First Coast Accounting Tech · Jacksonville, St. Johns County & St. Augustine, FL
What the IRS actually requires, what most small firms are missing, and how to close the gap before renewal season.
Call (904) 385-1416A Written Information Security Plan is a document describing how your practice protects client data: who is responsible for it, what could go wrong, what safeguards are in place, and what happens if there is a breach.
The IRS is direct that this is not optional. Its guidance for tax professionals states that they must have a written security plan, and it publishes two documents to help build one: Publication 4557, Safeguarding Taxpayer Data, and Publication 5708, a template aimed specifically at smaller practices.
Accounting practices are also treated as financial institutions under the Gramm-Leach-Bliley Act, which brings them under the FTC Safeguards Rule. A plan that satisfies one and ignores the other is only half done.
Downloading a template is the easy half. The plan describes safeguards — encryption, multi-factor authentication, access controls, backups, a named person responsible, an incident response procedure — and those safeguards have to actually exist.
A plan describing controls a firm does not have is worse than no plan at all. It is a written record, in your own words, of the gap between what you said and what you did.
So the real task is not the document — it is making the safeguards it describes genuinely true, and keeping them true as the practice changes. That is what to look for in whoever you bring in: someone who builds the controls, not someone who sells you a template.
PTIN renewal runs from roughly October through December, and it is the point at which most preparers confront the state of their security plan. Building one properly takes longer than the evening you set aside for renewal.
The IRS reinforces this at renewal: the PTIN application, Form W-12, includes a data-security attestation — you confirm you are aware that paid preparers are required by law to have a written data security plan (see Publication 4557 and Publication 5708).
Accounting practices are also treated as financial institutions under the FTC Safeguards Rule, which carries real enforcement exposure. The point is not a specific dollar figure — it is that this is a legal obligation with teeth, not a best-practice suggestion.
Yes. The requirement follows the PTIN and the handling of taxpayer data, not the size of the firm. Small and seasonal practices are covered.
Only if the safeguards it describes are genuinely in place. A template is a starting structure; the plan has to reflect how your practice actually operates.
It depends on what your practice already has in place. A provider should scope the timeline only after reviewing your current setup — be wary of anyone who quotes a fixed timeline sight-unseen. Plan for it outside filing season.
Cost depends on the size of your practice and what you already have in place. Ask for a scoped quote after a provider reviews your setup, and be cautious of a flat price offered before anyone has looked.
Security work generally sits alongside your tax software rather than replacing it. When you evaluate a provider, confirm they have worked with your specific packages — Drake, Lacerte, UltraTax, ProSeries, QuickBooks and the like.
Current as of July 2026. This page describes rules that change. It is general information about IRS and FTC requirements — not legal, tax or compliance advice, and not a complete statement of everything that may apply to your practice.
Requirements are set by the IRS and the Federal Trade Commission, and their guidance is updated from time to time. Check IRS Publication 4557, ftc.gov, or your own advisor before relying on anything here. If you spot something out of date, tell us and we will fix it.