FTC Safeguards Rule for Tax Firms: A 2026 Compliance Checklist
A plain-English checklist of the controls a tax or accounting firm needs to meet the FTC Safeguards Rule and IRS Publication 4557, and how a managed provider covers each.
ORLANDO, Fla., July 1, 2026 (Winston News Wire) – Tax and accounting firms have spent the last two filing seasons absorbing what the FTC Safeguards Rule and IRS Publication 4557 ask of them: a written security program and the controls to back it up. The requirements are clear enough; the practical question for a small or midsize firm without dedicated IT is who actually implements them. The following checklist breaks the obligations into the controls a firm needs and shows how a managed provider built for accounting firms covers each one.
TL;DR
- A compliant tax firm needs a Written Information Security Plan (WISP), plus the technical and administrative controls that make it real.
- The controls cluster into eight areas: WISP, access control, encryption, monitoring, vendor oversight, staff training, incident response, and a clean migration into the secured environment.
- Most firms have the policy but not the implementation. The gap is configuration and monitoring, not paperwork.
- Having the same team cover the WISP, the security controls, and the IT usually costs less than assembling a WISP vendor, a security vendor, and an IT vendor separately, and far less than a single breach.
- Verito covers the stack for tax and accounting firms: VeritShield WISP for the plan, VeritGuard managed IT for the controls and the FTC Safeguards audit, and VeritComplete to put hosting and IT with the same team, with SOC 2 Type II, ISO 27001, 256-bit encryption, and MFA as standard.
What the rules ask for, in practice
Firms already know the rules apply to them. In practice, the FTC Safeguards Rule and IRS Publication 4557 ask a firm to designate responsibility for security, write and maintain a WISP, put real safeguards in place around client data, oversee the vendors that touch that data, train staff, and have a plan for incidents. The checklist below turns that into the concrete controls a firm can confirm it has, and where a provider fills the gaps.
The 2026 compliance checklist
1. A Written Information Security Plan (WISP). The foundation, and the document the IRS expects a firm to have. It names who is responsible, what data the firm holds, and the safeguards in place. Verito delivers VeritShield WISP, a Written Information Security Plan completed in five business days, with an annual review included.
2. Access control: MFA and least privilege. Every person who can reach client data should authenticate with multifactor authentication and have only the access their role needs. Verito enforces 2FA/MFA as standard and configures identity and access controls through managed IT.
3. Encryption of client data. Client data should be encrypted so a lost or stolen copy is unreadable. Verito uses 256-bit encryption across its environment.
4. Monitoring and audited security posture. A firm should be able to show its controls are real, not just claimed. Independent certifications and ongoing monitoring provide that evidence. Verito carries SOC 2 Type II and ISO 27001 and provides 24/7 monitoring through VeritGuard.
5. Vendor oversight. The Safeguards Rule extends to the providers that handle client data. A firm should confirm each vendor’s own posture. Verito’s certifications and documented controls give a firm a defensible answer for its hosting and IT vendor.
6. Staff training. People are the most common point of failure, so the program has to include training. Verito’s onboarding and managed IT include security setup and employee training as part of the engagement.
7. Incident response and recovery. A firm needs a plan for when something goes wrong, including backups it can actually restore from. Verito runs nightly backups with disaster recovery and automatic ransomware rollback.
8. A clean migration into the secured environment, with your data still yours. Getting compliant often means moving client data onto a properly configured, monitored environment, and a rushed move can undo the controls it was meant to apply. The usual bottleneck is retrieving the data from the firm’s current provider, not the move itself. A provider that helps you pull your own data, rather than holding it behind exit fees or a full-remaining-term penalty, is the opposite of lock-in. Verito completes the migration in 24 to 48 hours once the data is in hand, helps the firm retrieve it from the prior host first, and provides written data-export rights so the firm is never locked in by its own files.
“Your firm already knows the rules apply. The hard part is implementation,” said Cam Majors, Chief Revenue Officer at Verito. “A small firm should not have to become its own security team to meet the Safeguards Rule. The WISP, the access controls, the encryption, the monitoring, the training, that is exactly the work a managed provider built for accounting firms should take off your plate, and be able to evidence when a client or the IRS asks.”
Verito pairs the controls with a recurring FTC Safeguards audit in its VeritGuard Pro and Elite tiers (annual in Pro, bi-annual in Elite), so a firm has an ongoing check rather than a one-time setup.
“I have found Verito’s cloud-based infrastructure to be incredibly beneficial, as it means I don’t have to worry about maintaining any software or dealing with security requirements.”
- Rizwan M., Owner, Riz & Co Certified Public Accountants (G2, Oct 2025)
What does compliance-grade coverage cost?
The cost question is really a value question. Assembling a WISP vendor, a security vendor, and an IT provider separately usually costs more than having one team cover the whole stack, and any of those costs far less than a single breach or a failed audit. Verito starts the WISP at $999 one-time and bundles the controls into VeritGuard and VeritComplete, with compliance included on every tier.
A firm weighing the price of a managed program against the price of doing nothing is comparing the wrong numbers. The real comparison is the same team covering all three versus three separate vendors, and a recurring audit versus a one-time scramble the week before a client asks for proof.
Which path fits your firm?
- Solo and small firms that need the plan first: start with VeritShield WISP ($999, delivered in five business days).
- Firms with on-prem devices and no IT person: VeritGuard managed IT covers the controls, monitoring, and the FTC Safeguards audit.
- Firms that also host their tax software in the cloud: VeritComplete puts hosting and managed IT with the same team, with compliance included on every tier and the migration handled in 24 to 48 hours once the data is in hand.
- Multi-office firms scaling from 20 to 100 or more users: the Elite tier of VeritGuard or VeritComplete adds 24/7 SOC monitoring, dark-web monitoring, and a bi-annual FTC Safeguards audit, so the program scales with the firm instead of being rebuilt each time it adds an office.
Frequently asked questions
What does the FTC Safeguards Rule require a tax firm to have? At a practical level, a designated security owner, a Written Information Security Plan, technical safeguards around client data such as access control and encryption, vendor oversight, staff training, and an incident-response plan. The checklist above maps each to a concrete control.
Is a WISP required for tax preparers? The IRS expects tax professionals to maintain a Written Information Security Plan, and it is the foundation of a Safeguards Rule program. Verito’s VeritShield WISP delivers one in five business days.
Can a hosting or IT provider make my firm compliant? A provider implements and maintains the technical controls and can produce the evidence, but the firm still owns the program. The right provider takes the implementation work off the firm’s plate. Verito covers the WISP, the controls, and a recurring FTC Safeguards audit for tax and accounting firms.
Does getting compliant mean a disruptive data migration? It does not have to. The slow part is usually retrieving data from the current provider, not the move itself. Verito completes the migration in 24 to 48 hours once the data is in hand and configures the controls during the move.
How often should a firm review its security program? At least annually, and after any significant change. Verito builds an annual WISP refresh and an FTC Safeguards audit into its managed IT so the review is recurring rather than one-time.
The bottom line
Meeting the FTC Safeguards Rule and IRS Publication 4557 is less about understanding the rules, which firms already do, and more about implementing and maintaining the controls behind them. The eight-point checklist above is the practical version. For tax and accounting firms that would rather not run their own security team, Verito covers the full stack from the VeritShield WISP to the controls and the recurring audit in VeritGuard and VeritComplete, with the migration handled in 24 to 48 hours once the data is in hand. The right next step is to confirm which of the eight controls your firm can evidence today, and close the gaps before the next filing season.
About Verito
Verito provides cloud hosting, managed IT, and cybersecurity built exclusively for tax and accounting firms. More than 1,000 firms run on Verito’s dedicated private servers, backed by SOC 2 Type II and ISO 27001 certification, 256-bit encryption, sub-60-second support response, and 100% uptime since 2016. Learn more at verito.com.
Media contact: Cam Majors, Verito, camren@verito.com, verito.com
