Blog

IRS Publication 4557: A Guide for Tax and Accounting Firms

IRS Publication 4557 outlines how tax professionals must protect taxpayer data. Learn the requirements, penalties, and how to stay in compliance.

minute read

Last Updated July 29, 2026

Image of IRS building in Washington DC

Share

IRS Publication 4557: A Guide for Tax and Accounting Firms

Every busy season, firms hand over more than tax returns. They hand over Social Security numbers, bank account details, and full financial histories, and criminals know it. Data thefts at tax professionals’ offices are on the rise, and identity thieves have placed tax practitioners firmly in their sights.

That’s exactly why the IRS published Publication 4557, Safeguarding Taxpayer Data, exists. Below, I’ll break down what IRS Publication 4557 actually covers, who has to follow it, and how it fits alongside the FTC Safeguards Rule and a written information security plan (WISP).

Key Takeaways

  • IRS Publication 4557 is the IRS’s official guide for tax preparers on how to safeguard taxpayer data and comply with federal law.
  • Compliance is required for every tax professional, whether you’re a sole practitioner or a large firm. Firm size is not an exemption.
  • The FTC Safeguards Rule legally mandates a written information security plan (WISP). Publication 4557 outlines what that plan must address.
  • Publication 4557 is education. A WISP is the legal document the FTC requires you to have on file. You need both.
  • Non-compliance can trigger an FTC investigation. A confirmed breach may affect EFIN access until the intrusion is identified and corrected.

What Is IRS Publication 4557?

IRS Publication 4557, Safeguarding Taxpayer Data, is an outreach guide the IRS developed for tax preparers, transmitters, and software developers through the Security Summit to support compliance with the FTC Safeguards rule.

What is the Security Summit? 

The Security Summit is a partnership between the IRS, state tax agencies, and the private tax industry, established to combat tax-related identity theft and cyberattacks targeting tax professionals. IRS Publication 4557 was developed through this partnership and reflects input from across the profession.

P4557 covers basic security steps, how to spot the warning signs of data theft, how to report and recover from a loss, and how to comply with the FTC Safeguards Rule.

The IRS doesn’t soften this: protecting taxpayer data is the law, and it’s also good business. A theft can cost a firm its reputation, its clients, and its money, on top of whatever legal exposure follows.

Who Has to Comply with IRS Pub 4557?

Publication 4557 applies to every tax professional, whether you’re a partner at a large firm or a sole practitioner, and every Authorized IRS e-File Provider. The Gramm-Leach-Bliley Act defines “financial institutions” broadly enough to sweep in professional tax return preparers, which is what puts them under FTC jurisdiction in the first place. Online providers carry an additional requirement: the six security and privacy standards in Publication 1345, the Handbook for Authorized IRS e-file Providers.

Graphic with Who needs to follow IRS publication 4557 - Return preparers, accounting professionals, enrolled tax reps, e-file providers

Firm size is not an exemption. A solo practitioner and a 50-partner firm are held to the same baseline.

Is IRS Publication 4557 Mandatory?

The practices in Publication 4557 reflect legally enforceable obligations under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, not optional recommendations. The publication itself is an IRS guidance document, but the underlying requirements it describes, including having a written information security plan and implementing specific safeguards, carry real legal consequences for non-compliance.

What Happens if You Do Not Comply with IRS P4557?

Penalties for non-compliance

Publication 4557 is direct: failure to create and enact a required security plan “may result in an FTC investigation.” That’s the specific consequence the publication spells out.

Beyond that formal exposure, the IRS frames the practical stakes just as seriously. A data theft can mean a loss of reputation, clients, and money, separate from any regulatory action. Firms that experience a breach can also lose their Electronic Filing Identification Number (EFIN) until they’ve determined how the intrusion happened and fixed it, which means real disruption to filing returns while that investigation plays out.

CTA image leading to security ebook

Key Security Practices Every Small Firm Should Have in Place

Publication 4557 doesn’t deal in vague principles. It hands firms a practical list to support compliance with the FTC Safeguards Rule. The core requirements fall into three areas:

1. Authentication and access controls

  • Turn on multifactor authentication for anyone accessing customer information.
  • Use strong, unique passwords. Eight or more characters minimum (15 or more for single-factor authentication), mixing letters, numbers, and symbols.
  • Limit access to taxpayer data to employees who actually need it to do their jobs.
  • Withdraw old power-of-attorney authorizations for clients you no longer represent.

2. Device and network security

  • Install anti-malware and antivirus software on every device, set to update automatically.
  • Encrypt sensitive files and emails, especially anything with personally identifiable information.
  • Back up sensitive data to a secure external source that isn’t connected full time to your network.

3. Monitoring and data handling

  • Recognize phishing attempts. Watch for emails posing as the IRS, e-Services, your tax software provider, or your cloud storage provider.
  • Check your EFIN and PTIN accounts weekly for total returns filed, and deactivate any EFINs you’re not using.
  • Keep audit trails of who accessed what, when, and what they changed.

4. Physical security

  • Physically destroy old hard drives and other digital storage media, large office copiers and printers with onboard memory, and paper files before disposing of them.

Image of 4 types of security software every firm needs

Publication 4557 also identifies four types of security software every firm needs:

  • Antivirus: Blocks malware
  • Anti-spyware: Stops unauthorized data theft
  • Firewall: Blocks unwanted connections
  • Drive encryption: Protects your data if a device is lost or stolen

What to do when you suspect a data breach

Publication 4557 includes guidance on breach response. If your firm suspects a data theft, act immediately: contact your IRS stakeholder liaison, notify your state tax agency, and report the incident to the appropriate authorities. The faster you identify the source of an intrusion and correct it, the sooner you can restore full operations, and the sooner your EFIN access can be reinstated.

Waiting to report, or attempting to manage a breach internally without disclosure, compounds both the legal and operational exposure.

CTA image leading to security ebook

How Does the FTC Safeguards Rule Relate to Publication 4557?

The FTC Safeguards Rule is the legal backbone behind everything Publication 4557 recommends. Under the Gramm-Leach-Bliley Act, the FTC requires “financial institutions,” tax return preparers included, to protect the consumer information they collect. That means creating and maintaining a written information security plan describing exactly how customer information is protected.

Publication 4557 doesn’t reprint the entire Safeguards Rule. Instead, it points firms to Publication 5708 for help building that written plan, while summarizing what the FTC expects a compliant program to include:

  • A designated, qualified individual responsible for overseeing and enforcing the program.
  • Multifactor authentication for anyone accessing customer information, using at least two of three factor types: something you know, something you have, or something you are.
  • A risk assessment covering every relevant area of the firm’s operations.
  • A safeguards program that’s monitored and tested on a regular basis.
  • Service providers who are contractually required to maintain safeguards, with the firm overseeing their handling of customer data.
  • Ongoing evaluation as the firm’s business or the threat environment changes.
  • Security awareness training with regular refreshers for staff.

IRS Publication 4557 vs. WISP

What’s the difference between IRS P4557 and a WISP? This trips up a lot of firms, so let’s clear it up.

Publication 4557 is education. It tells you what good security looks like and why it matters.

A WISP, your written information security plan, is the actual document the FTC Safeguards Rule legally requires every covered firm to have, and Publication 4557 sends you to Publication 5708 specifically for help drafting one.

Reading Publication 4557 and taking it seriously is a good start. It isn’t a substitute for having a signed, documented WISP on file. Firms need both: the practices in Publication 4557, formalized into the written plan the Safeguards Rule requires.

IRS Publication 4557 vs. IRS Publication 5708

What’s the difference between IRS P4557 and IRS P5708?

Publication 4557 is a broad outreach guide covering the full scope of taxpayer data security requirements: what to protect, how to protect it, and what to do when something goes wrong.

Publication 5708 is narrower, providing step-by-step guidance specifically for drafting a WISP. Most firms will need to work through both.

Implementing NIST Standards for Tax Data Security

Publication 4557 references the National Institute of Standards and Technology (NIST) in two places:

  1. First, it recommends building your data security plan using Publication 4557 alongside NIST’s Small Business Information Security: The Fundamentals.
  2. Second, in its FTC compliance checklist, the IRS notes that passwords should run a minimum of eight characters, calling that “the NIST standard.”

Publication 4557 doesn’t walk through the full NIST framework itself. Treat NIST’s fundamentals guide as the deeper technical resource, and Publication 4557 as the accounting-specific application of it.

Where to Go from Here

Meeting the requirements in Publication 4557 isn’t a one-time project. It’s an ongoing commitment: training your staff, monitoring your systems, and keeping your written security plan current as your firm grows and the threat environment changes.

If you’re still building out your compliance program, two IRS resources are the right starting point. IRS Publication 5708 walks you through drafting a WISP, which the Safeguards Rule requires every covered firm to have on file. NIST’s Small Business Information Security: The Fundamentals provides the technical depth that Publication 4557 points to but doesn’t replicate.

For a broader look at what a cybersecurity program built for accounting firms should include, from security awareness training to incident response to vendor oversight, the guide below covers the full picture.

CTA image leading to security ebook