The CPA & Tax Pro’s FTC Safeguards Cheat Sheet.
Everything a small accounting, tax, or bookkeeping firm must do to protect client financial data — and what it costs if you don’t — on one page. You got licensed to do tax and accounting work, not to read federal cybersecurity rules. Here’s the whole picture in plain English, so you know the right questions to ask before the FTC, the IRS, or a breach decides it for you.
One short form. Instant download. We never ask for client or taxpayer information.
Your cheat sheet is ready.
Download it now — we’ve also emailed you a copy so it’s easy to find later.
⬇ Download the FTC Safeguards Cheat Sheet Book your free security review →
Not sure where your practice stands? The review is a free HIPAA technical security review — a plain-English findings list, no obligation.
One page. The whole picture.
The mandate — why a tax firm is a “financial institution”
The FTC Safeguards Rule (16 CFR 314, under GLBA), the IRS WISP requirement tied to your EFIN, and California Board of Accountancy exposure. A single breach is a three-front problem.
The must-do list
A Written Information Security Plan (WISP) — required by both the FTC and IRS — a named Qualified Individual, a risk assessment, MFA and encryption, vendor oversight, and the monitoring the Rule requires. In order.
The 5,000-consumer trap & the 2026 penalties
Why “consumers” counts cumulatively across years of returns (spouses + dependents), how a small office crosses 5,000 quietly into the heavier rules, the FTC’s $53,088-per-violation maximum, and the EFIN-revocation risk. Real numbers, with the as-of date.
The “my IT guy handles this” myth
The questions to ask: “Do we have a current WISP, who’s our named Qualified Individual, and is client data encrypted on every laptop and backup?” Your PTIN renewal makes you attest you have a WISP — no document means you don’t have it.
General information only — not legal, tax, or compliance advice. The free review is a technical assessment of your IT environment, not a determination of your FTC Safeguards or IRS compliance.
Written for accounting firms — by people who speak your tax software.
Down the road — and around through tax season.
- Based in Menifee — Craig answers the phone himself.
- Remote-first — on-site across Menifee, Sun City, Murrieta, Temecula, Wildomar, Lake Elsinore when you need it.
- Member, Menifee Valley Chamber of Commerce.
- We build and maintain the WISP and own your technical safeguards.