Yes. The FTC Safeguards Rule names tax preparation firms as financial institutions, and the IRS says tax and accounting professionals are legally required to have a written information security plan. Firm size does not remove the obligation, and neither does being in Texas. A one-partner practice in Kyle is covered the same way as a large firm in Austin.
Below is what the rule requires, what a small firm is exempt from, the breach reporting requirement, and a seven-step place to start.
Why a CPA firm counts as a financial institution
The rule comes from the Gramm-Leach-Bliley Act, which requires financial institutions to protect customer data. The FTC's Safeguards Rule lists tax preparation firms among its examples of financial institutions. The IRS states it plainly: tax and accounting professionals are considered financial institutions and must implement a data security plan, and they are legally required to have a written, accessible plan that they review, test and update.
What the rule requires
The FTC's guidance for businesses lays out these requirements:
- A Qualified Individual. Name one person to oversee and enforce your information security program. That person can be an employee or an outside provider.
- A written risk assessment. Identify the foreseeable internal and external risks to customer information.
- Encryption. Encrypt customer information at rest and in transit over external networks.
- Multifactor authentication. Require it for anyone accessing an information system, unless your Qualified Individual approves an equivalent control in writing.
- Testing. Annual penetration testing, plus vulnerability assessments including system-wide scans every six months.
- Training. Security awareness training for your people, with regular refreshers.
- Service provider oversight. Choose vendors carefully and require safeguards by contract. That covers your tax software, cloud storage, client portal and e-signature vendors.
- A written incident response plan. It must cover how you respond to and recover from a security event.
- Reports to leadership. The Qualified Individual reports in writing at least once a year to the board or equivalent, which for a partnership means the partners.
- Ongoing updates. Keep the program current as your firm and the threats change.
What a small firm is exempt from
The rule includes an exemption for financial institutions that keep customer information on fewer than 5,000 consumers. Under 16 CFR 314.6, four provisions do not apply to them:
- The written risk assessment
- Continuous monitoring or annual penetration testing and six-month vulnerability assessments
- The written incident response plan
- The annual written report to the board
That helps a small practice, but it is narrower than it sounds. Encryption, multifactor authentication, a Qualified Individual, training, vendor oversight and a security program still apply. The IRS also expects tax professionals to keep a written plan, and its Publication 5708 is a 28-page template built for smaller practices. In practice, most firms are better off writing the plan and the risk assessment anyway, since you will need them the day something goes wrong.
The breach reporting requirement
Since May 13, 2024, a financial institution must notify the FTC as soon as possible, and no later than 30 days after discovery, of a notification event. That means unauthorized acquisition of unencrypted customer information involving at least 500 consumers. Notices go to the FTC electronically through a form on its website.
A firm with 200 clients can still have a serious breach, and Texas has its own reporting law with a lower threshold. We cover both in our post on what a Texas CPA firm must do after a data breach.
Where a small firm should start
- Name your Qualified Individual. Write down who it is.
- Get the IRS template. Use Publication 5708 to draft your written plan.
- Turn on multifactor authentication for email, your tax software, your file storage and remote access.
- Confirm encryption on laptops, servers and backups.
- List your vendors and check what each one does with client data.
- Assign training for everyone in the firm, including seasonal staff.
- Write down your incident steps and where the phone numbers are.
The IRS also lists what it calls the Security Six: anti-virus software, a firewall, two-factor authentication, backup software or services, drive encryption and a virtual private network. If your firm has all six today, you are ahead of the baseline.
This post is general information and not legal advice. Your attorney can confirm how the rule applies to your firm.
The bigger lesson
The rule reads like a paperwork problem, but nearly every item is a technical control someone has to run: multifactor authentication, encryption, backups, monitoring and vendor checks. A managed IT provider can act as your Qualified Individual or support the one you name, and keep the plan current as the firm changes.
The rule does not require you to be a security expert, and it allows you to use an outside provider as your Qualified Individual. safemode IT is a managed IT and cybersecurity provider based in Kyle, Texas. We support CPA firms and other small businesses along the I-35 corridor, from Bastrop and Austin to San Marcos. To talk through your plan, call 512-761-7652 or visit safemodeit.com.
Sources
- FTC, FTC Safeguards Rule: What Your Business Needs to Know
- eCFR, 16 CFR 314.4 Elements
- eCFR, 16 CFR 314.6 Exceptions
- IRS, Publication 5708 and WISP guidance
- IRS, Tax Security 2.0: The Taxes-Security-Together Checklist
- The Tax Adviser, Complying with the Safeguards Rule for information security
- ACA Global, The FTC Safeguards Rule Amendments Become Effective May 13, 2024
Not sure your IT is as solid as it should be? Take 10 minutes and tell us about your setup. No pressure, no obligation.
Book a 10-Minute Discovery Call →Frequently asked questions
Does the FTC Safeguards Rule apply to a one-person CPA practice?
Yes. The rule lists tax preparation firms as financial institutions, and size does not remove the obligation. Some provisions do not apply to firms holding customer information on fewer than 5,000 consumers.
What is a Qualified Individual?
It is the person you name to oversee and enforce your information security program. It can be an employee or an outside provider.
Does a small CPA firm need a written information security plan?
The IRS says tax and accounting professionals are required to have a written, accessible plan. Its Publication 5708 is a template built for smaller practices.
When must a CPA firm report a breach to the FTC?
Since May 13, 2024, the FTC must be notified as soon as possible and no later than 30 days after discovery of unauthorized acquisition of unencrypted customer information involving at least 500 consumers.
Can safemode IT manage this so we do not have to deal with it?
Yes. We support CPA firms along the I-35 corridor and can serve as your outside Qualified Individual. Learn more about our managed IT services or reach out for a free assessment.
Last updated: October 1, 2026


