Back to Articles

IRS Pub 1345 Online Provider Requirements Explained

Publication 1345 governs every Authorized IRS e-file Provider. If taxpayers log into a site your firm operates, you may be an Online Provider — which adds six specific security standards including EV SSL and weekly external vulnerability scanning.

Ram Parashar
August 7, 2026
Updated August 9, 2026
7 min read
Pub 1345e-filecompliancesecurityOnline Providertax firms

IRS Publication 1345 is the handbook every Authorized IRS e-file Provider of individual income tax returns must follow. If your firm operates a website where taxpayers create accounts, upload documents, or view returns, you are likely an Online Provider — a designation that adds six specific security standards on top of the ordinary rules, including an Extended Validation SSL certificate and weekly external vulnerability scanning.

Most firms discover these requirements after they have already launched a portal. This guide covers who is covered, the six standards, and how they interact with your other obligations.

What Publication 1345 is

Publication 1345, Handbook for Authorized IRS e-file Providers of Individual Income Tax Returns, is the operational rulebook for the e-file program. It governs signature requirements, record retention, advertising standards, transmission and acknowledgment handling, safeguarding e-file against fraud and abuse, and the additional standards for providers operating online.

It is revised periodically. Always work from the current revision on irs.gov rather than a cached copy or a vendor summary — including this one.

The provider roles, and which ones you hold

A single firm often holds several roles simultaneously. The distinction matters because obligations attach to roles, not to companies.

RoleWhat it doesTypical holder
ERO (Electronic Return Originator)Originates the electronic submission of a return it prepared or collectedThe tax firm. Most common role.
TransmitterSends return data directly to the IRSUsually the software vendor, not the firm
Software DeveloperWrites software that formats returns to IRS specificationsThe vendor
Intermediate Service ProviderProcesses return data between the ERO and a TransmitterService bureaus
Online ProviderOperates a website through which taxpayers' return information is handledAny provider with a taxpayer-facing portal

The role most firms overlook is the last one. If your clients log into something you operate, examine whether the Online Provider standards apply to you.

The six Online Provider standards

These come from the IRS and industry Security, Privacy and Business Standards incorporated into Pub 1345. They are concrete and testable, which is unusual for security guidance — and it means a gap is easy for an examiner to identify.

1. Extended Validation SSL certificate

The site must use an EV SSL certificate, not a standard domain-validated one. EV certificates require the certificate authority to verify your organization's legal existence, which takes time and paperwork. Most default hosting certificates — including free automated ones — are domain-validated and do not satisfy this.

2. Weekly external network vulnerability scans

Scans must be performed at least weekly by a scanning vendor certified by the PCI Security Standards Council (an Approved Scanning Vendor, sometimes referred to as a Trusted Partner). You must obtain passing scan reports and remediate failures.

This is a recurring operational cost and the single most commonly missed requirement. It is not a one-time penetration test, and running a free scanner yourself does not satisfy it.

3. Information privacy and safeguard policies

You must publish privacy and security statements on the site and comply with the FTC's financial privacy and safeguards rules. This overlaps directly with your WISP obligation — see our guide to WISP requirements for tax firms under the FTC Safeguards Rule.

4. Website challenge-response test

The site must implement a challenge-response mechanism — a CAPTCHA or equivalent — to prevent automated bots from creating accounts or submitting information.

5. Public domain name registration

The domain must be registered with a US-based, ICANN-accredited registrar, kept locked, and maintained with accurate public registration information. Expired or privacy-obscured registrations have caused problems here.

6. Reporting security incidents

You must report security incidents to the IRS promptly — Pub 1345 requires notification as soon as possible and no later than the next business day after the incident is confirmed — and provide a means for users to report suspected issues.

Confirm the current wording and reporting channel in the live publication before you need it. Build the contact path into your incident response plan now, not during an incident.

Beyond the six: what else Pub 1345 requires

  • Signature authorization. The ERO must obtain a signed Form 8879 before transmitting, and retain it — see Form 8879 and e-signature rules for tax firms for the identity-verification requirements that apply to remote signing.
  • Record retention. Generally three years, including signature authorizations and supporting documents not transmitted with the return.
  • Advertising standards. You may state that you are an Authorized IRS e-file Provider, but you may not imply IRS endorsement, and you may not use IRS logos or seals in ways the publication prohibits. Authorization is not endorsement.
  • Timely acknowledgment handling. Retrieve acknowledgments, correct rejects, and notify taxpayers when a return cannot be filed electronically.
  • Safeguarding e-file against fraud and abuse. Verify identities, watch for suspicious return patterns, and protect your EFIN from misuse.

How Pub 1345 relates to your other obligations

SourceGovernsApplies to
Pub 1345How you operate as an e-file provider, including online standardsAuthorized IRS e-file Providers
FTC Safeguards Rule (Pub 4557 / 5708)Your written security programAll tax preparers, regardless of e-file status
IRC §7216What you may do with taxpayer dataPreparers, software developers, e-file providers
Pub 1075Safeguarding federal tax information received from the IRSGovernment agencies — generally not private firms

The last row is worth internalizing. Pub 1075 is frequently cited in vendor marketing as a security standard, but it governs agencies receiving FTI from the IRS. The publications that actually bind a private tax practice are 1345, 4557, and 5708, plus §7216. If you are deciding what to hold your practice and your vendors to, start there.

A practical readiness checklist

  1. Determine, in writing, which provider roles your firm holds.
  2. Confirm whether your taxpayer-facing site makes you an Online Provider.
  3. Audit your TLS certificate — is it Extended Validation, or domain-validated?
  4. Engage an ASV and schedule weekly scans. Budget for it as a recurring line item.
  5. Publish privacy and security statements, and make sure they describe what you actually do.
  6. Add a challenge-response test to public account creation and submission forms.
  7. Verify your domain registrar is US-based and ICANN-accredited, and lock the domain.
  8. Document the IRS incident reporting path inside your incident response plan.
  9. Review advertising and website copy for anything implying IRS endorsement.
  10. Re-read the current Pub 1345 revision annually — the standards do change.

Frequently asked questions

Am I an Online Provider if I use a third-party client portal?

It depends on who operates the site and whose brand the taxpayer interacts with. Where a vendor operates the platform, much of the technical burden sits with them — but you remain responsible for overseeing that service provider, and your own site may still be in scope. Review the current publication and get the analysis in writing rather than assuming the vendor absorbs it.

Does an ERO need an ETIN?

Usually not. Most EROs transmit through their software vendor, who holds the ETIN. You need an ETIN only if you transmit directly to the IRS. See EFIN vs ETIN vs PTIN for how the identifiers differ.

Can I advertise that I am IRS approved?

No. You may accurately state that you are an Authorized IRS e-file Provider. You may not say or imply that the IRS endorses, approves, or recommends your firm or your software. This distinction is enforced.

Is a free automated TLS certificate enough?

Not for an Online Provider. Free automated certificates are domain-validated. The standard calls for Extended Validation, which requires organizational vetting by the certificate authority.

How long must I keep Forms 8879 and supporting records?

Generally three years. Pub 1345 measures the period from the return due date or the date the IRS received the return, whichever is later. Electronic retention is permitted if records remain complete and retrievable.

Where XyloDocs fits

XyloDocs is an AI tax workflow platform for tax firms. Clients send documents by SMS, WhatsApp, email, or secure portal; everything is organized by client and tax year with encryption, access controls, and an audit trail; and completed packages export to your tax software. That directly supports the data inventory, access control, encryption, and logging expectations described above for document handling.

It does not make your firm an Online Provider, and it does not discharge your obligations — the six standards attach to the sites and systems your firm operates. See how XyloDocs handles security and client data or review the full feature set.

Last verified: August 9, 2026 This article is general information about IRS e-file program rules, not legal advice. Publication 1345 is revised periodically — verify current requirements against the publication on irs.gov and consult qualified counsel about your firm's obligations.

Leave a Comment

Your comment is private and will only be visible to the author. We'll send you an email confirmation.