25+ Years Security Experience•Enterprise Security Leadership
Compliance Insights

FTC Safeguards Rule for CPA Firms

Understanding the 9 required elements and the 5,000 consumer threshold that most firms miscalculate

By Dan Pitre · Cloud Solutions Consulting•Published December 2025•Reviewed April 2026•10 min read

What is the FTC Safeguards Rule for CPAs?

The FTC Safeguards Rule mandates that CPA firms and tax preparers implement a Written Information Security Program (WISP) to protect client financial data. Key requirements include designating a Qualified Individual, enabling multi-factor authentication (MFA), and conducting regular risk assessments to prevent unauthorized access.

Already experiencing a breach?

If you suspect a data compromise has already occurred, stop reading and follow our CPA Breach Response Checklist immediately.

CPA Breach Response Checklist

The Dangerous Assumption

Your firm serves 200 business clients. You've been in practice for decades, built a reputation for excellence, and take client confidentiality seriously. When you hear about the FTC Safeguards Rule and its requirements for firms handling more than 5,000 consumer records, you do the math: 200 clients, well under the threshold. You assume certain requirements don't apply to you.

You're almost certainly wrong.

The 5,000 threshold doesn't count clients—it counts individual consumer records. And that distinction changes everything for CPA firms. A firm with 200 business clients routinely maintains tax records, W-2s, and financial data for thousands of individual employees, shareholders, and beneficiaries. What looks like a modest client roster often translates to 10,000, 15,000, or more individual consumer records.

This misunderstanding isn't just common—it's pervasive. And it leaves accounting firms exposed to regulatory enforcement, cyber insurance gaps, and the kind of data breach liability that can end a practice.

Why CPA Firms Are 'Financial Institutions'

The FTC Safeguards Rule exists under the Gramm-Leach-Bliley Act (GLBA), which requires "financial institutions" to protect consumer financial information. When most people hear "financial institution," they think of banks. But the GLBA definition is far broader.

The FTC explicitly identifies tax preparers and accounting firms as covered financial institutions. If your firm prepares tax returns, provides financial planning services, or handles client financial data in any capacity, the Safeguards Rule applies to you. There's no revenue threshold, no employee minimum, no exemption for professional services firms.

The revised Safeguards Rule (16 CFR Part 314) took full effect on June 9, 2023, introducing specific technical requirements that go well beyond the original "reasonable safeguards" standard. As of May 13, 2024, covered institutions must also notify the FTC within 30 days of discovering a breach affecting 500 or more consumers.

This isn't a gray area. The FTC has published guidance specifically addressing tax preparers and has pursued enforcement actions in the financial services sector. CPA firms are squarely within scope.

The 5,000 Consumer Threshold: What It Actually Means

The Safeguards Rule includes a provision that exempts certain firms from two specific requirements—maintaining a written incident response plan and providing annual reports to the board—if they maintain information on fewer than 5,000 consumers. This limited exemption has created widespread confusion about who must comply with what.

The critical distinction: The threshold counts individual consumer records, not client relationships.

A "consumer" under GLBA is any individual whose personal information you maintain. For a CPA firm, this includes:

  • Individual taxpayers whose returns you prepare
  • Employees of business clients (from payroll processing, W-2s, benefits administration)
  • Shareholders and partners of business entities
  • Beneficiaries named in trusts and estates
  • Dependents listed on tax returns
  • Historical records from prior years that you retain

A worked example:

Consider a regional CPA firm with 200 business clients. If those businesses average 50 employees each, the firm maintains W-2 data alone for 10,000 individuals. Add individual tax clients, shareholder information, trust beneficiaries, and five years of historical records, and the actual consumer count often reaches 15,000 to 25,000—five times what the firm assumed.

What this means for compliance: Firms under the 5,000 threshold are exempt from Elements 8 and 9 only (written incident response plan and board reporting). They must still comply fully with Elements 1 through 7, which include designating a Qualified Individual, conducting risk assessments, implementing technical safeguards, and maintaining an ongoing security program.

Most mid-sized CPA firms, once they count correctly, find they exceed the threshold. And even firms that genuinely fall below 5,000 records face the same core compliance requirements that drive the majority of implementation effort.

The 9 Required Elements: A CPA Firm Perspective

The FTC Safeguards Rule mandates nine specific elements for an information security program. Here's what each means for accounting practices.

Element 1: Designate a Qualified Individual

Your firm must appoint someone responsible for implementing and overseeing the security program. This can be an employee, someone at an affiliate, or a third-party service provider such as a virtual CISO (vCISO). The firm retains ultimate responsibility regardless of who fills the role. For most mid-sized CPA firms without dedicated IT security staff, a vCISO arrangement provides the required expertise without the overhead of a full-time hire.

Element 2: Conduct Written Risk Assessments

You must document a risk assessment identifying where consumer information is collected, stored, and transmitted. For CPA firms, this means mapping data flows through tax software, client portals, email systems, cloud storage, and any other systems touching client financial data. The assessment must be updated as your technology environment changes.

Element 3: Design and Implement Safeguards

Based on your risk assessment, implement controls addressing access management, data encryption, and multi-factor authentication (MFA). The rule specifically requires MFA for anyone accessing customer information. For CPA firms, this extends to tax software, document management systems, client portals, and remote access. You must also implement secure disposal procedures for data no longer needed and conduct access reviews when staff members change roles or leave the firm.

Element 4: Monitor and Test Systems

The rule requires continuous monitoring or periodic testing of your safeguards. This typically means annual penetration testing, semi-annual vulnerability assessments, and ongoing system monitoring. Many cyber insurance policies now require penetration testing as a condition of coverage, so this element often aligns with existing insurance obligations.

Element 5: Provide Security Training

All personnel must receive security awareness training upon hire and at least annually thereafter. Given that accountants are high-value targets—especially during tax season—training should emphasize phishing recognition, social engineering tactics, and secure handling of client data. Key security personnel need additional specialized training on current threats and countermeasures.

Element 6: Oversee Service Providers

You must evaluate the security capabilities of vendors with access to customer data, require contractual security commitments, and periodically assess their compliance. For CPA firms, this includes tax software vendors, cloud hosting providers, IT support companies, and any other third parties handling client information.

Element 7: Maintain the Program

Your security program must be reviewed and updated at least annually, with adjustments for new threats, technology changes, and business developments. Opening a new office, adopting new software, or expanding remote work capabilities all trigger the need for program updates.

Element 8: Create a Written Incident Response Plan

Required for 5,000+ records

Document roles, responsibilities, and procedures for responding to security incidents. The plan must address FTC notification requirements (30 days for breaches affecting 500+ consumers) and applicable state breach notification laws, which vary significantly in their timing and disclosure requirements.

Element 9: Report to Board/Leadership

Required for 5,000+ records

The Qualified Individual must provide written reports to the board of directors or equivalent governing body at least annually. For partnerships, this means formal reporting to partners on the firm's security posture, risk assessment findings, and any security incidents.

The Cyber Insurance Connection

FTC Safeguards compliance increasingly intersects with cyber insurance requirements. Insurers have tightened underwriting standards significantly over the past three years, and many now require specific security controls as conditions of coverage.

Common cyber insurance requirements that align with the Safeguards Rule include MFA implementation, employee security training, incident response planning, and—critically—having a designated individual responsible for security governance. Some carriers specifically ask whether the firm has a CISO or equivalent role.

Firms that exceed the 5,000 consumer threshold often face additional underwriting scrutiny. The logic is straightforward: more consumer records means more exposure in a breach, which means higher potential claims. Demonstrating robust compliance with all nine Safeguards elements can improve both insurability and premium rates.

Perhaps more importantly, non-compliance can void coverage. If a breach occurs and the subsequent investigation reveals that the firm misrepresented its security posture or failed to implement required controls, the carrier may deny the claim entirely.

Assessing Your Firm's Position

If you haven't evaluated your firm's FTC Safeguards compliance recently, start with two fundamental questions.

First, count your actual consumer records. Not clients—individuals. Include employees of business clients, individual taxpayers, beneficiaries, dependents, and historical records you retain. Most firms find this number is significantly higher than expected.

Second, evaluate your current compliance against all applicable elements. Even firms below the 5,000 threshold must comply with Elements 1 through 7. Do you have a designated Qualified Individual? A documented risk assessment completed within the past year? MFA on all systems accessing customer data?

We've developed a free FTC Safeguards Compliance Checklist specifically for CPA firms. The interactive assessment walks through all nine required elements and provides a gap analysis based on your firm's size and current practices. Most firms complete it in under ten minutes.

For firms that need expert guidance—particularly those requiring a Qualified Individual to satisfy Element 1—our vCISO services provide ongoing compliance support tailored to accounting practices. But whether you work with us or tackle compliance internally, the first step is understanding where you stand today.

Frequently Asked Questions

The FTC Safeguards Rule applies to "financial institutions" as defined under the Gramm-Leach-Bliley Act. This explicitly includes CPA firms, tax preparers, and any business that collects, stores, or transmits consumer financial information. If your firm prepares tax returns, provides financial planning, or handles client financial data in any capacity, you are covered by the rule.

The 9 required elements are: (1) Designate a Qualified Individual responsible for the security program, (2) Conduct written risk assessments, (3) Design and implement safeguards including access controls, encryption, and MFA, (4) Monitor and test systems regularly, (5) Provide security training to all personnel, (6) Oversee service providers with access to customer data, (7) Maintain and update the program annually, (8) Develop a written incident response plan (required for firms with 5,000+ consumer records), and (9) Provide annual reports to the board or governing body (required for firms with 5,000+ consumer records).

The revised FTC Safeguards Rule went into full effect on June 9, 2023. All covered financial institutions must now comply with all 9 required elements (or 7 elements for firms under the 5,000 consumer threshold). Additionally, the breach notification requirement became effective on May 13, 2024, requiring firms to notify the FTC within 30 days of discovering a breach affecting 500 or more consumers.

Count every individual whose personal information your firm maintains—not just your client count. This includes employees of business clients (from payroll and W-2 processing), individual taxpayers, beneficiaries listed on tax returns, dependents, trust beneficiaries, and partners or shareholders of business entities. Include both current and historical records you retain. A firm with 200 business clients often maintains records on 10,000–20,000 or more individual consumers.

Non-compliance can result in FTC enforcement actions including civil penalties up to $50,120 per violation. Beyond regulatory penalties, non-compliance often voids cyber insurance coverage, exposes the firm to malpractice claims following a data breach, and damages client trust irreparably. The FTC has actively pursued enforcement against tax preparers and financial services firms, making this a real and present risk.

Yes. The FTC explicitly allows the Qualified Individual to be an employee, someone at an affiliate, or a third-party service provider such as a virtual CISO (vCISO). However, the firm retains ultimate responsibility for the security program regardless of who serves as the Qualified Individual. For mid-sized CPA firms without dedicated security staff, a vCISO arrangement often provides the expertise required while remaining cost-effective.

Serving CPA Firms Nationwide

Team CSC provides vCISO compliance leadership for firms across the US, with deep expertise in state-specific overlays for Oregon, Nevada, Rhode Island, and Texas markets.

Assess Your FTC Safeguards Compliance

Use our free interactive checklist to evaluate your firm's compliance status in under 10 minutes.