Safeguards Rule Timeline and Deadlines: What to Do and When

Last reviewed 2026-07-04 · 6 min read

Many owners are waiting for a Safeguards Rule "deadline" to prepare for. There is nothing to wait for. The Rule is already law, and the relevant dates now are your own recurring business cycles. This guide lays out the timeline and a simple plan to get current.

The key dates

If your firm is not compliant today, it is already overdue, not early.

The cycles that actually drive your calendar

A simple 30/60/90-day plan

If you are starting from behind, do not try to do everything at once. Sequence it:

Start here

In your first 30 days, do three things: designate a Qualified Individual, turn on MFA for email and tax software, and download IRS Publication 5708. Those three alone move you off the bottom of the compliance scale.

Keep it current

Treat the WISP as a living document reviewed at least once a year and after any significant change to your systems or staff. The fastest way to know where you stand before each cycle is to run the 3-minute check on this site and see which elements are still open.

This is educational information, not legal advice. Confirm your specific obligations with a qualified professional.

Frequently asked questions

Is there a compliance deadline I am waiting for?
No. The updated Safeguards Rule has been enforceable since June 9, 2023, and the breach-notification amendment took effect May 13, 2024. If you are not compliant now, you are overdue rather than early.
Is it too late to get compliant?
No. The requirement is to have and maintain a program, so getting current now is exactly what the Rule expects. Start with a Qualified Individual, MFA, and the WISP template, then work through the remaining elements.
What should I do first?
In your first 30 days, do three things: designate a Qualified Individual, turn on MFA for your email and tax software, and download IRS Publication 5708 (https://www.irs.gov/pub/irs-pdf/p5708.pdf) to start your WISP. To make the WISP step concrete, our free one-page WISP starter checklist maps each move to the required elements, run the 3-minute check on this site and it is included with your gap report. Remember that the template and the checklist get you started; filling the plan in correctly and keeping it current is the ongoing work, and it is the part a managed provider can take off your plate entirely.
How often do I need to review my compliance?
At least annually, and after any significant change to your systems or staff. Tying the review to PTIN renewal or the start of filing season makes it easy to remember.

Check your firm in 3 minutes

← All guides · All FAQs