Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Building and managing secure IT for Canadian businesses since 2012 across Toronto, Hamilton, and Metro Vancouver.
If your firm files even one T1 or T2 return through CRA EFILE, the credential behind that filing is a regulated asset. The Canada Revenue Agency treats the EFILE number as a personal authorization granted to 1 named filer, and it can suspend that authorization without any finding of tax fraud.
For Canadian CPAs, the controls protecting the EFILE workflow are professional-practice infrastructure. They sit where the CRA Service Standards, the CPA Ontario Code, and PIPEDA overlap. Our AI for Canadian accounting firms guide covers the wider practice context.
Key takeaways
- The CRA can suspend or cancel an EFILE number where the filer fails to safeguard credentials. No tax-fraud finding is needed.
- MFA, encryption at rest, and a six-year audit trail are the three controls the EFILE Help Desk asks about first on an incident call.
- Rule 208 of the CPA Ontario Code is Confidentiality; Rule 207 is Unauthorized Benefits. The two get swapped constantly. Rule 208.3(b) is the one that reaches your outsourced IT provider.
- Sign-in to a CRA account uses multi-factor authentication for every user. That is separate from, and does not satisfy, MFA on the firm mailbox that receives CRA messages.
- For a 6-to-25 staff firm the realistic pre-season project is 90 days, CA$4,500 to CA$9,000 one-time, plus CA$180 to CA$250+ per user per month for the ongoing security baseline.
What is EFILE security, explained
According to the Canada Revenue Agency (2026), the EFILE number and password are confidential. Every participant agrees the filer is responsible for safeguarding both the credentials and the taxpayer data behind them. That binds the registered filer personally, which is why principals at small firms carry direct exposure.
The season shape matters as much as the rule. The agency runs T1 EFILE from late February through the following January, so a control that was adequate on opening day has to still be running eleven months later. That is the practical argument for quarterly attestation over an annual checklist.
Program changes land through the EFILE news and program updates page (2026) rather than by letter, so someone at the firm needs it on a reading list.
Not sure how your controls map to the Service Standards? Ask us for a 30-minute review →
When does the CRA suspend or revoke an EFILE number?
According to the Canada Revenue Agency (2026), EFILE privileges are granted after a suitability screening that is renewed, and the agency may suspend or cancel where a filer no longer meets the standards. A mid-season suspension is the closest thing in practice to a professional-licence freeze.
Three operational realities make it more likely than firms expect. Suitability is reassessed rather than granted once. The Help Desk asks precise questions about MFA, password rotation and last-known logon when a filing pattern is flagged. And an unreported prior-year incident tends to surface at renewal rather than staying buried.
Which IT controls does the CRA actually require?
According to the Canada Revenue Agency (2026), signing in to a CRA account uses multi-factor authentication, with a passcode grid, a third-party authenticator app, or a one-time passcode by text. A backup method is part of the enrolment flow, and users can be prompted to add one at sign-in.
Two things follow that most firms miss. First, CRA-side MFA protects the CRA account, not your tenant. Second, the mailbox that receives CRA messages, password resets and Help Desk replies is the higher-value target, and MFA there is the firm’s job.
Practitioner experience narrows the rest to 3 controls. MFA on every account touching the workflow. Encryption at rest on every device holding taxpayer records. And an access trail kept for the 6 years that matches the CRA records-retention rule.
On Microsoft 365 Business Premium those map to existing licensing. MFA runs through Entra ID Conditional Access. Encryption at rest comes from BitLocker on managed Windows endpoints plus SharePoint and OneDrive defaults. Six-year log coverage needs Purview Audit plus a documented quarterly export, at roughly CA$12 to CA$20 per user per month in incremental licence cost.
[REGULATOR QUOTE]
Shall keep records and books of account at the person’s place of business or residence in Canada or at such other place as may be designated by the Minister.
Income Tax Act, section 230(1), from the Justice Laws consolidation. Section 230(2) applies to qualified donees and requires an address in Canada recorded with the Minister.
PIPEDA vs CPA Ontario Rule 208: where the EFILE duty overlaps
According to the Office of the Privacy Commissioner of Canada (2026), PIPEDA requires safeguards appropriate to sensitivity. It also requires breach reporting wherever there is a real risk of significant harm. Taxpayer SIN, income and dependant data clear that threshold without argument.
Get the rule numbers right, because three published guides have them backwards. In the CPA Ontario Code of Professional Conduct (2026), Rule 208 is Confidentiality of Information and Rule 207 is Unauthorized Benefits. Rule 208.3(b) is the operative one for IT. A member who gives someone access to confidential client information must obtain that person’s written agreement to keep it confidential, which reaches an outsourced provider directly.
On timing, PIPEDA sets no 72-hour clock. Section 10.1 requires a report to the Commissioner as soon as feasible. The penalties in PIPEDA section 28 (2026) run to CA$10,000 on summary conviction and CA$100,000 on indictment, and they attach to knowingly contravening the breach-record and reporting obligations rather than to the breach itself.
So one hardening pass against the CRA expectation also carries most of PIPEDA, Rule 208, and the provincial statutes in Alberta, British Columbia and Quebec. Quebec Law 25 adds a designated privacy officer and prompt notification to the Commission d’accès à l’information rather than a fixed hour count, but the underlying controls do not change.
Want a side-by-side of your setup against CRA, PIPEDA and the CPA Ontario Code? Get in touch →
The EFILE control matrix: criteria for each control
According to the Canadian Centre for Cyber Security (2024), tested offline backups, restricted administrative privilege and multi-factor authentication head its prevention list. The matrix below is the working document Fusion Computing uses in a pre-season engagement, with the criteria that decide whether a control counts as in place.
| Control | CRA EFILE expectation | Overlapping duty | Implementation. |
|---|---|---|---|
| MFA on EFILE-adjacent accounts | First Help Desk question on any incident | PIPEDA safeguards, CPA Rule 208 | Entra ID Conditional Access, tax-software SSO. |
| Encryption at rest | Required for records held on local devices | PIPEDA safeguards, Law 25 | BitLocker, FileVault, SharePoint and OneDrive defaults. |
| Six-year access trail | Parallels the CRA six-year records rule | CPA Rule 208 evidentiary trail | Purview Audit plus quarterly export to cold archive. |
| Termination access removal | Filer owns the access lifecycle | CPA Rule 208.3(b) written agreement | Entra ID lifecycle workflow, tax-software role audit. |
| Encrypted client document exchange | Reasonable safeguard in transit | PIPEDA safeguards and limiting use | Vendor portal or Microsoft 365 secure share with expiry. |
| Phishing-resistant email | The credential-loss vector the Help Desk sees most | CPA Rule 208 staff training | Microsoft Defender for Office 365, quarterly simulation. |
| Incident response runbook | Same-business-day notification on compromise | PIPEDA s.10.1, as soon as feasible | Named owner, annual tabletop, written escalation path. |
| Backup with an offline copy | Records integrity under the Service Standards | CPA Rule 208 records continuity | An immutable backup platform holding one copy off the SaaS plane. |
[FIELD NOTE]
In Q1 2026 a 14-staff Toronto accounting firm called us six weeks into tax season, after the EFILE Help Desk flagged an unusual filing pattern on the principal’s number. The filings were legitimate. The principal had no MFA on the EFILE-adjacent mailbox and the credential had not been rotated in 11 months.
The firm escaped without revocation. Closing the file took 80 to 110 minutes of calls across three days, then a same-week MFA rollout and a 60-day log backfill. In our experience the missing MFA on the inbox is the gap the agency reads first.
Mike Pearlstein, CISSP, Fusion Computing.
How long does pre-season hardening take? The 90-day plan
According to the Canada Revenue Agency (2026), EFILE program changes and renewal windows are published ahead of each season rather than mailed out. Ninety days ahead of opening day is the window where a control change is cheap; six weeks in, it is an emergency.
- Days 0 to 30, inventory and baseline. Enumerate every account with EFILE access. Record MFA status, password age, last logon. Confirm disk encryption on every Windows endpoint. Pull a baseline log export. Output: a signed inventory and a gap list.
- Days 31 to 60, control rollout. Enforce MFA on every EFILE-adjacent account. Push encryption compliance from device management. Configure SharePoint and OneDrive retention. Tune the anti-phishing policy. Move client document exchange onto a portal. Output: changes signed off by the principal.
- Days 61 to 90, runbook and rehearsal. Write the incident runbook with named owners for the Help Desk call, the Commissioner report and the CPA body notification. Run a tabletop. Rotate the EFILE password. Confirm the log export path. Output: minutes, runbook, and a season-ready attestation.
Fusion Computing took the security side of our firm off our plate. The MFA rollout closed a gap I knew we had but could not prioritize during filing season, and the log retention proved its worth six months later when the agency called.
Practice principal, 14-staff Toronto accounting firm, anonymized. Engagement started Q1 2026.
Which four EFILE security mistakes do firms repeat?
According to the CPA Ontario Code of Professional Conduct (2026), the confidentiality duty in Rule 208 follows the information rather than the office it sits in. Every mistake below is a way of letting client information leave the boundary the Rule assumes.
- Do not share one EFILE number across the firm. A shared credential breaks the accountability chain and is the fastest route to a suitability problem when the agency spots an irregular filing.
- Do not keep taxpayer documents in a personal cloud account. Personal storage sits outside the firm’s log and retention rules, and it puts the Rule 208.3(b) written agreement out of reach.
- Do not skip MFA on the EFILE-adjacent inbox. That mailbox receives password resets, Help Desk replies and CRA messages. MFA on the filing screen alone leaves the recovery path open.
- Do not let the access trail lapse below six years. Default audit retention in most tenants is far shorter, so six-year coverage needs either the upgraded plan or a documented export procedure.
The 8-step rollout
For a firm starting from a Microsoft 365 Business Premium baseline with no formal EFILE control documentation, this is the sequence Fusion Computing runs. Each step has one owner and one output artifact. The full project ships in 12 weeks, and an 8-week path works for firms with a single filer and fewer than 10 staff.
- Account inventory. Every EFILE number, every tenant account, every tax-software seat. Owner: managing principal. Output: a signed inventory.
- MFA enforcement. Conditional Access requiring MFA on every interactive sign-in. Owner: IT lead. Output: a compliance report.
- Endpoint hardening. Disk encryption enforced on every managed device. Owner: IT lead. Output: a device compliance report.
- Log baseline. Audit logging enabled with the six-year retention path documented. Owner: IT lead. Output: a written archive procedure.
- Portal cutover. All client document exchange on the portal, no return drafts by attachment. Owner: managing principal. Output: a client FAQ.
- Phishing baseline. Anti-phishing policy on, baseline simulation run. Owner: IT lead. Output: results and a remediation list.
- Incident runbook. Named owners and escalation timing, including the Rule 208.3(b) provider agreement. Owner: principal and IT lead. Output: a signed runbook.
- Tabletop rehearsal. A 90-minute exercise on an EFILE credential compromise. Owner: managing principal. Output: minutes and lessons learned.
We measured the delivered cost of this engagement across our accounting-firm clients at CA$4,500 to CA$9,000 one-time, plus CA$180 to CA$250+ per user per month for the ongoing managed security baseline. Choosing who runs it is a separate decision, and our comparison of IT providers for Canadian accounting firms scores six provider types against the CPA Code and the CCCS control set.
Ready to scope the 8-step rollout for your firm? Contact us →
EFILE security is one slice of the regulator stack a Canadian firm carries through 2026. For money-laundering obligations, see our FINTRAC IT controls playbook. For the seasonal tempo, our tax-season cybersecurity guide. For the tax-software layer, our CCH iFirm and CaseWare hardening guide. For the AI side, our Microsoft 365 Copilot analysis for Canadian CPA firms. For the confidentiality duty beside EFILE, our cybersecurity guide for Canadian accountants.
Bottom line
EFILE security in 2026 is professional-practice infrastructure. The Service Standards make the filer personally responsible, and the Help Desk asks specific operational questions on every incident call. The overlap with PIPEDA and CPA Ontario Rule 208 means one disciplined hardening pass clears several duties at once.
CISSP-led reviews. Fusion Computing has hardened EFILE workflows for Canadian accounting firms since 2018.
Frequently asked questions
Can the CRA revoke an EFILE number for a cybersecurity incident alone?
Yes. The Service Standards let the agency suspend or cancel EFILE privileges where the filer fails to safeguard credentials or where there is reason to believe the number is compromised. No tax-fraud finding is required, because an unsafeguarded credential is itself the breach.
Do the Service Standards name multi-factor authentication?
They speak in terms of safeguarding credentials rather than naming a technology. Separately, signing in to a CRA account does use multi-factor authentication for every user. The Help Desk treats MFA as the first technical question on a compromise call, so it is the operational floor whatever the wording says.
How fast must I notify the CRA of a credential compromise?
The Service Standards set no hour count. The Help Desk operates as though same-business-day notification is the floor, and firms that wait two days find the review moves more slowly and the suspension option comes up sooner.
Does PIPEDA breach reporting cover an EFILE incident?
Yes, where the breach creates a real risk of significant harm, which taxpayer SIN and income data will. PIPEDA section 10.1 requires the report as soon as feasible rather than inside 72 hours. The Commissioner report is separate from the Help Desk call and both are filed in parallel.
What are the penalties under PIPEDA?
Section 28 sets a fine of up to CA$10,000 on summary conviction and up to CA$100,000 on indictment. They attach to knowingly contravening the breach-reporting and record-keeping obligations, or to obstructing the Commissioner, rather than to the breach itself.
Is it Rule 207 or Rule 208 that covers confidentiality?
Rule 208 is Confidentiality of Information. Rule 207 is Unauthorized Benefits. Published guides swap them regularly. Rule 208.3(b) is the clause that matters for IT. A member who gives anyone access to confidential client information must obtain that person’s written agreement to keep it confidential, and that reaches an outsourced provider.
How long must a firm keep an access log for CRA purposes?
The CRA records-retention rule is 6 years from the end of the tax year, and the access trail evidencing who touched those records carries the same expectation. Default tenant audit retention is much shorter, so six-year coverage needs the upgraded Microsoft plan or a documented quarterly export.
Can several people in my firm share one EFILE number?
No. The number is bound to the named registered filer personally. Sharing it breaks the accountability chain and is one of the fastest routes to a Service Standard finding. Each named filer holds an individual number.
What does the EFILE Help Desk ask first on an incident call?
Three questions recur. Was MFA enforced on the EFILE-adjacent accounts. When was the password last rotated. What is the timestamp of the last legitimate logon. Firms that answer the Canada Revenue Agency in writing within 1 hour materially improve their odds of staying active.
Does encryption in OneDrive and SharePoint satisfy the CRA expectation?
For documents held in those services, yes. It does not cover documents synced to a laptop, which is why disk encryption on managed devices stays in the control set. Records also have to stay at a place of business in Canada or somewhere the Minister designates, under Income Tax Act section 230.
What does hardening cost for a 6-to-25 staff firm?
The pre-season project runs CA$4,500 to CA$9,000 one-time. The ongoing managed security baseline runs CA$180 to CA$250+ per user per month. For a 12-staff firm that is roughly CA$23,000 to CA$35,000 across the first year including licensing.
How does Quebec Law 25 change things for a firm with Quebec clients?
Law 25 adds a designated privacy officer, prompt notification to the Commission d’accès à l’information with no fixed hour count, and tighter rules on transferring personal information outside Quebec. The underlying controls match the CRA expectation, so the work is designating the officer in writing and documenting a transfer assessment per cloud service.
Further reading and primary sources
- CRA EFILE for electronic filers. The Service Standards and the annual renewal process.
- Income Tax Act section 230. Where books and records must be kept.
- CPA Ontario Code of Professional Conduct. Rule 208 confidentiality, including 208.3(b).
[ORIGINAL DATA] HOW THIS GUIDANCE WAS ASSEMBLED.
This article draws on Fusion Computing anonymized client data from Canadian accounting-firm engagements between 2024 and 2026. It also draws on an FC internal benchmark covering EFILE control rollout and tenant hardening. Statutory text was read from the Justice Laws consolidations of the Income Tax Act and PIPEDA, and the Rule numbering from the CPA Ontario Code PDF itself, not from secondary summaries. Layered over it is first-person field observation from CEO Mike Pearlstein, CISSP.

