IRS Cybersecurity Requirements for Houston CPAs: What You Need to Know in 2026

IRS cybersecurity requirements for Houston CPAs come from the FTC Safeguards Rule, which treats every tax preparer as a financial institution and requires a written security plan, multi-factor authentication, and encryption regardless of firm size. The IRS backs it up through your PTIN renewal, your EFIN, and Circular 230. Texas adds its own breach deadlines on top.

Ask 5 tax firms what the IRS requires and you’ll get 5 answers. Some say Publication 4557 is the law. It isn’t. It’s guidance. Others quote a $100,000 fine for a missing plan, and I couldn’t trace that number to the FTC rule or to any IRS publication. I looked. Our IT services for financial firms in Houston start from the actual text, because that’s what an investigator, an underwriter, or an IRS liaison reads after something goes wrong at a firm like yours.

The risk isn’t theoretical. Tax professionals reported nearly 300 data breaches in the first half of 2025, affecting as many as 250,000 clients, according to the IRS Security Summit’s August 2025 release, which is still the agency’s most recent public count. Over at the FTC, about 163 breach notices came in under the Safeguards Rule in 2025, per its August 2026 Federal Register notice. That was the first full year its reporting requirement was in force.

Houston carries a lot of that exposure. Harris County had 694 CPA offices employing 10,896 people in 2025, plus 535 tax preparation offices averaging fewer than 3 employees each, according to private-sector counts in the BLS Quarterly Census of Employment and Wages. A 3-person office can still hold thousands of Social Security numbers. Small offices, big files. And every one of them answers to the same federal rule, whether it has 2 people or 200.

No IRS security rule covers every preparer. That job belongs to the FTC Safeguards Rule, which requires a written information security plan, a Qualified Individual, MFA, encryption, and activity logging at every firm size. The IRS adds a PTIN acknowledgment, a next-business-day incident report and possible sanctions for e-file providers, and Circular 230 discipline in willful cases. Texas adds a 30-day attorney general notice at 250 Texans and a duty to tell affected clients in writing immediately.

What are the IRS cybersecurity requirements for CPAs in 2026?

IRS cybersecurity requirements are the data security duties every paid preparer carries because federal law treats tax preparation as a financial activity. The security program itself is set by the FTC, at 16 CFR Part 314. IRS Publications 4557 and 5708 restate it, PTIN renewal makes you acknowledge it, and the IRS adds its own incident rule for e-file providers.

Six different sources can ask a Houston firm about the same client data. Same data, different questions. Different penalties, too.

SourceWhat it requiresWho enforces itWhat a failure can cost
FTC Safeguards Rule, 16 CFR Part 314A written security program, a Qualified Individual, MFA, encryption, logging, vendor oversight, and an FTC notice at 500 consumersFederal Trade CommissionAn FTC investigation, as IRS Publication 4557 warns
Form W-12, line 11A yes-or-no acknowledgment, at every PTIN application or renewal, that a written security plan is required by lawIRS, through the PTIN systemA form signed under penalties of perjury, though line 11 confirms awareness of the duty, not your controls
Publications 1345 and 3112A security incident report by the next business day after confirmation, and e-file application updates within 30 daysIRS e-file programA written reprimand, a suspension of 1 or 2 years, or expulsion from IRS e-file
Circular 230, sections 10.35 and 10.36Competence, which OPR says has been read to include technology, and adequate procedures across the firmIRS Office of Professional ResponsibilityDiscipline in cases of willfulness
Internal Revenue Code sections 6713 and 7216No unauthorized disclosure or use of tax return informationIRS and federal courtsCivil penalties under 6713 and criminal penalties under 7216
Texas Business and Commerce Code 521.053 and TSBPA Rule 501.75Notice to affected Texans within 60 days, to the attorney general within 30 days at 250 Texans, and to affected clients in writing immediatelyTexas Attorney General and the Texas State Board of Public AccountancyCivil penalties of $2,000 to $50,000 per violation under Section 521.151, plus possible board action

Now look at the last column. The only IRS civil penalty in it, under section 6713, punishes unauthorized disclosure, not a missing plan. No IRS publication sets a fine for the plan itself, not Publication 4557, not Publication 5708, and not Publication 1345. That doesn’t make the IRS toothless. It’s a gatekeeper.

Does the IRS actually enforce the Safeguards Rule?

No. The FTC does.

IRS guidance says so itself. Publication 4557 (Rev. 6-2024) tells preparers that federal law gives the FTC authority to set data safeguard rules, and that failing to create a security plan “may result in an FTC investigation.” What the IRS controls is your ability to work. Four levers matter.

Your PTIN and line 11

Every paid preparer renews a PTIN each year, and the IRS counts more than 800,000 of them, per its 2026 renewal announcement. Line 11 of Form W-12 (Rev. October 2025) asks you to confirm, yes or no, that “paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information.” You sign the form under penalties of perjury. Read what you’re signing.

It’s an awareness statement. Not an audit. You aren’t certifying your controls. But I wouldn’t sign it with a plan that still lists a server you retired in 2022. Update it first.

Your EFIN

Firms that e-file individual returns hold an EFIN, and Publication 1345 (Rev. 12-2025) binds them to report security incidents “as soon as possible but not later than the next business day after confirmation of the incident.” Violating any provision of that handbook can bring sanctions. Publication 3112 scales those sanctions from a written reprimand up to expulsion, and it requires updates to your e-file application within 30 days of any change to principals, addresses, or phone numbers.

One honest note. No IRS publication I read lists a missing WISP as an e-file infraction. Incident reporting is the hard rule. That’s the trap. Miss it, and you’ve broken an e-file requirement during the worst week of your year.

Circular 230

OPR spelled this lever out this summer. On July 22, 2026, the IRS Office of Professional Responsibility published Issue 2026-22, “How to Be a Careful WISP(er)”, which ties data security to the competence rule in section 10.35 and to section 10.36, the rule that makes the people running a firm’s tax practice responsible for adequate procedures. OPR wrote that failing to keep a WISP could, “in circumstances of willfulness,” subject a practitioner to discipline under Circular 230. Note the qualifier.

That’s the lever that reaches your right to practice before the IRS. Not your e-file number. Your practice.

The disclosure penalties

If weak security leads to an unauthorized disclosure, Publication 1345 points to penalties under Internal Revenue Code sections 7216 and 6713. OPR’s newsletter describes 6713 as civil and 7216 as criminal. Neither one cares how nicely your plan was formatted.

What changed for tax preparers in 2026?

Less than vendor emails suggest. Not one word of the Safeguards Rule has changed since May 13, 2024, when the FTC’s breach notice requirement took effect. What changed is how hard the IRS is pushing, and how you sign in.

  • In Issue 2026-22, published July 22, 2026, the IRS ethics office linked the WISP to Circular 230 discipline.
  • PTIN sign-in moved to ID.me for preparers with a Social Security number in the 2026 season, and setting up an ID.me account requires multi-factor authentication before you can renew.
  • On September 4, 2026, IR-2026-106 said the MFA requirement “applies to tax preparation firms regardless of size,” including access to client data in tax software.
  • Summer series release IR-2026-92 repeated that preparers are legally required to keep a written, accessible plan.
  • August 25, 2026, brought an FTC request to extend the paperwork clearance behind its breach reporting form, which expires December 31, 2026. Housekeeping, not a new rule.
  • Texas’s cybersecurity safe harbor law, Senate Bill 2610, finished its first year on September 1, 2026.

And one claim I’d ignore. Some vendor blogs say the 2026 PTIN renewal added a certification of your security controls, and at least 1 says it covers the “nine elements” of the Safeguards Rule. Neither the current Form W-12, its instructions, nor the IRS renewal announcement says anything of the kind, and line 11 reads exactly as it did in the October 2024 revision. “Nine elements” is the FTC’s own shorthand for Section 314.4(a) through (i). It isn’t on the W-12.

As of October 6, 2026, the IRS hadn’t announced the 2027 renewal season. Last year’s announcement came October 27, and every PTIN expires December 31 of the year it’s issued for. Expect it in late October.

Tax preparer holding a smartphone showing a padlock sign-in prompt next to a laptop on an office desk

Does the Safeguards Rule apply to a small Houston tax practice?

Yes. Every part that matters.

Section 314.6 gives firms holding customer information on fewer than 5,000 consumers a break on exactly 4 provisions. Everything else applies to a solo preparer in Pasadena the same way it applies to a 60-person firm downtown. Publication 5708 says the same thing from the IRS side, calling tax and accounting professionals financial institutions “regardless of size.”

ObligationFewer than 5,000 consumers5,000 or more consumers
Written security program and a Qualified IndividualRequiredRequired
MFA for anyone accessing any information systemRequiredRequired
Encryption in transit and at restRequiredRequired
Logging of authorized users’ activityRequiredRequired
Written risk assessment with set criteriaWaived, though the program still has to rest on a risk assessmentRequired
Annual penetration test and vulnerability scans every 6 monthsWaivedRequired, unless you run effective continuous monitoring
Written incident response planWaived by the rule, recommended by the IRSRequired
Annual written report to the board or a senior officerWaivedRequired
FTC notice at 500 or more consumersRequiredRequired

Count carefully. Consumers are what the rule counts, not returns, and a joint return names 2 people. Past clients are included. The rule covers the information you maintain, so clients from past seasons still sitting in your tax software count until you dispose of their data. Section 314.4(c)(6) sets 2 years after last use as the outer limit for disposal, unless you still need the data for business or the law requires you to keep it. E-filers already live with one of those exceptions, since Publication 1345 says to keep Forms 8878 and 8879 for 3 years from the return due date or the IRS received date, whichever is later.

Small offices are common here. For them, the 314.6 relief is real money, and our breakdown of what cybersecurity costs in Houston shows why a 12-person tax practice may owe less than a generic quote assumes. We walked through every paragraph of Section 314.4 in our guide to cybersecurity requirements for Dallas financial firms. The rule reads the same in Harris County.

What has to happen after a breach, and how fast?

Six notices may be due. If you e-file, the IRS deadline is the tightest fixed clock you face. Only Texas’s immediate-notice rules, like the accountancy board’s, move faster.

For an e-file provider, the deadline is the next business day after you confirm the incident, and Publication 1345 counts any event that can lead to unauthorized disclosure, misuse, modification, or destruction of taxpayer information. Firms that only originate returns report through their IRS Stakeholder Liaison, who alerts IRS Criminal Investigation and can help block fraudulent returns filed in your clients’ names, per the IRS data theft page for tax professionals.

There’s no Houston liaison listed. On the IRS Stakeholder Liaison contacts page, Texas shares a single Area 4 mailbox with Arkansas, Florida, Georgia, Louisiana, Mississippi, South Carolina, Puerto Rico, and the US Virgin Islands. The phone number is the same for every region. Put that contact in your incident plan now.

Who you notifyDeadlineWhat triggers itWhere it goes
IRS, if you hold an EFINNext business day after you confirm the incidentAny event that can expose, misuse, alter, or destroy taxpayer informationYour IRS Stakeholder Liaison
Affected clients of a Texas CPA firmImmediately, in writingLoss of, or loss of control over, client records, including a cybersecurity breachWritten notice under TSBPA Rule 501.75(d)
State tax agenciesAs soon as you canStolen data on clients who file in states with an income taxThe Federation of Tax Administrators data breach page
Federal Trade CommissionNo later than 30 days after discoveryUnencrypted information on 500 or more consumers acquired without authorizationThe FTC’s online Safeguards Rule form
Texas Attorney GeneralNo later than 30 days after you determine a breach occurredSensitive personal information of 250 or more TexansThe attorney general’s online form
Affected individualsNo later than 60 days after you determine a breach occurredSensitive personal information acquired by an unauthorized personWritten or electronic notice under Section 521.053

One local quirk. Texas isn’t on the Federation of Tax Administrators’ state contact list, and with no state income tax, a Texas-only practice may have no state revenue agency to call at all after a breach. Clients who moved here from California, or who own rental property in Louisiana, are a different story.

Encryption changes the FTC math. Only unencrypted data counts toward the 500-consumer trigger, and the rule treats data as unencrypted if someone accessed the key too. A stolen laptop with BitLocker on and the recovery key safe in your tenant is a bad day. Without encryption, the same laptop holding data on 500 consumers is an FTC filing. Turn BitLocker on.

On the client side, the IRS’s 2026 summer series tells preparers to recommend an Identity Protection PIN to affected clients. You can’t request one on a client’s behalf. Clients should file Form 14039 only after an IRS notice or a duplicate-filing reject, per the IRS data theft page. Our ransomware recovery guide for Texas businesses covers the first 72 hours from the technical side.

What does Texas law add for a Houston CPA firm?

Two duties and a carve-out.

Texas’s general security duty, Section 521.052, requires “reasonable procedures” to protect sensitive personal information. But subsection (c) says the section “does not apply to a financial institution as defined by 15 U.S.C. Section 6809,” and federal law counts tax preparation as a financial activity. So for a firm that prepares returns, the security standard isn’t Texas’s general one. It’s the FTC’s specific one. That’s our reading as an IT provider, not legal advice, and an audit-only firm may land somewhere else.

That’s where it stops. Section 521.053, the breach notice law, has no financial institution exception, as the statute text shows. A TSBPA rule on confidential client communications goes further. It requires “all reasonable measures” to keep client records confidential, and it requires a firm to notify affected clients in writing immediately once it learns it has lost control of their records, including through a cybersecurity breach. Firms must also keep a backup system so they can tell who was affected.

Then there’s Senate Bill 2610, in effect since September 1, 2025. It’s optional. A business with fewer than 250 employees that keeps a program built on a recognized framework, and scaled to its size tier, can’t be made to pay exemplary damages after a breach. Under 20 employees, the minimum includes password policies and employee training, and from 20 to 99 it includes CIS Controls Implementation Group 1. Chapter 542 doesn’t define “employee,” though. Ask your attorney how tax-season hires count.

What the attorney general’s breach list shows

We pulled the Texas attorney general’s data breach report list on October 6, 2026. It held 652 notices, nearly all posted in the prior 12 months. Reading every filer name, we counted 22 from accounting, tax preparation, bookkeeping, or payroll firms.

MeasureAccounting, tax, and payroll filersAll 652 filers
Median Texans affected per notice7131,668
Notices that included Social Security numbers86%83%
Notices that included financial account or card numbers64%47%
Notices that included driver’s license numbers45%52%
Median days from breach start to the reported discovery date10872

Look closer. Twelve of the 22 filed from outside Texas, and 1 Colorado payroll company alone accounted for 55% of the group’s Texans. Distance doesn’t exempt anyone. Five filers were in the Houston area, in Houston, Spring, and Conroe. Across all 22, 4 reported fewer than 250 Texans and filed anyway, including 1 firm in Spring. And there’s no category for tax information on the attorney general’s form, so the list can’t tell you how many returns were exposed.

The 108-day figure is the one I’d show a managing partner. It’s self-reported, only 14 of the 22 gave a start date, and some firms enter the day they finished reviewing files as the discovery date, so treat it as a signal rather than a benchmark. Still, if your own logs couldn’t reveal an intruder within 3 months, that’s a logging problem. Logging is one of the controls Section 314.6 never waives.

What evidence should a Houston CPA firm be able to show?

A plan is a document. Evidence proves it’s true.

The gap I worry about isn’t a missing plan. It’s a plan describing controls nobody can prove. In one Safeguards Rule engagement we wrote up as an FTC Safeguards Rule remediation case study, controls existed in practice but couldn’t be evidenced on demand. That’s fixable. It’s also the first question every reviewer asks.

Who asksWhat they want to seeThe artifact that answers it
An FTC investigatorA written program that matches your real systemsA dated WISP naming your Qualified Individual, plus the risk assessment it rests on
An IRS e-file monitoring visitOffice and security procedures, which Publication 3112 says reviewers may observeLocked file storage, screen locks, a current e-file application, and weekly EFIN usage checks
Your cyber insurance carrierProof MFA was on for every account on the day of the incidentSign-in logs or a Conditional Access report covering every user, including admins and shared logins
The Texas Attorney GeneralWhen you knew, what was exposed, and how many TexansAn incident log with the discovery date, data types, and a client count you can pull in a day
Your own partners, under Circular 230 section 10.36Procedures that cover every employee and contractorTraining records and signed acceptable use policies for seasonal staff, not just partners

Start with MFA. Screenshots aren’t proof. An export of sign-in logs that shows every account, including the front desk login nobody mentions, is. Our list of Microsoft 365 security settings Texas SMBs miss covers the Conditional Access and audit log settings behind those reports.

Accounting firm managing partner reviewing a printed security plan binder with an IT consultant at a conference table

How should a Houston firm get ready before the 2027 filing season?

Start now. Mid-October through December is the last quiet stretch before filing season, and PTIN renewal lands right in the middle of it.

  1. Name your Qualified Individual in writing. If it’s your IT provider, Section 314.4(a) still makes you name a senior person who oversees them.
  2. Turn on MFA for email, tax software, remote access, the client portal, and every admin account.
  3. Encrypt laptops, servers, and backups, and move client file exchange to an encrypted portal.
  4. Inventory where client data lives, then dispose of what you no longer need, keeping Forms 8879 for the 3 years Publication 1345 requires.
  5. Rewrite your WISP from the Publication 5708 template, and put a date on it.
  6. Check your e-file application, since changes to principals, addresses, or phone numbers are due within 30 days.
  7. Check EFIN and PTIN return totals weekly once filing season opens, as Publication 4557 recommends.
  8. Add the IRS Stakeholder Liaison, the FTA page, the FTC form, and the Texas attorney general form to your incident plan.
  9. Run a restore test and a phishing drill before January, using a fake “new client” email, since the IRS flagged those schemes in its 2026 summer series.
IT technician checking a network switch, firewall, and backup device in a small office network closet

We’ve done this before. One Texas CPA firm with about 20 employees passed a third-party compliance audit with zero issues after we added AES-256 encryption, monthly backup tests, quarterly security training, and simulated phishing campaigns. Devices patched within 24 hours went from 30% to 95%. Support tickets fell 40% in the first 90 days.

On cost, our Security Focus plan starts at $40 per user a month for firms that already have IT support. A program scoped to the Safeguards Rule, with scheduled risk analysis, evidence retention, and audit support, typically runs $175 to $250 per user a month in Houston, the band our Houston cost breakdown gives tax and mortgage offices under the FTC rule. Our cybersecurity services cover MFA, encryption, monitoring, and incident response, and our IT program for CPA and accounting firms ties them back to your WISP.

Fair warning. We sell this. If your firm already has an IT lead who owns MFA, encryption, and logging, you probably don’t need a managed service. You need someone to read your plan against the rule once a year and tell you where it’s thin.

Questions Houston tax pros ask about IRS security rules

Is a WISP an IRS requirement or an FTC requirement?

It’s an FTC requirement. The IRS backs it up. The Safeguards Rule requires a written security program, and the IRS asks every preparer to acknowledge that duty on line 11 of Form W-12 at PTIN renewal. Publications 4557 and 5708 explain what the plan should cover, and Publication 5708 includes a template.

Can the IRS fine my firm for not having a WISP?

Not directly. No IRS publication sets a fine for a missing plan. The IRS can still sanction your e-file participation for e-file violations such as a missed incident report, pursue penalties under sections 6713 and 7216 when client data is disclosed without authorization, and, in willful cases, seek Circular 230 discipline against the practitioner responsible. Enforcement of the rule itself sits with the FTC, and the Texas attorney general enforces the state’s breach notice law.

How fast do I have to report a breach to the IRS?

By the next business day after you confirm it, if you’re an Authorized IRS e-file Provider. Publication 1345 says so. Firms that only originate returns report through their Stakeholder Liaison, and the IRS asks every tax professional to report data theft right away so it can watch for fraudulent returns in clients’ names.

Is there an IRS Stakeholder Liaison in Houston?

None is listed by name. The IRS contact page puts Texas in a regional Area 4 group with 1 shared mailbox and phone line, so save it in your incident plan before you need it.

Do small tax offices need annual penetration testing?

Usually not. Section 314.6 waives the annual penetration test and the 6-month vulnerability scans for firms holding data on fewer than 5,000 consumers, and larger firms can skip them if they run effective continuous monitoring. Scans are still worth running before filing season, because that’s how you find an exposed remote desktop port before someone else does.

Does MFA really apply to a 2-person practice?

Yes. The IRS said in September 2026 that the MFA requirement applies to tax preparation firms regardless of size, and that includes signing in to tax software. Section 314.4(c)(5) allows an exception only when your Qualified Individual approves an equivalent or stronger control in writing.

Can our IT provider be the Qualified Individual?

Legally, yes. Section 314.4(a) lets an outside provider hold the role. Your firm keeps responsibility for compliance, though, and you have to name a senior person to direct and oversee the provider. Put the role, and the written reporting the provider owes you, in the contract.

Did PTIN renewal add a new security certification for 2026?

The IRS’s 2026 renewal announcement listed only 1 new item, ID.me sign-in for preparers with a Social Security number. Line 11 on Form W-12, the written security plan acknowledgment, has read the same since the October 2024 revision, and the current form doesn’t mention the FTC’s “nine elements” at all.

Want to know which of these your firm could prove today? We’ll check your MFA, encryption, logging, and WISP against the Safeguards Rule and the IRS reporting rules, then hand you a ranked gap list your partners can work through before filing season starts.

Get an Assessment

About Author

Learn More