Support Center | ☎︎ Call us: (845) 440-5000 | info@vjnetworks.com
Back to Blog

What Bergen County CPA Firms Need From Their IT Provider

Choosing an IT ProviderLocal IT Services
Last updated: September 3, 2026

A Bergen accounting firm needs an IT provider it can hold to the FTC Safeguards Rule in writing, because the rule makes overseeing that provider the firm’s own legal duty, not the provider’s.

Most conversations about accounting firms and IT start in the wrong place. Owners ask whether a provider “does security.” Wrong question. It’s also the reason a lot of firms get an unpleasant surprise two years in.

Almost nobody explains this part while you’re shopping. Under the FTC’s Safeguards Rule the obligation sits with your firm, not with your IT company, and what the rule actually asks is that you pick service providers capable of protecting client information, write what they owe you into the contract, and check on them periodically rather than once at signing. Three duties. All yours. So the provider isn’t a way to hand the problem off, the provider is one of the things the rule expects you to manage, and missing that distinction is how a firm ends up buying perfectly competent IT support while still being out of compliance on paper.

My team runs this for firms across Bergen County, from solo practices up to twenty-person offices, and the questions that separate a real provider from a plausible one turn out to be narrower than most owners expect. Six or seven of them. That’s it.

CPA firm owner and IT provider seated across a table discussing security requirements for client financial data

Your Provider Sits Inside the Rule, Not Outside It

The language lives in 16 CFR 314.4(f). A covered firm has to take reasonable steps to select providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess the provider based on the risk they present. Three separate verbs. Select, require, assess.

Read it again and notice what it doesn’t say. It never says your IT company inherits your compliance. The FTC’s own plain-language guidance on the rule keeps the duty on the covered business the whole way through.

In practice that’s unglamorous work. You need a contract that names the controls, and you need something on file showing you checked whether they’re actually running, which is a filing-cabinet problem rather than a firewall problem and therefore the one that gets skipped in almost every small firm I walk into. A provider who can’t help you produce that paperwork is making your life harder even when their technical work is genuinely good.

Most firms aren’t doing this. Not close. It’s the single biggest gap I find, and it’s administrative, not technical.

If you want the rule itself walked through element by element, we did that for advisory firms in the Safeguards Rule checklist, and the mechanics carry over to a tax practice almost unchanged.

Two States, Two Notification Clocks

This one is specific to where you sit. It catches Bergen firms more than anybody.

New Jersey’s breach-notification statute doesn’t work the way people assume, because there’s no numeric deadline written into it at all, and the requirement that does sit in there is unusual enough to matter, the State Police get notified before your clients do, through New Jersey’s breach reporting process. Firms tend to learn that ordering at the worst possible moment.

Then add the part that’s easy to miss. Plenty of Bergen practices carry clients who live in New York, across the bridge or up in Rockland, and New York’s SHIELD Act attaches to the residency of the person whose data you hold rather than to the address on your office door, which means one incident and one client list can put you inside two different rulebooks on the same afternoon. Two clocks. Different shapes. We covered what New York actually asks of a small business in the SHIELD Act breakdown.

Ask a prospective provider which of those two they’ve actually worked through with a client. The answer arrives fast, one way or the other.

Who Makes the Call When Something Happens

Your IT provider will almost certainly be the one who finds it. An odd login from a state nobody visited, a mailbox rule nobody created, a backup job that quietly started failing on a Thursday. Detection is their job.

Notification isn’t. That duty is yours and it stays yours, so the handoff between “we found something” and “you now have a legal clock running” needs to exist on paper before the day you need it, because a Tuesday in April is a terrible time to be inventing a process from scratch while clients are calling.

Three things belong in writing. Who calls whom, how fast, and what the provider hands you to work from. Nothing exotic. Most contracts just don’t say.

What proof looks like when somebody eventually asks for it is a longer subject, and we went through it in the audit-readiness piece on proof versus promises.

IT engineer pausing with a coffee mug in an office hallway, considering an escalation call to a client firm

The Turnover Problem Nobody Documents

Accounting practices staff up for filing season. Seasonal preparers, a part-timer who comes back every year, sometimes a contractor for six weeks in March. Every one of those people gets access to client financial data, and access is far easier to grant than to remember to remove.

The rule expects access to be limited to the people who need it and pulled when they don’t, which is a plain enough requirement on its own, and also the exact requirement that seasonal hiring quietly breaks in accounting offices every single spring. April ends. The logins don’t.

So ask a provider whether offboarding is a documented step they own with a record attached, or an email somebody remembers to send. Ask how they’d handle six seasonal accounts ending in the same week. A firm that has done it before answers immediately, without hedging, and usually tells you exactly what the record looks like.

What Belongs in the Contract

Short section. The table does the work. These are the requirements worth naming explicitly, the question that tests each one, and what it sounds like when somebody is talking around it.

What to RequireWhat to AskWhat a Vague Answer Sounds Like
Named safeguards in the contract, not the proposalWhich specific controls does our agreement obligate you to maintain?“Security is included in all our plans.”
MFA enforced on everything reaching client dataIs it required for every account, or available to anyone who turns it on?“MFA is fully supported in your environment.”
A restore that has actually been testedWhen did you last restore our data, and what did you send us afterward?“Backups run nightly and we monitor them.”
A written incident handoffIf you find something at 6pm on April 12th, who do you call and how fast?“We’d let you know right away.”
Documented offboarding with a recordShow me how the last account removal was logged.“Just send us a ticket when someone leaves.”
Change windows that respect a filing seasonWhat would you refuse to do to our systems in March?“We schedule maintenance after hours.”
Evidence you can hand a reviewerWhat do you give me when an insurer or a reviewer asks for proof?“We can put something together if that comes up.”

The MFA row deserves a footnote, because the enforced-versus-available gap is where plenty of firms believe they’re covered and aren’t. We pulled that apart in the piece on what “enforced” actually means.

What a Straight Answer Sounds Like

You don’t need to be technical to run this. You need to hear the difference between a specific answer and a comfortable one.

A specific answer has a noun in it. A date, a document, a name, a number. “We tested your restore on June 14th and sent your office manager the log” is specific. “Backups are monitored” is comfortable. Both sentences can come from an honest provider, and only one of them is any use to you on the afternoon somebody asks for proof.

Vagueness under direct questioning is information. It usually isn’t dishonesty either, it usually means nobody has built the thing yet, which is a perfectly fine answer to hear across a table in November and an expensive one to discover for yourself in the second week of April.

One more, and it’s the part I’d want to know sitting on your side of the table. Ask what they won’t do. A provider willing to tell you plainly that they don’t write your security plan and don’t sign compliance attestations for you is describing a real boundary honestly, and we don’t do either of those, because neither one is ours to give. What we do is build the controls, keep them documented, and make sure the written version matches what’s actually running.

Firms heading into filing season who want the operational readiness list instead of the provider-vetting one should start with the pre-January checklist. The wider picture of how we support accounting and CPA practices covers the software side, from the tax packages you run through Microsoft 365 and the help desk behind it. Bergen firms closer to Route 208 can also see how this looks locally in Fair Lawn.

What Firm Owners Ask Me About This

Our IT company says they handle our compliance. Is that a real thing?
Partly, and the distinction matters legally. A provider can build and run the controls the rule expects, and a good one will. What they can’t do is absorb your obligation, because 16 CFR 314.4(f) puts selecting, contracting with, and assessing that provider on your firm. If a salesperson tells you compliance is fully handled, ask them to point at the clause that says so.
We’re four people and one admin. Does any of this scale down?
Some of it does. Hold information on fewer than 5,000 consumers and the rule drops a few of the documentation requirements. The technical obligations don’t move at all, and vendor oversight is one of the ones that stays put. Small firms tend to read that exemption as much broader than it is.
Realistically, how much of this can I check myself before signing anything?
Most of it, in about twenty minutes of pointed questions. You’re not auditing anyone’s network. You’re finding out whether the answers contain specifics and whether the contract says what the sales call said, and that gap is the entire test. No technical background required.
What if we already signed and none of this is in there?
Ask for an addendum. Genuinely, that’s the whole move. Most providers will add a service-provider security schedule when a client asks, because it costs them nothing if they’re already doing the work. The ones who resist are telling you something useful about whether they are.
Does being in Bergen actually change the answer versus a firm in New York?
On the federal side, no. The Safeguards Rule and the IRS expectations are identical wherever the office sits. Notification is where it changes, because a New Jersey practice reports through the State Police and may also owe a New York obligation for New York clients. Same controls, more than one rulebook to answer to.
Our tax software vendor hosts everything. Doesn’t that make it their problem?
It makes them one more service provider you’re expected to oversee, which is the opposite of the problem going away. Hosted tax platforms change where the data lives, not who answers for it. You’d want them on the same vendor list, held to the same contract language, and checked the same way you’d check anyone else.
Find Out What Your Current Contract Actually Obligates

We’ll walk your firm through the seven requirements above and show you where the gaps sit. No obligation, and you keep the list either way.

Get Your Free IT Assessment →

Or call (845) 440-5000