Password and MFA Policy for Tax Firms: What Your WISP Must Include
Weak passwords and missing multi-factor authentication are responsible for the majority of tax preparer data breaches. Credential theft is the most common entry point for attackers targeting tax professionals.
What the Rule Requires
MFA was upgraded from a recommendation to a mandate in the 2024 update to IRS Publication 5708, and the FTC Safeguards Rule requires access controls in writing — which means your WISP has to say what yours are.
Password Requirements to Document
Minimum length, complexity, reuse rules, rotation policy, password manager use, and an explicit prohibition on shared logins. Each one belongs in the plan, not just in practice.
Which Systems Must Have MFA
Tax preparation software, email, cloud storage, client portals, and any remote access path. Not all MFA is equal — app-based and hardware tokens are stronger than SMS, and your policy should say which you accept.
Credential Compromise Response
A password policy without an incident path is half a policy. Your WISP should say what happens the moment a credential is suspected compromised.