Password and MFA Policy for Tax Firms: What Your WISP Must Include
Weak passwords and missing multi-factor authentication are responsible for the majority of tax preparer data breaches. Credential theft — someone getting your username and password — is the most common entry point for attackers targeting tax professionals.
The IRS knows this. The FTC knows this. Which is why password and MFA requirements are now explicitly required in your Written Information Security Plan, with MFA upgraded from a recommendation to a mandate in the 2024 update to IRS Publication 5708.
Here's exactly what your password and MFA policy needs to cover, why each requirement exists, and how to document it in your WISP.
Why This Matters More for Tax Professionals
Tax preparers are high-value targets. You have what attackers want: names, Social Security numbers, income data, bank account information, and tax returns for dozens or hundreds of clients. All in one place.
A single compromised login credential to your tax software, cloud storage, or email account can expose every client you've ever served. The IRS receives thousands of reports each year from tax professionals whose accounts were accessed by unauthorized parties.
A strong password and MFA policy is the single highest-impact security control you can implement — and it costs nothing but a few minutes of setup.
What the FTC Safeguards Rule Requires
The FTC Safeguards Rule requires covered financial institutions (which includes tax preparers) to implement technical safeguards including:
- Access controls — limiting who can access customer information and under what circumstances
- Authentication — using multi-factor authentication for any individual accessing any information system containing customer information
The IRS Publication 5708 (updated August 2024) echoes this, explicitly requiring MFA for access to any system containing client data. The only exception is if your Qualified Individual has approved an alternative control in writing that provides equivalent or better security.
In practice, that exception is very narrow. MFA is the standard. If you're not using it, you need a documented reason why, and you need an approved alternative.
Part 1: Password Requirements
Your WISP must document minimum password standards for all systems that access client data. Here's what a compliant password policy looks like:
Minimum Requirements to Document
Password Length Require a minimum of 12 characters. The 2024 NIST guidelines (which the FTC follows) have moved away from complex character requirements toward length as the primary security factor. Longer passwords are harder to crack, even if they're simpler.
Complexity While length matters most, documenting that passwords should include a mix of uppercase letters, lowercase letters, numbers, and special characters adds an additional layer. Some systems enforce this automatically.
No Reuse Employees should not reuse passwords across different systems. A password used for tax software should not be the same as the one used for email or cloud storage. Document a prohibition on password reuse across firm systems.
No Sharing Each employee must have their own unique login credentials. Shared accounts make it impossible to track who accessed what and when. Document that sharing login credentials is prohibited.
Password Manager Consider documenting that employees are encouraged or required to use a password manager (1Password, Bitwarden, LastPass, etc.). This makes it practical to have unique, complex passwords for every system without requiring anyone to memorize them.
Change Requirements Current NIST guidance no longer recommends mandatory periodic password changes unless there's evidence of compromise — frequent forced changes tend to result in weaker passwords (Password1, Password2, etc.). Document your approach: either require changes annually or upon suspected compromise.
What to Include in Your WISP
Password Policy:
All firm personnel with access to client data must comply with the following
password requirements:
- Minimum 12 characters in length
- Include a combination of uppercase, lowercase, numbers, and special characters
- Unique to each system — no password reuse across firm applications
- Not shared with other employees under any circumstances
- Changed immediately upon suspected compromise
The firm recommends using a password manager to maintain strong, unique
passwords across all systems.
Part 2: Multi-Factor Authentication (MFA) Requirements
MFA is now required, not optional. Your WISP must document which systems require MFA and how it's implemented.
What Is MFA?
Multi-factor authentication requires users to verify their identity using two or more of the following:
- Something you know — a password or PIN
- Something you have — a phone, hardware token, or authenticator app
- Something you are — a fingerprint or face scan
The most common implementation for small tax practices is an authenticator app (Google Authenticator, Microsoft Authenticator, Authy) that generates a time-sensitive code after entering your password.
Which Systems Must Have MFA
Your WISP must require MFA for all systems containing or accessing client data. For most tax practices, this includes:
Mandatory — High Priority:
- Tax preparation software (ProConnect, Drake, Lacerte, UltraTax, etc.)
- Cloud storage (Dropbox, Google Drive, OneDrive, ShareFile)
- Email accounts (Google Workspace, Microsoft 365)
- Practice management software (TaxDome, Canopy, etc.)
- Remote desktop or VPN access
Mandatory — Medium Priority:
- Document management systems
- Client portals
- Any cloud-based accounting software
Best Practice:
- Payment processing systems
- Any other system accessed via the internet
Types of MFA — What's Acceptable
Not all MFA is equal. Your WISP should specify acceptable MFA methods:
Strong (Recommended):
- Authenticator apps (Google Authenticator, Microsoft Authenticator, Authy)
- Hardware security keys (YubiKey)
- Push notifications to a registered device
Acceptable:
- SMS text message codes (less secure than app-based MFA due to SIM-swapping attacks, but far better than no MFA)
Not Acceptable as a Substitute:
- Security questions alone
- Email-only verification codes (if email itself is the system being accessed)
What to Include in Your WISP
Multi-Factor Authentication Policy:
Multi-factor authentication is required for all personnel accessing any
information system containing client data, including but not limited to:
- Tax preparation software
- Cloud storage and file sharing services
- Email accounts
- Practice management systems
- Remote access to firm systems
Acceptable MFA methods include authenticator apps, hardware security keys,
and SMS verification codes. MFA must be enabled by all personnel within
[X] days of this policy's adoption.
Any exception to this requirement must be approved in writing by the
Designated Security Coordinator and must document an equivalent or
superior alternative control.
Part 3: Remote Access and Device Policies
Your password and MFA policy should also address remote access, since this is where credential theft most often leads to unauthorized access.
Document the following:
- VPN or secure connection required when accessing firm systems remotely
- Firm-issued devices are preferred for accessing client data
- Personal devices used for work must meet the firm's minimum security requirements (password/PIN, screen lock, up-to-date OS)
- Public Wi-Fi should not be used to access client data without a VPN
Part 4: Incident Response for Credential Compromise
Your policy should address what happens when a password is compromised or an account is suspected of unauthorized access:
- Immediately reset all passwords for the affected account
- Notify your Designated Security Coordinator
- Review access logs for the affected system
- Determine what data may have been accessed
- Follow your incident response plan
Document this procedure in your WISP so employees know exactly what to do without having to figure it out under pressure.
Putting It All Together
A complete password and MFA policy section in your WISP covers:
- Minimum password requirements (length, complexity, no sharing, no reuse)
- MFA requirement for all systems with client data
- Acceptable MFA methods
- Remote access security requirements
- Incident response for suspected credential compromise
- Employee acknowledgment that they've read and will follow the policy
This section doesn't need to be long — two to three pages is sufficient for most small practices. What matters is that it's specific to your actual systems and signed by your staff.
Making It Practical
The biggest barrier to strong password and MFA practices isn't knowledge — it's friction. Here's how to reduce it:
Deploy a password manager firm-wide. 1Password Teams and Bitwarden for Business both cost under $5/user/month and eliminate the "I can't remember that many passwords" problem entirely.
Use authenticator apps, not SMS. Take 10 minutes with each employee to set up Google Authenticator or Microsoft Authenticator on their phone for every critical system. It becomes second nature within a week.
Make it a condition of employment. Document in your policy that compliance with password and MFA requirements is mandatory. New employees set everything up before accessing client data.
How WISP Creator Helps
WISP Creator generates a complete, customized password and MFA policy section for your WISP based on your answers to a few questions about your current systems and practices. It identifies gaps, recommends specific improvements, and produces policy language you can adopt immediately.
Build your password policy in minutes →
This article is for informational purposes and does not constitute legal advice. Always refer to the official FTC Safeguards Rule, IRS Publication 5708, and current NIST guidelines for authoritative requirements.