Authorization program · Last verified

Tax Information Security Guidelines for Federal, State and Local Agencies

IRS Publication 1075 sets the controls agencies, agents, contractors and sub-contractors must meet as a condition of receiving Federal Tax Information. The IRS's Office of Safeguards enforces it directly through on-site, remote or hybrid safeguard reviews, not through third-party certification.

Class
Authorization program
Owner
Internal Revenue Service — Office of Safeguards
Last verified

What it is

Publication 1075 is titled, on its own cover page, "Tax Information Security Guidelines For Federal, State and Local Agencies — Safeguards for Protecting Federal Tax Returns and Return Information."

The IRS states its own mission for the document: "The Mission of Safeguards is to promote taxpayer confidence in the integrity of the tax system by ensuring the confidentiality of IRS information provided to federal, state, and local agencies. Safeguards verifies compliance with Internal Revenue Code (IRC) § 6103(p)(4) safeguard requirements through the identification and mitigation of any risk of loss, breach or misuse of Federal Tax Information (FTI) held by external government agencies."

The IRS describes the document's purpose and its binding effect in its own words: "This publication provides guidance to ensure the policies, practices, controls, and safeguards employed by recipient agencies, agents, contractors, or sub-contractors adequately protect the confidentiality of FTI. ... This document contains the managerial, operational, and technical security controls that must be implemented as a condition of receipt of FTI."

The current version is Publication 1075 (Rev. 11-2021), as published on the IRS Safeguards Program page.

Who owns it

Publication 1075 is issued and enforced by the IRS Office of Safeguards, under the statutory safeguarding requirements of IRC § 6103(p)(4).

Who assesses it

The IRS's own document describes the review body: "A safeguard review is an on-site, remote, or a combination of both (hybrid) evaluation of the use of FTI and the measures employed by the receiving agency and its agents (where authorized) to protect the data," carried out by "Disclosure Enforcement Specialists (DES), Cybersecurity Reviewers (CSR), and Management Officials" from the IRS itself — not an independent accredited third-party body. The review "validates the accuracy of the SSR and conformance with the current version of Publication 1075 requirements and National Institute of Standards and Technology (NIST) Special Publication 800-53."

Who asks for it

Statutory (scoped). Verified only for agencies, agents, contractors or sub-contractors that receive Federal Tax Information (FTI) under an IRC § 6103(p)(2)(B) agreement — not a general public-sector obligation.

The IRS names who this applies to directly: "recipient agencies, agents, contractors, or sub-contractors" that receive FTI. Publication 1075 defines FTI as "federal tax returns and return information (and information derived from it) that is in the agency's possession or control that is covered by the confidentiality protections of the IRC and subject to the IRC § 6103(p)(4) safeguarding requirements including IRS oversight," received either directly from the IRS or "through an authorized secondary source such as Social Security Administration (SSA), Federal Office of Child Support Enforcement (OCSE), Bureau of the Fiscal Service (BFS) or Centers for Medicare and Medicaid Services (CMS)... pursuant to an IRC § 6103(p)(2)(B) Agreement."

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Tax Information Security Guidelines for Federal, State and Local Agencies." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/irs-pub-1075

All frameworks & audits →