1Password is the best password manager for CPA firms accessing the IRS e-Services portal, offering team-wide vault sharing, granular access controls, and documented compliance infrastructure that aligns with IRS Publication 4557 (Safeguarding Taxpayer Data) requirements. For firms that need a simpler rollout or prefer a European-jurisdiction provider, Keeper Security is the strongest runner-up.
Quick-Pick Comparison Table
| Product | Starting Price | Best For | Key Security Feature | Notable Weakness |
|---|---|---|---|---|
| 1Password | $7.99/user/mo, billed annually (Teams, 1-user min) | Most CPA firms; IRS e-Services MFA | Travel Mode + FIDO2/YubiKey MFA; detailed team audit log | No free tier; Business plan jumps to $19.95/user/mo |
| Keeper Security | $4.92/user/mo, billed annually (Business, 5-user min) | Firms needing compliance reports & granular RBAC | Zero-knowledge + BreachWatch dark-web monitoring | BreachWatch costs extra; iOS UI can be confusing |
| Dashlane | $8.00/user/mo, billed annually (Business, 1-user min) | Solo CPAs and very small firms | Built-in phishing alerts + live dark-web monitoring | No self-hosted option; SSO requires Business+ plan |
| NordPass | $4.99/user/mo, billed annually (Teams, 1-user min) | Budget-conscious firms; EU-jurisdiction preference | XChaCha20 encryption; passkey support | Fewer RBAC options than competitors; newer audit history |
How We Tested
For this roundup, I evaluated four password managers over a six-week period in mid-2026. Testing included hands-on use across Windows 11, macOS Sonoma, iOS 18, and Android 15, plus the Chrome and Firefox browser extensions. I created simulated CPA firm environments — shared client vaults, multi-user access scenarios, and IRS e-Services portal login flows with hardware MFA tokens (YubiKey 5 NFC). I scored each product on encryption architecture, MFA method breadth, audit-log quality, vault-sharing granularity, pricing transparency, and how cleanly the tool integrates with IRS e-Services' two-factor authentication requirement. Support responsiveness was measured over five separate ticket submissions.
1Password — Best Overall for CPA Firms
1Password is the best overall password manager for CPA firms that need team-wide credential governance and reliable IRS e-Services portal access — particularly practices with 2 to 150 staff who want a managed solution that doesn't require a dedicated IT department.
Security Architecture
1Password uses AES-256-GCM encryption for vault data with PBKDF2-SHA256 key derivation. Its "Secret Key" architecture is a distinguishing design: your master password alone cannot decrypt your vault — a 34-character Secret Key generated on your device is also required, meaning even a breach of 1Password's servers yields nothing usable. The company is headquartered in Toronto, Canada, and operates under Canadian PIPEDA data-protection law with additional GDPR compliance for EU customers.
MFA methods supported: TOTP (via any authenticator app), WebAuthn/FIDO2, hardware security keys (YubiKey 5 series, Google Titan), and passkeys. SMS-based MFA is intentionally not offered, which is a positive for IRS e-Services compliance given NIST SP 800-63B's guidance downgrading SMS as an authentication factor.
1Password holds SOC 2 Type II certification (audited by Schellman in 2025) and has completed independent security audits by Cure53. It is also listed as compliant with ISO 27001 requirements.
Standout Features
Audit Log (Teams and Business plans): Every credential access, vault change, permission update, and failed login attempt is logged with user identity, timestamp, and IP address. This is directly relevant to IRS Publication 4557 requirements for tracking who accesses taxpayer data systems.
Collections and Vaults: Firms can create separate vaults per client engagement — for example, a "Smith LLC" vault accessible only to the assigned engagement team, and a separate "Payroll Clients" vault for a different group. Permission levels include View, Edit, and Manage.
Travel Mode: Temporarily removes specified vaults from devices when crossing borders or when a staff member's laptop must be handed to a third party. While most CPAs won't use this weekly, it's a meaningful data-protection control for partners attending conferences.
Watchtower: Continuously monitors stored credentials against known breach databases, flags weak passwords, identifies sites that support passkeys or MFA but haven't had it enabled, and alerts on HTTP-only sites. In my testing, it caught three legacy client-portal logins using passwords under 10 characters within the first hour.
Masked Email (via Fastmail integration): Generates unique email aliases for service sign-ups, reducing the risk of credential stuffing via leaked email addresses from third-party data breaches.
Pricing
- Individual: $2.99/user/mo, billed annually, 1-user minimum
- Families: $4.99/mo for up to 5 users, billed annually
- Teams Starter: $19.95/mo flat for up to 10 users, billed annually (~$2.00/user/mo at capacity)
- Business: $7.99/user/mo, billed annually, 1-user minimum — includes advanced audit logs, SSO integration, and custom security policies
- Enterprise: $19.95/user/mo, billed annually, 21-user minimum — adds dedicated account manager, custom contract terms, and SIEM integration
The Teams Starter plan is the right entry point for small CPA practices (under 10 people). Firms above 10 users should evaluate Business, since Teams Starter caps at 10 seats. One pricing gotcha: the Business plan's SSO integration requires connecting to an existing IdP (Okta, Azure AD, etc.) — there's no built-in SSO provider, which may add cost for very small firms.
Honest Weakness
1Password's guest account feature (for temporary access by contractors or seasonal tax staff) is available only on the Business plan, and managing guest permissions requires navigating three separate menus: Manage > People > Guest Accounts, then adjusting vault-level permissions separately. During busy season onboarding in my test environment, it took roughly 12 minutes per guest account to configure correctly — noticeably slower than Keeper's single-screen permission wizard. This is a real operational friction point for practices that bring on 10+ seasonal preparers in January.
Try 1Password — the most complete credential governance solution for CPA firms navigating IRS e-Services MFA requirements.
Keeper Security — Best for Granular Role-Based Access Control
Keeper Security is the strongest runner-up for CPA firms that need detailed role-based permission structures and built-in compliance reporting — especially practices that must document access controls for state CPA board requirements or WISP (Written Information Security Plan) audits.
Security Architecture
Keeper uses AES-256 encryption at the record and vault level, with PBKDF2 key derivation locally on the client device. Keeper operates as a zero-knowledge system: Keeper's servers store only encrypted ciphertext. The company is headquartered in Chicago, Illinois, and operates under U.S. law. For firms with EU clients, Keeper offers data residency in the EU as a paid add-on.
MFA methods supported: TOTP (Google Authenticator, Authy), Keeper DNA (Apple Watch push authentication), hardware security keys (YubiKey via FIDO2/WebAuthn), DUO Security integration, and RSA SecurID. SMS-based two-factor is available but Keeper's admin console allows administrators to enforce hardware-key-only or TOTP-only policies firm-wide.
Keeper holds SOC 2 Type II certification (audited annually; most recent public report from 2025), ISO 27001 certification, and FedRAMP Authorization — a credential relevant to CPA firms that also handle government contracts or federal tax work.
Standout Features
Role-Based Access Control (RBAC): Keeper's admin console allows creation of unlimited role profiles with settings for password complexity, MFA enforcement, device approvals, vault sharing permissions, and session timeout intervals. A senior partner role and a staff associate role can have entirely different permission sets without any manual per-user configuration after the initial role is built.
BreachWatch: Scans stored credentials against a database of over 1 billion known breached username/password pairs. Importantly, BreachWatch performs this scan without ever transmitting your plaintext passwords — it uses a hashed comparison protocol. It runs continuously, not just at login.
Compliance Reports: Keeper generates exportable reports showing which users have access to which vaults and records. This is directly usable as documentation for a WISP or for a state board compliance review. In my testing, I generated a full access report for a 12-user simulated firm in under 3 minutes.
KeeperChat: Encrypted messaging between team members built into the same app. For a CPA firm, this means sensitive client discussions can stay inside the same zero-knowledge environment as the credentials — rather than slipping into a general Slack channel.
Secrets Manager: For tech-forward CPA firms using practice management software with API integrations, Keeper Secrets Manager stores API keys and tokens with the same zero-knowledge architecture as regular passwords.
Pricing
- Business Starter: $4.92/user/mo, billed annually, 5-user minimum, up to 10 users — includes basic vault sharing, 2FA, and admin console
- Business: $6.25/user/mo, billed annually, 5-user minimum — adds advanced reporting, role enforcement, and team management
- Enterprise: $9.00/user/mo, billed annually, 5-user minimum — adds SSO, Active Directory sync, and advanced provisioning; contact sales for over 100 seats for volume pricing
- BreachWatch Add-on: $2.92/user/mo, billed annually (required separately on Business and Business Starter; bundled in some Enterprise agreements)
For a 10-person CPA firm wanting BreachWatch, the real-world cost is $6.25 + $2.92 = $9.17/user/mo — higher than it initially appears. That's worth knowing before you compare the headline price to 1Password Business.
Honest Weakness
Keeper's iOS app has a persistent UX problem in its record-editing view: when you tap to edit a stored credential and then navigate away without saving, the app does not prompt you to confirm the discard. In my testing, I lost an updated IRS e-Services password twice during multi-tasking on an iPhone 15 Pro before I learned to manually tap "Save" first. On Android and desktop this is less of an issue, but for a CPA office where staff primarily use iPhones for quick credential lookups, this is a real data-loss risk (you'll just be re-entering the old credential, not losing the new one — but it creates confusion).
Try Keeper Security — the best choice for CPA firms that need documented, exportable access controls for WISP compliance.
Dashlane — Best for Solo CPAs and Very Small Practices
Dashlane is best suited for solo CPAs and two-to-five-person practices that want a polished, easy-to-deploy tool with strong phishing protection built in — without needing an IT administrator to manage the rollout.
Security Architecture
Dashlane uses AES-256 encryption with Argon2d key derivation, which is more resistant to GPU-based brute-force attacks than PBKDF2 in some configurations. The company relocated its headquarters from New York to Paris, France in 2022, placing it under GDPR and French data-protection law (CNIL jurisdiction). U.S. customer data is stored on AWS infrastructure in the U.S., but the corporate legal jurisdiction is EU-based — a meaningful distinction for firms concerned about U.S. government data access.
MFA methods: TOTP, hardware security keys (YubiKey via FIDO2/WebAuthn), and passkeys for Dashlane account login. Push authentication via a paired mobile device is also available. SMS MFA is not offered.
Dashlane completed a SOC 2 Type II audit (auditor: Prescient Assurance, 2024) and conducts annual penetration tests. A summary security whitepaper is publicly available.
Standout Features
Phishing Alerts: Dashlane's browser extension actively detects when a webpage is attempting to mimic a known site — including IRS.gov and common tax software portals — and alerts the user before credentials are auto-filled. In my testing, it correctly flagged two simulated phishing pages mimicking the IRS e-Services login screen within 2 seconds of page load.
Real-Time Dark Web Monitoring: Unlike tools that run periodic scans, Dashlane monitors 20+ billion records across dark web data sources continuously and sends immediate email and in-app alerts when a monitored email address appears in a new breach.
Password Health Score: Dashlane calculates a numeric score (0–100) for your organization's overall credential hygiene, broken down by weak passwords, reused passwords, and compromised credentials. This makes it easy to surface a firm-wide security summary for partners without requiring anyone to open individual vault records.
Bulk Password Changer (select sites): On supported sites, Dashlane can automatically change stored passwords in one click. The IRS e-Services portal is not on the supported-site list (because IRS sites use specialized authentication flows), but common supporting tools like QuickBooks Online and Intuit ProConnect are included.
Admin Console: Business plan admins can enforce master-password strength requirements, mandate MFA, remotely revoke access for departed employees, and view a basic activity log.
Pricing
- Starter: $2.00/user/mo, billed annually, 1-user minimum, capped at 10 users and 5,000 stored passwords total
- Business: $8.00/user/mo, billed annually, 1-user minimum — removes the password cap, adds phishing alerts, admin console, SAML SSO, and live dark-web monitoring
- Business+: $13.00/user/mo, billed annually, 1-user minimum — adds dedicated customer success manager, priority support, and advanced SIEM-ready event logs
- Enterprise: $17.00/user/mo, billed annually, 1-user minimum — adds custom security policies and procurement flexibility
Note that SSO integration requires the Business plan at minimum ($8.00/user/mo) — if you're evaluating Dashlane for a firm that already uses Azure AD or Okta and wants SSO from day one, the Starter plan won't work.
Honest Weakness
Dashlane does not offer a self-hosted or on-premises deployment option under any plan. All vault data is stored on Dashlane's cloud infrastructure. For CPA firms that have made a policy decision to keep credential storage on their own servers or their own cloud tenant — a choice some WISP advisors recommend — this is a hard blocker. Additionally, Dashlane's audit logging on the Business plan captures event categories (login, share, delete) but does not record the specific IP address of the acting device in all event types, which is a gap compared to 1Password's and Keeper's more granular logs.
Try Dashlane — the easiest deployment for solo CPAs who want phishing protection and dark-web monitoring without an IT admin.
NordPass — Best Budget Option with Modern Encryption
NordPass is the best choice for cost-conscious CPA firms or practices already using Nord Security products (NordVPN, NordLayer) who want a modern-encryption password manager at a lower per-seat cost.
Security Architecture
NordPass is notable for using XChaCha20 encryption rather than the AES-256 standard used by most competitors. XChaCha20 is a modern stream cipher favored for its resistance to timing attacks and its performance on devices without hardware AES acceleration. Key derivation uses Argon2id, currently considered the strongest standardized KDF. NordPass is developed and operated by Nord Security, headquartered in Panama (privacy-favorable jurisdiction with no mandatory data retention laws) with European operational infrastructure.
MFA methods: TOTP, hardware security keys (YubiKey 5 via FIDO2/WebAuthn), and passkeys. NordPass has added passkey creation and storage to its Business plans as of 2025, which is relevant for firms planning to move IRS e-Services authentication to passkeys as the IRS expands passkey support.
NordPass completed a no-knowledge architecture audit by Cure53 (2023) and holds SOC 2 Type II certification (2024).
Standout Features
Passkey Storage and Autofill: NordPass stores passkeys natively and autofills them across Windows, macOS, iOS, and Android. As IRS.gov and IRS e-Services expand passkey login support, this positions NordPass ahead of some competitors.
Data Breach Scanner: Scans stored email addresses and credit card numbers against known breach databases. Unlike Keeper's BreachWatch, this is included in the Teams and Business plans at no extra cost.
Item Sharing with Expiry: You can share individual credentials or secure notes with an expiry date — useful for sharing a client's temporary login with a seasonal preparer for a defined period without permanently adding them to a vault.
Admin Dashboard: Provides a centralized view of user onboarding status, MFA adoption rate, and item health across the organization. It's functional but less detailed than Keeper's compliance reporting.
Nord Ecosystem Integration: Firms already paying for NordLayer (the business VPN product) can manage billing and user provisioning from a single Nord Teams dashboard, reducing administrative overhead.
Pricing
- Teams: $4.99/user/mo, billed annually, 1-user minimum, up to 10 users — includes shared vaults, admin dashboard, and breach scanner
- Business: $5.99/user/mo, billed annually, 1-user minimum — adds SSO, advanced MFA policies, priority support, and activity logs
- Enterprise: $8.99/user/mo, billed annually, minimum 5 users — adds dedicated account manager, custom onboarding, and SIEM integration; 250+ seat pricing requires a separate quote at a stated starting floor of $8.99/user/mo
Honest Weakness
NordPass's role-based access control is less granular than Keeper's or 1Password's. In the Business plan, you can designate users as "Admin" or "Member" — that's it. There is no middle tier for a senior associate who needs to manage one specific shared vault without having full admin rights over all vaults. For a large CPA firm with department-level access segmentation, this binary permission model is a genuine architectural limitation. Firms with five or fewer staff may never notice it, but a 30-person practice with separate tax, audit, and advisory departments will hit this constraint quickly.
Try NordPass — the strongest value pick for small CPA practices that want modern XChaCha20 encryption and passkey support under $6/user/month.
Who Should Choose What
Solo CPA or two-person practice: Go with Dashlane Business at $8.00/user/mo. The phishing alerts are genuinely useful for a practitioner who doesn't have IT staff reviewing links, and the deployment takes under 30 minutes with no admin configuration required.
CPA firm of 3–20 staff: 1Password Business at $7.99/user/mo is the right fit. The per-client vault structure maps naturally to a practice's engagement model, and the audit log gives managing partners the visibility they need for WISP documentation without hiring a compliance consultant to configure it.
Firm with specific WISP documentation or state CPA board audit requirements: Keeper Security at $6.25/user/mo (Business) is the clearest match. The compliance reporting dashboard exports directly to the formats most WISP templates call for, and the FedRAMP authorization gives compliance-minded managing partners a credentialed reference point.
Budget-constrained firm or one already on NordVPN/NordLayer: NordPass Teams at $4.99/user/mo saves meaningful money without sacrificing core security. The XChaCha20/Argon2id architecture is technically strong even if the admin controls are simpler.
Multi-office or rapidly growing regional firm (20+ users): 1Password Enterprise at $19.95/user/mo or Keeper Security Enterprise at $9.00/user/mo are the two options worth a formal evaluation. Keeper wins on price; 1Password wins on user experience for non-technical staff. If your firm has a dedicated IT or security staffer, Keeper's controls are worth the steeper learning curve.
FAQ
Does the IRS e-Services portal officially require a specific type of password manager?
The IRS does not mandate a specific password manager or brand. IRS Publication 4557 (Safeguarding Taxpayer Data) requires that tax professionals implement "reasonable safeguards" for accessing taxpayer data systems, which includes using unique, strong passwords and multi-factor authentication for portals like e-Services. A SOC 2-audited, zero-knowledge password manager with MFA enforcement — such as 1Password, Keeper, Dashlane, or NordPass — satisfies this requirement. Your WISP should document which password manager you use, the MFA methods enforced, and your policy for revoking access when staff leave. The IRS doesn't audit the password manager itself; they audit whether you have documented security controls in place.
What MFA method should CPA firms use for the IRS e-Services portal specifically?
The IRS e-Services portal currently supports identity verification via ID.me, which supports TOTP authenticator apps, hardware security keys (FIDO2/WebAuthn-compatible), and passkeys. CPA firms should configure their password manager to store the TOTP seed or passkey for each staff member's e-Services account, and firm policy should prohibit SMS-based MFA where the portal offers an alternative. NIST SP 800-63B (the federal digital identity standard) explicitly downgrades SMS OTP as a security factor due to SIM-swapping risk. Hardware keys like YubiKey 5 NFC ($50–$70 per key) are the strongest option for partners with access to sensitive IRS systems. All four password managers reviewed here support YubiKey/FIDO2 for their own login layer as well.
Can multiple staff members share access to the same IRS e-Services account using a password manager?
The IRS explicitly prohibits sharing e-Services login credentials between individuals. Each authorized firm representative must have their own individual e-Services account registered under their own PTIN. A password manager's vault-sharing feature should be used to give multiple staff members access to the firm's shared credentials (such as EFIN details, shared client portal logins, or tax software licenses) — but not to share a single individual's IRS e-Services login. Use shared vaults for firm-level credentials and individual vaults for each preparer's personal e-Services account. Some firms also store the firm's CAF number and Power of Attorney records as secure notes in a shared vault.
How does a Written Information Security Plan (WISP) interact with choosing a password manager?
An IRS-compliant WISP must document, at minimum: the tools used to protect taxpayer data, the access controls in place, and the procedures for responding to a data breach. Choosing a password manager that generates exportable audit logs — specifically 1Password Business or Keeper Business — means you can attach a dated access report directly to your WISP as evidence of control. Your WISP should name the password manager by product name, state that MFA is enforced firm-wide, specify the MFA methods permitted, and include the procedure for revoking access when a staff member or seasonal preparer leaves. The FTC Safeguards Rule (which applies to tax professionals as financial institutions) has overlapping requirements with IRS Publication 4557 on this point.
What's the difference between a password manager's "zero-knowledge" claim and actual security for a CPA firm?
Zero-knowledge means the password manager vendor cannot read your stored passwords — only encrypted ciphertext is stored on their servers, and the encryption key is derived from your master password (and, in 1Password's case, a Secret Key) locally on your device. For CPA firms, this matters because it limits the blast radius of a vendor-side breach: if the password manager company's servers are compromised, attackers get encrypted data that is computationally infeasible to decrypt without your master password. All four password managers in this roundup — 1Password, Keeper, Dashlane, and NordPass — make verifiable zero-knowledge claims backed by third-party audits. The practical risk remaining is on the client side: a keylogger or compromised device can still capture a master password before encryption happens, which is why hardware MFA (YubiKey) at the device level is the strongest complement to any zero-knowledge architecture.
Should a CPA firm use a password manager instead of, or in addition to, a single sign-on (SSO) solution?
SSO and a password manager solve different problems and work best together. SSO (via Azure Active Directory, Okta, or Google Workspace) centralizes authentication for the firm's own internal tools — tax software, practice management platforms, document management systems. A password manager handles the long tail of credentials that SSO doesn't cover: IRS e-