If you run a small CPA firm, the FTC has already told you how it expects your staff to sign in. The guidance is short, in plain language, and aligns with a binding rule that covers tax preparers. This FTC password requirements accounting firm checklist walks through both so that you can score your firm in an afternoon.
The FTC's guide Start with Security: A Guide for Business includes a lesson titled "Require secure passwords and authentication." Read together with the FTC's broader data security guidance, it gives you five checks for your firm:
1. Passwords are complex and unique, and staff don't reuse them across business and personal accounts.
2. Passwords are stored securely, never in plain text.
3. Systems guard against brute-force guessing, for example by blocking unlimited rapid sign-in attempts.
4. Sensitive accounts require a second factor in addition to the password.
5. Every person signs in with their own credentials, not a shared login.
Be precise about where each one comes from. The first four appear in the FTC guide almost as listed. The guide recommends considering two-factor authentication, which is softer than a mandate. The fifth is not one of the guide's stated lessons, though its Chegg example faults credentials shared among employees. The requirement comes from the Safeguards Rule, which the next section covers.
The guide asks for complex and unique passwords, and its Drizly example defines those as long passwords not used for any other online service. IRS Publication 4557, the security guide for tax professionals, goes further and recommends passphrases and changing default or temporary passwords. Treat length as the practical means of meeting the FTC's complexity standard.
The guide itself is not binding. It shows how the FTC approaches data security.
The binding text is the Safeguards Rule. Three provisions matter for passwords.
Section 314.4(c)(5) is where the FTC's suggestion to consider multi-factor authentication becomes an obligation. It requires multi-factor authentication for any individual accessing any information system, unless your Qualified Individual approves in writing a reasonably equivalent or more secure control. The rule says "any information system." It does not say "sensitive accounts." If your tax software (such as Drake, UltraTax CS, or ProSystem fx), client portal, email, and remote access all hold customer information, the safe reading is that all of them need a second factor.
Section 314.4(c)(5) is where the FTC's "consider two-factor" becomes an obligation. It requires multi-factor authentication for any individual accessing any information system, unless your Qualified Individual approves in writing a reasonably equivalent or more secure control. The rule says "any information system." It does not say "sensitive accounts." If your tax software (such as Drake, UltraTax CS, or ProSystem fx), client portal, email, and remote access all hold customer information, the safe reading is that all of them need a second factor.
Section 314.4(c)(8) requires policies and controls to monitor and log authorized users' activity. That one decides the shared-login question, which comes next.
The rule applies to you as a tax preparer. IRS Publication 4557 instructs return preparers to develop a written information security plan (WISP) under the Safeguards Rule, and a contributed article in CPA Practice Advisor notes that the rule entered the enforcement stage on June 9, 2023. Firms that already follow Pub 4557 are partway there, since the two overlap heavily.
The Safeguards Rule never uses the phrase "shared login." It doesn't need to. A shared login breaks three of its requirements at once.
Start with authentication. Section 314.4(c)(1) asks you to authenticate users and permit access only to authorized ones. When four people use one username, the system authenticates a credential, not a person. You can't show an examiner who is authorized to do what.
Next, consider least privilege. The same provision requires that each person be limited to what they need. A shared account has a single permission level, so the bookkeeper sees what the partner sees.
Finally, look at logging. Section 314.4(c)(8) requires you to log authorized users' activities and detect misuse. A log entry that says "front-desk login opened the Henderson return at 9:40 p.m." tells you nothing useful. You can't investigate it, and you can't prove to a client or regulator that you tried.
Shared logins also create practical problems. When an employee leaves, you either change the password for everyone or leave the former employee's knowledge in circulation. A second factor attached to a shared account sends its codes to one phone, so everyone depends on one person's device.
The stakes extend past the FTC. IRS Tax Tip 2018-151, from September 2018 and now marked by the IRS as historical content, states that the IRS may treat a Safeguards Rule violation as a violation of Revenue Procedure 2007-40, which governs Authorized IRS e-file Providers. For a firm that files electronically, a login habit can become an e-file standing issue.
Most small firms pass the first check on paper. They have a password policy, and staff generally know not to use "Spring2026!". The failures tend to cluster in the other four.
Shared logins fail most often because they grow out of convenience. One account for the scanner, one for the tax software, one for the client portal. Nobody decided to break the rule. The account just never got split up.
MFA fails next, and usually in patches. Email has a second factor, but the tax software doesn't, or the office has it for in-building staff but not for remote access. Because the rule uses the term "any information system," partial coverage remains a gap.
Credential storage fails quietly. Passwords sit in a spreadsheet, a sticky note, or a browser profile on a shared computer. IRS Publication 4557 recommends a password manager, protected with a strong password.
Lockout fails because nobody checked. Many systems ship with lockout off or set to a very high number of attempts. The setting takes minutes to review and is rarely reviewed.
Here is a quick scorecard. Give your firm one point for each answer of yes:
Four or five points means you are in good shape and need to document it. Three or fewer means start with shared logins, then fill MFA gaps, because those two carry the largest compliance exposure and the smallest cost to fix.
As a managed IT service provider, PK Tech brings more than 16 years of experience working with small to medium-sized businesses. PK Tech holds AICPA SOC 2 Type II attestation, verified through an independent third-party audit of its security and privacy controls.
If you want a second set of eyes on your results, PK Tech can run this scorecard with you and write up the findings for your security plan. Get in touch with our team.