For CPA firms
An assessment your quality-management partner can read.
Tidebreak performs a practitioner-grade assessment of your firm's IT environment, mapped to the security framework your peer reviewers and carriers already recognize and to the quality-management and confidentiality obligations your firm already carries under SQMS No. 1 and the AICPA Code.
CIS CONTROLS v8.1.2 × AICPA CODE + SQMS 1
What the rule actually asks for
SQMS No. 1 (effective December 15, 2025) reshapes what a CPA firm has to be able to show. Under the new standard, a firm's system of quality management names information and technology resources as a component the firm must design, implement, and operate, with quality objectives, identified risks, and responses the firm can evidence; peer review wants independent evidence that the technology component is real and operating, not asserted. The AICPA Code of Professional Conduct (as updated through 2025) sits alongside it: section 1.700, the Confidential Client Information Rule, makes the protection of client information a professional obligation, and the rule does not soften because the data sits in a cloud tenant a managed service provider administers. For firms that prepare tax returns, the tax-practice overlay sharpens the point: IRS section 7216 governs the use and disclosure of taxpayer information, IRS Publication 4557 sets out the safeguarding expectations the Service holds tax preparers to, and the FTC Safeguards Rule (16 CFR Part 314, as amended 2023) reaches many tax-prep practices directly. Your quality-management partner tracks these. What the firm often lacks is an independent reading of the environment that maps each obligation to a tested control.
What SQMS No. 1 changes
The shift in SQMS No. 1 is that quality management stops being a manual on a shelf and becomes a system the firm operates and monitors. The standard asks the firm to set quality objectives, identify the risks to meeting them, and design responses, and it names the firm's information and technology resources as one of the components that has to be carried through that cycle. That is a meaningful change from the predecessor quality-control standards, which treated technology far more lightly. A firm can write a technology component into its quality-management documentation in an afternoon. Demonstrating that the component is designed against real risks, operating as designed, and monitored over time is the harder thing, and it is exactly the thing peer review is being trained to look for. An independent assessment, mapped to CIS Controls v8.1.2, gives the firm tested evidence that the technology responses it documented are the technology responses actually in force.
The confidentiality obligation runs underneath all of it. AICPA Code section 1.700 makes client information something the member must protect, and a firm whose client files, working papers, and tax data live in systems an outside provider administers has extended the surface over which that obligation operates without always extending the oversight to match. The tax-practice overlay is where the exposure becomes concrete: a firm preparing returns holds taxpayer information that section 7216 protects, that Publication 4557 expects to be safeguarded under a written security plan, and that the FTC Safeguards Rule may govern as customer information. None of these regimes asks the firm to become a security shop. They ask the firm to be able to show that it understands where client and taxpayer data lives, who can reach it, and whether the controls protecting it are real.
What the firm receives
In practice, the assessment hands the firm a reading organized the way SQMS No. 1 is organized. Each finding carries its evidence reference, the CIS Controls v8.1.2 safeguard it implicates, and the quality-management or confidentiality provision it touches, so the Executive Report can sit inside the firm's quality-management documentation as independent evidence and the Full Assessment Report can move to the IT provider's remediation queue without a meeting to interpret it. We test a risk-based sample of the controls most likely to matter under peer-review and confidentiality pressure, document why we sampled there, and reconcile what the environment shows against what the provider reports. The boundary is firm. The firm operates and monitors its own system of quality management; the firm's leadership makes every professional determination. Our work is the independent input that monitoring rests on, not the monitoring itself, and nothing we issue is an attest opinion.
Worked example
Representative finding
Standing vendor access to the tax-prep file store, never reviewed
CIS Safeguard 6.8 Access Control Management · SQMS No. 1 information-and-technology-resources component and AICPA Code 1.700
The firm's tax-preparation working files lived in a cloud file store that the firm's managed service provider administered. Two provider engineers held standing administrative access granted at onboarding. No periodic access review had been performed in the three years since. The firm's quality-management documentation named technology as a component but pointed to no evidence that access to the client- and taxpayer-data store was scoped, reviewed, or revoked on any cadence.
This is the most common CPA-firm pattern we expect to see as SQMS No. 1 takes hold. The access is operationally convenient and was never a decision anyone made on the record. It becomes a quality-management finding the moment a peer reviewer asks for evidence that the technology component is operating, and a confidentiality finding the moment anyone asks who can read the taxpayer data and how the firm would know if that list drifted. The remediation is procedural, not technical: scope the access, review it on a defined cadence, and keep the evidence.
What Tidebreak does, and what it does not
A Tidebreak assessment delivers an Executive Report your quality-management partner can place in the firm's quality-management evidence and forward to a peer reviewer or carrier, and a Full Assessment Report your IT provider can remediate against. The methodology is documented procedurally and maps directly to the technology component your system of quality management names and to the confidentiality obligation the AICPA Code carries. See the methodology
Tidebreak is independent. Tidebreak is not a CPA firm, does not issue attest opinions, and does not perform your firm's own SQMS No. 1 monitoring. We perform a practitioner-grade assessment of your IT environment. Our findings inform your system of quality management; they do not replace it.
Why this matters
For a CPA firm, the technology component of SQMS No. 1 is now part of what peer review examines, and peer review outcomes follow a firm into every proposal it writes and every license it holds. A firm that can produce an independent, framework-mapped reading of its environment answers the reviewer's technology questions with evidence; a firm that points to a documented component with nothing operating behind it invites a deficiency. The confidentiality stakes are just as direct: a breach of client or taxpayer data is an AICPA Code 1.700 problem, a section 7216 problem for the tax practice, and a client-trust problem that does not stay quiet. A cyber carrier underwriting a firm that holds returns and working papers prices the maturity of the firm's controls into the policy. And the exposure lands at the partner level, because the quality-management partner and the firm's leadership are the ones who certify the system is operating. An independent assessment is how the firm turns "technology is a named component" into evidence the firm designed it, operates it, and can show it.
Who runs the assessment
We assess MSPs. I used to run one.
Jeff White has spent twenty-five years in the IT business. Enterprise infrastructure architecture. Eight years at Microsoft Consulting Services. Most recently, VP of Engineering Services at a mid-market MSP, where he built out the service delivery organization and a 24/7 security operations center from the ground up.
Now he works for you, not your provider. Tidebreak exists to give firms like yours a read most don't have a way to get: an independent look at whether the IT you pay for is actually the IT you're getting.
VP Engineering Services, MSP · 8 years Microsoft Consulting Services · Azure Solutions Architect Expert · Assessments mapped to CIS Controls v8.1.2 and NIST CSF 2.0