Accounting firms count as financial institutions under federal law, so the FTC Safeguards Rule requires multi-factor authentication, encryption, access controls, and secure disposal on every system holding client data. Firm size does not change that.
Most of the accounting firm owners I talk to in Rockland, Westchester, and Bergen believe cybersecurity rules are something that happens to banks. Their firm has nine people. Two of them are seasonal. The idea that federal regulators wrote a rule with them in mind sounds like something an IT company made up to sell a product.
I understand the reaction. I would be skeptical too. But the rule text names your line of work specifically, and it has been enforceable since June 2023.
It is not a proposal.
What follows is what the rule actually says, what a small firm is genuinely exempt from, and what it is not exempt from no matter how few people work there. If you want the broader picture of how we support this vertical, that lives on our IT services for accounting and CPA firms page. This piece is narrower. It is about the security controls themselves, and it sits under our cybersecurity services practice.

You Are Already a Financial Institution
Not by opinion. By definition.
The Gramm-Leach-Bliley Act tells the FTC to set data security standards for financial institutions, and the resulting Safeguards Rule at 16 CFR Part 314 defines that term far more broadly than ordinary conversation does. Section 314.2(h) lists thirteen examples of covered businesses, and tax preparation firms appear on that list alongside mortgage brokers and collection agencies.
The IRS says the same thing in plainer language. In IR-2026-92, issued August 18, 2026, the Security Summit restated that tax and accounting professionals are considered financial institutions and must implement a data security plan. That release also points firms to Publication 5708, a 28-page template built specifically for smaller practices that need a written plan and do not have a compliance department to write one.
There is no threshold to cross. A sole practitioner with a PTIN and a laptop is covered on exactly the same terms as a forty-person firm with three offices, because coverage under this rule turns on the activity you perform rather than the size of the operation you perform it in. What changes with size is a short list of paperwork obligations, and I will get to exactly which ones in a moment, because that is where nearly every firm I speak with has been given bad information.
The Nine Things the Rule Names
Section 314.4 lists nine elements your information security program has to include. Nine is not many. Reading the regulation cold is rough going, so here is the translation for a firm with a dozen people and a server in the back room.
| What 314.4 requires | What it looks like in a small firm |
|---|---|
| (a) Designate a Qualified Individual | One named person owns security. Can be a partner, can be your IT provider, but a partner still supervises them. |
| (b) Risk assessment | Know what client data you hold and where. Under 5,000 consumers, it does not have to be written. |
| (c) Design and implement safeguards | The technical core. Access controls, data inventory, encryption, app review, MFA, disposal, change management, logging. |
| (d) Test your safeguards | Continuous monitoring, or annual penetration testing plus vulnerability scans every six months. |
| (e) Train your staff | Security awareness training with refreshers. Seasonal preparers count as staff. |
| (f) Oversee your service providers | Your contracts have to spell out security expectations, and you have to reassess the vendor periodically. |
| (g) Keep the program current | Revisit it when the firm changes. New office, new software, new partner, new review. |
| (h) Written incident response plan | Who decides, who calls whom, in what order. Under 5,000 consumers, not required in writing. |
| (i) Annual written report to leadership | The Qualified Individual reports to the partners at least once a year. Under 5,000 consumers, not required. |
Nothing in that list is exotic. Most of it is what a competently run firm is doing anyway, just without anybody writing down that they are doing it.
The Exemption Everybody Reads Wrong
Here is the sentence that causes the most confusion in this entire area of law. Section 314.6 reads, in full: “Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.”
That is the whole exemption. Four sub-paragraphs. Read it again if you have been told your firm is too small to worry about this, because what it takes off the table is the written risk assessment, the penetration testing and scanning schedule, the written incident response plan, and the annual report to the partners.
Everything else stays.
Multi-factor authentication stays. Encryption of client data at rest and in transit stays. Access controls stay. The data inventory stays, the disposal requirement stays, the change management requirement stays, the activity logging stays, staff training stays, and vendor oversight stays. All of it. The rule does not create a small firm tier where those become optional. It creates a small firm tier where four documents become optional.
I have watched that distinction get flattened in conversation more times than I can count. Somebody hears “under 5,000 is exempt” and stops listening. The exemption is real, it is just far narrower than the shorthand suggests.
One more thing on the counting. The threshold is written in consumers rather than clients, and what it measures is the customer information you currently maintain rather than the number of returns you happened to file this past season, which are very different numbers for a firm that has been in business a while. Two decades of prior-year records add up quickly. Count what is actually on your systems before you conclude you are under the line.

What This Looks Like on the Software You Actually Run
Regulations are abstract. Your Tuesday is not.
The single biggest gap I find in accounting firms is email. Almost every firm in this area runs Microsoft 365, and 365 will happily let a preparer sign in with a password alone unless somebody turns that off. Client data moves through that mailbox constantly during filing season. Turning on multi-factor authentication across every account, including the ones for people who only work January through April, closes the most likely path into your client files. It also happens to be the thing 314.4(c)(5) requires by name. Turn it on.
Encryption at rest is the second gap, and it is usually a laptop problem rather than a server problem. Whole-disk encryption is built into the Windows and macOS machines your firm already owns. It is off by default on plenty of them. Check yours. A preparer’s laptop with three years of returns cached locally and no disk encryption is the scenario the rule was written about.
Then there is the access control question, which is really an offboarding question. Whoever left the firm in May should not still have a login in September. Same for the bookkeeper who moved to a different client set and no longer needs the whole document library. Periodic review is written into the rule, and it is the requirement that decays fastest without someone owning it, because nothing visibly breaks when you skip it and nobody sends you a reminder.
On passwords, BitWarden is our recommended system. Shared credentials taped inside a desk drawer are still out there, and I do not say that to be unkind. It is just what happens when nobody was ever given a better option.
Your tax software matters here too. Drake, Lacerte, UltraTax, ProSeries, and the document portals that hang off them all handle client data, and 314.4(c)(4) expects you to have evaluated the security of the applications you use. That does not mean auditing a vendor’s source code. It means knowing whether the portal your clients upload their W-2s into supports multi-factor authentication, whether anyone at your firm has actually switched it on, and who at the vendor you would call if a client told you their documents had shown up somewhere unexpected.
Two States, Two Different Phone Calls
Plenty of firms here have clients on both sides of the Hudson, and the two states do not handle a breach the same way. Order matters.
New York’s SHIELD Act requires any business holding private information about New York residents to maintain reasonable administrative, technical, and physical safeguards. It also expanded what counts as a breach to include unauthorized access, not only acquisition, which is a lower bar than most people assume. Notice runs through the Attorney General’s data breach reporting portal, which forwards to the Department of State and the State Police automatically.
New Jersey inverts the order. Under N.J.S.A. 56:8-163, a business has to report the breach to the Division of State Police in advance of notifying the affected customers, and the state says so directly. Get that sequence backwards and you have a compliance problem layered on top of the breach you already have. Backwards is its own violation.
Layer the federal duty on top of both. Under 314.4(j), a security event involving at least 500 consumers goes to the FTC within 30 days of discovery, and that clock started in May 2024.
Where I Would Start
If you are reading this and recognizing gaps, the order matters more than the completeness. Working through it in this sequence gets you the most protection soonest.
- MFA on every Microsoft 365 account. Highest impact, lowest cost, usually done in an afternoon.
- Turn on whole-disk encryption everywhere, and confirm it, because assuming it is on is how firms find out it was not.
- Pull a list of every active login and delete the ones belonging to people who no longer work there.
- Write the WISP. Publication 5708 is a template. You are filling in blanks, not drafting from scratch, and it does double duty for the IRS and the FTC.
- Read your IT contract and find the clause about security responsibilities. If there isn’t one, that is a finding.
- Book the assessment. Ours is free, and you keep the findings whether or not you hire us.
Number four is the one firms skip, and it is the one both regulators ask about first. Do it anyway.
Worth saying plainly: none of this requires a security budget that competes with your payroll. Our managed IT starts at $995 a month for firms in the 5 to 60 employee range, and a meaningful share of what the Safeguards Rule asks for turns out to be configuration work on software your firm is already licensed for, done once and then left alone. If you want the tax-season operational side rather than the regulatory side, we wrote that up separately in what accounting firms should sort out before January.
What Firm Owners Actually Ask Me
Is there a firm size where this stops applying?
Who is on the hook when the data lives in someone else’s cloud?
How is a WISP different from what the FTC wants?
What actually happens if we do nothing?
What breaks when you switch MFA on?
How long does this take, start to finish?
A free assessment maps your firm against the Safeguards Rule element by element and tells you what is already covered. No obligation, and you keep the findings.
