top of page

Navigating New FTC Safeguard Rules and IRS Mandates for Financial Professionals What You Need to Know

  • Jul 14
  • 4 min read

The landscape for tax professionals, CPAs, accountants, and bookkeepers is changing fast. The Federal Trade Commission (FTC) Safeguard Rules and the IRS’s new mandates under the ETAAX Act are introducing stricter requirements for those holding Preparer Tax Identification Numbers (PTIN) and Electronic Filing Identification Numbers (EFIN). These changes, set to take effect by December 31, 2026, will reshape how financial professionals manage cybersecurity, risk, and compliance.


If you run a small practice or are a solopreneur in the financial services space, this shift means more than just updating a document. It demands real accountability, governance, and ongoing risk management. This post breaks down what you need to know, what to expect, and how to prepare to avoid costly violations.



What the New IRS and FTC Requirements Mean for Financial Professionals


The IRS, through the ETAAX Act, is tightening the recertification process for PTIN and EFIN holders. The goal is to harden security and ensure tax professionals are better equipped to protect sensitive client data. The FTC Safeguard Rules complement this by requiring firms to implement comprehensive information security programs.


Key new requirements include:


  • Enhanced identity verification during recertification to prevent fraud.

  • Mandatory cybersecurity training for all PTIN and EFIN holders.

  • Regular risk assessments to identify and address vulnerabilities.

  • Stronger vendor risk management to ensure third-party providers meet security standards.

  • Proof of a documented and actively maintained Written Information Security Program (WISP).

  • Ongoing monitoring and incident response plans to quickly detect and respond to breaches.


These requirements apply not only to large firms but also to small businesses and individual practitioners who handle tax filings or financial data.



What CPAs, Accountants, Tax Professionals, and Bookkeepers Can Expect


For many professionals, these changes will feel like a significant increase in compliance burden. The IRS and FTC expect more than just paperwork; they want evidence of active governance and security practices.


You can expect:


  • More frequent audits and reviews of your security programs.

  • Higher standards for data protection including encryption and access controls.

  • Increased accountability for any data breaches or lapses.

  • A need to demonstrate ongoing training and risk management efforts.

  • Pressure to vet and monitor vendors who handle client data or software.


Small firms and solo practitioners will face particular challenges. Many currently rely on generic WISP templates downloaded online, which often fail to meet these new standards. The IRS and FTC will expect tailored, actionable plans that reflect your actual business risks.



Eye-level view of a tax professional reviewing cybersecurity compliance documents
Tax professional reviewing cybersecurity compliance documents


The Impact on Small Business Owners and Solopreneurs


Small practices often juggle multiple roles and may lack dedicated compliance staff. The new mandates will require them to:


  • Develop and maintain a customized Written Information Security Program (WISP) that goes beyond a simple document.

  • Implement risk management processes that include vendor risk assessments and ongoing monitoring.

  • Train themselves and any staff regularly on cybersecurity best practices.

  • Prepare for potential penalties if they fail to meet the new standards.


Without proper guidance, many small business owners will struggle to keep up. Downloading free or generic WISP templates will no longer be enough. The IRS and FTC expect proof of active governance, which means documented policies must be backed by real actions and controls.



Six Main Steps to Avoid Violations and Stay Compliant


To prepare for the December 31, 2026 deadline, financial professionals should take these six steps:


  1. Conduct a thorough risk assessment

    Identify all areas where client data could be exposed, including software, hardware, and third-party vendors.


  1. Develop a tailored Written Information Security Program (WISP)

    Create a living document that reflects your specific risks and includes policies for data protection, access control, and incident response.


  2. Implement vendor risk management

    Review contracts and security practices of all vendors who handle sensitive data. Require them to meet your security standards.


  1. Provide regular cybersecurity training

    Ensure everyone involved in your practice understands their role in protecting data and knows how to spot threats.


  2. Set up monitoring and incident response plans

    Establish procedures to detect breaches quickly and respond effectively to minimize damage.


  1. Document and review all compliance activities

    Keep records of training, risk assessments, vendor reviews, and incident responses to demonstrate ongoing governance.



Why Governance Matters More Than Ever


Governance means more than having a policy document on file. It means active management, accountability, and continuous improvement of your security posture. The FTC and IRS want to see that you are not just compliant on paper but are actively protecting client data every day.


This shift reflects the growing threat of cyberattacks targeting financial professionals. Governance ensures you have the right controls, training, and oversight to reduce risks and respond quickly when issues arise.



How Cardinalsbyte.com Helps You Get Compliant


Many small firms face the pain of trying to do this themselves. Downloading free WISP templates or generic policies often leads to gaps and vulnerabilities. Cardinalsbyte.com offers tailored compliance solutions designed specifically for tax professionals, CPAs, and small financial practices.


They help you:


  • Build a custom WISP that fits your business.

  • Implement vendor risk management and ongoing monitoring.

  • Provide training and support to keep your team informed.

  • Maintain documentation to prove compliance during audits.

  • Navigate the complex requirements of the FTC Safeguard Rules and IRS mandates with confidence.


This support reduces the risk of violations and frees you to focus on serving your clients.



Three Key Takeaways


  • The IRS and FTC are raising the bar for cybersecurity and compliance for PTIN and EFIN holders by the end of 2026.

  • Small practices must move beyond generic documents to active governance, risk management, and vendor oversight.

  • Partnering with experts like Cardinalsbyte.com can simplify compliance and protect your business from costly penalties.



Meeting these new requirements will be challenging, but with the right approach, financial professionals can turn compliance into a competitive advantage. Start early, build strong governance, and protect your clients’ data with real, ongoing security practices.


 
 
 

Comments


bottom of page