MYCPE ONE

Cybercriminals target tax professionals and accounting firms because a single breach can expose Social Security numbers, income records, bank details, and other sensitive data. With breaches costing millions, cybersecurity is no longer optional for tax practices.

The IRS requires professional preparers to maintain a Written Information Security Plan (WISP), while the FTC Safeguards Rule and PTIN security requirements add further obligations.

This guide covers federal mandates, essential technical controls, documentation requirements, and common compliance gaps that can put tax firms at risk in 2026.

Key Takeaways

  • Tax preparers face overlapping federal cybersecurity requirements in 2026, including IRS Publication 4557, the FTC Safeguards Rule, and PTIN security requirements.
  • Essential controls include MFA, AES-256 encryption, endpoint detection and response, 3-2-1 backups, VPNs, and network segmentation.
  • Strong technical controls are not enough. Firms must maintain written documentation, including a current WISP and incident response plan.
  • Vendor oversight is critical because third-party risks can expose sensitive client data and create compliance issues.
  • Cyber insurers increasingly require documented security controls, training, backups, and vendor risk management.

Effective cybersecurity compliance requires both strong technical controls and thorough documentation.

What Are the Federal Cybersecurity Requirements for Tax Preparers and Accounting Firms?

Tax preparers face three overlapping federal cybersecurity requirements in 2026:

  • IRS Publication 4557 mandates a Written Information Security Plan covering the Security Six controls
  • FTC Safeguards Rule for accounting firms requires nine specific program elements with 30-day breach notification
  • PTIN renewal now has mandatory security acknowledgement on Form W-12.

Violations trigger criminal penalties up to $1,000 and one year imprisonment under IRC Section 7216, plus civil fines reaching $10,000 each year under Section 6713.

IRS Publication 4557 and Written Information Security Plan Requirements

The Gramm-Leach-Bliley Act classifies tax and accounting professionals as financial institutions and places them under Federal Trade Commission jurisdiction.

IRS Publication 4557 translates this into practical requirements:

  • Understand simple security steps
  • Recognize data theft signs,
  • Respond to breaches
  • Comply with the FTC Safeguards Rule

Cybersecurity for accounting firms starts with a compliant WISP that addresses employee management and training, information systems protection, and detection of system failures.

The IRS requires firms to designate a qualified individual to coordinate the security program. This includes conducting formal risk assessments, implementing and regularly testing safeguards, overseeing service providers through contractual requirements, and evaluating the program as threats evolve.

Publication 1345 establishes six security and privacy standards beyond the baseline WISP requirements for authorized e-file providers.

CTA

FTC Safeguards Rule for Accounting Firms: Core Mandates

The FTC defines financial institutions to include professional tax preparers providing services for personal, family, or household purposes. Tax preparation and accounting services fall within this definition.

Your information security program must have nine mandatory elements:

  1. Designating a qualified individual
  2. Conducting periodic risk assessments
  3. Implementing safeguards with specific technical controls
  4. Monitoring effectiveness
  5. Training staff on cybersecurity awareness
  6. Overseeing service providers
  7. Maintaining current protections against emerging threats
  8. Creating a written incident response plan
  9. Providing annual reports to governing bodies.

Firms keeping information on fewer than 5,000 consumers receive exemptions for risk assessments, testing protocols, written response plans, and board reporting, though encryption, multi-factor authentication, and secure disposal remain mandatory.

PTIN Renewal Security Obligations Under Form W-12

Form W-12 Line 11 now requires preparers to acknowledge awareness of their legal obligation to maintain a data security plan and provide system security protections for all taxpayer information. This acknowledgment references IRS Publication 4557 and Publication 5293 as the authoritative resources.

Falsely certifying WISP compliance constitutes perjury and can result in PTIN revocation or license suspension.

Criminal and Civil Penalties: IRC Section 7216 and 6713

Section 7216 establishes criminal liability for preparers who knowingly or recklessly disclose tax return information without authorization. Violators face fines up to $1,000 or imprisonment for one year, or both. Disclosure involving identity theft crimes increases penalties to $100,000.

Section 6713 imposes civil penalties of $250 per unauthorized disclosure, capped at $10,000 each year. Identity theft-related violations carry civil penalties of $1,000 per incident with a $50,000 annual maximum.

What Technical Controls Must Tax Preparers Implement in 2026?

Meeting cybersecurity requirements for tax preparers in 2026 requires six core technical controls. For a broader overview, see our guide to cybersecurity for accounting firms.

Technical Controls Must Tax Preparers Implement

  1. Multi-factor authentication (MFAfor systems accessing client data
  2. AES-256 encryption for data at rest and in transit
  3. Endpoint detection and response (EDR) for endpoint protection
  4. 3-2-1 backup strategies with encrypted offsite copies
  5. VPNs with strong encryption for secure remote access
  6. Next-generation firewalls with network segmentation

Implementing these controls is only part of compliance. Firms should also maintain documented evidence of their security measures in their WISP.

Multi-Factor Authentication for Client Data Systems

MFA adds an extra layer of protection for systems containing customer data. Options include authenticator apps, hardware security keys, push notifications, and SMS codes.

Authenticator apps and security keys generally provide stronger protection than SMS-based MFA, which can be vulnerable to SIM-swapping attacks.

Encryption for Data at Rest and in Transit

Encrypt sensitive taxpayer information both when it is stored and when it is transmitted. Use full-disk encryption on workstations, laptops, external drives, and other devices that access client data.

Data transmitted over networks should also use strong encryption. Backup data should be encrypted both at rest and in transit.

Endpoint Detection and Response (EDR)

Traditional antivirus primarily detects known malware signatures. EDR continuously monitors endpoint activity and can identify suspicious behavior and potential threats.

It also provides visibility into processes, file changes, and network activity, helping firms investigate and respond to security incidents.

Backup Systems and the 3-2-1 Rule

The 3-2-1 backup strategy maintains three copies of data across two media types, with one copy stored offsite. This helps protect taxpayer information from ransomware, hardware failures, and other disruptions.

Backups should be encrypted and protected with MFA. Regular restore testing should also be documented to confirm that backups can be recovered when needed.

VPNs for Remote Tax Preparation

VPNs encrypt connections between remote employees and office networks, helping protect sensitive data during remote work.

Require MFA for VPN access and use strong encryption. Firms should also maintain connection logs and monitor remote access for unusual activity.

Firewalls and Network Segmentation

Next-generation firewalls help monitor and control network traffic while detecting potential threats. Configure firewalls to allow only authorized services and document the business purpose of permitted connections.

Network segmentation further limits the impact of a breach by separating sensitive client-data systems from other parts of the network.

How Do You Create a Compliant Data Security Plan for Tax Professionals?

A data security plan for tax professionals requires five documented steps:

Compliant Data Security Plan for Tax Professionals

  1. Designate a qualified individual to oversee the firm's information security program and enforce security policies.
  2. Conduct a written risk assessment covering internal and external threats to taxpayer data.
  3. Document service provider oversight and require appropriate security controls and breach notification procedures.
  4. Create an incident response plan covering detection, containment, recovery, and client notification.
  5. Establish employee training and testing with documented training, phishing simulations, and completion records.

Step 1: Designate a Qualified Information Security Individual

Appoint a specific person to oversee your information security program. This individual should coordinate security measures, enforce policies, and ensure risk assessments are completed on schedule.

Small firms can assign this role to an owner or managing partner. Larger practices may designate an operations or IT lead. Document the person's responsibilities and authority in your WISP.

Step 2: Conduct a Written Risk Assessment

Identify internal and external threats to taxpayer data. These may include employee errors, phishing attacks, system vulnerabilities, and weaknesses in data-handling processes.

Document where sensitive data is collected, stored, processed, and transmitted. Assess the likelihood and potential impact of each risk and assign appropriate risk levels.

Step 3: Document Service Provider Oversight

Your responsibility for protecting client data extends to vendors that access or manage sensitive information. Review the security practices of tax software providers, cloud services, IT firms, and other third-party vendors.

Document your vendor assessment and monitoring procedures in your WISP. Contracts should include data protection requirements and breach notification provisions. Where appropriate, request SOC 2 reports or detailed security questionnaires.

Step 4: Build an Incident Response Plan

Create clear procedures for detecting, containing, and recovering from security incidents. Your plan should define internal reporting, external communications, and recovery responsibilities.

Include procedures for notifying affected clients and relevant authorities when required. Employees and remote staff should know how to report suspected security incidents quickly.

Step 5: Establish Employee Training and Testing

Provide security awareness training to employees who have access to taxpayer data. Training should cover security policies, phishing risks, password practices, and incident reporting procedures.

Use phishing simulations and regular testing to measure employee awareness. Keep records of training completion, test results, and any remedial actions. This documentation can help demonstrate compliance with your security requirements.

Protect your tax practice from cyber threats. Schedule a call.

What Are the Most Common Compliance Gaps and Enforcement Actions?

Most cybersecurity compliance gaps for tax preparers come from documentation failures rather than missing security controls. Firms may have MFA and encryption in place but lack written evidence showing that these controls are consistently implemented.

Documentation Failures

Firms can face compliance issues when security controls are not properly documented. Regulators and assessors increasingly expect clear evidence that security measures are implemented and operating effectively.

Missing documentation can lead to compliance findings, certification delays, higher costs, and potential contract losses.

Vendor Security Oversight

Third-party vendors remain a major security risk for accounting firms. Firms are responsible for protecting client information even when vendors handle or access that data. As cyber threats continue to evolve, firms should closely monitor the security practices of their vendors.

Vendor contracts should define security requirements, data-handling responsibilities, breach notification timelines, and audit rights. Regular vendor reviews can help identify changing cybersecurity risks.

EFIN Protection and IRS e-Services Security

Tax professionals should regularly monitor their EFIN activity for unauthorized use, especially during filing season. Unexpected increases in return activity may indicate fraudulent filings.

Phishing attacks often target IRS e-Services credentials and EFIN information. Tax professionals should verify suspicious emails and protect their e-Services accounts with strong security controls.

FTC Enforcement Actions

The FTC can take action against financial institutions that fail to adequately protect sensitive consumer information. Recent enforcement cases have increased attention on stronger, phishing-resistant MFA.

Organizations should review their authentication practices and avoid relying solely on vulnerable methods such as SMS-based MFA where stronger options are available.

Cyber Insurance Requirements

Cyber insurers increasingly require documented proof of security controls before providing coverage or favorable premiums. Common requirements include:

  • MFA and EDR
  • Tested and immutable backups
  • Email security
  • Employee security training and phishing simulations
  • Current WISP and incident response plans
  • Vendor risk management
  • Signed data protection agreements

Maintaining these controls and documenting them properly can improve both compliance readiness and cyber insurance outcomes.

CTA

Conclusion

Meeting cybersecurity requirements for tax preparers in 2026 just needs both technical implementation and written documentation. Firms that deploy MFA and encryption but fail to document these controls in a WISP face similar audit findings to those with no protections at all.

We've covered federal mandates, the Security Six technical baseline, WISP creation steps, and common gaps that trigger penalties. Your cybersecurity investments reshape from audit liabilities into proven compliance assets through documentation.

FAQs

Tax preparers must maintain a Written Information Security Plan (WISP) covering employee training, system protection, risk assessments, safeguards, vendor oversight, and ongoing security reviews. It should also document the implementation of controls such as MFA, encryption, and backups. 

Tax preparers can face criminal and civil penalties for cybersecurity violations, including fines and imprisonment for unauthorized disclosure of tax information. FTC Safeguards Rule violations can also result in significant daily fines, depending on the violation. 

Tax preparers should use AES-256 encryption to protect taxpayer information on devices, backups, and other storage systems. Data transmitted online should also use FIPS 140-compliant encryption through secure VPN solutions. 

Tax preparers should document vendor security procedures in their WISP and include data protection and breach notification requirements in vendor contracts. Firms should also review SOC 2 reports or security questionnaires and regularly assess vendor compliance. 

Tax preparation firms must provide documented security awareness training to employees who access taxpayer data. Firms should maintain training records, conduct phishing simulations, track results, and document any remedial actions taken. 

Blaise Wabo

Blaise Wabo

Blaise Wabo is a cybersecurity and compliance expert with 12+ years of experience helping organizations meet security and regulatory requirements. As the Healthcare and Financial Services Lead at A-LIGN, he advises businesses on SOC, HIPAA, and HITRUST compliance. Since 2013, he has led more than 500 SOC reviews and 300 HITRUST/HIPAA assessments for Fortune 500 and growing companies. Blaise is recognized for simplifying complex compliance challenges into practical, scalable security solutions.

Must Read Blogs