Updated 5 min read
The FTC Safeguards Rule in Plain English: A Guide for Tax and CPA Firms
The short answer
If your firm prepares tax returns or keeps clients' financial information, the FTC Safeguards Rule applies to you. It asks for a written security plan (your WISP), one person in charge of it, MFA and encryption, staff training, an eye on your vendors and a plan for when something goes wrong. Firms holding information on fewer than 5,000 consumers can skip four parts, but not the written plan.

Plenty of firms are surprised the rule covers them at all. It comes from the Gramm-Leach-Bliley Act and talks about “financial institutions,” which sounds like banks, but the FTC counts tax preparers and accounting firms in that group. That includes firms that keep clients’ financial information for bookkeeping, payroll or advisory work. The updated rule has been in full effect since June 2023.
The Safeguards Rule checklist
The rule itself lists ten parts of an information security program:
- Put one person in charge: name a “Qualified Individual” to run the program.
- Write down your risks: what client information you have, where it lives and what could realistically go wrong.
- Put safeguards in place: the eight the rule names (listed below) to control those risks.
- Check that they work: monitor your systems continuously, or run a penetration test every year and vulnerability scans every six months.
- Train your team: regular, practical security training for everyone.
- Keep an eye on your vendors: choose ones that can protect client data, require it in their contracts and check on them from time to time.
- Keep the program current: adjust it as your firm, its technology and the threats change.
- Write an incident response plan: what you’ll do, and who does it, when something goes wrong.
- Report once a year: the Qualified Individual reports in writing to the firm’s owners or partners.
- Tell the FTC about a breach: within 30 days if unencrypted information about 500 or more consumers is taken (see below).
The Qualified Individual can be a partner, an office manager or an outside IT provider. If it’s an outside provider, someone senior at the firm still oversees their work.
The eight safeguards the rule names in step 3:
- Give people access only to the client information their job needs.
- Know what data, devices and systems you have.
- Encrypt client information, both when it’s stored and when it’s sent.
- If you build your own software, develop it securely.
- Use multi-factor authentication (MFA) for anyone signing in to your systems.
- Securely dispose of client information you no longer need, generally within two years of when it was last used.
- Keep track of changes to your systems.
- Log what people do on your systems, and watch for anything unusual.
If your firm is small
Firms that keep information on fewer than 5,000 consumers don’t have to do four of those ten: the written review of risks (step 2), the monitoring or testing schedule (step 4), the written incident response plan (step 8) and the annual written report (step 9).
Everything else still applies, including the written security program, the Qualified Individual, MFA and encryption. Even where they aren’t required, we’d still keep a short written review of risks and a one-page incident plan on file. A cyber insurer is likely to ask about both at renewal.
Where GLBA fits
The Safeguards Rule comes from the Gramm-Leach-Bliley Act (GLBA), the federal law that requires financial institutions to protect their customers’ information. The FTC’s rule is the part of it that covers financial businesses that aren’t banks, which is where tax preparers and accounting firms come in. So when a client, an insurer or a software vendor asks about GLBA, they almost always mean the Safeguards Rule.
For the tax and CPA firms we look after, our security practices are aligned with GLBA and the Safeguards Rule, and we help you write down what’s in place. The plan, and the decisions in it, stay yours.
If something goes wrong
Since May 2024, firms must tell the FTC within 30 days if they discover that unencrypted information about 500 or more consumers was taken without authorization. Information that was encrypted doesn’t count, as long as the encryption key wasn’t taken too. That’s one more reason encryption is near the top of the list.
California has its own breach notification law covering the clients themselves, so a real incident usually means talking to your attorney as well. If it happens, here’s how to handle the first hour.
Where the IRS fits in
The IRS expects tax professionals to protect taxpayer data and to have a written information security plan, usually called a WISP. The PTIN application and renewal form, Form W-12, asks preparers to confirm on line 11 that they know the law requires one, and in August 2026 the IRS and its Security Summit partners reminded tax professionals again.
IRS Publication 4557 explains the safeguards, and Publication 5708 includes a sample plan written for small tax and accounting practices. One well-written plan can cover both the IRS’s expectations and the FTC rule. Our step-by-step guide to writing a WISP walks through it.
Where to start
If this feels like a lot, these four steps cover most of the real risk:
- Turn on MFA for email, your tax software and any remote access.
- Check that your backups run, and that you can restore from them.
- Encrypt laptops, and send returns and statements through a secure portal instead of as email attachments.
- Write a short plan: who’s in charge, what you protect, and what you’ll do if something goes wrong. That’s the start of your WISP.
For what this looks like in a real office, see the seven gaps we find most often in accounting firms and our tax season IT checklist.
How we help
We help tax and CPA firms across Orange County with the day-to-day security the rule expects, and we’ll help you write the plan itself in plain language, sized to how your firm works. You won’t get a binder nobody reads, and we won’t push things you don’t need.
If you’d like to talk through where your firm stands, book a free IT check-in. You can also read more about our IT support for accounting and CPA firms.
This guide is general information, not legal advice. For questions about your firm’s specific obligations, talk to your attorney or compliance advisor.
Sources
- FTC Safeguards Rule: What Your Business Needs to Know (FTC)
- 16 CFR Part 314: Standards for Safeguarding Customer Information (eCFR)
- Safeguards Rule notification requirement now in effect (FTC, May 2024)
- IRS Publication 4557, Safeguarding Taxpayer Data
- IRS Publication 5708, Creating a Written Information Security Plan for your Tax and Accounting Practice
- IRS Form W-12 (Rev. October 2025), line 11
- IR-2026-92: IRS and Security Summit remind tax pros they need a written information security plan (August 18, 2026)

