The Federal Trade Commission's Safeguards Rule names the work, not the firm. One of its own examples of a covered financial institution is an accountant or other tax preparation service in the business of completing income tax returns, which makes cybersecurity for CPA firms a legal duty with a written deliverable rather than an IT preference.
A product list is the easy half of the answer: multi-factor authentication, encryption, backups, staff training. Those controls are real, and they are in the rule. So are a named owner, a documented risk assessment, a testing cadence, a disposal clock, and a reporting duty with a deadline on it.
The rule reads shorter than its reputation. It runs to a handful of elements, a short list of what changes when a firm is small, and a layer the IRS adds on top.
Why Cybersecurity for CPA Firms Is a Legal Duty
You are covered because of the work you do, not because of your size or your software.
The Safeguards Rule defines a financial institution by activity rather than by industry label, and its own list of examples includes an accountant or other tax preparation service that is in the business of completing income tax returns (eCFR, Safeguards Rule definitions at section 314.2). The FTC's own compliance guide puts a number on that list: section 314.2(h) gives 13 examples of the kinds of entities that are financial institutions under the rule, tax preparation firms among them (FTC, Safeguards Rule: What Your Business Needs to Know).
The same section closes the other half of the question. A person who becomes your client for the purpose of obtaining tax preparation services has a continuing customer relationship, and any record containing nonpublic personal information about that customer is customer information, whether it sits on paper, on a screen, or in a vendor's cloud (eCFR, section 314.2).
Coverage also runs wider than your own client list. The scope paragraph applies the rule to all customer information in your possession, whether it pertains to individuals you have a customer relationship with or to customers of other financial institutions that handed you the information (eCFR, Safeguards Rule purpose and scope at section 314.1).
The IRS says the same thing in plainer language. Publication 4557 states that protecting taxpayer data is the law, that federal law gives the Federal Trade Commission authority to set data safeguard regulations for professional tax return preparers, and that failing to create and enact a security plan may result in an FTC investigation (IRS Publication 4557, Safeguarding Taxpayer Data).
The Deliverable Is a Written Program, Not a Product
What the rule asks you to produce is a document, and every element it lists is something you decide, write down or schedule.
Section 314.3 requires a comprehensive information security program, written in one or more readily accessible parts, containing administrative, technical and physical safeguards appropriate to your size and complexity, the nature and scope of your activities, and the sensitivity of the customer information at issue (eCFR, standards for safeguarding customer information at section 314.3).
The IRS calls that document a written information security plan, or WISP. Publication 4557 points firms to Publication 5708 for information on creating one, and adds that online providers must also follow the six security and privacy standards in Publication 1345, the handbook for authorized IRS e-file providers (IRS Publication 4557). The Security Summit has published a plain language sample plan that practitioners can use as a starting point rather than drafting from a blank page (IRS Publication 5709, How to Create a WISP).
Read the size language for what it does and does not do. It scales the depth of the program to the practice. It does not switch the program off, and the rule keeps its own short list of what a smaller firm may leave out.
What Section 314.4 Requires, Element by Element
Every element below is a paragraph of section 314.4, nine of them by the FTC's own count (FTC, Safeguards Rule: What Your Business Needs to Know). Paragraph (f), on service providers, gets its own section further down, next to the disclosure rules that travel with it.
Name a Qualified Individual, Even If You Hire the Work Out
Section 314.4(a) makes one person accountable. You designate a Qualified Individual responsible for overseeing, implementing and enforcing the program, and that person may be employed by you, an affiliate, or a service provider (eCFR, Safeguards Rule elements at section 314.4).
Where the role sits with a service provider or an affiliate, the same paragraph attaches three conditions. You retain responsibility for compliance with the part, you designate a senior member of your personnel responsible for direction and oversight of the Qualified Individual, and you require that provider or affiliate to maintain an information security program that protects you in accordance with the rule (eCFR, section 314.4).
A managed IT contract moves the labor. It does not move the duty, and it does not remove the need for a partner who owns the relationship.
Write the Risk Assessment Down
The program has to be based on a risk assessment, and paragraph (b)(1) says that assessment is written. It has to include criteria for evaluating and categorizing the security risks or threats you face, criteria for assessing the confidentiality, integrity and availability of your information systems and customer information including the adequacy of existing controls, and requirements describing how identified risks will be mitigated or accepted (eCFR, section 314.4).
Paragraph (b)(2) then asks you to perform additional risk assessments periodically. The decision it drives is a date. Pick a month, reassess then, and reassess again after anything material changes.
The Eight Safeguards in Paragraph (c)
Paragraph (c) turns the risk assessment into controls, and each of the eight lands as a decision the firm has to make (eCFR, section 314.4).
- Access controls. Authenticate and permit access only to authorized users, and limit each user to the customer information they need for their duties. The decision is a named list of who reaches what, kept current as people join and leave.
- Asset inventory. Identify and manage the data, personnel, devices, systems and facilities that let you do business, ranked by their importance to your objectives. The decision is whether you can name every place a client file lives, including a laptop in somebody's spare room.
- Encryption. Protect customer information in transit over external networks and at rest. Where you determine encryption is infeasible, you may use effective alternative compensating controls, but they have to be reviewed and approved by your Qualified Individual. The decision is that the exception is a recorded call by a named person, not an assumption.
- Application security. Adopt secure development practices for anything you build in-house, plus procedures for evaluating, assessing or testing the security of outside applications you use to transmit, access or store customer information. The decision is how a new portal or tax add-in gets vetted before it touches a return.
- Multi-factor authentication. Required for any individual accessing any information system, unless the Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls. The decision is that switching it off anywhere is a written act by a named person.
- Secure disposal. Maintain procedures for the secure disposal of customer information in any format no later than two years after the last date it was used in connection with providing a service to that customer, unless it is needed for business operations or another legitimate business purpose, is required to be kept by law, or targeted disposal is not reasonably feasible given how the data is held. The same paragraph asks you to review the retention policy periodically. The decision is a retention rule that cuts against the instinct to keep everything.
- Change management. Adopt procedures for change management. The decision is who approves and records a change to the systems that hold client data.
- Activity monitoring. Monitor and log the activity of authorized users, and detect unauthorized access to, use of, or tampering with customer information by those users. The decision is who reads the logs, and how often.
Test It, Train the Team, and Report Once a Year
The next four elements decide whether the program stays alive after the first draft.
Testing comes first. Paragraph (d)(1) requires you to regularly test or otherwise monitor the effectiveness of the safeguards' key controls, systems and procedures, including those that detect actual and attempted attacks. Paragraph (d)(2) says that for information systems this means continuous monitoring, or, absent effective continuous monitoring, annual penetration testing plus vulnerability assessments at least every six months and whenever there are material changes to your operations or business arrangements (eCFR, section 314.4).
Paragraph (e) covers the people. It asks for security awareness training updated to reflect the risks the assessment identified, qualified information security personnel sufficient to manage those risks, security updates and training for those personnel, and verification that they take steps to maintain current knowledge of changing threats and countermeasures (eCFR, section 314.4).
Paragraph (i) is the one that puts the program in front of whoever governs the firm. It requires the Qualified Individual to report in writing, regularly and at least annually, to your board or equivalent governing body, or, where none exists, to a senior officer responsible for the program. The report covers the overall status of the program and your compliance with the rule, along with material matters such as risk management and control decisions, service provider arrangements, testing results, and security events and the responses to them (eCFR, section 314.4).
Paragraph (g) closes the loop. You evaluate and adjust the program in light of the testing results, any material changes to your operations or business arrangements, the results of later risk assessments, or anything else you know or have reason to know may have a material impact on it.
The Incident Response Plan and the Reporting Clock
Paragraph (h) requires a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity or availability of customer information in your control, and it lists what the plan addresses: the goals, the internal response processes, clear roles and levels of decision-making authority, internal and external communications, remediation requirements for identified weaknesses, documentation and reporting of events, and revision of the plan after an event (eCFR, section 314.4).
Paragraph (j) attaches the deadline. Where a notification event involves the information of at least 500 consumers, you notify the Federal Trade Commission as soon as possible and no later than 30 days after discovery, electronically, on a form on the FTC's website (eCFR, section 314.4). The duty carries a start date of its own: section 314.4(j) is effective as of May 13, 2024 (eCFR, effective date at section 314.5).
The definition is broader than a confirmed theft. A notification event is the acquisition of unencrypted customer information without the authorization of the individual it pertains to, and unauthorized acquisition is presumed to include unauthorized access to that information unless you hold reliable evidence showing there has not been, or could not reasonably have been, unauthorized acquisition (eCFR, section 314.2). Read the encryption carve-out before you lean on it, because the same definition treats customer information as unencrypted if the encryption key was accessed by an unauthorized person.
The clock also starts earlier than it looks. The event counts as discovered on the first day it is known to you, and you are deemed to know it once it is known to any employee, officer or other agent other than the person who committed the breach.
What Changes When Your Firm Is Small
Less than the phrase "small firm exception" suggests, and the exact list is short.
Section 314.6 lifts four requirements from a financial institution that maintains customer information concerning fewer than five thousand consumers: section 314.4(b)(1), (d)(2), (h) and (i) (eCFR, exceptions at section 314.6). The FTC states the same exemption in the guide it publishes as the small entity compliance guide under the Small Business Regulatory Enforcement Fairness Act (FTC, Safeguards Rule: What Your Business Needs to Know).
The list of four is the part everyone quotes. What decides how a small practice actually runs is what stands underneath them, because in two of the four the exception lifts a subparagraph and leaves its parent in force.
- (b)(1) is the requirement that the risk assessment be written and carry the listed criteria. Paragraph (b) itself stands, so the program is still based on a risk assessment, and the periodic reassessment in (b)(2) still applies. A small firm is excused from the document, not from the thinking behind it.
- (d)(2) is the penetration testing and vulnerability assessment cadence. Paragraph (d)(1), the duty to regularly test or otherwise monitor the effectiveness of the safeguards, is untouched. The prescribed schedule drops. The duty to check your own controls does not.
- (h) is the written incident response plan. This one lifts whole.
- (i) is the Qualified Individual's written report to the board or a senior officer. This one lifts whole as well.
Everything else applies at any size: the written program itself, the Qualified Individual and the senior person overseeing them, all eight safeguards including multi-factor authentication and encryption, personnel training, service provider oversight, and the notification duty with its deadline.
Then count carefully, because the threshold counts consumers rather than engagements. The rule's consumer is an individual who obtains a financial product or service used primarily for personal, family or household purposes, so the count generally follows individual taxpayers rather than entity clients (eCFR, section 314.2). The scope paragraph also reaches customer information that belongs to the customers of other financial institutions and was handed to you, which matters in a practice that prepares returns under another firm's name (eCFR, section 314.1).
What the IRS Adds on Top
The FTC sets the program. The IRS sets the daily habits and the phone list.
Publication 4557 reads like an operations checklist: implement multi-factor authentication for anyone accessing customer information on your system, encrypt sensitive files and emails, back up sensitive data to a secure external source that is not connected to a network full time, limit access to taxpayer data to individuals who need to know, implement audit trails that record who performed an activity, when it happened and what changed, and check e-file applications and PTIN accounts weekly against the returns actually filed (IRS Publication 4557).
That weekly check carries an eligibility rule worth knowing before you write it into a procedure. Only preparers who are attorneys, CPAs, enrolled agents or Annual Filing Season Program participants, and who file 50 or more returns, may obtain the PTIN return counts (IRS Publication 4557).
The reporting path is the part that is easy to leave blank until the day it is needed. Publication 4557 tells practitioners to report a client data theft to their local IRS Stakeholder Liaison, to contact the local FBI office if the IRS directs it, to file a police report, and to reach the states where they prepare returns through the Federation of Tax Administrators' report a data breach page. It also says to bring in a security expert to determine the cause and scope, to notify the insurance carrier, and, for a ransomware attack, to contact the FBI and the Cybersecurity and Infrastructure Security Agency in addition to the IRS (IRS Publication 4557).
Put those contacts in the plan while nothing is on fire. Assembling them during an incident costs hours you will not have.
Where the Duty Follows Work That Leaves the Firm
Your program does not stop at the office door.
Paragraph (f) makes service provider oversight an element of the program. You take reasonable steps to select and retain providers capable of maintaining appropriate safeguards for the customer information at issue, require those safeguards by contract, and periodically assess each provider based on the risk it presents and the continued adequacy of its safeguards (eCFR, section 314.4).
Tax work adds a second layer that is about disclosure rather than security. The section 7216 regulations govern when tax return information may pass to another preparer at all, and they tighten where that preparer sits outside the United States (eCFR, taxpayer consent at section 301.7216-3).
Keep the two layers apart when you draft the contract. One asks whether the other party can hold the data safely. The other asks whether your client agreed to the data going there at all.
Where to Start If the Plan Does Not Exist Yet
Work in this order. It front-loads the requirements that carry no size exception and the decisions everything else hangs off.
- Count the consumers whose customer information you hold, since that number decides whether four of the requirements drop away.
- Name the Qualified Individual, and if that person sits outside the firm, name the partner who directs and oversees them.
- Run the risk assessment. Above the threshold, write it down using the criteria the rule lists. Below it, the assessment still has to happen and still has to drive the program.
- Turn on multi-factor authentication everywhere and encrypt data in transit and at rest, because neither has a size exception.
- Write the retention and disposal rule, with the two-year clock and its exceptions stated plainly.
- Write the incident response plan, or at minimum the call list inside it, naming the FTC notice, the IRS Stakeholder Liaison and the state contacts.
- Put the reassessment and the testing on a calendar, with an owner against each, and add the annual written report if you are above the threshold.
- Add the service provider clause to every contract that touches client data, and set the date you will reassess each one.
Questions CPA Firms Ask About Cybersecurity
Does the Safeguards Rule Apply to a Two-Person Firm?
Yes. Coverage turns on the activity, and completing income tax returns is on the rule's own list of covered activities. Size changes only which four paragraphs you may leave out, and those four are the written form of the risk assessment, the penetration testing cadence, the written incident response plan and the annual report.
What Is a WISP, and Is It Required?
A WISP is the written information security plan the rule requires, and the IRS uses the same acronym for the same document. It is required. The rule wants it written in one or more readily accessible parts and scaled to the size and complexity of the practice, and the IRS publishes a sample plan a firm can adapt.
When Does a Breach Have to Be Reported?
There is more than one clock, and only one of them has a size test on it. The FTC notice is the one carrying numbers: at least 500 consumers, and no later than 30 days after discovery (eCFR, section 314.4). The IRS path has no size test at all, and Publication 4557 routes the state notices separately, through the Federation of Tax Administrators (IRS Publication 4557). Discovery is the part worth reading twice, because it runs from the first day the event is known to any employee, officer or other agent other than the person who caused it, which can land well before it reaches a partner.
Start With the Document, Not the Software
Cybersecurity for CPA firms looks like an IT problem and lands as a documentation problem. A practice already running multi-factor authentication and encrypted backups owns real parts of the answer. The parts that do not come from a vendor are the written program, the named owner, the dated risk assessment, the retention rule, and the call list for the worst morning of the year.
Start with the count, the name and the calendar. Each of those three is a decision rather than a purchase, and the rest of the program hangs off them.
Then apply paragraph (f) to anyone you let near a live client file: capable of the safeguards, bound by contract, reassessed on a date you set. Work quality is the separate question, and it is the one you can settle before any file moves. Don't trust us, test us. Our Free 40-Hour Proof Pilot runs a block of your own representative work through the full review chain on your software and your procedures, so your reviewer grades real output first.
