Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Free IRS Publication 1075 Compliance Checklist:
Would Your Agency Pass a Safeguard Review?

IRS Publication 1075 Risk Check

  • 9 quick questions
  • Takes about 2 minutes
  • No sign-up to see your result

Your top next moves

    Nothing critical flagged. Keep everything current and re-check yearly.

    Book a call

    Use the interactive IRS Publication 1075 risk check below to see where your agency or department actually stands.

    Answer 8 quick questions, weighted toward encryption, access control, physical storage of FTI, and your SSR/SSP documentation, and get your audit-readiness score in about 2 minutes: your risk level, the specific gaps to close, and a printable checklist you can hand to your team or IT provider.

    No sign-up to see your result.

    What IRS Publication 1075 actually covers (the short version)

    IRS Publication 1075 sets the security and privacy rules for any state, local, or municipal agency, or contractor, that receives Federal Tax Information (FTI) from the IRS, think revenue and tax departments, child support enforcement, unemployment and benefits offices, and any finance or accounting office that touches FTI to do its job.

    It requires:

    • A documented System Security Plan (SSP) describing how you protect FTI
    • An annual Safeguard Security Report (SSR) submitted to the IRS Office of Safeguards
    • A set of technical, physical, and administrative safeguards: encryption, least-privilege access, physical storage controls, background-investigated staff, annual training, audit logging
    • A 24-hour incident-reporting process

    Agencies with recurring FTI access are also subject to a Safeguard Review, an on-site inspection the IRS Office of Safeguards conducts roughly every three years to verify all of the above.

    The checklist below is organized around those requirements.

    The Full IRS Publication 1075 Checklist

    Work through each area below. Anything you can’t confirm is a gap. If you can’t prove it, a reviewer can’t either.

    • 1. System Security Plan (SSP) and Safeguard Security Report (SSR):

      ✓ A current, written SSP describing how your agency protects FTI, updated within the last 12 months.

      ✓ Your annual SSR submitted to the IRS Office of Safeguards on time, every year, whether or not you’re due for an on-site review.

      ✓ A named owner for the SSR/SSP calendar so the submission doesn’t quietly lapse.

    • 2. Access Control and Least Privilege:

      ✓ A unique login for every user with FTI access, no shared accounts.

      ✓ Access granted strictly on a need-to-know basis, tied to job function.

      ✓ Access removed the same day someone changes roles or leaves.

    • 3. Encryption:

      ✓ FTI encrypted at rest with a FIPS-validated cryptographic module, on servers, laptops, and backups alike.

      ✓ FTI encrypted in transit (TLS 1.2 or higher) whenever it moves over a network, including the internet.

      ✓ Cloud environments storing or processing FTI held to the same encryption standard as on-prem systems.

    • 4. Physical Storage (the “Two Barrier Rule”):

      ✓ FTI in physical form (printouts, files, media, devices) stored behind at least two real barriers during non-duty hours, for example a locked cabinet inside a room with controlled entry.

      ✓ Restricted areas that hold FTI limited to authorized personnel, with entry controlled by a key card, cipher lock, or equivalent.

      ✓ Visitor logs and escort procedures for anyone without a need-to-know entering a restricted area.

    • 5. Background Investigations:

      ✓ A background investigation, including fingerprinting and a criminal-history check, completed for every employee and contractor before they’re granted FTI access.

      ✓ Coverage confirmed for existing staff, not just new hires going forward.

    • 6. Security Awareness Training:

      ✓ Annual security awareness training completed by everyone with FTI access, with signed records retained.

      ✓ Periodic refreshers between annual sessions.

    • 7. Audit Logging and Monitoring:

      ✓ Access logging enabled on every system that stores or processes FTI.


      ✓ Someone assigned to actually review those logs on a regular schedule, not just collect them.

    • 8. Incident Response and 24-hour Reporting:

      ✓ A written incident-response plan specific to a suspected FTI breach, loss, or improper disclosure.

      ✓ A named point of contact responsible for notifying the Treasury Inspector General for Tax Administration (TIGTA) and the IRS Office of Safeguards within 24 hours of discovering a possible incident.

    • 9. Media and Device Disposal:

      ✓ Secure destruction or sanitization of any device or media that held FTI before disposal or reuse.

      ✓ A documented disposal process staff actually follow, not just a policy on paper.

    • 10. Safeguard Review Readiness:

      ✓ Documentation organized so a triennial on-site Safeguard Review is a document walkthrough, not a scramble.

      ✓ A single point of contact who can produce the SSP, SSR history, training records, and background-investigation records on request.

    How to read your gaps?

    • 0 – 2 Gaps

      Strong Shape

    • 3 – 6 Gaps

      Real, findable gaps that would draw findings in a Safeguard Review.

    • 7+ Gaps or 2+ Critical Gaps

      You’d likely fail that review today, and depending on what’s missing, your agency’s FTI access itself may be at risk.

    Most of the technical items above, encryption, access controls, audit logging, live in your IT setup, not a policy binder, which is the half of IRS Publication 1075 a managed IT and cybersecurity partner operates for you.

    IRS Publication 1075 FAQ

    What is IRS Publication 1075 and who does it apply to?

    It’s the IRS’s tax information security guideline for any federal, state, or local agency, or their contractors, that receives, stores, processes, or transmits Federal Tax Information (FTI). That commonly includes revenue and tax departments, child support enforcement offices, unemployment and public-benefits agencies, and finance or accounting offices that use FTI for eligibility or verification work.

    How often does the IRS conduct a Safeguard Review?

    The IRS Office of Safeguards conducts on-site Safeguard Reviews on roughly a three-year (triennial) cycle for agencies with recurring FTI access, involving document review, interviews, and a physical inspection of where FTI is stored and processed.

    What is a Safeguard Security Report (SSR) and how often is it due?

    The SSR is the agency’s written report to the IRS Office of Safeguards describing its safeguards for FTI. It’s required annually, every year, independent of whether a triennial on-site Safeguard Review is scheduled that year. Missing or late SSRs are a common, avoidable finding.

    What happens if an agency fails a Safeguard Review?

    The IRS can suspend or terminate an agency’s FTI access when safeguards are inadequate, which, for many agencies, means losing access to the very data a program or funding stream depends on. Individuals can also face criminal penalties for unauthorized disclosure or inspection of FTI, and civil liability, separate from the agency-level consequences.

    What encryption does Publication 1075 require?

    FTI must be encrypted with a FIPS-validated cryptographic module both at rest (servers, laptops, backups) and in transit (TLS 1.2 or higher), and the requirement applies the same way whether the system is on-premises or in the cloud.

    Do small departments or single-purpose offices really need to comply?

    Yes. Publication 1075 applies based on whether you receive FTI, not on agency size. A small office with a handful of staff accessing FTI is still expected to meet the same SSP, SSR, encryption, access-control, and training requirements as a large state agency, just scaled to a smaller footprint.

    What do we do if we suspect an FTI breach or improper access?

    Notify the Treasury Inspector General for Tax Administration (TIGTA) and the IRS Office of Safeguards within 24 hours of discovering a possible incident, even before your investigation is complete. Speed of notification matters more than having every detail up front.

    Ready to close your gaps?

    If your result flagged gaps in encryption, access control, physical storage, or your SSR/SSP documentation, most of that is technical and process work an IT and cybersecurity partner handles day to day.

    LeadingIT helps Chicagoland government agencies and finance offices build the encryption, access controls, audit logging, and physical and administrative safeguards IRS Publication 1075 requires, and keep the SSP/SSR documentation current between reviews. We deliver this FOR agencies; there’s no IRS Safeguards “certification” an IT company can hold, and we don’t claim one.

    Email yourself the full result from the tool above, book a free 30-minute gap review, or contact us and see how we deliver IRS 1075-aligned IT and cybersecurity controls as a managed service.