Your IT Company Is Not Your Security Team: What CPA Firms Actually Need
Filing season concentrates the exposure. What IT covers, what a security operation covers, and the reporting path the IRS walks after a preparer breach.
Read articleCompliance
What a tax practice should put in its WISP, the evidence to retain and the FTC notification rule, with IRS and FTC sources.
A CPA or tax-preparation firm's WISP should describe who protects taxpayer information, the risks the firm faces, the safeguards in use and how they are checked. Start with IRS Publications 4557 and 5708, then map the actual firm to the FTC Safeguards Rule. A signed template without operating controls is not the goal.
Obsidian Ridge's Ridge Core includes endpoint MDR and Microsoft 365 or Google Workspace ITDR at $25 per person per month, month-to-month with no minimum and business onboarding separate. Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States. Ridge Plus costs $50 per person per month on an annual term, billed monthly, with no minimum. It adds staff training, email-security configuration and a secure browser to Ridge Core; business onboarding is separate. These services can produce part of the evidence described below; they do not replace your firm's plan or legal advice about its obligations.
IRS Publication 4557 explains taxpayer-data safeguards. Publication 5708 supplies a WISP template for tax and accounting practices. Use the template to document the firm's decisions, not to claim that the IRS has certified your programme.
The FTC Safeguards Rule is 16 CFR Part 314. The FTC identifies tax-preparation firms among the financial institutions it covers. Its exception for institutions holding information about fewer than 5,000 consumers removes certain provisions, not the entire programme or every duty. Assess applicability using the actual activities and records, not employee headcount. FTC business guidance.
Use this checklist with the IRS template and the rule's applicable requirements:
The checklist summarizes topics to work through; it is not a substitute for the rule text. Keep the current approved version and the history of material changes. IRS WISP template; 16 CFR Part 314.
Build a small evidence register rather than a folder of unexplained screenshots. For each record, write the system, date, responsible person, period covered and where the original can be found.
| WISP topic | Practical evidence to organize | Who must own the answer |
|---|---|---|
| Account access | User/admin roster, MFA settings, access removal records | Firm and identity administrator |
| Endpoint monitoring | Deployment inventory, detection and response records | Security provider and firm contact |
| Training | Assigned topics, completion dates, follow-up actions | Programme owner |
| Backups | Backup scope and a dated restore-test result | Backup/IT provider |
| Vendor oversight | Inventory, review decisions, relevant agreements | Firm leadership |
| Plan maintenance | Approved plan, risk decisions, test findings and changes | Firm's designated owner |
Our accounting programme, managed ITDR and training service explain the parts we operate. Backup remains outside the monthly tiers. Ridge Reserve costs $70 per person per month on an annual term, billed monthly, with no minimum and onboarding separate. It adds an incident-response plan and annual tabletop, quarterly admin-access review, monthly patch reporting and an annual questionnaire refresh to Ridge Plus. Ask for records from each responsible party rather than assuming one invoice supplies them all.
Section 314.4(j) requires a covered institution to notify the FTC as soon as possible, and no later than 30 days after discovery, when a notification event involves at least 500 consumers. This concerns unauthorized acquisition of unencrypted customer information. Encrypted information counts as unencrypted if the key was accessed; unauthorized access is presumed to involve acquisition unless reliable evidence shows otherwise. The deadline is not permission to wait 30 days. FTC guidance; rule text.
That is the FTC notice, not a complete list of notices to individuals, states, insurers or other bodies. When an incident occurs, preserve records and involve qualified incident-response and legal help to determine which obligations apply.
Choose an owner, compare the draft with the real inventory, and assign each unresolved safeguard to someone with a date. Test whether the evidence answers the question: a configured backup job and a completed restore test are different records.
The Readiness Sprint costs $1,500 to $3,500 once for a 7-business-day engagement. The deliverable is the same at each scope: a signed evidence pack and a record of controls and gaps. The Sprint organizes agreed control evidence and gaps; it does not transfer the firm's legal responsibility. Use the questionnaire worksheet or request free application help to start with the carrier's actual questions.
Fetched October 2, 2026.
Last updated
October 2, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
IRS Publication 5708 provides a written information security plan template for tax and accounting practices. Publication 4557 covers safeguarding taxpayer data. Adapt the template to the firm and the controls actually in use.
Small size alone is not a blanket exemption. The FTC identifies tax-preparation firms among covered financial institutions, and the fewer-than-5,000-consumer provision exempts only certain requirements. Confirm which rules apply to the services and information your firm holds.
A notification event involving at least 500 consumers requires notice to the FTC as soon as possible and no later than 30 days after discovery.
It concerns unauthorized acquisition of unencrypted customer information, including information whose encryption key was accessed. Other reporting duties may also apply.
No. A subscription can supply controls and records that support the plan. The firm must approve and maintain its own plan, assign responsibility and address requirements outside the provider scope.
Related reading
Filing season concentrates the exposure. What IT covers, what a security operation covers, and the reporting path the IRS walks after a preparer breach.
Read articleWhat cyber insurance for CPA and tax firms actually covers in 2026, the underwriting questionnaire controls carriers review.
Read articleWhat IRS Publication 4557 and the FTC Safeguards Rule actually require of CPA firms in 2026 — the safeguards, the written program, and where firms slip.
Read article