
IRS Publication 4557 is the IRS's primary guidance document telling tax professionals how to protect taxpayer data, and every paid preparer who collects, stores, or transmits that data has to follow it. The publication, titled "Safeguarding Taxpayer Data: A Guide for Your Business," translates two federal laws, the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, into six required technical controls known as the Security Six, plus a written security plan requirement called a WISP. Ignoring it is not a paperwork risk. A practice without a compliant WISP or working Security Six controls can lose its EFIN, face FTC civil penalties, and face separate state-level enforcement on top of federal action.
Tax preparation files concentrate more personal data per record than almost any other small business: Social Security numbers, dates of birth, EINs, bank routing numbers, investment details, and years of income history. That concentration is why ransomware groups and identity fraud rings target tax offices specifically, and why the IRS updates this guidance periodically through the Security Summit, a public-private partnership between the IRS, state tax agencies, and the tax industry formed to fight identity theft refund fraud.
Quick Answer
IRS Publication 4557 requires every paid tax preparer to implement six baseline security controls, known as the Security Six, and maintain a Written Information Security Plan (WISP) documenting how taxpayer data is protected. The Security Six covers antivirus or EDR, a professional firewall, multi-factor authentication, encrypted backups, drive encryption, and a VPN for remote access. The legal authority comes from the Gramm-Leach-Bliley Act and the FTC Safeguards Rule (16 CFR Part 314). Non-compliance can lead to EFIN suspension, FTC civil penalties, and state enforcement action, and the requirement applies year-round, not just during filing season.
Tax preparers are covered because the Gramm-Leach-Bliley Act (15 U.S.C. §§ 6801-6809) classifies any business that collects financial information on behalf of consumers as a "financial institution," a definition broad enough to include solo preparers and franchise chains alike. The Federal Trade Commission enforces that law for tax preparers through the Safeguards Rule (16 CFR Part 314), and the 2023 amendments expanded the technical requirements every covered business now has to meet. See our guide to the FTC Safeguards Rule qualified individual requirement for how the rule applies to a tax practice specifically.
The obligation applies to anyone preparing federal or state returns for compensation, with no minimum client count or revenue threshold that creates an exemption. That includes CPAs and enrolled agents, seasonal and home-office preparers, franchise locations, accounting firms that also do tax work, VITA and TCE volunteer programs handling taxpayer data, and the software vendors that host returns on preparers' behalf. If you hold a Preparer Tax Identification Number (PTIN) and use it for paid work, Publication 4557 applies to you. Our PTIN requirements page walks through how these rules attach to different practice structures.
Compliance Is a Year-Round Obligation
IRS Publication 4557 compliance is not seasonal. If your WISP has not been reviewed in the past 12 months, or your Security Six controls have gaps, address them now rather than waiting for the 2027 filing season to open in January. Practices without a compliant WISP or working controls risk EFIN suspension, FTC enforcement referral, and state attorney general action at any time of year.
The Security Six are the minimum technical controls every covered preparer must run, not a complete security program on their own. The IRS and FTC treat a misconfigured control the same as no control at all: a firewall with logging disabled or antivirus running outdated signatures fails review just as thoroughly as having nothing installed.
IRS Security Six Controls
- Endpoint protection with behavioral detection (EDR), not signature-only antivirus, on every device that touches taxpayer data
- A next-generation firewall with intrusion prevention and connection logging, not a consumer-grade router
- Multi-factor authentication on tax software, email, cloud storage, and remote access accounts, with phishing-resistant options preferred over SMS codes
- Encrypted, off-site or cloud backups isolated from production systems, tested for successful restoration monthly
- Full-disk encryption (AES-256, FIPS 140-2 validated) on every computer storing client data
- A business-grade VPN required for all remote access to taxpayer data over any public connection
Multi-factor authentication deserves particular attention because it stops the most common way preparer accounts get compromised: stolen or phished passwords. NIST's Digital Identity Guidelines (SP 800-63B) identify phishing-resistant MFA, FIDO2 or WebAuthn hardware keys, as the strongest available option, and flag SMS codes as the weakest accepted form because they are vulnerable to SIM-swapping. Our guide to setting up MFA on your IRS Tax Pro Account covers the setup steps for the account most preparers use daily.
Backups matter just as much. A ransomware attack that reaches backup storage connected to your production network defeats the control entirely, which is why backups need to be encrypted independently and stored off the main network. Our backup guide for tax practices and access control guide cover the configuration details for both controls.
A Written Information Security Plan is a documented, practice-specific description of how your firm actually protects taxpayer data, not a generic template filed away unread. The IRS will not accept a form that does not reflect your real systems, staff, and data flows. A compliant WISP names a specific security coordinator responsible for the program, inventories every device, application, and cloud service that touches taxpayer data, documents how each Security Six control is implemented in your environment, and spells out the procedure staff follow when an incident occurs.
The incident response section carries real deadlines. New York's SHIELD Act requires notifying the state attorney general within 72 hours of discovering unauthorized access, and Massachusetts requires immediate notification with specific content requirements. Neither window is realistic without a documented incident response plan written and tested before an incident happens, not during one. The IRS publishes a sample structure in Publication 5708 as a starting point, but it still has to be customized to your practice and reviewed at least annually, or whenever you add staff, change software, or move offices. Our WISP guide for tax preparers covers the full build process.
WISP Compliance Checklist
- Designate a named security coordinator responsible for the WISP
- Inventory every device, application, and cloud service that touches taxpayer data
- Document how client data flows through your systems
- Enable MFA on all tax software, email, cloud storage, and remote access accounts
- Configure encrypted, off-site backups and test restoration monthly
- Enable full-disk encryption on every workstation and laptop storing client data
- Write a documented incident response procedure with specific notification timelines
- Conduct and document annual security awareness training for staff
- Include security provisions in vendor contracts for any third party accessing client data
- Review and update the WISP at least once a year, and after any significant change
Need a WISP that will pass review?
Bellator builds a custom Written Information Security Plan for tax practices, starting at $749 for up to 5 users, with a custom quote for larger firms. Most practices recoup the cost against the 20 to 40 billable hours a self-written WISP typically takes to research and draft.
Publication 4557 sets the federal floor. States add their own requirements on top of it, often with tighter deadlines and higher per-record penalties, and a practice serving clients across state lines has to meet all of them at once.
Massachusetts 201 CMR 17.00 is generally considered the strictest state standard. It requires encryption on all portable devices, a written security program with technical detail beyond a basic WISP, documented annual training, and vendor contracts that require equivalent protections from any third party touching Massachusetts resident data. Penalties can reach $5,000 per compromised record, and the requirement applies to any practice serving Massachusetts residents regardless of where the office sits. New York's SHIELD Act, actively enforced by the state attorney general since March 2020, requires safeguards proportionate to the sensitivity of the data and 72-hour notification to the attorney general after discovering unauthorized access. California's CCPA and CPRA create a private right of action for breaches, letting affected consumers sue for $100 to $750 per person per incident, a real exposure for any practice with a large California client base. Texas and Florida both require breach notification, within 60 and 30 days respectively, and both states have increased enforcement activity in recent years. Our state and federal compliance breakdown covers how these obligations stack.
The Security Six is a floor, not a ceiling. Practices with higher client volumes or exposure to stricter state law are layering additional controls: zero trust access that verifies every request instead of trusting anything inside the network perimeter, managed detection and response (MDR) that pairs 24/7 monitoring with the EDR tools already required, and role-based security awareness training, since phishing remains the leading way attackers get into tax practices. Simulated phishing tests typically show 15 to 30 percent failure rates before training and 3 to 8 percent after consistent reinforcement. AI-generated phishing and deepfake voice impersonation are making that training more necessary, not less. Our Security Six checklist and phishing threat guide go deeper on both.
The cost of skipping any of this is not abstract. FTC Safeguards Rule penalties have no statutory cap and are adjusted for inflation each year, and a prolonged enforcement action can reach seven or eight figures. An EFIN suspension during filing season stops a practice from filing electronically at the worst possible time. According to IBM's 2024 Cost of a Data Breach Report, the average breach cost $4.88 million and took 277 days to identify and contain, figures that would be an existential threat to most solo and small-firm practices. State attorneys general have gotten more active too: Massachusetts has collected real penalties from small businesses that failed to meet its standard, and New York's SHIELD Act lets affected individuals sue directly on top of regulatory penalties. Our breakdown of non-compliance consequences walks through what an actual enforcement action looks like.
Talk with a cybersecurity expert
Get a specific assessment of your practice's Security Six controls and WISP documentation ahead of the next filing season.
Frequently Asked Questions
IRS Publication 4557, "Safeguarding Taxpayer Data: A Guide for Your Business," is the IRS's primary compliance document for tax professionals. First published under the Security Summit initiative in 2015 and updated periodically, it translates the Gramm-Leach-Bliley Act and the FTC Safeguards Rule into the Security Six technical controls and the WISP documentation requirement that every paid tax preparer must follow.
Yes. The requirement applies to every preparer who files federal or state returns for compensation, with no minimum client count, revenue level, or business size that creates an exemption. A solo preparer working from a home office has the same Security Six and WISP obligations as a multi-partner firm.
Non-compliance can lead to FTC civil penalties under the Safeguards Rule, which have no statutory maximum and are adjusted for inflation each year, EFIN suspension that blocks electronic filing, and separate enforcement action from state attorneys general in states such as Massachusetts and New York.
The Security Six are six required technical controls: EDR or antivirus, a professional firewall, MFA, encrypted backups, full-disk encryption, and a VPN. The WISP is the written plan that documents how those controls, plus staff procedures and incident response steps, actually work in your specific practice. The IRS requires both, not one or the other.
At minimum once a year, and also whenever a significant change happens, such as hiring new staff, adopting new tax software, or moving office locations. A WISP that has not been reviewed since the last filing season is a common gap the IRS and FTC flag during review.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



