Frequently asked questions
Common questions about the FTC Safeguards Rule and the IRS WISP requirement for accounting and tax firms. For the full picture, read the guides or run the 3-minute check.
The FTC Safeguards Rule for Accounting and Tax Firms: A Complete Plain-English Guide
- Does the FTC Safeguards Rule apply to accountants?
- Yes. The FTC defines "financial institution" broadly, and its guidance explicitly lists accountants and CPAs as covered. If your firm handles clients' nonpublic financial information, you are almost certainly covered, and you are responsible for building and maintaining a written security program to prove it.
- Does it apply to tax preparers?
- Yes, and tax preparers carry a second, separate obligation on top of the FTC Rule. Beyond being covered as a "financial institution," the IRS requires every paid preparer to maintain a Written Information Security Plan (WISP), tied to your PTIN and e-file participation, regardless of firm size. So a tax preparer has to satisfy both the FTC Safeguards Rule and the IRS WISP mandate, and keep both current, not just meet one.
- What counts as customer information under the Rule?
- Any record with nonpublic personal information about a client that you handle to provide your service: names, Social Security numbers, income, bank details, and the contents of a tax return. The format does not matter, whether server, cloud, email, or paper.
- Is my firm too small to be covered?
- No firm is too small to be covered, but firms with information on fewer than 5,000 consumers are exempt from a few written requirements (the written risk assessment, testing, written incident-response plan, and annual report). The core safeguards still apply, and the IRS WISP requirement applies to paid preparers regardless of size.
- What are the nine required elements of the Safeguards Rule?
- A Qualified Individual, a written risk assessment, designed safeguards (access controls, encryption, MFA, disposal, monitoring and more), regular testing, staff training, service-provider oversight, keeping the program current, a written incident-response plan, and an annual written report to leadership.
- When did the FTC Safeguards Rule take effect?
- The updated Rule became fully enforceable on June 9, 2023. A breach-notification amendment took effect May 13, 2024, requiring notice to the FTC within 30 days of a breach affecting at least 500 consumers.
The WISP Requirement for Tax Preparers: Who Is Covered and What Goes In It
- Do I really need a WISP if I am a small or solo preparer?
- Yes. The IRS requires paid tax preparers to maintain a Written Information Security Plan, and it is tied to PTIN renewal and e-file participation. Firm size does not remove the requirement.
- Where do I get a WISP template?
- The IRS publishes a free sample template, Publication 5708 ("Creating a Written Information Security Plan for Your Tax and Accounting Practice"), a roughly 28-page document built for smaller practices: https://www.irs.gov/pub/irs-pdf/p5708.pdf. Be clear about what the template is, though: it is a starting document, not compliance. Having Publication 5708 on your drive does not make you compliant. The real work is filling it in accurately for your specific firm, actually turning on the safeguards it describes, and maintaining the program as your systems, staff, and the rules change. The template gives you the outline; keeping a living, defensible plan is the ongoing job, and it is exactly the part firms most often hand to a managed provider.
- What has to be in a WISP?
- At minimum: a designated Qualified Individual, a risk assessment, administrative/technical/physical safeguards (including access controls and MFA), procedures to monitor and test them, and service-provider oversight. Publication 5708 also recommends a data inventory, network controls, a breach-response plan, employee agreements, and retention and disposal policies.
- Does the IRS actually check for a WISP?
- The obligation is tied to your PTIN and e-file status, and the IRS has repeatedly reminded practitioners of it. A missing WISP is a clear compliance gap and an exposure at renewal and in the event of an incident.
- How often should I update my WISP?
- Review it at least once a year and after any significant change to your systems, software, or staff. A WISP is meant to be a living document, not a one-time form.
- What if I outsource my IT or use tax software in the cloud?
- You are still responsible for the WISP and for overseeing those providers. The Rule requires you to select providers capable of protecting client data and to require safeguards by contract. Your WISP should document who your providers are and how they protect data.
Multi-Factor Authentication and the 2024 Update Every Tax Firm Should Know
- Is MFA legally required for tax firms?
- Effectively yes. The FTC Safeguards Rule requires MFA for accessing systems with customer information, and the 2024 IRS Publication 5708 update reinforced it as universal for systems that touch client data.
- Does MFA need to be on my email too?
- Yes, and email should be first. It is the most common breach entry point and usually the password-reset path for your other accounts.
- Is text-message (SMS) MFA good enough?
- It is much better than no MFA, but an authenticator app or a hardware security key is stronger, because SMS codes can be intercepted or redirected via SIM-swap attacks. Prefer app-based or hardware MFA for email and tax software.
- How much does MFA cost?
- Usually nothing extra. Most business email and tax/accounting platforms include MFA. The effort is enrollment and a small habit change, not spend.
- What if a staff member resists using MFA?
- MFA is a documented safeguard tied to a legal requirement, so it is a firm policy, not an option. Provide a backup recovery method and a short walkthrough; enrollment friction is brief and one-time.
What Non-Compliance Costs: Penalties, Breach Reporting, and PTIN Exposure
- What is the maximum penalty for a Safeguards Rule violation?
- Knowing violations of the FTC rules can carry civil penalties up to $53,088 per violation, a figure adjusted for inflation each year. Because it is per violation, exposure can compound.
- Do I have to report a data breach, and to whom?
- Yes. Since May 13, 2024, covered financial institutions must notify the FTC no later than 30 days after discovering a breach of unencrypted customer information affecting at least 500 consumers. State law may impose additional notification duties.
- Can I lose my PTIN or e-file access over this?
- PTIN renewal and IRS e-file participation assume a current WISP, so lacking one creates exposure around those authorizations. For a tax firm, losing e-file eligibility is often a bigger threat than a fine.
- Does encryption change my breach-reporting exposure?
- Yes. The FTC reporting trigger is the acquisition of unencrypted customer information. Properly encrypted data (where the key was not also accessed) changes whether an event is reportable, which is one more reason encryption is a priority safeguard.
- Is compliance really cheaper than the alternative?
- For almost every firm, yes, but not because getting compliant is trivial. Non-compliance is what is genuinely expensive: a civil penalty, a mandatory breach disclosure, a PTIN or e-file problem, and lost client trust are all costly and often recurring. Getting compliant and staying compliant is real, ongoing work: a written risk assessment, safeguards actually implemented and tested, staff training, vendor oversight, and a plan kept current as threats and rules change. The math still favors doing it, because the cost of doing the work, in-house or with a provider who handles it for you, is far smaller than the cost of a failure. The question is not whether to invest, but whether to carry that ongoing work yourself.
Safeguards Rule Timeline and Deadlines: What to Do and When
- Is there a compliance deadline I am waiting for?
- No. The updated Safeguards Rule has been enforceable since June 9, 2023, and the breach-notification amendment took effect May 13, 2024. If you are not compliant now, you are overdue rather than early.
- Is it too late to get compliant?
- No. The requirement is to have and maintain a program, so getting current now is exactly what the Rule expects. Start with a Qualified Individual, MFA, and the WISP template, then work through the remaining elements.
- What should I do first?
- In your first 30 days, do three things: designate a Qualified Individual, turn on MFA for your email and tax software, and download IRS Publication 5708 (https://www.irs.gov/pub/irs-pdf/p5708.pdf) to start your WISP. To make the WISP step concrete, our free one-page WISP starter checklist maps each move to the required elements, run the 3-minute check on this site and it is included with your gap report. Remember that the template and the checklist get you started; filling the plan in correctly and keeping it current is the ongoing work, and it is the part a managed provider can take off your plate entirely.
- How often do I need to review my compliance?
- At least annually, and after any significant change to your systems or staff. Tying the review to PTIN renewal or the start of filing season makes it easy to remember.
Does the FTC Safeguards Rule Apply to Your Firm? Who Has to Comply
- Does the FTC Safeguards Rule really apply to accountants?
- Yes. The FTC's definition of "financial institution" explicitly includes accountants, tax-preparation services, and bookkeepers. If you handle clients' nonpublic financial information, you are covered.
- Does it apply to tax preparers?
- Yes, and more so. A tax preparer is covered by the FTC Safeguards Rule as a financial institution, and separately the IRS requires every paid preparer to keep a Written Information Security Plan (WISP) tied to your PTIN and e-file participation, no matter how few consumers you serve. That means two obligations to meet and keep current, which is why many preparers hand the whole program to a managed provider rather than track both themselves.
- I am a small or solo firm. Am I too small to be covered?
- No. There is no exemption from the Rule based on being small. Firms with information on fewer than 5,000 consumers are excused from a few written requirements, but the core safeguards still apply, and tax preparers still need a WISP.
- I only serve business clients, not consumers. Am I still covered?
- Very likely. If you handle nonpublic personal information about individuals in the course of your work, including owners, employees, or individual filers, you are handling the data the Rule protects.
- I already have antivirus. Is that enough to comply?
- No. Antivirus is one small control. The Rule requires a documented program with a Qualified Individual, access controls, MFA, encryption, training, vendor oversight, and more. Software alone does not satisfy it.
- What if I outsource my IT to a provider?
- You are still responsible for compliance. The Rule requires you to select providers capable of protecting client data and to require safeguards by contract. A provider can implement and document the program for you, but the obligation remains yours.
Why Cybersecurity Matters for Accounting and Tax Firms
- Why would a hacker target a small accounting firm?
- Because small firms concentrate high-value data, Social Security numbers, income, and bank details for many clients, while often running lighter defenses than banks. That mix of rich data and thinner security makes them attractive, low-effort targets.
- What does a data breach actually cost a firm?
- Far more than the fine. IBM's Cost of a Data Breach Report 2025 puts the global average breach in the millions once you include investigation, client notification, downtime, remediation, potential litigation, and lost clients. For a billable-hours business, recovery time is a major hidden cost.
- Isn't the FTC fine the main risk?
- No. The penalty is real, but it is usually the smallest part. The larger costs are operational downtime, especially during filing season, and the loss of client trust and referrals that follows a public breach.
- Will clients really leave after a breach?
- The risk is real. In consumer trust surveys, such as Vercara's 2024 consumer research, a large share of customers say they would take their business elsewhere after a company loses their data. In a referral-driven profession, that kind of reputational hit compounds over time.
- If I am compliant, does that mean I am secure?
- Compliance is the floor, not the ceiling. Meeting the Rule forces the basics that stop the most common attacks, but real security is an ongoing practice. Clearing the Rule deliberately gets you most of the way there.