to document which method you use, how you provision new employees, and the process for a lost or compromised device. Many practices fail IRS audits not because they lack MFA, but because their WISP does not describe the policy in enough detail. See our IRS Tax Pro Account MFA setup guide for a walkthrough of enabling MFA on IRS systems directly.

2026 Filing Season Deadline

The IRS expects tax preparers to have Security Six controls, including VPN configuration, MFA enforcement, and log retention, documented in a current WISP before the 2026 filing season opens. Review your documentation now, before peak season begins.

Common VPN Mistakes Tax Practices Make

Using a consumer VPN service. Services like NordVPN or ExpressVPN are built for individual privacy browsing, not business access control. They cannot integrate with enterprise MFA, do not generate the connection logs an audit requires, and route traffic through shared servers.

Skipping the kill switch. Without one, a device may keep transmitting data over an unencrypted connection if the VPN drops, unnoticed, especially on shared WiFi in coffee shops, airports, or hotels.

Retaining logs for too short a period. IRS Publication 4557 expects records that demonstrate your controls work as documented. Many default VPN configurations only keep 30 to 90 days of logs; extend retention to at least 12 months and back logs up before any vendor migration.

Skipping endpoint checks. A valid VPN session from a malware-infected device still gives an attacker authenticated access to your network. Enterprise VPN platforms that support device posture checks can block non-compliant endpoints automatically before granting access.

Integrating VPN with the Rest of the Security Six

VPN works as one piece of a layered system, not a standalone fix. Configure your firewall to restrict VPN traffic to the ports it needs, commonly UDP 500/4500 for IPsec or TCP 443 for SSL/TLS, and to limit what each user can reach based on role. Pair VPN access controls with a broader cloud and network security strategy that also covers unmanaged home networks.

Train staff to recognize phishing attempts targeting VPN credentials, such as fake expiration notices or security alerts asking them to re-enter login details. Your tax season cybersecurity checklist should include VPN-specific incident response steps: who to contact, which systems to isolate, and how to preserve logs if a connection is compromised or an unusual login location appears.

Selecting a Compliant VPN Vendor

When evaluating a VPN for tax professionals, confirm the platform provides AES-256 encryption, native MFA integration (Duo, Microsoft Authenticator, or FIDO2 hardware tokens), a centralized console for provisioning and revoking access, 12-month log retention in a tamper-evident format, role-based access controls, and device posture checks. Ask about the uptime SLA and vendor support hours during filing season, when an outage has the most impact.

Enterprise VPN platforms commonly used in tax practices include Cisco AnyConnect, Palo Alto GlobalProtect, Fortinet FortiClient, SonicWall NetExtender, and cloud-managed options like Perimeter 81 or Twingate. Expect to budget roughly $10 to $25 per user per month for a platform with management, licensing, and support included, a small fraction of the cost of a breach or a PTIN suspension. Request references from other accounting or tax firms of similar size and ask how the vendor performed during peak filing season and when an IRS audit requested VPN logs.

Bottom Line

VPN is one of six mandatory IRS Security Six controls, and it only satisfies the requirement when configured correctly: AES-256 encryption, enforced MFA, a working kill switch, and 12-month log retention. Consumer VPN services do not meet IRS audit requirements under any configuration. Document every control in your WISP before the filing season begins.

Talk with a cybersecurity expert

Get help configuring a compliant VPN and documenting it in a WISP that holds up to an IRS audit.

Frequently Asked Questions

A compliant VPN uses AES-256 encryption for data in transit, enforces MFA on every connection, retains logs for at least 12 months, includes a kill switch, and applies role-based access controls. These controls need to be documented in your WISP. Consumer VPN services do not meet these requirements because they lack centralized management, enterprise MFA integration, and audit-ready logging.

No. Consumer services such as NordVPN or ExpressVPN cannot integrate with enterprise MFA, do not provide centralized user management, and do not generate the connection logs an IRS audit expects. Budget for an enterprise-grade platform instead.

Possibly. You may still need a VPN to reach local servers, connect home networks to office infrastructure, or satisfy a software vendor's requirement to connect from a trusted IP range. Review your full technology environment before assuming cloud tools remove the need for one.

Enterprise VPN platforms for tax practices typically run $10 to $25 per user per month, including management, licensing, and support. A 5-person practice should plan for roughly $50 to $125 per month.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.