Pro Blog | PK Tech

The CPA Firm Tech Stack for 5–75 People: What Runs Where, and Who Should Own It

Written by Jordan Hetrick | October 1, 2026

Most CPA firms in this size range didn't design their tech stack. They accumulated it. A partner picked practice management software in 2018. Someone's nephew set up the file server. QuickBooks got added because a client insisted. Five years later, the firm has eleven tools, three of them talking to each other, and nobody can say with confidence who's responsible when one of them breaks.

This is what happens when a service business grows by adding clients and staff faster than it adds infrastructure planning. But at 5 to 75 people, the gaps start to matter. A five-person firm can survive on a shared drive and good memory. A 75-person firm can't, and the accounting firm tech stack that got you from 5 to 25 usually isn't the one that should carry you to 75.

This blog breaks down what a firm's tech stack consists of at this size, which pieces belong to which layer, and who inside (or outside) the firm should own each one.

The Five Layers of a CPA Firm's Tech Stack

A CPA firm's technology sorts into five functional layers: practice management, production software, document and data infrastructure, client-facing communication, and security and compliance. Every firm has all five, whether or not anyone has named them that way.

Practice management is the operational backbone: time tracking, billing, workflow, due-date tracking, client and engagement records. This is the system of record for who's doing what and when it's due.

Production software is what produces the deliverable: tax preparation software such as UltraTax CS, CCH ProSystem fx, or Drake, audit tools, bookkeeping platforms like QuickBooks Online or Xero, and any specialty tools for niche services like R&D credit studies or valuations. This layer is usually the most fragmented because different service lines need different tools, and it's the layer that most firms feel least free to change, since staff fluency in a specific tax software package has taken years to build.

Document and data infrastructure covers where client files, working papers, and firm data live: SharePoint, a document management system like SmartVault or Doc.It, or in some smaller firms, still a shared network drive. This layer also includes backup and client document retention, where many firms have real exposure without realizing it.

Client-facing communication includes the client portal, e-signature tools, email, and increasingly, scheduling and intake tools that reduce back-and-forth during busy season. This layer is where clients form their opinion of the firm's competence, often independent of the quality of the actual work.

Security and compliance infrastructure is the layer most firms underinvest in relative to its actual legal weight. This includes identity and access management, multi-factor authentication, endpoint protection, encrypted transmission, and the written information security plan that ties it together. This layer is important because it carries legal obligations.

 Under the Gramm-Leach-Bliley Act, the FTC classifies tax return preparers as financial institutions, which means the FTC's Safeguards Rule requires firms to maintain safeguards to protect the security of customer information. In 2021, updates added more concrete requirements. An amendment adopted in 2023 and in effect since May 2024 requires firms to notify the FTC when unencrypted customer information of 500 or more people is acquired without authorization. The IRS reinforces the same expectation in Publication 4557, its guide to safeguarding taxpayer data. The current edition covers basic controls such as multi-factor authentication, encryption, and backups, how to spot and report data theft, and how to comply with the Safeguards Rule, and it points firms to Publication 5708 for building the written plan. 

How a CPA Firm's Tech Stack Changes From 5 to 75 People

At 5 to 15 people, the stack is usually thin by necessity, and that's fine. One practice management tool, one production suite per service line, a document system, and a portal cover most of what's needed. Ownership at this size is almost always the managing partner or a firm administrator wearing multiple hats, and that's an appropriate match for the workload. The risk at this stage is neglect, meaning that security tasks, in particular, tend to get skipped because no one explicitly owns them.

At 15 to 40 people, gaps start to show. Firms typically add a dedicated operations or administrative manager around this point, and that person often inherits software administration by default rather than by design. This is also where firms tend to accumulate redundant tools because different partners or departments adopted their own solutions before anyone coordinated purchases. A firm this size usually benefits from formally assigning a systems owner for each of the five layers, even if that person doesn't work on technology full-time.

At 40 to 75 people, the stack needs actual architecture. Firms at this size typically need either a part-time IT lead, a managed service provider relationship with oversight from inside the firm, or a full-time operations/IT hybrid role. The cost of an uncoordinated stack scales with headcount: a broken integration or a security gap that affects five people is an inconvenience, but the same problem affecting sixty people during the first two weeks of April is a crisis.

Who Should Own Each Layer of a CPA Firm Tech Stack

Ownership questions come up constantly in firm technology discussions, and the honest answer is that it depends less on firm size than on which layer is being discussed.

Practice management ownership belongs with someone who understands the firm’s workflow. This is usually an operations manager or a partner with operations insight. This person does not need deep software knowledge. They need to enforce consistent use. Practice management tools often fail due to inconsistent adoption rather than technical problems.

Production software ownership should sit close to the service line it supports. This means that the tax software administrator should be someone who prepares or reviews returns, because configuration decisions in tax software have technical implications that a purely administrative person will miss. The same logic applies to audit and bookkeeping tools.

Document infrastructure and security are where firms most often get ownership wrong. These two layers require actual technical competence, and assigning them to a partner or office manager without that background creates exposure. This is the layer where a managed service provider relationship earns its cost, provided someone inside the firm still owns the relationship and reviews what the provider reports back. A financial institution under FTC jurisdiction remains responsible for ensuring its affiliates and service providers safeguard customer information, so outsourcing execution doesn't outsource accountability. Firms should designate one internal person, even if their day job is something else entirely, as the accountable party who signs off on the security plan and knows what's in it.

Client communication tools usually work best when jointly owned, with an administrative lead handling day-to-day configuration. In contrast, a partner or marketing-minded staff member owns the client experience, since portal friction directly affects how clients perceive the firm.

Common Mistakes of CPA Firms With 5-75 People

The most frequent mistake is confusing "we bought good software" with "we're covered." A modern practice management platform doesn't create a written information security plan on its own, and a cloud-based tax product doesn't satisfy the FTC's requirement for a designated qualified individual overseeing the program. Firms are required to designate a single Qualified Individual to oversee their information security program, and firms that hold information on 5,000 or more consumers must also have that person report to leadership in writing at least once a year. That's a person, not a purchase.

The second common mistake is letting tool selection follow whoever complains loudest. A staff accountant who dislikes the current time tracker isn't necessarily right that a switch will help. Partners sometimes greenlight replacements out of frustration rather than a thorough cost-benefit review. Changing core software costs real time in migration and retraining, and firms in this size range often underestimate that cost until they're mid-migration during a busy period.

The third mistake, and probably the most expensive one, is treating security work as something to get to later. Every busy season, a CPA firm collects W-2s, 1099s, K-1s, bank statements, and Social Security numbers. The Safeguards Rule requires firms to encrypt customer information in transit over external networks and at rest, or to use alternative controls their Qualified Individual approves. Sending these documents as unencrypted email attachments is hard to square with that requirement.

How to Improve a CPA Firm Tech Stack Without Starting Over

None of this is suggesting firms should scrap everything and start over. Most firms with 5 to 75 people can get most of the way there by doing three things: naming an actual owner for each of the five layers (even informally); writing down the security plan the firm is already supposed to have, rather than assuming it exists somewhere; and reviewing the stack annually against headcount rather than letting tools persist by default.

The CPA firms that struggle most are the ones where nobody can answer a simple question quickly: who owns this, and what happens if it breaks during the second week of March. A firm's technology posture largely depends on the ability to clearly answer that question.

As a managed IT service provider, PK Tech brings more than 16 years of experience focused on accounting firms. PK Tech holds AICPA SOC 2 Type II attestation, verified through an independent third-party audit of its security and privacy controls.

Schedule a tech stack review with PK Tech.