IRS Publication 1345 is the handbook every Authorized IRS e-file Provider of individual income tax returns must follow. If your firm operates a website where taxpayers create accounts, upload documents, or view returns, you are likely an Online Provider — a designation that adds six specific security standards on top of the ordinary rules, including an Extended Validation SSL certificate and weekly external vulnerability scanning.
Most firms discover these requirements after they have already launched a portal. This guide covers who is covered, the six standards, and how they interact with your other obligations.
What Publication 1345 is
Publication 1345, Handbook for Authorized IRS e-file Providers of Individual Income Tax Returns, is the operational rulebook for the e-file program. It governs signature requirements, record retention, advertising standards, transmission and acknowledgment handling, safeguarding e-file against fraud and abuse, and the additional standards for providers operating online.
It is revised periodically. Always work from the current revision on irs.gov rather than a cached copy or a vendor summary — including this one.
The provider roles, and which ones you hold
A single firm often holds several roles simultaneously. The distinction matters because obligations attach to roles, not to companies.
| Role | What it does | Typical holder |
|---|---|---|
| ERO (Electronic Return Originator) | Originates the electronic submission of a return it prepared or collected | The tax firm. Most common role. |
| Transmitter | Sends return data directly to the IRS | Usually the software vendor, not the firm |
| Software Developer | Writes software that formats returns to IRS specifications | The vendor |
| Intermediate Service Provider | Processes return data between the ERO and a Transmitter | Service bureaus |
| Online Provider | Operates a website through which taxpayers' return information is handled | Any provider with a taxpayer-facing portal |
The role most firms overlook is the last one. If your clients log into something you operate, examine whether the Online Provider standards apply to you.
The six Online Provider standards
These come from the IRS and industry Security, Privacy and Business Standards incorporated into Pub 1345. They are concrete and testable, which is unusual for security guidance — and it means a gap is easy for an examiner to identify.
1. Extended Validation SSL certificate
The site must use an EV SSL certificate, not a standard domain-validated one. EV certificates require the certificate authority to verify your organization's legal existence, which takes time and paperwork. Most default hosting certificates — including free automated ones — are domain-validated and do not satisfy this.
2. Weekly external network vulnerability scans
Scans must be performed at least weekly by a scanning vendor certified by the PCI Security Standards Council (an Approved Scanning Vendor, sometimes referred to as a Trusted Partner). You must obtain passing scan reports and remediate failures.
This is a recurring operational cost and the single most commonly missed requirement. It is not a one-time penetration test, and running a free scanner yourself does not satisfy it.
3. Information privacy and safeguard policies
You must publish privacy and security statements on the site and comply with the FTC's financial privacy and safeguards rules. This overlaps directly with your WISP obligation — see our guide to WISP requirements for tax firms under the FTC Safeguards Rule.
4. Website challenge-response test
The site must implement a challenge-response mechanism — a CAPTCHA or equivalent — to prevent automated bots from creating accounts or submitting information.
5. Public domain name registration
The domain must be registered with a US-based, ICANN-accredited registrar, kept locked, and maintained with accurate public registration information. Expired or privacy-obscured registrations have caused problems here.
6. Reporting security incidents
You must report security incidents to the IRS promptly — Pub 1345 requires notification as soon as possible and no later than the next business day after the incident is confirmed — and provide a means for users to report suspected issues.
Confirm the current wording and reporting channel in the live publication before you need it. Build the contact path into your incident response plan now, not during an incident.
Beyond the six: what else Pub 1345 requires
- Signature authorization. The ERO must obtain a signed Form 8879 before transmitting, and retain it — see Form 8879 and e-signature rules for tax firms for the identity-verification requirements that apply to remote signing.
- Record retention. Generally three years, including signature authorizations and supporting documents not transmitted with the return.
- Advertising standards. You may state that you are an Authorized IRS e-file Provider, but you may not imply IRS endorsement, and you may not use IRS logos or seals in ways the publication prohibits. Authorization is not endorsement.
- Timely acknowledgment handling. Retrieve acknowledgments, correct rejects, and notify taxpayers when a return cannot be filed electronically.
- Safeguarding e-file against fraud and abuse. Verify identities, watch for suspicious return patterns, and protect your EFIN from misuse.
How Pub 1345 relates to your other obligations
| Source | Governs | Applies to |
|---|---|---|
| Pub 1345 | How you operate as an e-file provider, including online standards | Authorized IRS e-file Providers |
| FTC Safeguards Rule (Pub 4557 / 5708) | Your written security program | All tax preparers, regardless of e-file status |
| IRC §7216 | What you may do with taxpayer data | Preparers, software developers, e-file providers |
| Pub 1075 | Safeguarding federal tax information received from the IRS | Government agencies — generally not private firms |
The last row is worth internalizing. Pub 1075 is frequently cited in vendor marketing as a security standard, but it governs agencies receiving FTI from the IRS. The publications that actually bind a private tax practice are 1345, 4557, and 5708, plus §7216. If you are deciding what to hold your practice and your vendors to, start there.
A practical readiness checklist
- Determine, in writing, which provider roles your firm holds.
- Confirm whether your taxpayer-facing site makes you an Online Provider.
- Audit your TLS certificate — is it Extended Validation, or domain-validated?
- Engage an ASV and schedule weekly scans. Budget for it as a recurring line item.
- Publish privacy and security statements, and make sure they describe what you actually do.
- Add a challenge-response test to public account creation and submission forms.
- Verify your domain registrar is US-based and ICANN-accredited, and lock the domain.
- Document the IRS incident reporting path inside your incident response plan.
- Review advertising and website copy for anything implying IRS endorsement.
- Re-read the current Pub 1345 revision annually — the standards do change.
Frequently asked questions
Am I an Online Provider if I use a third-party client portal?
It depends on who operates the site and whose brand the taxpayer interacts with. Where a vendor operates the platform, much of the technical burden sits with them — but you remain responsible for overseeing that service provider, and your own site may still be in scope. Review the current publication and get the analysis in writing rather than assuming the vendor absorbs it.
Does an ERO need an ETIN?
Usually not. Most EROs transmit through their software vendor, who holds the ETIN. You need an ETIN only if you transmit directly to the IRS. See EFIN vs ETIN vs PTIN for how the identifiers differ.
Can I advertise that I am IRS approved?
No. You may accurately state that you are an Authorized IRS e-file Provider. You may not say or imply that the IRS endorses, approves, or recommends your firm or your software. This distinction is enforced.
Is a free automated TLS certificate enough?
Not for an Online Provider. Free automated certificates are domain-validated. The standard calls for Extended Validation, which requires organizational vetting by the certificate authority.
How long must I keep Forms 8879 and supporting records?
Generally three years. Pub 1345 measures the period from the return due date or the date the IRS received the return, whichever is later. Electronic retention is permitted if records remain complete and retrievable.
Where XyloDocs fits
XyloDocs is an AI tax workflow platform for tax firms. Clients send documents by SMS, WhatsApp, email, or secure portal; everything is organized by client and tax year with encryption, access controls, and an audit trail; and completed packages export to your tax software. That directly supports the data inventory, access control, encryption, and logging expectations described above for document handling.
It does not make your firm an Online Provider, and it does not discharge your obligations — the six standards attach to the sites and systems your firm operates. See how XyloDocs handles security and client data or review the full feature set.
Last verified: August 9, 2026 This article is general information about IRS e-file program rules, not legal advice. Publication 1345 is revised periodically — verify current requirements against the publication on irs.gov and consult qualified counsel about your firm's obligations.
Leave a Comment
Your comment is private and will only be visible to the author. We'll send you an email confirmation.