Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

What Is IRS Publication 1075? The Plain-English Guide to FTI Safeguards

August 11, 2026
hero-what-is-irs-publication-1075-1.png

IRS Publication 1075 is the federal rulebook for protecting Federal Tax Information, or FTI. Its full title is “Tax Information Security Guidelines for Federal, State and Local Agencies.” The IRS Office of Safeguards issues and enforces it under Internal Revenue Code section 6103(p)(4). The goal is simple: keep taxpayer data safe wherever the government shares it.

The Office of Safeguards says its mission is to protect taxpayer confidence in the tax system. It does that by making sure FTI stays confidential wherever an agency holds it. The current version of Publication 1075 dates to November 2021.

If you work for a state agency, county program, or FTI contractor, this guide is for you. We’ll cover what counts as FTI, who must comply, and what the safeguards require.

Key Takeaways

  • IRS Publication 1075 protects Federal Tax Information (FTI) held by government agencies, not general business data.
  • It is not the FTC Safeguards Rule. That rule covers financial institutions under GLBA, a different law entirely.
  • FTI includes paper, electronic, and verbal data, tracked from the moment it’s received to final disposal.
  • Compliance flows down to every contractor, subcontractor, and cloud provider that touches FTI on an agency’s behalf.
  • The standard requires physical, technical, and operational safeguards, all built on the NIST SP 800-53 Rev 5 baseline.

Is IRS Publication 1075 the Same as the FTC Safeguards Rule?

No, IRS Publication 1075 is not the FTC Safeguards Rule. They’re two separate federal rules that happen to share a name. Confusing them can send you to the wrong compliance checklist entirely.

Publication 1075 governs Federal Tax Information held by government agencies. The FTC Safeguards Rule governs customer financial data at banks, lenders, and other financial institutions. Different issuing body, different protected data, different audience.

FeatureIRS Publication 1075FTC Safeguards Rule
Issued byIRS Office of SafeguardsFederal Trade Commission
ProtectsFederal Tax Information (FTI)Customer financial data under GLBA
Applies toGovernment agencies and their contractorsFinancial institutions and their service providers
Governing lawIRC section 6103(p)(4)Gramm-Leach-Bliley Act

If you run a bank, lender, or dealership, you may actually need the FTC Safeguards Rule explainer instead. This guide stays focused on FTI and the agencies that handle it.

What Counts as Federal Tax Information (FTI)?

FTI is any tax return or return information the IRS shares with an agency. It also covers information the agency generates from that data. The format doesn’t matter. FTI is FTI whether it’s on paper, in a database, or spoken out loud in a meeting.

FTI Chain-of-Custody Stages

Publication 1075 requires protection across every format, including:

  • Paper documents and printouts
  • Electronic files, databases, and emails
  • Verbal information shared in meetings or on the phone
  • Data embedded inside a derived report or spreadsheet

That’s the chain-of-custody standard, and it’s the part agencies most often underestimate. FTI has to be tracked from the moment it arrives. That includes every stage after: processing, storage, transmission, and final disposition or destruction. It isn’t enough to encrypt a file and call it done. An agency needs to know exactly where every piece of FTI lives, at every stage, at all times.

Who Has to Comply With Publication 1075?

Two groups are on the hook. First, the agency that receives FTI to run a program. Second, everyone downstream that touches FTI on that agency’s behalf. That includes contractors, subcontractors, cloud service providers, and data centers. The obligation flows down contractually, not just to the agency’s own staff.

Who Must Comply

In practice, that means Publication 1075 shows up across a wide range of government programs:

If your agency or your client falls into any of these categories, and FTI crosses your network at any point, Publication 1075 applies to you.

What Does Publication 1075 Actually Require?

Pub 1075 layers FTI-specific rules on top of the NIST SP 800-53 Rev 5 baseline mentioned earlier. Those rules split into three categories: physical, technical, and operational safeguards.

Physical Safeguards

Physical safeguards control who can physically get near FTI. Every person with access needs a background check first. Agencies must also run regular internal inspections of the spaces where FTI is stored.

Spec block listing the four components of the Tier 2 background investigation IRS Publication 1075 requires before FTI access.

The standard also applies a two-barrier rule. At least two independent physical barriers must separate FTI from anyone without a need-to-know, such as a locked door to a restricted area plus a separate locked cabinet inside it. FTI is treated as Moderate Risk Public Trust data, which requires a Tier 2 background investigation before access is granted. That investigation covers:

  • FBI fingerprinting, reviewed for suitability issues through the Identity History Summary
  • Local law enforcement checks covering everywhere the person lived, worked, or studied in the last 5 years
  • Citizenship and work-authorization verification, typically Form I-9 plus E-Verify
  • A recheck at least every 5 years, satisfied through enrollment in the FBI’s Rap Back program

Technical Safeguards

Technical safeguards protect FTI once it’s inside a system. They cover encryption, access control, and monitoring. This is where most of an IT contractor’s day-to-day work actually lives. Key technical controls include:

Operational Safeguards

Operational safeguards cover the day-to-day discipline that keeps the other two categories honest. Media sanitization procedures apply to any device that ever held FTI, before it’s reused or retired. Continuous monitoring runs through a SIEM (Security Information and Event Management) system, watching for suspicious activity in real time rather than relying on periodic checks alone.

The 2025 Safeguards Enhancements

Starting January 1, 2025, Publication 1075 asks for more than technical controls. Three new requirements sit on top of the NIST SP 800-53 Rev 5 baseline described above.

New Safeguards Requirements
  • Role-based security training for anyone who accesses FTI, completed before access is granted and refreshed every year after that
  • A documented insider-threat-awareness program, not just an external-threat posture
  • A tested incident response plan, meaning a plan that’s actually been run through a drill, not just written and filed away

For an agency’s IT contractor, this shifts the compliance conversation. Training records and drill logs now matter as much as firewall configs. If your MSP can’t show you a completed tabletop exercise, that’s a real gap heading into your next review.

How Compliance Is Verified

Publication 1075 doesn’t work like a certification you earn once and keep forever.

There is no official “Pub 1075 certified” status a business or IT vendor can buy. Compliance is demonstrated on an ongoing basis, not proven with a one-time certificate.

Instead, an agency proves compliance two ways: the document it files, and the review the IRS runs.

The Safeguard Security Report (SSR)

The Safeguard Security Report is the core document an agency submits to the IRS Office of Safeguards. It describes the processes, procedures, and security controls protecting FTI. If it’s sent by email, it has to use IRS-approved encryption methods. No exceptions.

The On-Site Review Cycle

The IRS Office of Safeguards reviews each agency that receives FTI at least once every three years. Reviewers evaluate the physical and logical controls protecting FTI. They trace it from the moment it’s received through processing, transmission, storage, and final disposition.

These reviews are now usually hybrid: a mix of on-site and remote activity. After the closing conference, the agency gets two documents.

One more requirement often gets missed. An agency planning to disclose FTI to a new contractor or agent has to notify the IRS Office of Safeguards in advance of that disclosure. Build this into your contracting timeline early. A rushed notification can delay a project launch.

What Happens If FTI Is Mishandled

The clock starts the moment you suspect a problem, not when you confirm one.

If FTI is lost, stolen, or improperly disclosed, the agency (or its contractor) must report the incident to the IRS Office of Safeguards and TIGTA within 24 hours of discovery.

That’s Section 10.0 of Publication 1075, “Reporting Improper Inspections or Disclosures.” TIGTA is the Treasury Inspector General for Tax Administration, the watchdog with jurisdiction over IRS-related matters. Both agencies need to hear from you, not just one.

The penalty structure behind that reporting clock is serious, and it applies at the individual level, not just the agency level:

Notice that unauthorized inspection alone, an employee just looking up a return they had no reason to view, is enough to trigger criminal exposure. It doesn’t require sharing the data with anyone.

What Compliance Looks Like Day to Day

None of this lives in a binder that gets reviewed once a year. It lives in the daily decisions an agency and its IT contractor make together.

A spreadsheet exported for a one-time report. A screen share on a support call. Both are FTI in motion, and both need the same chain-of-custody discipline as a database at rest.

That’s a lot of moving parts to track by memory. If you want the full requirement set laid out as one working document, the IRS Pub 1075 / FTI Safeguards checklist breaks every category above into a checkable list.

See Where You Stand

Not sure where your agency or your IT vendor actually stands against these requirements? Answer a few plain-English questions and get a clear read on your readiness level and the gaps to close before your next Office of Safeguards review. No sign-up required to see your result.

Take the free 2-minute IRS Pub 1075 / FTI Safeguards Risk-Check

Frequently Asked Questions

FTI stands for Federal Tax Information. It is a tax return, or information related to one, that the IRS shared with a government agency or generated from data the agency provided. It has to be protected the same way whether it is on paper, in a database, or discussed out loud in a meeting.

Publication 1075 is not itself a statute. It is the IRS’s official guidance for implementing the confidentiality safeguard requirements written into Internal Revenue Code section 6103(p)(4). Agencies that receive FTI are contractually and legally bound to follow it as a condition of getting that data.

The IRS Office of Safeguards enforces it. That office reviews each agency receiving FTI at least once every three years and collects the Safeguard Security Report each agency files describing its controls.

Yes. Any contractor, subcontractor, cloud provider, or data center that touches FTI on an agency’s behalf is bound by the same safeguard requirements as the agency itself. The obligation flows down through the contract, not just to government employees.

You must report it to the IRS Office of Safeguards and TIGTA within 24 hours of discovering it. Depending on what happened, individuals involved can also face federal criminal charges and the affected taxpayer can sue for civil damages.

They protect different data under different laws. Publication 1075 protects Federal Tax Information held by government agencies under the Internal Revenue Code. The FTC Safeguards Rule protects customer financial data at financial institutions under the Gramm-Leach-Bliley Act. They share a name and not much else.

No. There is no official Pub 1075 certification a business can earn or buy. Compliance is demonstrated on an ongoing basis through the agency’s Safeguard Security Report and its IRS Office of Safeguards review, not through a one-time credential.

Ready to Get Your Environment in Shape?

Publication 1075 compliance is an ongoing partnership between your agency and whoever manages your technical environment. LeadingIT supports government agencies and their contractors across Chicagoland with the encryption, access control, audit logging, and monitoring these requirements demand.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.