Thomson Reuters Hosting Compliance for CPA Firms: Security & Provider Checklist

CPA professionals reviewing compliance documents for Thomson Reuters hosting IRS and GLBA requirements

Quick Summary: Thomson Reuters hosting can support a CPA firm’s security and compliance responsibilities, but hosting UltraTax CS, Practice CS, Accounting CS, or other CS Professional Suite applications in the cloud does not make the firm compliant by itself.

  • The CPA firm still owns its security responsibilities, including its WISP, employee access decisions, risk management, and service-provider oversight.
  • The hosted environment should support strong safeguards such as MFA, controlled user access, encryption, monitoring, backups, and disaster recovery.
  • Thomson Reuters configuration matters too. CS Professional Suite applications should use supported data locations, permissions, and connectivity rather than unsupported cloud-sync locations for active data.
  • Evaluate evidence, not a “compliant hosting” claim. Ask how the provider protects client data, manages access, supports recovery, and fits into your firm’s documented security program.

Bottom line: Secure Thomson Reuters hosting works best as part of a CPA firm’s broader security program, with clear responsibilities shared between the firm, its hosting provider, and Thomson Reuters.

Introduction

Hosting UltraTax CS, Accounting CS, Practice CS, FileCabinet CS, or other Thomson Reuters applications can support a CPA firm’s security program, but moving those applications to the cloud does not automatically make the firm compliant. The hosting provider may manage important technical safeguards, while the practice still remains responsible for its information-security program, employee access, risk decisions, service-provider oversight, and internal policies.

For firms evaluating Thomson Reuters hosting compliance, the useful question is therefore not, “Does this provider have a compliance badge?” It is whether the hosted environment supports the safeguards the firm needs, follows appropriate Thomson Reuters application requirements, provides reliable recovery, and gives the practice enough control to meet the responsibilities that remain with it.

What Does Thomson Reuters Hosting Compliance Actually Mean?

There is no single certification called “Thomson Reuters hosting compliance” that automatically satisfies every obligation of a CPA firm. In practice, the phrase describes whether the environment running Thomson Reuters applications provides appropriate technical safeguards while allowing the firm to carry out the security and oversight responsibilities that apply to its business.

The distinction matters because a hosting provider does not become the CPA firm’s compliance department simply by running UltraTax CS on a remote server. Under the FTC Safeguards Rule, covered financial institutions must maintain a written information-security program appropriate to their size, complexity, activities, and the sensitivity of the customer information they handle. Tax preparation firms fall under the types of financial institutions covered by the Rule, although the Rule’s applicability to an individual CPA practice depends on the activities it performs.

The Rule also governs relationships between financial institutions and their service providers. Firms must select providers that can maintain appropriate safeguards, define security requirements in their agreements, monitor provider performance, and periodically reassess whether those providers remain suitable for the job.

That makes a Thomson Reuters hosting provider an important part of the firm’s security environment—but not a replacement for the firm’s own responsibilities.

How IRS Security Guidance Fits Into a Thomson Reuters Environment

The IRS continues to tell tax professionals that protecting taxpayer information is a legal responsibility. Its current resources direct practitioners to Publication 4557, Publication 5708, Publication 5709, and related Security Summit materials when developing and maintaining their information-security programs.

In June 2026, the IRS again emphasized the importance of a Written Information Security Plan and explained that the plan should reflect the size, scope and complexity of the practice and the sensitivity of the customer information it handles. The IRS highlights employee management, information systems, and detecting and managing system failures as important areas for a WISP.

For a firm hosting the CS Professional Suite, that means the WISP should reflect the real environment rather than treating “the cloud” as one generic control. The practice needs to understand how users access UltraTax or Accounting CS, how staff create and remove accounts, which systems store taxpayer information, how the practice manages backups and recovery, and when staff should escalate an issue to the hosting provider or Thomson Reuters.

OneUp Networks already has a separate WISP guide covering how a firm can build and maintain that broader plan. This Thomson Reuters compliance article should therefore remain focused on how the hosted application environment fits into that plan, rather than repeating the entire WISP process.

The Shared Responsibility Behind Thomson Reuters Hosting

A managed cloud environment works best when responsibilities are explicit. Problems arise when a CPA firm assumes its provider handles everything, or when the provider assumes the firm is handling controls that nobody has actually assigned.

AreaCPA Firm ResponsibilityHosting Provider RoleThomson Reuters Consideration
User accessDecide who should access client informationCreate, secure and remove hosted accounts as agreedCS applications need appropriate user and folder permissions
MFAEnsure required users follow access policyEnforce MFA for hosted access where configuredProtects the access path into hosted applications
WISPMaintain and update the firm’s written planSupply technical information about hosted controlsHosting arrangement should be reflected accurately
EncryptionUnderstand how customer information is handledProtect data within the managed infrastructure and connectionCS Connect has its own documented security mechanisms
Application setupMaintain valid licenses and workflow decisionsConfigure supported server environmentFollow Thomson Reuters paths, permissions and connectivity requirements
Backups and DRSet business recovery expectationsOperate backup and recovery systems under the service agreementInclude relevant CS application and data locations
Incident responseMaintain the firm’s response processDetect, investigate and escalate provider-side incidentsCoordinate with Thomson Reuters where an application issue is involved
Vendor oversightEvaluate and periodically reassess the providerProvide information needed for due diligenceFirm retains responsibility for service-provider oversight

The table is intentionally not a compliance certification checklist. The FTC expects safeguards to reflect the organization and its actual risks rather than every business following an identical technology configuration.

MFA and Access Control Need to Start With Individual Users

For covered firms, multi-factor authentication is one of the clearest technical requirements in the current FTC Safeguards Rule. The Rule requires MFA for people accessing customer information systems unless the Qualified Individual approves a reasonably equivalent alternative control in writing.

That makes shared remote-desktop credentials a poor foundation for a CPA hosting environment. Staff should have identifiable accounts so access can be granted according to business need and removed when an employee, contractor, or seasonal preparer no longer requires it.

The FTC also requires covered institutions to periodically review access controls and determine whether users continue to have a legitimate business need for customer information. This becomes particularly important for CPA firms that bring in temporary employees during filing season and then reduce staffing after major deadlines.

Encryption Protects Data, but You Need to Know Where the Data Travels

The Safeguards Rule requires covered institutions to protect customer information through encryption in transit and at rest, subject to the Rule’s provisions for approved equivalent controls where encryption is not feasible.

For Thomson Reuters users, there is another layer to understand. Thomson Reuters uses CS Connect to provide services such as e-filing and encrypts information transmitted through CS Connect. The company also uses TLS 1.2 to protect data as it moves between the firm’s environment and Thomson Reuters.

That does not eliminate the need to secure the hosted environment itself. The provider still needs to protect the remote connection, server infrastructure, stored data, backup copies, and administrative access used around the applications.

Thomson Reuters Data Locations Can Affect Security and Reliability

One of the biggest opportunities for this article to provide information that generic compliance guides miss is application configuration.

Thomson Reuters explains that UltraTax CS normally stores data on computer drives or servers. It also warns firms not to use third-party cloud-storage services that do not support Microsoft Remote Desktop Services as active locations for CS Professional Suite data. Thomson Reuters identifies Dropbox as an example and says unsupported live-data configurations can contribute to corrupt data, slow performance, application crashes, and read/write errors.

This becomes important during cloud migrations because simply copying every folder into a convenient sync directory can create a configuration Thomson Reuters does not support. A hosting provider working with the CS Professional Suite should understand the firm’s existing data locations, how different CS applications find one another, and which paths need to remain consistent after migration.

Practice CS, for example, uses configured file locations to integrate with applications such as Accounting CS, FileCabinet CS, Fixed Assets CS and UltraTax CS. A migration therefore needs to preserve workflows as well as files.

Windows Permissions Also Need Thomson Reuters-Specific Planning

A traditional least-privilege discussion becomes more complicated when an application vendor documents particular Windows permissions that its software needs to operate properly.

Thomson Reuters publishes specific permissions for CS Professional Suite installations and data locations. Its guidance identifies read, write and modify requirements for server application and data folders, along with additional local permissions for various CS applications.

That does not mean every hosted user should receive unrestricted access to the entire server. It means the hosting design needs to reconcile Thomson Reuters’ technical requirements with the firm’s broader security controls.

This is another reason generic hosting and application-aware managed hosting are not identical. The team configuring the environment needs to understand both the security objective and the software behavior it is trying to preserve.

Firewalls Cannot Simply Block Everything

A tightly controlled firewall is valuable, but Thomson Reuters applications still need to communicate with vendor systems for authentication, downloads, CS Connect, and related services.

Thomson Reuters currently documents required domains and connectivity for CS Professional Suite applications and notes that ports including 80, 443 and, in certain configurations, 8080 may be required. Port 443 is used by CS Connect for encrypted communication.

The practical lesson is not to weaken the firewall. It is to configure it deliberately so the environment permits the communications Thomson Reuters requires without unnecessarily exposing other services.

That type of application-aware configuration is difficult to achieve when a provider treats UltraTax or Practice CS as no different from any other Windows program.

Monitoring Should Help You Detect Problems, Not Just Produce Logs

The FTC Safeguards Rule requires covered firms to maintain procedures and controls for monitoring authorized users’ activity and detecting unauthorized access. It also requires organizations to regularly test or otherwise monitor the effectiveness of their safeguards.

For a hosted Thomson Reuters environment, monitoring can span remote access, server security, endpoint activity, administrative events, suspicious authentication attempts, system health, and other infrastructure events. The exact logging available inside individual Thomson Reuters applications may differ, so firms should not assume a cloud provider can reproduce every action performed within every tax return merely because the server itself has security logging.

A more useful due-diligence question is: What security and access activity does the provider monitor, how long is relevant information retained, and what can the provider supply if the firm needs to investigate an incident?

That question produces more meaningful evidence than asking whether the provider is simply “audit-ready.”

Backup and Disaster Recovery Are Part of the Security Conversation

A secure login does little good if a CPA firm cannot recover after ransomware, accidental deletion, hardware failure, or a larger infrastructure incident. Recovery therefore belongs in the hosting review alongside MFA, encryption and monitoring.

OneUp Networks currently publishes a three-location backup model consisting of one onsite and two geographically separated offsite locations, together with 120-day rolling retention and disaster-recovery capability in its managed hosting infrastructure.

For a Thomson Reuters environment, the practical question is whether the provider’s backup scope captures the application and data locations that actually matter to the firm’s CS Professional Suite workflow. Firms should also understand how recovery is initiated and what recovery objectives apply to the service instead of assuming that “daily backup” explains the entire recovery strategy.

A Note About IRS Publication 1075

The existing version of this article gives IRS Publication 1075 a much broader role than it should have.

Publication 1075 supports the IRS Safeguards Program for federal, state, and local agencies and authorized contractors that receive Federal Tax Information under IRC 6103. Private CPA and tax preparation firms should not treat Publication 1075 as a universal compliance framework simply because they prepare federal tax returns.

Most private tax practices evaluating a normal commercial hosting relationship should start with the rules and guidance that actually apply to their activities, particularly the FTC Safeguards Rule and IRS taxpayer-data security resources. Firms operating under government contracts or other arrangements involving FTI should obtain advice specific to those obligations.

Removing the old blanket Publication 1075 positioning improves both legal accuracy and topical focus.

What Should CPA Firms Ask a Thomson Reuters Hosting Provider?

Instead of asking, “Are you compliant?”, ask questions that reveal how the environment actually works.

A strong evaluation should determine whether the provider can enforce MFA for hosted users, remove user accounts promptly, encrypt data, monitor infrastructure activity, securely store backups, perform reliable recovery, and meet Thomson Reuters application requirements.

The firm should also ask how provider responsibilities appear in the service agreement. The FTC specifically expects covered financial institutions to select capable service providers, establish appropriate contractual security expectations, monitor them, and periodically reassess their suitability.

Finally, find out how support responsibilities are divided. Thomson Reuters states that its support team focuses on Thomson Reuters product issues and that hardware configuration, Windows permissions, network/server administration and third-party software may require qualified IT personnel or the relevant vendor.

For a CPA firm, having a hosting provider that can work across that boundary can reduce the number of issues that bounce between unrelated support teams.

How OneUp Networks Supports Thomson Reuters Hosting Security

OneUp Networks provides managed hosting for properly licensed Thomson Reuters applications, including UltraTax CS, Accounting CS, Practice CS, Fixed Assets CS and compatible CS Professional Suite applications. Clients continue to own or purchase their software licenses from Thomson Reuters; OneUp Networks manages the hosting environment rather than reselling those software licenses.

Its published hosting environment includes dedicated servers, enterprise endpoint protection, MFA, encryption in transit, network segmentation and 24/7 monitoring. OneUp Networks states that its infrastructure operates in Tier III/IV data-center facilities supporting standards including SOC 2, ISO 27001, HIPAA and PCI DSS.

Recovery capabilities include up to 120-day rolling backups across three locations and managed disaster-recovery processes. These infrastructure controls can support a CPA firm’s information-security program, but they do not replace the firm’s responsibility for its WISP, employee policies, user approvals, risk assessment or service-provider governance.

OneUp Networks can also host multiple properly licensed applications in one managed environment, allowing firms to run Thomson Reuters applications alongside compatible applications such as QuickBooks and Microsoft tools where licensing and technical requirements permit.

A hosting environment can contain strong security controls without proving that every obligation applicable to the CPA firm has been satisfied. Security describes measures that reduce risk; compliance requires the firm to understand and fulfill the legal, contractual and professional responsibilities that actually apply to its activities.

That is why OneUp Networks should not position Thomson Reuters hosting as a product that “makes your CPA firm compliant.” A more defensible—and more useful—position is that properly designed managed hosting can support the firm’s security and compliance responsibilities by providing technical safeguards and reducing the amount of infrastructure the firm must manage internally.

This distinction strengthens trust because it gives the CPA firm a realistic picture of what it is buying.

Frequently Asked Questions About Thomson Reuters Hosting Compliance

Does Thomson Reuters cloud hosting automatically make a CPA firm compliant?

No. Moving UltraTax CS, Practice CS, Accounting CS or another Thomson Reuters application to the cloud can support technical security controls, but the CPA firm remains responsible for the information-security program and other obligations that apply to its business. The FTC Safeguards Rule also places service-provider oversight responsibilities on covered financial institutions.

Is MFA required for CPA firms using hosted tax software?

For firms covered by the FTC Safeguards Rule, MFA is required for people accessing customer-information systems unless the Qualified Individual approves a reasonably equivalent alternative control in writing. That makes MFA an important requirement to examine when evaluating remote Thomson Reuters hosting.

Can UltraTax CS data be stored in Dropbox or another cloud-sync folder?

Not as a supported active data location when the service does not support Microsoft Remote Desktop Services. Thomson Reuters specifically warns that third-party cloud-storage services such as Dropbox can cause slow performance, crashes, read/write errors and data corruption when used for live CS Professional Suite application or client data.

What should a CPA firm check before choosing a Thomson Reuters hosting provider?

Review user access and MFA, encryption, infrastructure monitoring, backup and disaster recovery, service-provider security obligations, and the provider’s knowledge of CS Professional Suite data locations, permissions and connectivity. The firm should also understand how provider controls fit into its own WISP and risk-management process.

Make Thomson Reuters Hosting Part of Your Security Program, Not a Substitute for It

Thomson Reuters hosting compliance is ultimately about more than putting UltraTax CS or Accounting CS on a secure server. A CPA firm needs an environment where access controls, authentication, encryption, monitoring, recovery and application configuration work together while the firm’s own policies and oversight remain intact.

The strongest hosting relationship is therefore one where responsibilities are clear. The firm governs its people, information-security program and service providers; the hosting partner manages the agreed infrastructure; and Thomson Reuters remains the authority for its applications and software requirements.

OneUp Networks helps CPA and accounting firms migrate and manage properly licensed Thomson Reuters applications in dedicated cloud environments with managed security, backups, disaster recovery and technical support. Firms evaluating their current setup can use the controls in this guide to identify gaps before deciding whether optimization, additional safeguards or a hosting migration makes sense.

Talk to a Cloud Hosting Expert about your Thomson Reuters environment. If your current system cannot clearly demonstrate access control and audit visibility, the issue is not security—it is verification.

LinkedIn
Email
Print
Arun Singh

Arun Singh

Arun is a B2B technology and marketing professional with 2 years of experience creating content around cloud hosting, cybersecurity, virtual desktop infrastructure, and digital solutions for accounting and tax-focused businesses. At OneUp Networks, he focuses on simplifying complex hosting and IT topics for CPAs, accountants, tax professionals, and business owners who need secure, reliable, and performance-driven cloud environments.

His writing is shaped by real client challenges such as remote team access, QuickBooks hosting performance, data security, compliance concerns, server speed, backup reliability, and tax-season workload pressure. Arun works closely with industry insights, client requirements, and technical solution knowledge to create practical, easy-to-understand content that helps businesses make informed decisions about cloud hosting and managed IT services.

OneUp Networks is Rated & Recommended by the Best -

G2 Award or badge for High Performer as cloud hosting partner
G2 Award or badge for easiest to do business with as cloud hosting partner
G2 Award or badge for most likely to recommend as cloud hosting partner
G2 Award or badge for easiest to use as cloud hosting partner
Upcity badge as managed service provider given to OneUp Networks
Qb Intuit affiliate badge for OneUp Networks
Capterra badge provided to OneUp networks as 5 star rating
Serchen Logo used for review platform
QuickBooks logo by intuit
Design Rush Badge 2 black
goodfirms rating badge given to OneUp Networks
Proven expert badge for OneUp Networks
saashub verified OneUp Networks
G2 logo with a round circle along with OneUp Networks partnership
alignable logo with text

Discover How!

Newsletter

Sign up our newsletter to get update information, news and free insight.

Latest Blogs

Get Your Quote for Hosting Thomson Reuters Apps in the Cloud!

Get a customized quote in seconds! Experience blazing-fast performance, 24/7 expert support, and seamless Thomson Reuters hosting—all at the best price.

🔹 Transparent Pricing | ⚡ No Hidden Fees | 💯 Hassle-Free Setup

Get Started with QuickBooks Cloud Hosting – Buy Now!

  • Lightning-fast performance with zero downtime
  • Free migration & expert setup—no effort needed
  • 24/7 real human support—whenever you need help
  • No hidden fees | Month-to-month billing | Cancel anytime
  • Start Your 15-Day Free Trial – No Commitment!

Get Your Quote for Hosting QuickBooks in the Cloud!

Get a customized quote in seconds! Experience blazing-fast performance, 24/7 expert support, and seamless QuickBooks Enterprise hosting—all at the best price.

🔹 Transparent Pricing | ⚡ No Hidden Fees | 💯 Hassle-Free Setup

oneup logo in footer

We Don’t Just Host in the Cloud — We Own It.

99.99% Uptime  ·  24/7 Support  ·  12,000+ Users  ·  Upto 120-day Backup

All product names and trademarks belong to their respective owners and are used for identification purposes only. Customers are responsible for maintaining valid licenses for software hosted by OneUp Networks. Information on this website is provided for general informational purposes and does not constitute legal, regulatory, or compliance advice.

Copyright © 2026 OneUp Networks. All rights reserved.