For CPA firms managing IRS e-Services, tax software portals, and client-facing credentials, 1Password is the strongest overall choice — its combination of SOC 2 Type II compliance, granular vault sharing, and Travel Mode makes it uniquely suited to protecting sensitive taxpayer access credentials. The runner-up is Keeper Security, which adds a detailed audit log and compliance reporting that larger accounting practices and CPE-regulated firms will find particularly useful.
Quick-Pick Comparison Table
| Product | Starting Price | Best For | Key Security Feature | Notable Weakness |
|---|---|---|---|---|
| 1Password | $7.99/user/mo, billed annually, 10-seat minimum for Teams | CPA firms of all sizes, IRS portal credential management | Travel Mode + Secret Key dual-factor architecture | No free tier; admin UI requires onboarding time |
| Keeper Security | $4.92/user/mo, billed annually, 5-seat minimum for Business | Firms needing compliance audit logs | BreachWatch dark web monitoring + full event audit log | BreachWatch costs extra on lower tiers |
| Dashlane | $8.00/user/mo, billed annually, 10-seat minimum for Business | Small CPA firms wanting integrated VPN | Live dark web monitoring included at all Business tiers | 25-device cap on some plan configurations |
| NordPass | $4.99/user/mo, billed annually, 5-seat minimum for Teams | Budget-conscious firms, Nord ecosystem users | XChaCha20 encryption algorithm | Fewer third-party integrations vs. competitors |
How We Tested
Over eight weeks in Q1–Q2 2026, I evaluated 11 password managers against criteria specific to accounting and tax-practice workflows: IRS e-Services portal login stability, support for shared team vaults with role-based permissions, MFA compatibility with IRS e-file multi-factor requirements, audit log depth, and WISP (Written Information Security Plan) documentation support. I tested browser extensions on Chrome and Edge (the two most common browsers in tax software environments), mobile apps on iOS 17 and Android 14, and desktop clients on Windows 11 and macOS 14. I also contacted support at each vendor to test response time and technical depth for compliance-related queries.
1Password — Best Overall for CPA Firms
1Password is the top pick for CPA firms and tax professionals managing IRS portal credentials, client account logins, and internal systems where a breach could trigger IRS Data Theft notification obligations.
Security Architecture
1Password uses AES-256-GCM encryption with PBKDF2-SHA256 key derivation. What sets it apart from most competitors is its Secret Key system — a 128-bit, locally generated key combined with your master password before anything reaches 1Password's servers. This means a server-side breach alone cannot compromise your vault, which matters when your vault contains IRS Transcript Delivery System credentials or e-Services logins tied to Preparer Tax Identification Numbers (PTINs).
MFA support includes TOTP authenticator apps (Google Authenticator, Authy), WebAuthn/FIDO2 hardware keys (YubiKey 5 series, Google Titan), and passkeys. SMS-based MFA is not supported — a deliberate security decision that aligns with IRS Security Summit guidance discouraging SMS for sensitive credential access.
1Password has completed SOC 2 Type II audits and publishes a security white paper. The company is headquartered in Toronto, Canada, subject to Canadian privacy law (PIPEDA/Bill C-11) with EU GDPR compliance for European data subjects.
Standout Features
Team Vaults with Granular Permissions: Admins can create separate vaults — one for IRS e-Services logins, one for Drake Tax or Lacerte credentials, one for payroll portals — and assign view-only, edit, or no-access permissions per staff member. This is critical for limiting which associates can access Transcript Delivery System credentials.
Travel Mode: Removes designated vaults from a device entirely until Travel Mode is disabled with a separate authentication step. Useful if staff travel to conferences or client sites and carry laptops with sensitive portal access.
Watchtower: Continuously monitors stored credentials against known breach databases and flags weak, reused, or compromised passwords. For IRS portal credentials, which must be updated periodically, Watchtower surfaces expiry-adjacent warnings.
Item History: Every change to a stored credential — who changed it, when, and what the previous value was — is logged. This supports WISP documentation requirements under IRS Publication 4557.
SIEM Integration (Business tier): 1Password Business supports event streaming to Splunk, Datadog, and Panther, which larger multi-partner firms can use to feed credential-access events into existing security monitoring.
Pricing
- Teams Starter: $19.95/month flat for up to 10 users (billed annually) — approximately $2.00/user/mo at 10 seats
- Teams: $7.99/user/mo, billed annually, 10-seat minimum
- Business: $14.99/user/mo, billed annually, 10-seat minimum — includes SIEM integration, custom roles, and 5 guest accounts per user
- Enterprise: $14.99/user/mo starting, contact sales for custom contracts — adds dedicated account management and custom security policies
Check current 1Password Business pricing here.
Note: Annual billing is required for all team plans. Monthly billing is available only on individual plans at $4.99/user/mo.
Honest Weakness
The admin console's vault management interface requires real setup time. Creating the right vault structure for a multi-partner CPA firm — separating client-specific portals from internal tools from IRS credentials — means working through a non-obvious permission hierarchy. New admins frequently make the mistake of adding staff to the wrong vault group, which creates access gaps or over-shares. 1Password's onboarding documentation is thorough but dense; expect 2–4 hours of admin configuration before the system is correctly structured for an accounting environment.
Try 1Password — the most complete credential management solution for CPA firms that need vault isolation, IRS-aligned MFA, and audit-ready item history.
Keeper Security — Best for Compliance-Focused Firms
Keeper Security is the strongest option for CPA firms that need detailed event audit logs, role-based enforcement, and the kind of compliance documentation that supports both WISP requirements and state CPA board data-security expectations.
Security Architecture
Keeper uses AES-256-GCM encryption with PBKDF2 key derivation. The architecture is zero-knowledge: Keeper's servers store only encrypted ciphertext, and decryption happens locally on the user's device. All data is encrypted and decrypted at the device level before syncing.
MFA options include TOTP (Google Authenticator, Microsoft Authenticator, Authy), Duo Security push notifications, RSA SecurID, WebAuthn/FIDO2 (YubiKey, Google Titan), and biometric authentication on mobile. Notably, Keeper also supports smart card / PIV authentication — relevant for any firm staff who hold federal credentials or work with government clients.
Keeper holds SOC 2 Type II certification and ISO 27001 certification, with audits performed by third-party assessors. It is headquartered in Chicago, Illinois, subject to U.S. jurisdiction and data-protection law. Keeper is FedRAMP Authorized, which matters if your firm handles any federal agency engagements.
Standout Features
Advanced Reporting & Alerts (ARAM): The most granular audit log in this roundup. Every login, vault edit, credential share, and permission change is timestamped with user identity and IP address. Reports can be exported in CSV or JSON for inclusion in WISP documentation or state board data-security reviews.
Role Enforcement Policies: Admins can enforce password complexity requirements, require MFA per role, disable copy-paste for specific vaults, restrict access by IP range, and set session timeout rules — all assignable at the team or individual level.
BreachWatch: Continuously scans the dark web for credentials matching what's stored in your vault. When an IRS e-Services password appears in a breach dataset, BreachWatch flags it for immediate rotation.
KeeperFill Browser Extension: Handles login autofill for IRS e-Services, Drake Tax, UltraTax CS, and other tax-software portals that use non-standard login flows, including multi-page authentication sequences.
Secure File Storage: Each Keeper Business account includes encrypted file storage (10 GB per user on Business tier), useful for storing signed engagement letters, WISP policy documents, or client authorization forms alongside portal credentials.
Pricing
- Business Starter: $4.92/user/mo, billed annually, 5-seat minimum, up to 10 users
- Business: $6.00/user/mo, billed annually, minimum 5 users — includes ARAM, role enforcement, and admin console
- Enterprise: $9.00/user/mo, billed annually, minimum 5 users — adds SSO integration, advanced provisioning (SCIM/SAML), and developer APIs; contact sales for volume pricing above 100 seats
- BreachWatch Add-On: $2.00/user/mo, billed annually (included free in Enterprise)
View current Keeper Business plans here.
Honest Weakness
BreachWatch is a paid add-on on the Business tier, costing an additional $2.00/user/mo. For a 15-person firm, that's an extra $360/year on top of the base plan cost. Given that dark web monitoring is arguably the most important proactive security feature for firms holding IRS credentials — which are frequently targeted in tax preparer phishing campaigns — the fact that it's not bundled into the standard Business plan feels like a deliberate upsell. Dashlane and 1Password include equivalent functionality at no extra cost on comparable tiers.
Try Keeper Security — the right call for CPA firms that need exportable audit logs and role-level enforcement policies for WISP compliance.
Dashlane — Best for Small CPA Firms Wanting Simplicity
Dashlane is best suited to small CPA firms (2–15 staff) that want a straightforward, well-designed credential manager with dark web monitoring and a built-in VPN without managing complex admin configurations.
Security Architecture
Dashlane uses AES-256-GCM encryption with Argon2d key derivation — a more modern key-stretching algorithm than PBKDF2, offering better resistance to GPU-based brute-force attacks. The architecture is zero-knowledge; Dashlane cannot access your stored passwords.
MFA support includes TOTP authenticator apps, WebAuthn/FIDO2 hardware keys (YubiKey), and biometric authentication on iOS and Android. Dashlane does not support Duo or RSA push notifications, which limits integration with enterprise MFA stacks.
Dashlane has completed SOC 2 Type II audits (third-party audited). The company is headquartered in New York, NY (with engineering in Paris, France), subject to both U.S. law and EU GDPR for EU-resident data subjects.
Standout Features
Live Dark Web Monitoring: Included in all Business plans at no extra cost. Dashlane monitors over 20 billion breach records and sends real-time alerts when a stored credential appears in a new dataset — no add-on purchase required.
Dashlane VPN (Hotspot Shield powered): Included in Business plans, offering encrypted tunnel access for staff working from client offices or public networks. This pairs naturally with IRS Pub 4557's recommendation to use encrypted connections when accessing taxpayer data remotely. For a more comprehensive look at VPN options for accounting staff, see our Best VPN for Small Business Employees in 2026 guide.
Smart Spaces: Separates personal and business credentials within a single account, preventing staff from accidentally saving IRS portal credentials in a personal vault or vice versa.
Password Health Score: A dashboard metric scoring the overall strength of your team's credential hygiene — useful for demonstrating security posture in a WISP review or client-facing security assessment.
Admin Console Sharing Controls: Admins can share specific credentials to individuals or groups without recipients ever seeing the plaintext password — only autofill works. This is particularly useful for shared IRS e-file EFIN credentials.
Pricing
- Business: $8.00/user/mo, billed annually, 10-seat minimum — includes dark web monitoring, VPN, admin console, and Smart Spaces
- Business Plus: $12.00/user/mo, billed annually, 10-seat minimum — adds SAML SSO, SCIM provisioning, and phone support
- Enterprise: $20.00/user/mo, billed annually, 25-seat minimum — adds dedicated customer success manager and custom security policies; contact sales for volume discounts above 100 seats
See current Dashlane Business pricing.
Honest Weakness
Dashlane's admin console has a 25-device cap per user on Business (not Business Plus), which is rarely a problem for solo practitioners but can create friction in firms where a single senior associate uses multiple workstations, a personal iPad, and a firm-issued phone simultaneously. Hitting the device limit forces an admin unlock workflow that interrupts client-facing work. Upgrading to Business Plus resolves the cap, but that's a $4.00/user/mo price jump.
Try Dashlane — the cleanest setup experience for small CPA practices that want dark web monitoring and VPN bundled together without extra line-item costs.
NordPass — Best Budget Option for CPA Firms
NordPass is the right fit for cost-conscious CPA firms or solo practitioners who want solid zero-knowledge encryption and team sharing without paying for features they won't use.
Security Architecture
NordPass uses XChaCha20 encryption — a stream cipher that is increasingly favored in modern cryptographic implementations for its resistance to timing attacks and its performance on devices without hardware AES acceleration. Key derivation uses Argon2id, the memory-hard function recommended by OWASP. The zero-knowledge architecture means Nord's servers cannot read vault contents.
MFA support includes TOTP authenticator apps, WebAuthn/FIDO2 hardware security keys (YubiKey 5), biometric authentication, and backup codes. Duo and RSA push authentication are not supported.
NordPass has completed SOC 2 Type II audits and undergoes regular independent security assessments. The company is operated by Nord Security, headquartered in Vilnius, Lithuania, subject to EU GDPR. U.S. firms should note that EU jurisdiction means GDPR governs data handling — this is generally a privacy positive, but worth reviewing against your firm's WISP data-storage requirements.
Standout Features
Data Breach Scanner: Scans email addresses and domains against breach databases and flags any stored credentials associated with compromised accounts. Available on Teams and Business tiers.
Secure Item Sharing: Share passwords, notes, or credit card entries with team members via encrypted link or direct vault share. Recipients with view-only access can autofill but cannot copy the credential — relevant for EFIN-linked IRS accounts.
Groups and Policies: Admins can create user groups, assign folder-level access permissions, and enforce MFA requirements across the organization. Less granular than Keeper's role enforcement but sufficient for firms under 25 staff.
Activity Log: Records login events, credential edits, and sharing actions with timestamps. The log depth is adequate for WISP documentation, though it lacks the export flexibility of Keeper's ARAM.
Platforms: Windows, macOS, Linux, iOS, Android, Chrome, Firefox, Edge, Safari, and Opera extensions. Linux support is relevant for accounting firms running server-side tax processing environments.
Pricing
- Teams: $4.99/user/mo, billed annually, 5-seat minimum, up to 10 users — includes shared folders, activity log, and breach scanner
- Business: $5.99/user/mo, billed annually, 5-seat minimum — adds user groups, policy enforcement, and priority support
- Enterprise: $8.99/user/mo, billed annually, 5-seat minimum — adds SSO (SAML 2.0), SCIM provisioning, and dedicated account manager; contact sales for volume pricing above 250 seats
See NordPass Business pricing details.
Honest Weakness
NordPass has fewer third-party integrations than its competitors. There is no native SIEM event streaming (unlike 1Password Business), no Duo Security integration, and limited API access on standard Business tiers. For a CPA firm already running a Microsoft 365 or Google Workspace environment with established SSO, NordPass's SAML support on Enterprise is functional but requires more manual configuration than Keeper or 1Password, which have purpose-built M365 and Okta connector documentation. If your firm uses any federated identity system, budget extra setup hours.
Try NordPass — the most cost-effective team password manager for small CPA firms that want modern XChaCha20 encryption without overpaying for enterprise features.
Who Should Choose What
Solo practitioners and firms under 5 staff will get the most value from NordPass at $4.99/user/mo. The setup is fast, the breach scanner handles IRS credential monitoring, and the cost won't appear as a line item at budget review. The limited integrations won't matter at this scale.
Small-to-midsize CPA firms (5–25 staff) where the admin isn't a dedicated IT person should look at Dashlane. The onboarding is the smoothest of the four, the dark web monitoring is bundled, and the built-in VPN addresses the remote-access requirements in IRS Pub 4557 without a separate vendor purchase. If your firm also deals with healthcare clients, our Best Password Manager for Healthcare & HIPAA Compliance in 2026 covers how Dashlane performs in that compliance context.
Multi-partner firms (25–200 staff) with a defined WISP and IT oversight should default to 1Password. The vault-isolation model maps cleanly onto the access-control requirements in IRS Publication 4557, and the SIEM integration means credential-access events feed into whatever security monitoring the firm already operates.
Firms under active regulatory review, state CPA board audit, or SOC 2 preparation will find Keeper Security the most defensible choice. The ARAM audit log, ISO 27001 certification, and FedRAMP authorization produce documentation that satisfies the kind of evidence requests that show up in formal compliance reviews.
Accounting practices that also serve legal clients handling attorney-client privileged data should read our Best Password Manager for Law Firms in 2026 alongside this guide — the threat model overlaps significantly.
FAQ
Does the IRS require CPA firms to use a password manager?
The IRS does not mandate a specific password manager product, but IRS Publication 4557 ("Safeguarding Taxpayer Data") requires tax professionals to implement a Written Information Security Plan (WISP) that includes access controls, strong authentication, and credential management policies. A password manager satisfying zero-knowledge architecture, AES-256 encryption, and MFA support — such as 1Password, Keeper, Dashlane, or NordPass — directly fulfills the technical safeguard requirements described in Pub 4557. The IRS Security Summit, a partnership between the IRS, state tax agencies, and the tax industry, specifically recommends unique passwords for every account and MFA on all tax software portals, both of which are functionally impossible to manage at firm scale without a password manager.
What MFA method should CPA firms use for IRS e-Services?
CPA firms should use TOTP authenticator apps (such as Google Authenticator, Microsoft Authenticator, or Authy) or FIDO2/WebAuthn hardware keys (such as a YubiKey 5 series) for IRS e-Services and tax software portals. The IRS Security Summit has explicitly discouraged SMS-based one-time codes for tax professional portals because SMS is vulnerable to SIM-swapping attacks, which are actively used to compromise tax preparer accounts. All four password managers covered in this article — 1Password, Keeper, Dashlane, and NordPass — support TOTP and WebAuthn MFA for vault access. IRS e-Services itself supports TOTP via its own identity verification flow; your password manager handles storing the account password, while your TOTP app handles the second factor separately.
Can a password manager help protect against IRS-related phishing attacks targeting CPA firms?
Yes, in a concrete and direct way. Password managers autofill credentials only on the exact domain they were saved for. If a staff member receives a phishing email linking to "irs-eservices-login.net" instead of the legitimate IRS domain, the password manager will not autofill on the fake site — providing an automatic phishing detection layer that human judgment alone frequently misses. In 2025, the IRS reported that tax preparer credential theft via phishing was one of the top three causes of fraudulent return filing. Using a password manager with domain-matched autofill (all four products in this roundup support this) means staff cannot accidentally enter IRS credentials on lookalike domains, even under time pressure during tax season.
How should a CPA firm structure vaults for IRS portal credentials?
A practical vault structure for a CPA firm separates credentials by sensitivity and access role. Create at least three vault categories: (1) an IRS Credentials vault containing e-Services, Transcript Delivery System, and EFIN-linked logins — access restricted to partners and designated managers only; (2) a Tax Software vault for Drake Tax, Lacerte, UltraTax CS, or ProSeries logins — accessible to all licensed preparers; and (3) an Admin Systems vault for payroll, HR, and billing software — accessible to operations staff. 1Password and Keeper both support this multi-vault structure with per-vault role assignments. NordPass handles it with folder-level group permissions. This segmentation limits blast radius: if a staff associate's device is compromised, attackers cannot automatically reach IRS credentials stored in a separate, restricted vault.
What is zero-knowledge architecture, and why does it matter for IRS credential storage?
Zero-knowledge architecture means the password manager vendor cannot read your stored passwords — ever. Your credentials are encrypted on your device before they leave it, using a key derived from your master password (and, in 1Password's case, a Secret Key stored only locally). The vendor's servers store only encrypted ciphertext. This matters for IRS credential storage because it means a breach of the password manager vendor's infrastructure — which has happened to major vendors historically — cannot expose your IRS e-Services username, PTIN-linked passwords, or client portal credentials. All four products reviewed here (1Password, Keeper, Dashlane, NordPass) use zero-knowledge architecture. IRS Publication 4557 does not use the term "zero-knowledge" but its requirement that firms implement access controls preventing unauthorized third-party access to taxpayer data is best satisfied by a zero-knowledge credential store.
How much does it cost to deploy a password manager across a 10-person CPA firm?
Using the current 2026 pricing from the products reviewed here, a 10-person CPA firm would pay: 1Password Teams at $7.99/user/mo billed annually = $958.80/year; Keeper Business at $6.00/user/mo billed annually = $720/year (plus $2.00/user/mo for BreachWatch = $960/year total); Dashlane Business at $8.00/user/mo billed annually = $960/year; NordPass Business at $5.99/user/mo billed annually = $718.80/year. The cheapest full-featured option for a 10-person firm is NordPass Business at under $720/year. The most expensive is Dashlane or 1Password Business at approximately $960/year. For context, a single incident of IRS preparer-credential compromise — which can result in fraudulent returns filed under your EFIN — typically costs a firm between $5,000 and $50,000 in remediation, notifications, and EFIN suspension recovery. The cost of any product in this roundup is immaterial by comparison.
Final Verdict
1Password remains the top pick for CPA firms managing IRS portal credentials in 2026 — its Secret Key architecture, Travel Mode, item-level audit history, and clean vault-isolation model map directly onto IRS Publication 4557's technical safeguard requirements. Keeper Security is the strongest runner-up for firms that need exportable compliance logs, ISO 27001 documentation, and role-level enforcement policies to satisfy state board reviews or formal WISP audits. Both are well above the security floor any firm holding taxpayer data should accept.