
MFA for Tax Software: What the IRS and FTC Require
Multi-factor authentication (MFA) for tax software is a mandatory compliance requirement under both the IRS Security Six framework and the FTC Safeguards Rule (16 CFR Part 314). Tax professionals who handle taxpayer data must implement MFA across all in-scope systems or face real regulatory consequences, including Preparer Tax Identification Number (PTIN) suspension, e-filing privilege revocation, and civil penalties up to $250,000 per incident.
The reason tax firms attract so much attacker attention is straightforward: Drake Tax, Lacerte, ProSeries, UltraTax CS, and similar platforms hold Social Security numbers, financial records, and personally identifiable information (PII) for hundreds or thousands of clients. That concentration of sensitive data makes a single compromised login extraordinarily valuable to attackers. According to the 2025 Verizon Data Breach Investigations Report (DBIR), stolen or weak credentials remain the leading cause of hacking-related breaches. MFA directly neutralizes that attack vector by making stolen passwords alone insufficient for account access.
This guide covers what the IRS and FTC actually require, which MFA methods meet those standards, step-by-step setup for Drake, ProSeries, Lacerte, and UltraTax CS, and how to document your implementation in a compliant Written Information Security Plan (WISP).
Tax Cybersecurity By The Numbers
IBM Cost of a Data Breach Report 2025
Documented penalties for Safeguards Rule violations, plus personal liability risk for firm principals
Verizon DBIR 2025, stolen or weak credentials are the top cause of hacking-related breaches
What the IRS and FTC Actually Require
Two separate federal regulatory frameworks govern MFA requirements for tax professionals, and both carry enforcement authority. Understanding which rules apply and where they overlap is the foundation of a compliant security posture.
IRS Security Six and Publication 4557
The IRS Security Six is a set of baseline cybersecurity actions required of all tax professionals. MFA is listed explicitly as one of the six. IRS Publication 4557, the Data Security Resource Guide for Tax Professionals, specifies in Section 3.4 that MFA must be enabled on all systems that access, store, or transmit taxpayer information. That scope extends beyond tax preparation software to include email, cloud storage, and client portals.
The technical standard aligns with NIST SP 800-63B Digital Identity Guidelines, targeting Authenticator Assurance Level 2 (AAL2), which requires two distinct authentication factors from separate categories. Non-compliance puts your PTIN at risk. The IRS has signaled increasing enforcement of cybersecurity requirements, and failure to implement MFA can result in e-filing privilege suspension, effectively shutting down your practice during filing season. For a complete breakdown of what is required to maintain your PTIN, see our guide to PTIN and WISP requirements for tax preparers.
FTC Safeguards Rule (16 CFR Part 314)
The Gramm-Leach-Bliley Act (GLBA), enacted in the late 1990s, established the legal foundation for protecting consumer financial data by defining "financial institutions" broadly. That definition explicitly includes tax preparation services. The FTC updated its implementing Safeguards Rule in 2021, with MFA provisions taking full effect in June 2023.
Under 16 CFR Section 314.4(c), tax preparers must implement access controls that include MFA for any individual accessing customer information systems. The rule permits a narrow exception for firms that document why MFA is not technically feasible for a specific system. In practice, that exception rarely applies, and convenience is not a valid justification. The FTC has pursued enforcement actions against firms of all sizes, with penalties documented at over $100,000 plus personal liability risk for firm principals. Learn more about how these requirements apply to your practice in our guide to FTC Safeguards Rule compliance for tax preparers.
2026 Compliance Requirement: MFA Is Mandatory
The IRS requires all tax preparers to have MFA implemented across all in-scope systems before the 2026 filing season. Firms without compliant authentication controls face potential PTIN suspension and FTC enforcement action. There is no size exemption. Solo preparers, small firms, and large practices are all subject to the same requirements under IRS Publication 4557 and 16 CFR Part 314.
MFA Methods: Which One Should Tax Firms Use?
Multi-factor authentication requires users to verify their identity using at least two factors from distinct categories: something you know (password or PIN), something you have (phone, hardware token, or smart card), or something you are (fingerprint or facial recognition). Combining factors from different categories is what makes MFA for tax software effective. If an attacker steals a password, they still cannot access the system without the physical device or biometric tied to that account.
For tax software specifically, five authentication methods are in common use, and they are not all equal in terms of security or regulatory alignment.
Authenticator Apps (Recommended): Microsoft Authenticator, Google Authenticator, or Duo Mobile generate time-based one-time passwords (TOTP) that rotate every 30 seconds. This method satisfies NIST SP 800-63B AAL2 requirements, is the IRS preferred approach, works offline, costs nothing, and is not vulnerable to SIM-swapping attacks.
SMS Text Message Codes: A verification code sent to a registered mobile number. NIST guidelines classify SMS as a reduced-security option due to SIM-swapping and SS7 protocol vulnerabilities. Acceptable for baseline compliance but not the preferred method for accounts with access to all client data.
Hardware Tokens: Physical devices like YubiKey or RSA SecurID generate or store authentication credentials independently of a smartphone. These provide the strongest security posture and are worth considering for practice owners and administrators with broad access to client records.
Push Notifications: Mobile app notifications, common in Duo Security and Microsoft Authenticator, that require an explicit tap to approve. Fast, user-friendly, and substantially more secure than SMS.
Biometric Authentication: Fingerprint or facial recognition, typically layered on top of a password as the second factor. Widely available on modern smartphones and laptops, and increasingly integrated into tax software login flows.
Authenticator apps offer the best combination of strong security, zero cost, and ease of use for most tax practices. Hardware tokens are worth the investment for owners or administrators whose credentials would give an attacker access to every client's records. SMS is a fallback, not a first choice, particularly as NIST and the FTC continue signaling that SMS-based MFA may face stricter scrutiny in future guidance updates.
MFA Rollout: Implementation Steps for Tax Practices
Inventory All In-Scope Systems
List every system that accesses, stores, or transmits taxpayer data: tax software, email, cloud storage, client portals, VPNs, and practice management tools. Every item on this list requires MFA under Publication 4557 and the Safeguards Rule.
Select a Standard Authenticator App
Standardize on one app across all staff, Microsoft Authenticator, Google Authenticator, or Authy. A single app supports unlimited accounts, which simplifies training and reduces support requests.
Enable MFA on Tax Software Platforms
Configure MFA in Drake Tax, ProSeries or Lacerte (via Intuit Account), or UltraTax CS (via CS Professional Suite Portal). Platform-specific steps are detailed in the section below.
Enable MFA on Email and Cloud Storage
Secure Microsoft 365 or Google Workspace with MFA before or alongside tax software. A compromised inbox can reset passwords on every other platform your firm uses.
Require MFA at the VPN and Remote Desktop Gateway
Remote access systems must require MFA before granting network access. Unauthenticated remote access is one of the leading entry points for ransomware attacks targeting tax practices.
Train All Staff and Save Backup Codes
Walk each team member through the setup. Confirm every staff member has backup codes saved and knows how to use them well before filing season begins.
Document Implementation in Your WISP
Record the authentication method for each in-scope system, device registration procedures, and your annual review schedule. Without this documentation, your MFA deployment is invisible to regulators.
Step-by-Step MFA Setup for Major Tax Software Platforms
Each major tax software platform has its own MFA configuration path. Setup is straightforward across all of them, typically taking under 10 minutes per user account.
Drake Tax MFA Configuration
Drake Tax supports authenticator apps (recommended), SMS verification, and email-based backup codes. MFA applies to both the desktop application login and Drake Portal online services. To enable MFA, log into your Drake Tax account at drakesoftware.com, navigate to Account Settings, and select Two-Factor Authentication. Follow the prompts to scan the QR code with your authenticator app or enter your mobile number for SMS. Drake recommends enabling MFA on the practice owner account first, then rolling out to all staff before configuring portal access for clients.
ProSeries and Lacerte (Intuit Account)
ProSeries and Lacerte share a unified authentication system through the Intuit Account platform. Log into accounts.intuit.com, navigate to Sign In and Security, and select Two-step verification. Intuit supports authenticator apps, SMS, and voice call verification. Select the authenticator app option and scan the QR code with Microsoft Authenticator, Google Authenticator, or Authy.
A useful feature of Intuit's implementation: a single MFA setup covers the entire Intuit product ecosystem. Tax professionals using ProSeries Tax Online or Lacerte Tax Online benefit from unified MFA that protects both desktop and cloud environments simultaneously. Firm administrators can access the Team Management section to audit MFA compliance status across all staff accounts. Verify that every team member has MFA active well before January.
UltraTax CS and CS Professional Suite (Thomson Reuters)
Thomson Reuters provides MFA setup through the CS Professional Suite Portal. Administrators navigate to Security Settings, then Multi-Factor Authentication, to enable firm-wide policies. UltraTax CS supports role-based authentication policies, letting practice administrators configure different MFA requirements by user role and access level, a useful control for larger firms with tiered staff permissions.
For enterprise practices, UltraTax CS integrates with SAML-based single sign-on (SSO) providers including Microsoft Azure Active Directory, Okta, and OneLogin, centralizing authentication management across all business systems. If your firm already uses one of these identity providers, configure UltraTax CS to authenticate through your existing SSO rather than maintaining a separate credential set. For broader guidance on securing all technology your practice uses, review our overview of tax client portal security and document handling.
MFA Compliance Checklist for Tax Firms
- MFA enabled on all tax software platforms (Drake, ProSeries, Lacerte, UltraTax CS)
- MFA enabled on all firm email accounts (Microsoft 365, Google Workspace)
- MFA enabled on cloud storage platforms (ShareFile, Dropbox Business, OneDrive)
- MFA required at VPN and remote desktop gateway before network access is granted
- MFA enabled on practice management software (Canopy, TaxDome, Karbon)
- MFA enabled on client portals for all staff accounts
- All staff have completed MFA setup and have backup codes saved
- WISP documents the authentication method and procedures for every in-scope system
- Device registration and emergency access procedures are documented and tested
- Annual MFA review is scheduled and assigned to a named staff member
- Former staff MFA-enrolled devices removed from all platforms upon departure
Need a WISP That Documents Your MFA Setup?
Our security team has helped thousands of tax professionals build compliant Written Information Security Plans that satisfy IRS Publication 4557 and FTC Safeguards Rule documentation requirements.
WISP Documentation Requirements for MFA
IRS Publication 4557 frames MFA as one component of a broader security strategy, not a standalone fix. Section 3.4 is explicit: MFA must be implemented on all in-scope systems, and tax professionals must document their implementation as part of their Written Information Security Plan (WISP). Without that documentation, your MFA deployment is invisible to regulators reviewing your compliance posture.
That documentation requirement serves two purposes. First, it demonstrates compliance if you are ever subject to an IRS audit, PTIN review, or FTC inquiry. Second, it provides operational continuity guidance so staff know exactly what to do when a device is lost, an account is locked, or a new employee needs onboarding.
A WISP that references MFA in general terms without specifics does not satisfy the requirement under Publication 4557. Your WISP's MFA section should include:
- A complete inventory of all systems where MFA is enabled
- The authentication method used for each system
- Device registration and replacement procedures
- Emergency access and backup authentication protocols
- Staff training records with completion dates
- Annual review dates with the staff member responsible for MFA policy maintenance
The IRS Publication 5708 sample WISP provides an official starting point, but it requires customization to reflect your firm's actual systems and procedures. For guidance on building or updating a compliant plan, see our detailed PTIN and WISP requirements guide.
Bottom Line
MFA is not optional for tax preparers. Both IRS Publication 4557 and the FTC Safeguards Rule independently require it, and both carry enforcement authority. Authenticator apps satisfy all current regulatory requirements, cost nothing, and take under 10 minutes per user to configure. The WISP documentation requirement is equally binding and equally enforceable, your MFA deployment must be recorded in writing.
Overcoming Common MFA Implementation Challenges
Tax practices encounter predictable obstacles when deploying MFA for tax software and related systems. Most are solvable with planning, and implementation is substantially easier when it happens during the off-season rather than in January under filing deadline pressure.
Managing Multiple Software Platforms
Firms using both Drake for individual returns and UltraTax CS for business returns face the practical problem of managing multiple MFA setups across different vendor systems. The solution is standardizing on a single authenticator app across all platforms. Microsoft Authenticator and Google Authenticator both support unlimited accounts, so staff can manage every platform's MFA codes from one app rather than juggling separate authentication tools. This single-app approach also makes staff training straightforward: learn the process once, apply it everywhere.
Seasonal Workflow Pressure
Any additional login step creates friction during peak filing season, and staff will resist changes that slow them down under deadline pressure. Address this proactively by deploying MFA between May and August, configuring "remember this device" policies for trusted firm-owned office workstations, and setting session timeout policies appropriate for tax season workflows. A 30 to 60 minute inactivity window is typically appropriate rather than aggressive 10-minute lockouts that frustrate staff in the middle of complex return preparation. Before January 1st, verify that all staff have backup codes saved and know how to use them.
Solo and Small Practice Constraints
Solo and small practices often assume MFA requires significant technology investment. It does not. Authenticator apps are free, every major tax software platform includes MFA at no additional charge, and setup takes less than 10 minutes per user. For practices without in-house IT support, a specialized cybersecurity provider for accounting firms can handle deployment, staff training, and WISP documentation, typically for far less than the cost of a single data breach incident response engagement. There is no size exemption under the FTC Safeguards Rule, and the IRS applies the same Publication 4557 requirements regardless of whether a firm files 50 returns or 5,000.
Remote and Mobile Access
Practices with remote staff or field preparers need MFA configured at multiple layers: at the VPN for network access, at the workstation login for device access, and at the tax software level for application access. This layered approach ensures that bypassing one authentication step still leaves additional controls in place. Establish clear procedures for how remote staff handle MFA when working from areas with limited cell coverage. Hardware tokens work without a network connection and provide reliable authentication in those situations. Our remote work security guide for small teams covers VPN configuration, device management, and access controls for distributed practices.
MFA Beyond Tax Software: Securing Your Entire Practice
Implementing MFA for tax software satisfies the most visible compliance requirement, but both the IRS Security Six and the FTC Safeguards Rule apply to your entire technology environment. Any system that accesses, stores, or transmits taxpayer information is in scope.
A compromised email account can expose every client document attachment and communication thread your firm has ever sent or received. Tax professionals are high-value targets for phishing attacks, since email is the primary delivery mechanism for phishing campaigns and the first account attackers pursue once they have a foothold in your network. The systems requiring MFA in a typical tax practice extend well beyond preparation software:
- Email (Microsoft 365, Google Workspace): Enable MFA on all firm email accounts without exception. Attackers routinely use compromised inboxes to reset passwords on every other in-scope platform.
- Cloud Storage (ShareFile, Dropbox Business, OneDrive): Any platform used to store or share tax documents requires MFA for all users with access.
- Client Portals: Portals used for document collection must implement MFA for staff access. Encouraging or requiring it for clients submitting sensitive documents adds an additional layer of protection.
- Practice Management Software (Canopy, TaxDome, Karbon): These platforms contain client records, case notes, billing data, and communication histories. They are explicitly in scope under Publication 4557 and the Safeguards Rule.
- Remote Access Systems: VPNs and remote desktop gateways must require MFA before granting network access. Compromised remote access credentials are a leading entry point for ransomware attacks targeting tax practices.
- Accounting and Billing Software (QuickBooks Online, Bill.com): These systems contain sensitive firm financial data and are targeted by attackers who establish a foothold through tax software before pivoting to financial systems.
The practical approach is building your MFA deployment around a single authenticator app that covers all platforms. Once staff are comfortable using it for tax software, adding accounts for email and cloud storage takes seconds per user.
Why Tax Preparers Are Classified as Financial Institutions
Many tax professionals are surprised to learn they are classified as financial institutions under federal law, and that this classification directly creates their MFA obligation. The Gramm-Leach-Bliley Act, enacted in the late 1990s, defined financial institutions broadly to include any business that provides financial products or services to consumers. Tax preparation falls squarely within that definition, which subjects tax preparers to the FTC's Safeguards Rule regardless of firm size, revenue, or number of returns filed annually.
The practical consequence is that the MFA requirement has two independent legal sources. Even if the IRS were to modify its Security Six guidance, the FTC Safeguards Rule would still independently require MFA for any individual accessing customer information systems. Non-compliance exposes tax professionals to enforcement from two separate federal agencies, a dual liability that makes the compliance calculus straightforward.
The reputational consequences of a breach extend beyond regulatory penalties. Tax professionals who experience a data breach face client loss, potential professional liability claims, and in severe cases, business closure. Understanding the full scope of what to do after a data breach, including notification obligations, regulatory reporting, and client communication, reinforces why preventive controls like MFA are far less disruptive than incident response. For firms that want to build a full incident preparedness posture, our incident response plan guide for tax practices covers the key components required under Publication 4557.
Given that MFA implementation costs nothing for most platforms and takes minutes to configure, the risk profile for non-compliance is difficult to justify.
Staying Current as MFA Requirements Evolve
The regulatory environment around MFA for tax software is tightening, not stabilizing. The FTC has signaled ongoing review of its Safeguards Rule technical requirements as authentication technology evolves, and the IRS has increased its focus on cybersecurity enforcement as part of broader efforts to combat tax-related identity theft. The identity theft prevention resources for tax professionals through the IRS Security Summit initiative reflect this increased regulatory attention to authentication specifically.
The National Association of Tax Professionals (NATP) and IRS Stakeholder Liaison teams regularly publish updated guidance on security requirements. Following these channels keeps your firm ahead of regulatory changes rather than scrambling to catch up after a policy update.
The direction of travel is toward stronger authentication methods. SMS-based MFA, while currently acceptable for baseline compliance, faces increasing scrutiny from NIST and the FTC as SIM-swapping attacks become more common. Firms that adopt authenticator apps or hardware tokens now will be positioned for future regulatory updates without needing to re-deploy their entire authentication infrastructure.
Annual review of your MFA implementation, documented in your WISP, satisfies the review requirements under both IRS Publication 4557 and the FTC Safeguards Rule. That review should include verifying that every in-scope system still has MFA enabled, confirming that new staff have completed MFA setup and training, updating the system inventory if new platforms were added during the year, and testing backup and recovery procedures to confirm they work when needed. If any staff members left the firm during the year, verify that their MFA-enrolled devices have been removed from all platforms to prevent unauthorized access through former employee credentials.
Get Your Tax Practice Fully MFA-Compliant in 2026
Our cybersecurity team specializes in helping tax professionals meet IRS Publication 4557 and FTC Safeguards Rule requirements, including MFA deployment, WISP documentation, and staff training.
Frequently Asked Questions
MFA is legally required under two independent federal frameworks. IRS Publication 4557 (Section 3.4) mandates MFA on all systems that access, store, or transmit taxpayer data as part of the IRS Security Six. The FTC Safeguards Rule (16 CFR Section 314.4(c)) independently requires MFA for any individual accessing customer information systems. Both rules carry real enforcement authority. Non-compliance can result in PTIN suspension, e-filing privilege revocation, and FTC civil penalties that have exceeded $100,000 in documented enforcement actions.
Authenticator apps (Microsoft Authenticator, Google Authenticator, Duo Mobile) are the preferred method for tax professionals. They satisfy NIST SP 800-63B Authenticator Assurance Level 2 (AAL2) requirements, work offline, cost nothing, and are not vulnerable to SIM-swapping attacks. SMS text codes are acceptable for baseline compliance but are classified as a reduced-security option by NIST due to SIM-swapping and SS7 protocol vulnerabilities. Use SMS only as a fallback or for lower-risk secondary accounts. For practice owners and administrators with broad access to all client records, hardware tokens provide the strongest security posture available.
MFA is required on every system that accesses, stores, or transmits taxpayer information. Under IRS Publication 4557 and the FTC Safeguards Rule, that scope includes firm email (Microsoft 365, Google Workspace), cloud storage (ShareFile, Dropbox Business, OneDrive), client portals, practice management software (Canopy, TaxDome, Karbon), VPNs, remote desktop gateways, and accounting software. A compromised email account alone can expose every client document your firm has ever handled, and attackers routinely use email access to reset passwords on every other in-scope platform.
Failure to implement MFA puts your PTIN at risk in two ways. First, the IRS has the authority to suspend or revoke e-filing privileges and PTIN registration for tax professionals who do not comply with Publication 4557 security requirements. Second, a data breach resulting from missing MFA controls can trigger an IRS investigation that may result in suspension while the breach is under review. E-filing suspension during tax season effectively shuts down your practice. The IRS has increased cybersecurity enforcement activity since 2022, and these consequences are not theoretical.
Your Written Information Security Plan (WISP) must include a dedicated section on access controls that covers: a complete inventory of every system where MFA is enabled, the specific authentication method used for each system, device registration and replacement procedures, emergency access and backup authentication protocols, staff training records with completion dates, and your annual review schedule with the responsible staff member named. A WISP that references MFA in general terms without this level of specificity does not satisfy the IRS Publication 4557 documentation requirement. Use the free WISP template to build a compliant document or update an existing plan.
No. There is no size-based exemption under either IRS Publication 4557 or the FTC Safeguards Rule. Solo preparers and single-person firms are subject to the same MFA requirements as large national firms. The FTC Safeguards Rule provides a narrow technical feasibility exception, but convenience and cost are not valid justifications under that exception. Authenticator apps are free, every major tax platform includes MFA at no additional charge, and setup takes under 10 minutes per user account.
Two-factor authentication (2FA) is a specific case of MFA that uses exactly two factors. MFA is the broader term covering any system requiring two or more factors from distinct categories: something you know (password or PIN), something you have (phone, hardware token), or something you are (fingerprint or facial recognition). IRS Publication 4557 and the FTC Safeguards Rule both use the term MFA, and both require at minimum two factors from different categories. In practice, most tax software implementations are technically 2FA, but the terms are used interchangeably in compliance contexts.
Remote staff require MFA at multiple layers: at the VPN for network access before connecting to firm resources, at the workstation login for device-level control, and at the tax software and email level for application access. This layered approach means that if one authentication layer is bypassed, additional controls remain in place. For staff working from areas with limited or no cellular service, hardware tokens are the most reliable backup since they generate authentication codes independently without requiring a network connection. Document remote access MFA procedures in your WISP, including what to do when a device is lost or a staff member cannot complete authentication.
IRS Publication 4557 and the FTC Safeguards Rule both require annual review of your Written Information Security Plan, which includes your MFA implementation. That annual review should verify that every in-scope system still has MFA enabled, confirm that new staff have completed MFA setup and training, update the system inventory to include any platforms added during the year, test backup and recovery procedures, and verify that former employees' MFA-enrolled devices have been removed from all systems. Schedule this review between May and September, well before the next filing season, and document the review date and responsible party in your WISP.
The IRS Publication 4557 and FTC Safeguards Rule MFA requirements apply to your firm's staff accounts, the individuals accessing, storing, or transmitting taxpayer data. Requiring MFA for clients accessing a portal is not explicitly mandated for clients themselves, but it is a recommended best practice, particularly where clients upload or access tax documents. At minimum, all staff accounts for administering those portals must have MFA enabled. Some portal providers, including ShareFile and TaxDome, offer configurable MFA policies for client accounts. Enabling it where available significantly reduces the risk of unauthorized access to client-uploaded documents.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.


