Skip to main content
 

Find details about security requirements for individuals who work under contract with the IRS. This includes eligibility requirements, background investigations, training and data security.

Contractor eligibility requirements

Individuals must meet these eligibility requirements to serve as a contractor with the IRS.

All contractors must have filed all required tax returns and paid all taxes due or be current on a payment plan for taxes due. Contractor employees must remain tax compliant while actively working on IRS contracts.

All males born after 1959 must be registered with Selective Service. If not registered or exempt, the contractor must have a Status Information Letter from Selective Service. Refer to who needs to register at the Selective Service System.

Contractors must meet these requirements:

U.S. citizenship or residency requirements based on position risk level

Position risk levelU.S. citizenship or residency requirement
Low riskU.S. citizen or Lawful Permanent Resident (LPR)
Moderate riskU.S. citizen or LPR with at least three consecutive years of U.S. residency from the date of legal entry as an LPR.
High riskU.S. citizen

All IRS contractors are subject to Continuous Vetting (CV). CV is a process that involves regularly reviewing a cleared individual’s background to ensure they continue to meet security clearance requirements and should continue to hold positions of trust. Specifically, CV conducts automatic record checks of security-relevant information allowing the national security program to detect potential eligibility and suitability risks early, so mitigation and adjudication can be done quickly. 

The automatic records check, seven in total, include data related to potential terrorism, criminal activity, foreign travel, suspicious financial transactions, quarterly credit reports, and activities available in public records.  All non-sensitive public trust holders will be enrolled automatically. 

If you have questions or concerns about these requirements, contact your COR.

Submitting background investigation forms

After your contract has been awarded, but before work begins, you must send specific forms to start a background investigation for each potential contractor.

The contracting officer's representative (COR) of the awarded contract will explain the process, provide access to the forms and outline any additional requirements. The COR will be your liaison with IRS Personnel Security. 

Provide complete and accurate information 

The information you provide for background investigations should be complete and free from errors. Forms must not have contradictory information. We recommend you set up an internal review process to ensure quality information is provided to the COR. 

All completed forms must contain the applicant’s full and correct:

  • Legal name that matches their identification
  • Social Security number
  • Phone number 
  • Personal email address

Discrepancies within the paperwork will delay the investigation process.

Required training

You must complete mandatory briefings and role-based security IT training before beginning work and each year after completing the trainings. 

Contact your IRS COR for more details on these policies.

You must take all mandatory briefings before we grant you access to facilities, systems or sensitive but unclassified (SBU) data.

You must report the completion of the mandatory briefings by sending Form 14616, Contractor Mandatory Briefings Certification and Form 11370, UNAX, to your COR for submission.

Additional information is available in Policy & Procedures 10.8.1. Contact your COR for more details on these briefings.

You must complete security training pertinent to your role if you perform system administration, network administration, database administration, programming, developing or other specialized information technology security services listed below. Security training is also required if your work is 50 percent or more related to the Federal Information Security Act (FISMA).

If you work in more than one position, then you must complete the greater number of security training hours between the different positions. You must complete training outside the IRS. SITS training is not available through our systems or links.

Send the certificates of completion to your COR.

Specialized information technology roles, and hours of training required for each role per IRM 10.8.1 and IRM 10.8.2

The following specialized IT roles each require 8 hours of training:

  • Computer audit specialist
  • Database administrator (DBA)
  • Enterprise architect
  • Functional workstation specialist
  • Information system security engineer
  • Live data functional coordinator (LDFC)
  • Management/Program analyst
  • Network administrator (NA)
  • Physical security analyst
  • Physical security specialist
  • Program developer/Programmer security specialist (SecSpec)
  • System administrator (SA)
  • System designer
  • Systems operations staff
  • Technical support staff (Desktop)
  • Telecommunications specialist
  • User administrator (UA)
  • Web developer

Data breach information for contractors

You're responsible for protecting all information entrusted to you. This information includes federal tax returns, return information and other information subject to the Privacy Act. Internal Revenue Code Section (§)6103 (Cornell Law School) outlines the steps you need to take to protect and disclose confidential returns and return information. The Privacy Act of 1974 (Department of Justice) outlines what you need to do to protect information covered by the Act.

You're prohibited by federal law from disclosing federal returns or return information unless allowed by statute. You and those who work for you have a responsibility to understand and apply the provisions of the law that relate to your job.

You must follow Publication 4812, Contractor Security Controls, PDF if you have information, will need access to information, or maintain or use information systems.

You must be aware of your responsibilities under the law to safeguard sensitive information. Publication 4465-A, Protecting Federal Tax Information for Contractors PDF, contains the steps you need to take when data is lost or compromised and the penalties for unauthorized disclosure.

You must follow breach response policies and procedures as defined in Publication 4812, Section 18, Incident Response, when responding to an identified unauthorized disclosure or data breach.

You must report all accidental unauthorized disclosures of tax information to your Contracting Officer’s Representative (COR) or Project Manager within one hour of detection. Your COR is the liaison responsible for managing the contract and communicating with you. Your COR will report the disclosure to incident management using the incident reporting form.

You should assign a trained Point of Contact (POC) to help with mitigating the breach. To notify the COR, create a breach report with the below information:

  • Name of contact for resolving data breach with contact information,
  • Date and time the breach occurred,
  • Date and time the breach was discovered,
  • How the breach was discovered,
  • Description of the breach and the data involved, including specific data elements, if known,
  • Potential number of FTI records involved; if unknown, give a range, if possible,
  • Address where the breach occurred and
  • Any information technology (IT) involvement (e.g., laptop, server or mainframe).

Contact your COR immediately if FTI may has been involved in an unauthorized disclosure or data breach. Then conduct your internal investigation to confirm this information.

Notification to affected individuals regarding an unauthorized disclosure or data breach is based upon the Breach Response Plan.