Skip to the main content.
For CPA, Accounting, and Tax Firms

Your firm runs on trust. Your Microsoft 365 should prove it.

The FTC classifies tax preparation firms as financial institutions, and the IRS requires every paid preparer to keep a Written Information Security Plan. ABT manages Microsoft 365 for 750+ banks, credit unions, and mortgage companies under the same rule family. Your firm can run the same platform, with the same protections, at the same published price.

  • Tier 1 Microsoft Cloud Solution Provider
  • 750+ financial institutions
  • Since 1999
  • SOC 1 Type II and SOC 2 Type I attestations
Microsoft 365

The nine elements the FTC expects

  • 1A named Qualified Individual
  • 2A written risk assessment
  • 3Safeguards: access controls, encryption, MFA
  • 4Regular testing and monitoring
  • 5Security awareness training
  • 6Service provider oversight
  • 7A program you keep current
  • 8A written incident response plan
  • 9Annual reporting to leadership

From the FTC Safeguards Rule, 16 CFR 314.4. The readiness check below walks your firm through them in about two minutes.

The Two-Minute Check

Safeguards Readiness Check

Ten questions. Two minutes. See where your firm stands against the nine elements the FTC already expects.

Answer from what you know is true today, not what the plan says. Yes, no, and not sure all count, and not sure is often the most useful answer of the three. The ten questions are practical checkpoints across the elements, not the whole rule; the assessment verifies the technical half against the actual tenant.

Is one named person accountable for information security at your firm?Qualified Individual

Do you have a written information security plan you could show the IRS or a client tomorrow?Written plan

Is multifactor authentication required for every account, with no exceptions for partners?Access controls

Is client data encrypted in transit and at rest, including email that leaves the firm?Encryption

Can former employees or old vendor accounts still sign in?Access review

Would you know within a day if someone signed in from an unexpected country?Monitoring

Have staff been phishing-tested in the last 12 months?Training

Do you know which vendors touch client data, and have you reviewed their security?Service providers

Do you have a written plan for what happens in the first 24 hours of a breach?Incident response

Could you produce a security report for your partners or an insurer this week?Reporting

0 of 10 answered

?
Your grade
0
Points out of 10
0
Elements to look at

Your answers are self-reported, so this grade is a conversation starter, not an audit. The free security assessment is the version where our engineers read the actual tenant.

The grade computes right here in your browser. Nothing is stored or sent anywhere unless you choose to submit the assessment form below.

How this check is scored
  • Each yes counts one point. Each not sure counts half a point and gets flagged to verify, because a control nobody can confirm is not a control you can rely on. Each no counts zero.
  • Question five runs the other way. Former employees or old vendor accounts still being able to sign in is the problem, so a no earns the point there.
  • Grades follow the total: A at nine points or better, B at seven and a half, C at six, D at four, and F below that.
  • The ten questions are checkpoints across the nine elements, not a complete test of the rule. A firm can score well here and still have gaps that only show up in the tenant itself.
Start the free assessment

The engineer-run version of what you just did by hand. Free, no obligation.

The Two Letters Behind This Page

Is a CPA firm really a financial institution?

For any firm that prepares returns for pay, yes. Federal regulation says so in as many words, and the IRS repeats the requirement every filing season. Two documents put your firm in the same category as a bank.

FTC

The Safeguards Rule says it in the rule text

"An accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution."

16 CFR 314.2(h), the FTC Safeguards Rule's own definitions

That sentence is not an interpretation. It is an example printed in the rule itself, and the FTC's Safeguards guidance lists tax preparation firms among covered businesses. Covered firms owe the FTC an information security program built on the nine elements above, and must notify the FTC within 30 days of discovering a breach involving 500 or more consumers' information. A firm holding information on fewer than 5,000 consumers is excused from four pieces: the written risk assessment, the prescribed continuous monitoring or annual testing regime, the written incident response plan, and the annual report. It is not excused from the program itself or the Qualified Individual.

IRS

The IRS requires the written plan

Every paid tax preparer is required to have a written information security plan.

IRS Publication 4557 and the annual Security Summit reminders

The IRS and its Security Summit partners remind preparers every filing season that federal law requires them to maintain a Written Information Security Plan, and IRS Publication 4557 points the requirement straight back at the Safeguards Rule. If you prepare returns for pay, this is already your obligation, whether or not anyone has said the words "financial institution" to you. The plan has to describe safeguards your firm actually runs, which is why the Microsoft 365 configuration underneath the document matters as much as the document. We walk through the requirement in plain language in our guide to the tax preparer WISP requirement.

The full story, with the rule text and every business the FTC's examples reach: read our breakdown of who the FTC Safeguards Rule actually covers.

The Baseline

What does bank-grade actually mean here?

It is not a slogan. It is a specific Microsoft 365 security baseline, verified by ABT's engineering team, deployed for every client from day one, and built under the same rule family that covers your firm.

80

Policies from day one

Guardian deploys 80 policy templates across 11 categories to every client tenant, covering 169 Microsoft Secure Score controls. Not a menu you pick from. The baseline.

11

Conditional Access policies

Enforcing MFA, risk-based access controls, device compliance, geo-blocking, and legacy authentication blocking through Microsoft Entra ID.

62

Mapped to your rule

62 of the 80 baseline policies are formally mapped to 16 CFR 314.4. That is the FTC Safeguards Rule, the one that covers CPA firms. Our mortgage clients live under it today, so the mapping already speaks your language.

DLP

Data loss prevention that acts

GLBA-focused DLP across Exchange, SharePoint, OneDrive, and Teams detects Social Security numbers, bank account numbers, credit card numbers, and ITINs. Matching outbound email is automatically encrypted, and matches generate alerts.

0

Tolerance on risky sign-ins

On any risk detection, ABT's automation immediately revokes all sessions and tokens, on top of Microsoft's Continuous Access Evaluation and the risk-based Conditional Access policies.

Nightly

Reporting with something behind it

Guardian Security Insights refreshes nightly, and ABT reviews it with clients on a scheduled cadence. The reporting element of the rule stops being a blank page.

Guardian configures Microsoft controls (Microsoft Entra ID, Purview, Defender, Intune) and monitors them for drift. The session and token revocation is ABT's own automation. Microsoft features are licensed by the firm; Guardian configures and operates what the licensing makes available.

The Map, Element by Element

Where Microsoft 365 supports the nine elements

ElementWhat the rule asks forHow Microsoft 365 helps
Qualified IndividualOne named person accountable for the programMicrosoft Entra ID admin roles give that person real scope and a full audit trail
Risk assessmentA written assessment of where client data is at riskMicrosoft Purview classification maps where the sensitive data actually lives
SafeguardsAccess limited to who needs it, data encrypted, MFA onEntra ID Conditional Access enforces MFA; Microsoft Purview encrypts sensitive outbound email
Testing and monitoringRegular testing of the safeguards, watching for unusual activitySign-in logs, audit logs, and Microsoft Secure Score read the tenant's real state
TrainingSecurity awareness training for everyone who touches client dataMicrosoft Defender for Office 365 attack simulation training phishes your own staff safely
Service providersVendors chosen and overseen for securityMicrosoft Defender for Cloud Apps shows which third-party apps reach your tenant
Keep it currentThe program updated as the firm and the threats changeSecure Score recommendations track Microsoft's current guidance, not last year's
Incident responseA written plan for the first 24 hours of a breachMicrosoft 365 audit logs and Defender alerts are where those hours actually happen
Annual reportingWritten reporting to owners or partners at least annuallyGuardian Security Insights refreshes nightly; ABT reviews it with clients on a cadence

The Price

One price list. It does not ask what industry you are in.

ABT publishes its security pricing, and the catalog has no industry dimension anywhere in it. A community bank, a mortgage lender, and a twelve-person tax office see the same numbers on the same page.

Guardian Foundation

The hardened tenant baseline plus Guardian Security Insights, included at no additional charge with Microsoft licensing through ABT.

The response tiers above it

Published per-user prices with 50-user minimums, listed for anyone to read.

Microsoft licensing

Billed at Microsoft's price.

This is not a discount, a match, or a promotion. It is how the catalog is built. The security a bank buys from ABT is the security your firm buys from ABT, at the price on the page.

Busy season is the wrong time to find out.

The assessment now, the hardening before January, and filing season runs on a tenant that is already locked down.

CPA Firm Security Assessment

Turn the check into your real picture

Our security engineers read your actual Microsoft 365 tenant through a secure, read-only connection, then hand you a written report: findings, risk ratings, and a step-by-step hardening roadmap, walked through on a call. Free, no obligation, and the report is yours either way.

Please fill in every field, then try again.

Free for CPA, accounting, and tax firms. No obligation, and nothing in your tenant changes during the assessment. If you used the readiness check above, your grade and answers ride along with this request so our engineers start with context. We use your information only to run your assessment and follow up about it.

Got it. You are on the list.

Our team will reach out within one business day to line up your CPA Firm Security Assessment. Nothing to prepare: the first call takes about fifteen minutes.

Questions

Fair questions, straight answers

Does the FTC Safeguards Rule apply to CPA firms?

Yes, if the firm is in the business of completing income tax returns. That example appears in the rule text itself, at 16 CFR 314.2(h), and the FTC's guidance lists tax preparation firms among covered businesses. The IRS reinforces it: paid tax professionals are required to maintain a Written Information Security Plan, and IRS Publication 4557 ties that duty to the Safeguards Rule.

What is a WISP and who needs one?

A WISP is a Written Information Security Plan: the written program the FTC Safeguards Rule requires of covered firms, and the document the IRS and its Security Summit partners tell paid preparers to maintain every filing season. It has to describe the safeguards your firm actually runs, which is why the Microsoft 365 configuration underneath the document matters as much as the document itself.

Can the Qualified Individual be outsourced?

The rule permits it. The Safeguards Rule allows the Qualified Individual to work for an affiliate or a service provider, as long as your firm retains ultimate responsibility for the program, designates a senior member internally to direct and oversee that person, and requires the provider to maintain its own information security program. What cannot be outsourced is the accountability: the program stays yours.

What does the free CPA Firm Security Assessment include?

Our security engineers connect to your Microsoft 365 tenant through a secure, read-only connection, review your configuration, and deliver a written report with specific findings, risk ratings, and a step-by-step hardening roadmap, then walk you through it on a call. Nothing in your tenant changes, there is no obligation, and the report is yours to keep whether or not we ever work together.

What does ABT cost for a CPA firm?

The same as it costs a bank. One price list. It does not ask what industry you are in. Guardian Foundation is included at no additional charge with Microsoft licensing through ABT, the response tiers carry published per-user prices with 50-user minimums on the Guardian page, and Microsoft licensing is billed at Microsoft's price. The free assessment is how you find out what, if anything, your firm actually needs.

Find out where your firm stands

Ten questions get you a grade. One form gets you the engineer-run version, free. Either way, you will know more about your firm's footing this afternoon than you did this morning.

Prefer to talk it through first? Talk to an expert.