Skip to main content
All resources
IRS Requirements

The IRS 'Security Six': What Tax Preparers Must Document in Their WISP

The IRS Security Six from Publication 4557 — antivirus, firewalls, MFA, backups, drive encryption, and VPN — is the technical baseline for tax preparers. Here's what the IRS expects for each, and how to document them as named controls in your WISP.

August 202610 min read
By the WISPWolf Compliance Team· August 2026Reviewed by WISPWolf Compliance TeamLast Updated: August 2026 · Verified August 30, 2026
Short answer

The IRS Security Six — antivirus software, firewalls, multi-factor authentication, backups, drive encryption, and a VPN — is the minimum technical baseline every tax preparer must have and document. Each control belongs in your WISP with a named tool, an owner, and a verification method. The Six are necessary but not sufficient: a compliant WISP also requires the governance elements of IRS Pub 5708 and the FTC Safeguards Rule.

In a hurry? Get your free Compliance Score, then come back to this guide.

Take the Free Quiz View Sample WISP

The "Security Six" is the IRS Security Summit's minimum technical baseline for tax professionals, drawn from Publication 4557. It is deliberately short — six controls any practice can understand and implement. But there is a gap between having the six tools and being able to prove you have them, and that gap is where most tax preparers fail an IRS inquiry or an insurance application. The IRS doesn't just expect the controls to exist; under Publication 5708 and the FTC Safeguards Rule, each one must be documented in your WISP as a named control — which tool, who is responsible, and how it is verified. This guide walks through each of the six, what the IRS actually expects, the gaps preparers most commonly have, and the documentation language that turns "installed" into "evidenced."

1. Antivirus and anti-malware software

What the IRS expects: active, automatically-updating endpoint protection on every device that touches taxpayer data — workstations, laptops, and any personal device used for client work. Microsoft Defender satisfies this for most small practices when it is genuinely running; third-party products (Bitdefender, CrowdStrike, SentinelOne) satisfy it too.

Common gaps: protection disabled or expired on one machine; a personal laptop used for client email with nothing installed; no central visibility, so nobody knows a device fell out of protection months ago.

How to document it: "Endpoint protection is provided by Microsoft Defender for Business on all firm devices. The Qualified Individual reviews the device health report monthly and investigates any device reporting disabled or out-of-date protection." Name the product, name the owner, name the verification cadence.

2. Firewalls

What the IRS expects: a barrier between your network and the internet, plus host firewalls on individual devices. For a small office this is typically the router's firewall plus the OS firewall on each machine. For a home office, the same — the ISP router plus Windows or macOS firewall enabled.

Common gaps: the router still running its factory admin password; guest Wi-Fi sharing the same network as the production machines; the OS firewall turned off years ago to fix a printer problem and never turned back on.

How to document it: "Network firewalling is provided by the office router (make/model) with a changed administrative credential and a separate guest network. Host firewalls are enabled by policy on all firm devices and verified quarterly." Note the guest-network separation explicitly — it is one of the first things a reviewer checks.

3. Multi-factor authentication

What the IRS expects: MFA on every account that accesses taxpayer data — email, tax software, e-Services, client portals, cloud storage, payroll, remote access. The FTC Safeguards Rule made MFA a hard legal requirement in the 2023 amendments, so this control is both IRS guidance and federal regulation. Phishing-resistant factors (authenticator apps, FIDO2 keys) are the 2026 baseline; SMS-only MFA is increasingly flagged as a weak control by insurers.

Common gaps: MFA on the tax software but not on email (the account that resets every other password); a shared login that can't do per-user MFA; one legacy account that "doesn't support it" and was never replaced.

How to document it: "MFA is enforced on all systems listed in the data inventory, using authenticator-app or hardware-key factors. Enforcement is verified monthly via the Microsoft 365 MFA status report; exceptions require written approval by the Qualified Individual." For the full element walkthrough, see the FTC Safeguards Rule checklist.

4. Backup software and services

What the IRS expects: automatic, encrypted backups of taxpayer data, stored somewhere a ransomware actor cannot reach — off-site or in a separate cloud tenant — and, critically, tested for restorability. A backup that has never been restored is a hypothesis, not a control.

Common gaps: backups that ran successfully to an external drive that ransomware would encrypt along with everything else; cloud sync (OneDrive, Dropbox) mistaken for backup; no restore test on record, ever.

How to document it: "Client data is backed up nightly to [service], encrypted in transit and at rest, retained 90 days. The Qualified Individual performs a test restore of a sample client file quarterly and records the result." The restore test is the line that separates a documented control from a checkbox.

5. Drive encryption

What the IRS expects: full-disk encryption on every device that stores taxpayer data — BitLocker on Windows, FileVault on macOS — plus encryption of any portable media. The Safeguards Rule requires encryption at rest as a named element, and Pub 4557 treats an unencrypted stolen laptop as a reportable data theft.

Common gaps: the desktop encrypted but the laptop not; recovery keys never escrowed, so a failed update locks the owner out of their own client data; USB drives in a drawer with unencrypted client files on them.

How to document it: "All firm devices use full-disk encryption (BitLocker/FileVault), verified at provisioning and audited semi-annually. Recovery keys are escrowed in the firm's password manager. Client data may not be stored on unencrypted removable media." The prohibition sentence matters as much as the encryption sentence.

6. Virtual private network (VPN)

What the IRS expects: encrypted remote access whenever taxpayer data is touched outside the trusted office network — working from home, a client site, or a hotel during tax season. For cloud-first practices, the modern equivalent is enforcing encrypted, MFA-gated access to cloud tenants rather than a traditional tunnel, but Pub 4557 still names the VPN explicitly.

Common gaps: preparers working from home over plain RDP exposed to the internet; public Wi-Fi use with no tunnel; remote access that exists in practice but appears nowhere in the written plan.

How to document it: "Remote access to client data occurs only through [VPN product / encrypted cloud tenant with MFA and conditional access]. Direct remote-desktop exposure to the internet is prohibited. Remote access configuration is reviewed annually." State which model you use — tunnel or conditional access — and prohibit the unsafe alternative in writing.

The four-field test for every control

For each of the Security Six, your WISP should answer four questions: which tool, who owns it, how is it verified, and when was it last checked. A control that can answer all four is documented. A control that can only answer the first is an assumption.

Why the Security Six is not a WISP

This is the distinction that trips up most preparers. The Security Six is six technical controls. A WISP — under IRS Publication 5708 and the FTC Safeguards Rule — is the entire security program those controls live inside. A firm can have antivirus, a firewall, MFA, backups, encryption, and a VPN all running perfectly and still have no compliant WISP, because the Six say nothing about the governance half of the rule:

  • A designated Qualified Individual accountable for the program in writing.
  • A written risk assessment identifying where client data lives and what could go wrong.
  • Vendor oversight — due diligence and contracts for your tax software, portal, and cloud providers.
  • Training for everyone who touches client data, documented annually.
  • A written incident response plan with IRS Stakeholder Liaison and state notification steps.
  • An annual review that evaluates and adjusts the program as the practice changes.

Think of the Security Six as the technical floor and the WISP as the building around it. The FTC's nine elements at 16 CFR § 314.4 are the full framing — the Six map onto roughly one and a half of them. For the complete picture, see what a Written Information Security Plan actually is and the IRS Publication 5708 guide.

"My IT provider handles that" is not documentation

If an MSP manages your Security Six, your WISP must still name the controls, name the provider as a service provider under the Safeguards Rule, and describe how you verify their work. Outsourced execution never outsources accountability.

How WISPWolf documents the Security Six for you

WISPWolf's intake maps each of the Security Six to a named control in your generated WISP — tool, owner, verification method, review date — and the living platform then tracks the evidence behind each one. When your Microsoft 365 MFA report changes, when a device drops encryption, or when a quarterly restore test comes due, the gap is flagged before an IRS reviewer or insurance underwriter finds it. The Security Six stops being a list of things you believe are true and becomes a set of controls you can prove.

Frequently asked questions

What is the IRS Security Six?

The Security Six is the IRS's minimum technical baseline for tax preparers, published in Publication 4557: antivirus/anti-malware software, firewalls, multi-factor authentication, backup software or services, drive encryption, and a virtual private network (VPN) for remote access. The IRS describes these as the basic protections every tax professional should have in place.

Is the Security Six the same thing as a WISP?

No. The Security Six is six technical controls. A WISP is the complete written security program required by IRS Publication 5708 and the FTC Safeguards Rule — it includes the Security Six plus governance elements like a designated Qualified Individual, a written risk assessment, vendor oversight, training, incident response, and an annual review. You can have all six tools installed and still not have a compliant WISP.

Does the Security Six apply to solo tax preparers?

Yes. Publication 4557 makes no distinction by firm size. A sole proprietor working from a home office is expected to have all six controls: endpoint protection, a firewall (including the one built into the operating system or router), MFA, tested backups, drive encryption, and a VPN or equivalent encrypted remote access.

Do I need a VPN if I never work remotely?

If you genuinely never access client data outside your office network, the VPN's purpose — encrypting connections over untrusted networks — may be covered another way. But 'remote access' in 2026 includes cloud tax software and web portals, and the moment you work from home, a client site, or a hotel, a VPN or an equivalent encrypted tunnel is the documented expectation. Your WISP should state which scenario applies to you and why.

Is Windows Defender enough for the antivirus requirement?

For most small practices, yes — Microsoft Defender is a real, current endpoint protection product and satisfies the antivirus element when it is active, updating, and monitored. What the IRS and FTC care about is that protection is present, current, and documented. The gap is usually not the product; it is the machine where it got disabled six months ago and nobody noticed.

How do I prove the Security Six to the IRS or an insurer?

Write each control into your WISP with four fields: the specific tool (vendor and product), the person responsible for it, how it is verified (e.g., monthly MFA report, quarterly backup restore test), and the date of last verification. Then keep the verification records. 'Installed' is a claim; a named control with a verification trail is evidence.

Related resources

Get Your Compliance Score

References

Sources & References

Primary regulatory and standards sources used throughout WISPWolf's compliance guidance.

  1. IRS Publication 4557 — Safeguarding Taxpayer Data
  2. IRS Publication 5708 — Creating a Written Information Security Plan
  3. IRS — Security Summit 'Security Six' Guidance for Tax Professionals
  4. FTC Safeguards Rule (16 CFR Part 314)
Free Compliance Starter Kit

Get the free WISPWolf Compliance Starter Kit

Download the starter kit and identify your compliance gaps. Includes an IRS WISP starter template (not a completed customized WISP), FTC Safeguards Rule checklist, GLBA checklist, risk assessment worksheet, cyber insurance guide, and tax preparer compliance checklist.

Free WISP Compliance Score

Get Your Free WISP Compliance Score

See how your firm's security practices compare to FTC Safeguards Rule and IRS WISP expectations. Answer 15 questions and get a personalized scorecard in minutes.

IRS Pub 5708 Compliant · FTC Safeguards Rule · AES-256 Encrypted · No Credit Card Required