Why a tax practice counts as a financial institution
The rule's own list of examples includes "an accountant or other tax preparation service that is in the business of completing income tax returns." The IRS repeats this in Publication 4557, its data security guide for tax professionals. It applies to solo preparers, enrolled agents, CPA firms, and bookkeeping firms that prepare returns.
The plan is step one. Testing is step two.
When you apply for or renew your PTIN, the form asks you to confirm you know the law requires a written information security plan. The IRS publishes a template for that plan in Publication 5708. A plan on paper says what you intend to do. The Safeguards Rule also expects you to check that it works. IRS Publication 4557 puts it this way: design and implement a safeguards program, and regularly monitor and test it.
What the rule asks for
Section 314.4(d)(2) of the rule (16 CFR Part 314) says that unless you have continuous monitoring in place, you must conduct "annual penetration testing" of your information systems and vulnerability assessments "at least every six months," and again whenever your operations change in a material way.
The rule defines a penetration test as an attempt "to circumvent or defeat the security features of an information system" from outside or inside your systems. A vulnerability scan on its own does not meet that definition. You need both.
What you are protecting
Client files hold Social Security numbers, bank account numbers for refunds, W-2s, prior year returns, and copies of identification. Criminals use stolen client files to file false returns in your clients' names. The systems in scope are the ones you control: your office network, your workstations and laptops, remote access for staff who work from home, your website, and any client portal you host.
The small firm exception
If you keep customer information on fewer than 5,000 consumers, section 314.6 exempts you from the fixed testing schedule above. Count carefully. The count is the number of consumers whose information you keep, so clients from prior years who are still in your files count too. Either way you still need the written plan and you still have to test your safeguards regularly. Many smaller firms run the same tests anyway because a cyber insurance application asks for them.
Why fall is the time to test
A test in the fall gives you time to fix what it finds before client documents start arriving in January. The 30-day window includes retests, so you can confirm each fix and start the season with a clean, dated report.
Both requirements, one checkout
- Automated external penetration test, from $1,995 for a 30-day window (1 external IP or domain). You set the scope, it starts in minutes, it safely attempts real exploitation, it includes retests after you fix things, and it ends with a report you can keep with your written security plan.
- Automated internal penetration test, from $2,995 for a 30-day window (up to 25 internal hosts), for your office network and workstations.
- External vulnerability scanning, from $595 a year (10 IPs), run on a schedule so the every-six-months assessment is covered all year.
- Internal vulnerability scanning, from $1,095 a year (up to 128 internal IPs), for the computers inside your office.
When you need an engineer
If your insurer, a client, or your attorney asks for a test led by a named engineer, our managed penetration testing team does that.
This page is general information, not legal advice. Ask your attorney or compliance advisor how the rule applies to your business.
Will your auditor accept it? See what is in the report.
See pen test pricing and buy online · Talk to a specialist
Related: FTC Safeguards Rule overview, auto dealerships, mortgage brokers and lenders, cyber insurance, penetration test cost
