Cybercriminals target tax professionals and accounting firms because a single breach can expose Social Security numbers, income records, bank details, and other sensitive data. With breaches costing millions, cybersecurity is no longer optional for tax practices.
The IRS requires professional preparers to maintain a Written Information Security Plan (WISP), while the FTC Safeguards Rule and PTIN security requirements add further obligations.
This guide covers federal mandates, essential technical controls, documentation requirements, and common compliance gaps that can put tax firms at risk in 2026.
Effective cybersecurity compliance requires both strong technical controls and thorough documentation.
Tax preparers face three overlapping federal cybersecurity requirements in 2026:
Violations trigger criminal penalties up to $1,000 and one year imprisonment under IRC Section 7216, plus civil fines reaching $10,000 each year under Section 6713.
The Gramm-Leach-Bliley Act classifies tax and accounting professionals as financial institutions and places them under Federal Trade Commission jurisdiction.
IRS Publication 4557 translates this into practical requirements:
Cybersecurity for accounting firms starts with a compliant WISP that addresses employee management and training, information systems protection, and detection of system failures.
The IRS requires firms to designate a qualified individual to coordinate the security program. This includes conducting formal risk assessments, implementing and regularly testing safeguards, overseeing service providers through contractual requirements, and evaluating the program as threats evolve.
Publication 1345 establishes six security and privacy standards beyond the baseline WISP requirements for authorized e-file providers.
The FTC defines financial institutions to include professional tax preparers providing services for personal, family, or household purposes. Tax preparation and accounting services fall within this definition.
Your information security program must have nine mandatory elements:
Firms keeping information on fewer than 5,000 consumers receive exemptions for risk assessments, testing protocols, written response plans, and board reporting, though encryption, multi-factor authentication, and secure disposal remain mandatory.
Form W-12 Line 11 now requires preparers to acknowledge awareness of their legal obligation to maintain a data security plan and provide system security protections for all taxpayer information. This acknowledgment references IRS Publication 4557 and Publication 5293 as the authoritative resources.
Falsely certifying WISP compliance constitutes perjury and can result in PTIN revocation or license suspension.
Section 7216 establishes criminal liability for preparers who knowingly or recklessly disclose tax return information without authorization. Violators face fines up to $1,000 or imprisonment for one year, or both. Disclosure involving identity theft crimes increases penalties to $100,000.
Section 6713 imposes civil penalties of $250 per unauthorized disclosure, capped at $10,000 each year. Identity theft-related violations carry civil penalties of $1,000 per incident with a $50,000 annual maximum.
Meeting cybersecurity requirements for tax preparers in 2026 requires six core technical controls. For a broader overview, see our guide to cybersecurity for accounting firms.
Implementing these controls is only part of compliance. Firms should also maintain documented evidence of their security measures in their WISP.
MFA adds an extra layer of protection for systems containing customer data. Options include authenticator apps, hardware security keys, push notifications, and SMS codes.
Authenticator apps and security keys generally provide stronger protection than SMS-based MFA, which can be vulnerable to SIM-swapping attacks.
Encrypt sensitive taxpayer information both when it is stored and when it is transmitted. Use full-disk encryption on workstations, laptops, external drives, and other devices that access client data.
Data transmitted over networks should also use strong encryption. Backup data should be encrypted both at rest and in transit.
Traditional antivirus primarily detects known malware signatures. EDR continuously monitors endpoint activity and can identify suspicious behavior and potential threats.
It also provides visibility into processes, file changes, and network activity, helping firms investigate and respond to security incidents.
The 3-2-1 backup strategy maintains three copies of data across two media types, with one copy stored offsite. This helps protect taxpayer information from ransomware, hardware failures, and other disruptions.
Backups should be encrypted and protected with MFA. Regular restore testing should also be documented to confirm that backups can be recovered when needed.
VPNs encrypt connections between remote employees and office networks, helping protect sensitive data during remote work.
Require MFA for VPN access and use strong encryption. Firms should also maintain connection logs and monitor remote access for unusual activity.
Next-generation firewalls help monitor and control network traffic while detecting potential threats. Configure firewalls to allow only authorized services and document the business purpose of permitted connections.
Network segmentation further limits the impact of a breach by separating sensitive client-data systems from other parts of the network.
A data security plan for tax professionals requires five documented steps:
Appoint a specific person to oversee your information security program. This individual should coordinate security measures, enforce policies, and ensure risk assessments are completed on schedule.
Small firms can assign this role to an owner or managing partner. Larger practices may designate an operations or IT lead. Document the person's responsibilities and authority in your WISP.
Identify internal and external threats to taxpayer data. These may include employee errors, phishing attacks, system vulnerabilities, and weaknesses in data-handling processes.
Document where sensitive data is collected, stored, processed, and transmitted. Assess the likelihood and potential impact of each risk and assign appropriate risk levels.
Your responsibility for protecting client data extends to vendors that access or manage sensitive information. Review the security practices of tax software providers, cloud services, IT firms, and other third-party vendors.
Document your vendor assessment and monitoring procedures in your WISP. Contracts should include data protection requirements and breach notification provisions. Where appropriate, request SOC 2 reports or detailed security questionnaires.
Create clear procedures for detecting, containing, and recovering from security incidents. Your plan should define internal reporting, external communications, and recovery responsibilities.
Include procedures for notifying affected clients and relevant authorities when required. Employees and remote staff should know how to report suspected security incidents quickly.
Provide security awareness training to employees who have access to taxpayer data. Training should cover security policies, phishing risks, password practices, and incident reporting procedures.
Use phishing simulations and regular testing to measure employee awareness. Keep records of training completion, test results, and any remedial actions. This documentation can help demonstrate compliance with your security requirements.
Most cybersecurity compliance gaps for tax preparers come from documentation failures rather than missing security controls. Firms may have MFA and encryption in place but lack written evidence showing that these controls are consistently implemented.
Firms can face compliance issues when security controls are not properly documented. Regulators and assessors increasingly expect clear evidence that security measures are implemented and operating effectively.
Missing documentation can lead to compliance findings, certification delays, higher costs, and potential contract losses.
Third-party vendors remain a major security risk for accounting firms. Firms are responsible for protecting client information even when vendors handle or access that data. As cyber threats continue to evolve, firms should closely monitor the security practices of their vendors.
Vendor contracts should define security requirements, data-handling responsibilities, breach notification timelines, and audit rights. Regular vendor reviews can help identify changing cybersecurity risks.
Tax professionals should regularly monitor their EFIN activity for unauthorized use, especially during filing season. Unexpected increases in return activity may indicate fraudulent filings.
Phishing attacks often target IRS e-Services credentials and EFIN information. Tax professionals should verify suspicious emails and protect their e-Services accounts with strong security controls.
The FTC can take action against financial institutions that fail to adequately protect sensitive consumer information. Recent enforcement cases have increased attention on stronger, phishing-resistant MFA.
Organizations should review their authentication practices and avoid relying solely on vulnerable methods such as SMS-based MFA where stronger options are available.
Cyber insurers increasingly require documented proof of security controls before providing coverage or favorable premiums. Common requirements include:
Maintaining these controls and documenting them properly can improve both compliance readiness and cyber insurance outcomes.
Meeting cybersecurity requirements for tax preparers in 2026 just needs both technical implementation and written documentation. Firms that deploy MFA and encryption but fail to document these controls in a WISP face similar audit findings to those with no protections at all.
We've covered federal mandates, the Security Six technical baseline, WISP creation steps, and common gaps that trigger penalties. Your cybersecurity investments reshape from audit liabilities into proven compliance assets through documentation.
Tax preparers must maintain a Written Information Security Plan (WISP) covering employee training, system protection, risk assessments, safeguards, vendor oversight, and ongoing security reviews. It should also document the implementation of controls such as MFA, encryption, and backups.
Tax preparers can face criminal and civil penalties for cybersecurity violations, including fines and imprisonment for unauthorized disclosure of tax information. FTC Safeguards Rule violations can also result in significant daily fines, depending on the violation.
Tax preparers should use AES-256 encryption to protect taxpayer information on devices, backups, and other storage systems. Data transmitted online should also use FIPS 140-compliant encryption through secure VPN solutions.
Tax preparers should document vendor security procedures in their WISP and include data protection and breach notification requirements in vendor contracts. Firms should also review SOC 2 reports or security questionnaires and regularly assess vendor compliance.
Tax preparation firms must provide documented security awareness training to employees who access taxpayer data. Firms should maintain training records, conduct phishing simulations, track results, and document any remedial actions taken.
Blaise Wabo is a cybersecurity and compliance expert with 12+ years of experience helping organizations meet security and regulatory requirements. As the Healthcare and Financial Services Lead at A-LIGN, he advises businesses on SOC, HIPAA, and HITRUST compliance. Since 2013, he has led more than 500 SOC reviews and 300 HITRUST/HIPAA assessments for Fortune 500 and growing companies. Blaise is recognized for simplifying complex compliance challenges into practical, scalable security solutions.
Cybersecurity Best Practices Every Business Needs to Follow in 2026
Blaise Wabo
Benefits of Endpoint Security: Why Managed Services Protect Your Business Better
Blaise Wabo