Safeguards Rule Timeline and Deadlines: What to Do and When
Last reviewed 2026-07-04 · 6 min read
Many owners are waiting for a Safeguards Rule "deadline" to prepare for. There is nothing to wait for. The Rule is already law, and the relevant dates now are your own recurring business cycles. This guide lays out the timeline and a simple plan to get current.
The key dates
- June 9, 2023: the updated Safeguards Rule became fully enforceable.
- May 13, 2024: the FTC breach-notification requirement took effect (notify the FTC within 30 days of a breach affecting 500 or more consumers).
- August 2024: IRS Publication 5708 was updated, reinforcing universal MFA and revised password standards.
If your firm is not compliant today, it is already overdue, not early.
The cycles that actually drive your calendar
- Before each filing season: confirm your WISP is current and MFA is enabled everywhere client data is reachable.
- At PTIN renewal: your renewal assumes a current WISP, so treat renewal season as your annual compliance checkpoint.
- Annually: if you are not exempt by size, your Qualified Individual should deliver a written report on the program to ownership.
A simple 30/60/90-day plan
If you are starting from behind, do not try to do everything at once. Sequence it:
- First 30 days: name your Qualified Individual, turn on MFA for email and tax software, and download the Publication 5708 WISP template.
- Days 30 to 60: complete a basic data inventory (where client data lives), enable encryption on devices and file transfer, and fill in the WISP section by section.
- Days 60 to 90: write a one-page incident-response plan, confirm your service-provider contracts include security obligations, and schedule annual staff training and your yearly review.
In your first 30 days, do three things: designate a Qualified Individual, turn on MFA for email and tax software, and download IRS Publication 5708. Those three alone move you off the bottom of the compliance scale.
Keep it current
Treat the WISP as a living document reviewed at least once a year and after any significant change to your systems or staff. The fastest way to know where you stand before each cycle is to run the 3-minute check on this site and see which elements are still open.
This is educational information, not legal advice. Confirm your specific obligations with a qualified professional.
Frequently asked questions
- Is there a compliance deadline I am waiting for?
- No. The updated Safeguards Rule has been enforceable since June 9, 2023, and the breach-notification amendment took effect May 13, 2024. If you are not compliant now, you are overdue rather than early.
- Is it too late to get compliant?
- No. The requirement is to have and maintain a program, so getting current now is exactly what the Rule expects. Start with a Qualified Individual, MFA, and the WISP template, then work through the remaining elements.
- What should I do first?
- In your first 30 days, do three things: designate a Qualified Individual, turn on MFA for your email and tax software, and download IRS Publication 5708 (https://www.irs.gov/pub/irs-pdf/p5708.pdf) to start your WISP. To make the WISP step concrete, our free one-page WISP starter checklist maps each move to the required elements, run the 3-minute check on this site and it is included with your gap report. Remember that the template and the checklist get you started; filling the plan in correctly and keeping it current is the ongoing work, and it is the part a managed provider can take off your plate entirely.
- How often do I need to review my compliance?
- At least annually, and after any significant change to your systems or staff. Tying the review to PTIN renewal or the start of filing season makes it easy to remember.