Before you sign, make sure your answers hold up.
Your PTIN renewal, your cyber insurance application and the cyber supplement to your E&O renewal all ask about your firm's security. This check scans your email domain, asks the 10 questions those forms turn on, grouped the way insurers group them, and shows which answers you can prove today, sized to your firm. Then take home a written security plan marked where you fall short.
What a CPA firm has to be able to show in 2026
Tax and accounting firms are financial institutions under the FTC Safeguards Rule. That means a written security program, a named person responsible for it, multi-factor authentication for anyone who accesses your systems, encryption, training and vendor oversight. Firms holding data on fewer than 5,000 consumers are excused from four items, not from the rest.
In Texas, a 2025 law (Business and Commerce Code chapter 542) protects firms under 250 employees from punitive damages after a breach, but only if they can show they implemented and maintained a qualifying cybersecurity program at the time. What qualifies depends on headcount. Cyber insurers ask the same questions, and the answers matter: in Travelers v. International Control Services (2022), the parties agreed the policy was void from the start after the application said MFA was in place and a ransomware attack showed otherwise.
How the check works: Yes means you could show the proof today. No and Not sure both count as gaps. If you are not sure, assume you could not prove it. The scans use public sources and your company domain only, and nothing is sent to anyone at your firm.
Your answers stay in your browser. If you ask for the proof pack, it arrives as a Word document built from your answers: your result, the rules for a firm your size, the deadlines, and a written security plan you can edit. This is a readiness tool, not legal advice.
CPA firm security questions, answered
Insurers and regulators ask for proof, not policies. We test the controls in your actual systems and show what holds up.
Since May 1, 2026, our forensic audits have prevented $2.2M in wire fraud, none of it flagged first by the client's IT team, managed service provider, bank or security tools.
.png)