Cybersecurity Requirements for Maryland CPA Firms: State Rules, Federal Requirements, and WISP

Share Post :

For CPA firms operating in Maryland, cybersecurity obligations are driven by several layers of regulation rather than a standalone state CPA rule devoted to cybersecurity. The Maryland Department of Labor’s Board of Public Accountancy regulates the profession and CPA firms, while Maryland’s Board of Individual Tax Preparers separately imposes data-security requirements on covered tax preparers. Federal requirements add another important layer for tax and accounting practices, including the legal requirement for tax professionals to maintain a Written Information Security Plan.

An actively licensed Maryland CPA is exempt from Maryland’s individual tax-preparer registration requirement, so the state’s tax-preparer cybersecurity rule should not simply be described as a blanket requirement imposed on every Maryland CPA. The firm’s actual obligations depend on the services it provides, the information it handles, and the federal and state rules that apply to its activities.

This comprehensive guide breaks down the compliance landscape across multiple regulatory tiers:

  • Maryland professional regulation
  • Maryland tax-preparer data security
  • Federal requirements and the Gramm-Leach-Bliley Act
  • Written Information Security Plan frameworks
  • Essential technical security controls
  • Third-party vendor management
  • State data breach notification statutes
  • Maryland privacy law applicability
  • Practical compliance execution checklists

Does Maryland have a specific cybersecurity requirement for CPA firms?

Maryland does not have a standalone CPA cybersecurity mandate.

The Maryland Board of Public Accountancy operates within the Maryland Department of Labor and is responsible for professional standards, licensing, and regulation of CPAs and CPA firms. However, the state’s CPA regulatory framework should not be represented as a dedicated cybersecurity statute.

A Maryland CPA firm’s cybersecurity obligations do not come from one single provision called a Maryland CPA cybersecurity law. Instead, several requirements can apply simultaneously depending on the operational profile of the practice.

A CPA firm providing accounting or tax services is not automatically the same legal category as an individual registered Maryland tax preparer. That distinction prevents inaccurate claims that Maryland requires all CPAs to maintain a WISP under its tax-preparer law.

The professional regulator and the data-security regulator are distinct authorities governed by separate statutory boundaries.

What Maryland requires for client data security

Maryland addresses client records and data security specifically through COMAR 09.38.01.05, which governs individual tax preparers registered under the state Board of Individual Tax Preparers.

The regulation requires the individual tax preparer to implement reasonable safeguards to protect client data and maintain a Written Information Security Plan designed to ensure compliance with best cybersecurity practices.

Maryland’s individual tax-preparer registration requirements explicitly include statutory exemptions for actively licensed CPAs, attorneys in good standing, and enrolled agents.

This regulatory exemption means that while registered tax preparers are directly bound by COMAR data-security rules, actively licensed CPAs are governed primarily by their professional licensing standards, federal financial data rules, and general state privacy statutes.

The Maryland rule establishes the overarching state obligation to protect client information, but a firm’s technical controls must scale appropriately to its operational risks rather than relying on a single state checklist.

What the federal requirements add for CPA and tax practices

The federal compliance layer is not an optional addition for professional practices. Federal regulatory standards directly govern tax and accounting practices, specifically mandating that tax professionals maintain a comprehensive Written Information Security Plan to safeguard sensitive client records.

The Gramm-Leach-Bliley Act (GLBA) and the FTC Safeguards Rule form the core of this federal framework. The FTC explicitly designates tax preparation firms and professional accounting practices as financial institutions subject to its oversight.

The FTC Safeguards Rule mandates several core program elements:

  • A written information-security program
  • A designated qualified individual responsible for program oversight
  • Comprehensive risk assessments
  • Administrative, technical, and physical safeguards
  • Robust access controls
  • Data encryption across all storage tiers and transmission channels
  • Mandatory multi-factor authentication
  • Continuous monitoring and regular testing of security controls
  • Formal employee security awareness training
  • Oversight and vetting of third-party service providers
  • Documented incident response procedures

A Maryland CPA firm cannot determine its regulatory exposure solely by reviewing state licensing provisions. Because these firms routinely handle sensitive financial and taxpayer data, federal rules apply directly to their daily operations.

The Internal Revenue Service (IRS) reinforces these federal mandates through official administrative guidance, emphasizing that tax professionals must maintain an active security plan regardless of firm size.

Key federal reference resources include:

  • IRS Publication 4557 (Safeguarding Taxpayer Data)
  • IRS Publication 5708 (Creating Your WISP)
  • Publication 5293 and Publication 5709 security documentation
  • The official Taxes-Security-Together Checklist

Federal law establishes the statutory legal obligations, while IRS publications provide actionable blueprints to operationalize those security mandates within accounting practices.

What a Maryland CPA firm’s WISP should contain

A Written Information Security Plan serves as the core operational blueprint governing a firm’s data protection architecture. The IRS specifies that an effective WISP must match the precise operational profile, scale, complexity, and sensitivity profile of the accounting practice.

The information security program requires a dedicated leader. For small CPA practices, this does not mean creating a corporate Chief Information Security Officer position.

The mandate requires that administrative responsibility is explicitly assigned to a qualified individual possessing sufficient authority, technical knowledge, and operational oversight to supervise the security controls.

Every security plan must begin with a comprehensive data inventory. A firm cannot secure sensitive files if it fails to track where files reside across digital workspaces.

Primary data categories requiring strict cataloging include:

  • Social Security numbers and federal tax identification numbers
  • Completed individual and corporate tax returns
  • W-2, 1099, and comprehensive payroll schedules
  • Bank account details, routing codes, and payment card information
  • Balance sheets, income statements, and source financial documents
  • Government-issued identification credentials
  • Portal credentials, user accounts, and authentication keys

The security plan must map out exact data storage and transmission channels across the technological environment.

This environment typically includes:

  • Local workstations, office laptops, and mobile devices
  • Dedicated tax preparation and bookkeeping software instances
  • Cloud storage directories and remote file servers
  • Local and cloud-based backup systems
  • Client communication portals and encrypted email servers

Once information assets and storage channels are mapped, the plan must document foreseeable internal and external threats.

Critical threat vectors include credential theft via phishing, business email compromise, ransomware injection, unauthorized staff access, lost mobile hardware, and vulnerable software dependencies. The WISP documents exact technical safeguards deployed to mitigate each identified risk vector, outlines incident detection protocols, and sets mandatory intervals for program review based on operational shifts or software updates.

Cybersecurity controls Maryland CPA firms should have in place

Technical security controls form the operational wall defending client data against active intrusions. Deploying these controls requires multi-layered technical measures rather than basic perimeter tools.

Multi-factor authentication must be enforced across all systems handling sensitive client data. Mandatory deployment targets include email clients, tax preparation portals, cloud storage volumes, remote desktop access gateways, and administrator privilege accounts.

Data encryption must secure files across two operational states:

  • Data at rest, covering local hard drives, portable storage media, and cloud database volumes
  • Data in transit, securing files moving across web portals, client communications, and local networks

Access controls must enforce strict least-privilege permissions. Individual employee accounts prevent shared credential risks, while strict access reviews ensure departing staff lose network access immediately.

Secure document exchange replaces traditional unencrypted email attachments with dedicated client portals featuring authenticated login layers and automated expiration protocols. Endpoint security requires active vulnerability patching, supported operating system lifecycles, and managed endpoint detection and response software.

Robust backup management demands offline or immutable backup repositories capable of withstanding ransomware encryption attacks. Regular recovery testing ensures that stored data can be restored cleanly within acceptable operational timeframes.

Third-party service providers and Maryland CPA firms

CPA firms routinely rely on external technology vendors for tax software, cloud accounting platforms, payroll processing, managed IT services, and cloud storage hosting. Outsourcing software infrastructure does not transfer legal accountability for client data protection.

Federal tax guidance and FTC standards require accounting practices to vet service providers prior to engagement.

Firms must actively verify vendor security controls, including MFA enforcement, data encryption standards, access management protocols, and contractual breach notification timelines. Contracts must specify data deletion standards upon termination and restrict unauthorized subcontractor usage.

Maryland data breach requirements for CPA firms

When a security incident breaches a firm’s digital defenses, statutory response obligations take effect under the Maryland Personal Information Protection Act (PIPA).

PIPA protects personal information defined as an individual’s first name or initial and last name combined with sensitive identifiers such as Social Security numbers, driver’s license numbers, or financial account credentials.

When a security event occurs, the firm must perform a prompt internal investigation to determine the exact scope, nature, and exposure level of the incident before triggering public notifications.

If the investigation confirms that misuse of personal information has occurred or is reasonably likely to occur, the firm must notify affected Maryland residents and the Maryland Office of the Attorney General.

State statute mandates that consumer notifications must be delivered as soon as reasonably practicable, not exceeding 45 days from the discovery of the security breach. Notices directed to the Attorney General must include a detailed narrative of the incident, the count of impacted residents, sample copies of issued notices, and remediation steps taken to secure systems.

Does Maryland’s Online Data Privacy Act apply to CPA firms?

The Maryland Online Data Privacy Act (MODPA) establishes a broad comprehensive consumer privacy framework. However, determining its applicability to a CPA firm requires evaluating specific statutory exemptions and volume thresholds.

MODPA incorporates a specific structural exemption for financial institutions and affiliates subject to the Gramm-Leach-Bliley Act (GLBA).

Because many CPA firms handling financial and tax data fall under GLBA jurisdiction as financial institutions, they frequently qualify for this statutory carve-out from MODPA consumer rights and data processing rules.

Firms must evaluate their specific service lines, data volumes, and revenue thresholds to confirm whether any non-exempt data processing brings them within the scope of Maryland’s privacy enforcement framework.

How the requirements fit together for a Maryland CPA firm

Understanding the multi-layered compliance obligations requires a clear structural hierarchy:

  • Maryland Department of Labor (Board of Public Accountancy): Governs general professional licensure, firm permits, and ethical practice standards.
  • Maryland Board of Individual Tax Preparers (COMAR 09.38.01.05): Imposes tax-preparer data security mandates, noting that actively licensed CPAs maintain statutory exemptions from individual registration.
  • Internal Revenue Service (IRS): Mandates that all tax professionals protect taxpayer data and maintain an active Written Information Security Plan.
  • Federal Trade Commission (FTC Safeguards Rule / GLBA): Requires covered financial and tax preparation institutions to implement formal information security programs with designated oversight.
  • Maryland Personal Information Protection Act (PIPA): Governs statutory data breach investigations and 45-day notification timelines.
  • Maryland Online Data Privacy Act (MODPA): Enforces broader consumer privacy mandates where activities fall outside GLBA exemptions or statutory thresholds.

Maryland CPA firm cybersecurity compliance checklist

To ensure full operational compliance across state and federal regulatory frameworks, Maryland CPA practices should execute and maintain the following checklist steps:

1. Regulatory & Licensing Review

  • Confirm active Maryland CPA firm permits with the Board of Public Accountancy.
  • Verify whether any non-CPA administrative support staff require individual tax preparer registrations under COMAR.
  • Audit applicability triggers under state data breach and privacy statutes.

2. Federal Compliance Alignment

  • Assess coverage status under the FTC Safeguards Rule based on financial services provided.
  • Implement mandated IRS taxpayer data safeguarding controls across all workstations.
  • Formally assign program management responsibility to a designated qualified individual.

3. WISP Documentation & Asset Mapping

  • Build a complete inventory of all sensitive client files, Social Security numbers, and tax returns.
  • Map digital storage channels, cloud servers, mobile hardware, and email transit paths.
  • Document foreseeable threat vectors, including ransomware and phishing vectors.
  • Outline formal incident response workflows and yearly program review schedules.

4. Technical Security Controls Deployment

  • Enforce multi-factor authentication across email, tax software, cloud storage, and admin portals.
  • Deploy end-to-end data encryption for all files at rest and in transit.
  • Implement least-privilege user access controls and immediate offboarding protocols.
  • Establish secure client document exchange portals to eliminate unencrypted email attachments.
  • Maintain immutable backup repositories with verified periodic recovery testing.

5. Third-Party Vendor Auditing

  • Review cloud service contracts, tax software vendors, and managed IT provider agreements.
  • Verify vendor MFA compliance, data encryption standards, and breach notification terms.

What Maryland CPA firms should be able to demonstrate

Regulatory compliance requires active operational proof rather than static paper documentation.

Examiners and federal oversight bodies look for verifiable operational evidence:

  • An up-to-date WISP reflecting current firm infrastructure and software tools
  • Formal documentation of periodic risk assessments
  • Assigned leadership credentials for information security oversight
  • Signed employee cybersecurity training attendance records
  • Periodic user access review logs and prompt offboarding timestamps
  • Third-party vendor security assessment questionnaires and signed contracts
  • Regular backup verification and recovery test results
  • Incident response logs detailing historical event investigations and WISP review updates

FAQs

Do Maryland CPA firms have a specific state cybersecurity law?

No standalone Maryland CPA cybersecurity statute exists. Cybersecurity obligations for CPA firms are shaped by a combination of professional licensing standards, tax data security regulations, federal GLBA and FTC rules, and state data breach statutes.

Are Maryland CPAs required to register as tax preparers?

Actively licensed CPAs maintain a statutory exemption from Maryland’s individual tax-preparer registration requirements under the Maryland Board of Individual Tax Preparers framework.

Are tax professionals required to have a WISP?

Yes. Federal tax authorities require tax professionals to create and maintain an active Written Information Security Plan to safeguard sensitive client and taxpayer data.

Does the FTC Safeguards Rule apply to CPA firms?

The FTC explicitly lists tax preparation and accounting practices among financial institutions covered by the Safeguards Rule, requiring formal written information security programs.

What does Maryland require after a client-data breach?

Under PIPA, firms must execute an internal investigation and, if data misuse is likely, notify affected Maryland residents and the Maryland Attorney General within 45 days.

Does MODPA apply to Maryland accounting firms?

Applicability depends on statutory data thresholds and exemptions, notably including exclusions for financial institutions and data governed directly by the GLBA.

Search

Recent Posts

Scroll to Top