United States: IRS and Security Summit Mandate Written Security Plans for Tax Professionals

The IRS and Security Summit partners issued a joint reminder on August 18, 2026 (IR-2026-92) that all tax professionals handling taxpayer data must maintain a Written Information Security Plan (WISP) as required by the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule and IRS Publication 4557. With cyberattacks on tax firms escalating—particularly ransomware and business email compromise (BEC) schemes targeting client PII during filing season—the Summit emphasized that a WISP is not optional but a legal obligation for any “financial institution” under GLBA, which includes tax preparers, CPAs, and enrolled agents. The reminder coincides with the FTC’s 2023 Safeguards Rule amendments requiring specific risk assessments, access controls, encryption, and incident response plans.

Key Takeaways

  • Mandatory WISP Components: Plans must include designated security officer, risk assessment, access controls (MFA mandatory), encryption for data at rest and in transit, vendor management, and a tested incident response plan with 72-hour breach notification procedures.
  • FTC Enforcement Alignment: The updated Safeguards Rule (16 CFR 314.4) requires annual penetration testing and vulnerability assessments for firms with 5,000+ consumer records, directly impacting mid-to-large tax practices.
  • PTIN Renewal Certification: The IRS now requires PTIN renewing preparers to certify WISP compliance, creating a direct enforcement nexus between preparer credentialing and data security obligations.

Disclaimer: This article is compiled and summarized by the AI based on publicly available information and is for general information purposes only. It does not constitute any form of formal tax advice, legal opinion, or basis for performance. Please consult a qualified professional tax advisor or legal counsel for tax advice.

Source: Read Official Announcement