What the FTC Safeguards Rule Actually Requires From Tax and Accounting Firms

Technology | October 2, 2026

What the FTC Safeguards Rule Actually Requires From Tax and Accounting Firms

A plain-language breakdown of what the FTC Safeguards Rule and IRS Publication 4557 mean for tax and accounting firms.

Mark Johnson CPA

Most tax and accounting firm owners have heard of the FTC Safeguards Rule by now, usually secondhand and usually as a vague sense that “there’s some new data security requirement.” Far fewer could say specifically what it requires, because the rule itself is written for regulators and lawyers, not for a five-person tax practice trying to figure out what to actually do before the next filing season.

Here’s what it actually requires, in plain terms.

Why this applies to your firm at all

The FTC Safeguards Rule falls under the Gramm-Leach-Bliley Act, and it applies to any business considered a “financial institution” under the Act’s broad definition—which explicitly includes tax preparers, not just banks and lenders. The IRS reinforces this directly in Publication 4557, Safeguarding Taxpayer Data, which every paid preparer is expected to follow. If your firm prepares tax returns for compensation, this isn’t optional guidance; it’s a compliance obligation you likely already have, whether or not you’ve formalized anything around it.

The core requirement: A Written Information Security Plan (WISP)

The centerpiece of the rule is a Written Information Security Plan—a documented, firm-specific plan covering how client data is protected, who’s responsible for it, and what happens if something goes wrong. This isn’t a generic template you download and file away; the FTC and IRS both expect it to reflect your firm’s actual size, complexity, and the kind of data you actually handle.

A defensible WISP typically covers:

  • Who at the firm is designated to oversee the security program (a named person, not “IT” in the abstract).
  • What data the firm collects and where it’s stored.
  • Access controls—who can reach client data, and whether that access is actually necessary for their role.
  • Encryption for data in transit and at rest.
  • A written incident response plan for what happens if data is lost, stolen, or exposed.
  • A schedule for reviewing and updating the plan, not a one-time document.

The “Security Six” the IRS specifically calls out

IRS Publication 4557 names six baseline protections it expects every preparer to have in place: anti-virus software, firewalls, multifactor authentication, backup software or services, drive encryption, and a VPN if remote access is involved. None of these are exotic—the point isn’t cutting-edge technology, it’s making sure the basics are actually implemented and documented, not assumed.

Where firms actually fall short

In practice, the gap usually isn’t a firm ignoring security entirely—it’s a firm that has reasonable practices in place informally but nothing written down, no designated owner, and no evidence they could produce if a regulator or a cyber-insurance carrier asked for it. A WISP that exists only as institutional knowledge in one partner’s head doesn’t satisfy the rule, and it doesn’t survive that partner being unavailable when an incident actually happens.

Multifactor authentication is the other common gap—it’s inexpensive and widely available, but firms that have used the same login workflow for years are often slow to add it, even though it’s explicitly one of the IRS’s six named baseline protections.

What to actually do next

Firms that haven’t formalized a WISP yet don’t need to start from a blank page—the FTC publishes a small-business compliance guide, and the IRS’s own Publication 4557 lays out the “Security Six” in plain language. The realistic starting point is an honest audit: which of the six protections does the firm already have, which are missing, and who is going to own writing the plan down. That last part—a named owner and an actual document—is usually the difference between a firm that’s compliant and a firm that assumes it is.

ABOUT THE AUTHOR:

Mark Johnson, CPA, is an accounting and technology advisor at Cloud Innovics, which provides secure cloud hosting for QuickBooks and tax preparation software.

Photo credit: rawpixel.com/Freepik

Sign in to get access to this free resource, and all of our whitepapers and reports.

Download this content today!

Register to get free access to this content, as well as newsletters, continuing education, podcasts, and more…

Leave a Reply