Free IRS Publication 1075 Compliance Checklist:
Would Your Agency Pass a Safeguard Review?
- 9 quick questions
- Takes about 2 minutes
- No sign-up to see your result
Your top next moves
Use the interactive IRS Publication 1075 risk check below to see where your agency or department actually stands.
Answer 8 quick questions, weighted toward encryption, access control, physical storage of FTI, and your SSR/SSP documentation, and get your audit-readiness score in about 2 minutes: your risk level, the specific gaps to close, and a printable checklist you can hand to your team or IT provider.
No sign-up to see your result.
What IRS Publication 1075 actually covers (the short version)
IRS Publication 1075 sets the security and privacy rules for any state, local, or municipal agency, or contractor, that receives Federal Tax Information (FTI) from the IRS, think revenue and tax departments, child support enforcement, unemployment and benefits offices, and any finance or accounting office that touches FTI to do its job.
It requires:
- A documented System Security Plan (SSP) describing how you protect FTI
- An annual Safeguard Security Report (SSR) submitted to the IRS Office of Safeguards
- A set of technical, physical, and administrative safeguards: encryption, least-privilege access, physical storage controls, background-investigated staff, annual training, audit logging
- A 24-hour incident-reporting process
Agencies with recurring FTI access are also subject to a Safeguard Review, an on-site inspection the IRS Office of Safeguards conducts roughly every three years to verify all of the above.
The checklist below is organized around those requirements.
The Full IRS Publication 1075 Checklist
Work through each area below. Anything you can’t confirm is a gap. If you can’t prove it, a reviewer can’t either.
- 1. System Security Plan (SSP) and Safeguard Security Report (SSR):
✓ A current, written SSP describing how your agency protects FTI, updated within the last 12 months.
✓ Your annual SSR submitted to the IRS Office of Safeguards on time, every year, whether or not you’re due for an on-site review.
✓ A named owner for the SSR/SSP calendar so the submission doesn’t quietly lapse. - 2. Access Control and Least Privilege:
✓ A unique login for every user with FTI access, no shared accounts.
✓ Access granted strictly on a need-to-know basis, tied to job function.
✓ Access removed the same day someone changes roles or leaves. - 3. Encryption:
✓ FTI encrypted at rest with a FIPS-validated cryptographic module, on servers, laptops, and backups alike.
✓ FTI encrypted in transit (TLS 1.2 or higher) whenever it moves over a network, including the internet.
✓ Cloud environments storing or processing FTI held to the same encryption standard as on-prem systems. - 4. Physical Storage (the “Two Barrier Rule”):
✓ FTI in physical form (printouts, files, media, devices) stored behind at least two real barriers during non-duty hours, for example a locked cabinet inside a room with controlled entry.
✓ Restricted areas that hold FTI limited to authorized personnel, with entry controlled by a key card, cipher lock, or equivalent.
✓ Visitor logs and escort procedures for anyone without a need-to-know entering a restricted area. - 5. Background Investigations:
✓ A background investigation, including fingerprinting and a criminal-history check, completed for every employee and contractor before they’re granted FTI access.
✓ Coverage confirmed for existing staff, not just new hires going forward. - 6. Security Awareness Training:
✓ Annual security awareness training completed by everyone with FTI access, with signed records retained.
✓ Periodic refreshers between annual sessions. - 7. Audit Logging and Monitoring:
✓ Access logging enabled on every system that stores or processes FTI.
✓ Someone assigned to actually review those logs on a regular schedule, not just collect them. - 8. Incident Response and 24-hour Reporting:
✓ A written incident-response plan specific to a suspected FTI breach, loss, or improper disclosure.
✓ A named point of contact responsible for notifying the Treasury Inspector General for Tax Administration (TIGTA) and the IRS Office of Safeguards within 24 hours of discovering a possible incident. - 9. Media and Device Disposal:
✓ Secure destruction or sanitization of any device or media that held FTI before disposal or reuse.
✓ A documented disposal process staff actually follow, not just a policy on paper. - 10. Safeguard Review Readiness:
✓ Documentation organized so a triennial on-site Safeguard Review is a document walkthrough, not a scramble.
✓ A single point of contact who can produce the SSP, SSR history, training records, and background-investigation records on request.
How to read your gaps?
- 0 – 2 Gaps
Strong Shape
- 3 – 6 Gaps
Real, findable gaps that would draw findings in a Safeguard Review.
- 7+ Gaps or 2+ Critical Gaps
You’d likely fail that review today, and depending on what’s missing, your agency’s FTI access itself may be at risk.
Most of the technical items above, encryption, access controls, audit logging, live in your IT setup, not a policy binder, which is the half of IRS Publication 1075 a managed IT and cybersecurity partner operates for you.
IRS Publication 1075 FAQ
It’s the IRS’s tax information security guideline for any federal, state, or local agency, or their contractors, that receives, stores, processes, or transmits Federal Tax Information (FTI). That commonly includes revenue and tax departments, child support enforcement offices, unemployment and public-benefits agencies, and finance or accounting offices that use FTI for eligibility or verification work.
The IRS Office of Safeguards conducts on-site Safeguard Reviews on roughly a three-year (triennial) cycle for agencies with recurring FTI access, involving document review, interviews, and a physical inspection of where FTI is stored and processed.
The SSR is the agency’s written report to the IRS Office of Safeguards describing its safeguards for FTI. It’s required annually, every year, independent of whether a triennial on-site Safeguard Review is scheduled that year. Missing or late SSRs are a common, avoidable finding.
The IRS can suspend or terminate an agency’s FTI access when safeguards are inadequate, which, for many agencies, means losing access to the very data a program or funding stream depends on. Individuals can also face criminal penalties for unauthorized disclosure or inspection of FTI, and civil liability, separate from the agency-level consequences.
FTI must be encrypted with a FIPS-validated cryptographic module both at rest (servers, laptops, backups) and in transit (TLS 1.2 or higher), and the requirement applies the same way whether the system is on-premises or in the cloud.
Yes. Publication 1075 applies based on whether you receive FTI, not on agency size. A small office with a handful of staff accessing FTI is still expected to meet the same SSP, SSR, encryption, access-control, and training requirements as a large state agency, just scaled to a smaller footprint.
Notify the Treasury Inspector General for Tax Administration (TIGTA) and the IRS Office of Safeguards within 24 hours of discovering a possible incident, even before your investigation is complete. Speed of notification matters more than having every detail up front.
Ready to close your gaps?
If your result flagged gaps in encryption, access control, physical storage, or your SSR/SSP documentation, most of that is technical and process work an IT and cybersecurity partner handles day to day.
LeadingIT helps Chicagoland government agencies and finance offices build the encryption, access controls, audit logging, and physical and administrative safeguards IRS Publication 1075 requires, and keep the SSP/SSR documentation current between reviews. We deliver this FOR agencies; there’s no IRS Safeguards “certification” an IT company can hold, and we don’t claim one.
Email yourself the full result from the tool above, book a free 30-minute gap review, or contact us and see how we deliver IRS 1075-aligned IT and cybersecurity controls as a managed service.