How Much Should an Accounting Firm Website Cost in 2026?
On 18 August 2026 the IRS put out a news release with nothing in it about websites. It reminded tax and accounting professionals that federal law requires them to keep a Written Information Security Plan, listed what the Federal Trade Commission expects that plan to cover, and pointed at a free template. Read it as a builder rather than a preparer and it is a specification document, because almost every requirement in it lands somewhere on your website: the form clients type into, the place their documents come to rest, who can log in, and which outside company holds the file.
That is why a price for an accounting firm website is harder to give honestly than a price for a landscaping company website, and why most published answers are useless. They price the brochure. Every figure below was read on the seller's own page on 25 August 2026, every legal citation points at the regulation rather than a summary of it, and where a number is our own arithmetic the sentence says so. Websites are what we sell, including to firms in this category, so read what follows as a price list published by one of the vendors on your shortlist.
The 30-second answer
A website for an accounting or tax firm is a one-time build in the low thousands, or a subscription: the accounting-specific platforms we priced run from $90 to $500 a month, and one agency in this niche publishes $499 for a one-time three-page build. We charge $1,499 as a flat one-time fee, or $2,499 a month when the site is treated as continuing work. The website is the small number. The platform that carries client documents is priced per person, from $19 to $149 per user per month across the five platforms that price it that way, so a five-person firm faces roughly $1,140 to $8,940 in year one on the portal alone against about $1,080 for the site itself. That split is not an accident of the market. Federal law treats an accounting firm as a financial institution, and the encryption, multi-factor authentication and vendor oversight it demands all live on the expensive side of the split.
Federal law prices your website differently from a plumber's
Your firm is a financial institution, and the regulation says so by name. The FTC Safeguards Rule defines its own scope at 16 CFR 314.2, and its list of worked examples includes this one: "An accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution because tax preparation services is a financial activity." No revenue threshold, no headcount test, no distinction between a sole practitioner in a spare room and a hundred-person firm.
What follows from that is what the FTC counts as nine required elements in 16 CFR 314.4. Four of them are decisions you make when you buy or build a website. You must designate a Qualified Individual to run the program. You must "protect by encryption all customer information held or transmitted by you both in transit over external networks and at rest." You must implement multi-factor authentication for anyone accessing an information system that holds customer information. And you must oversee your service providers, which now includes whoever hosts your site, by selecting them for their safeguards, requiring those safeguards by contract, and periodically assessing them.
Small firms get less relief here than they expect. 16 CFR 314.6 exempts firms holding information on fewer than five thousand consumers from exactly four things: the written risk assessment, the continuous monitoring or penetration testing and vulnerability assessment duty, the written incident response plan, and the annual report. Encryption is not on that list. Multi-factor authentication is not on that list. Service provider oversight is not on that list. A two-person practice with four hundred clients is exempt from the paperwork and bound by the controls.
The IRS says the same thing in plainer language. Its release of 18 August 2026, IR-2026-92, opens with "Federal law requires tax and accounting professionals to create and maintain a Written Information Security Plan," names the Gramm-Leach-Bliley Act as the source, and lists the FTC's requirements to designate a coordinator, assess risks, monitor and test safeguards, and select service providers whose contracts require compliance. It also restates a reporting rule that is easy to miss, and we will come back to that at the end.
What the website itself costs
Between about $90 and $500 a month if you buy a platform built for this profession, or a low four-figure one-time fee if you buy a build. Here is what the vendors publish, read on 25 August 2026.
CPA Site Solutions prices four tiers on its pricing page: Silver at $90.00 a month, Gold at $111.00, Platinum at $137.00 and Diamond at $166.50. All four include what it calls a Secure Firm Portal, with storage rising by tier from 5GB to unlimited. CountingWorks Pro sells a bigger bundle and prices it monthly with an annual discount: Starter at $150 a month or $1,620 a year, Grow at $200 or $2,160, Premier at $300 or $3,240, and Premier Plus at $500 or $5,400. Each tier includes one website, except Premier Plus which includes two, and each caps users and contacts: one user and 250 contacts at Starter, ten users and 5,000 contacts at Premier Plus.
TaxDome takes a third approach and folds the website into a practice management seat. Its pricing page lists Essentials, Pro and Business at $800, $1,000 and $1,200 per seat per year on a one-year commitment, dropping to $700, $900 and $1,100 on a three-year commitment, all billed upfront. A "fully managed professional website for your firm" appears in the Pro tier, alongside a custom firm URL and branded emails. So the website is free in the sense that a second bedroom is free when you buy the house.
Outside the platforms, published one-time prices in this niche are rare but they exist. MITCO Tech states on its accountant page that "Pricing starts from $499 for a new 3-page, SEO optimized website, including design and build." Build Your Firm, one of the older names in accounting marketing, publishes no price anywhere on its home page. Our own build is $1,499 as a flat one-time fee, or $2,499 a month if you want the site worked on continuously rather than delivered and left alone.
Twelve months of the cheapest of those tiers, CPA Site Solutions Silver, comes to $1,080. Twelve months of its Diamond tier comes to $1,998, which buys a custom design and a certificate we will come back to.
One caution before you budget from any of these. On the same day, CPA Site Solutions' home page advertised "For as low as $76.00 a month" while its own pricing page put the cheapest tier at $90.00. That is a fourteen dollar gap between two pages on one website, and it is the reason the only price worth planning around is one a salesperson has put in an email with a date on it.
The bill nobody quotes: the portal is priced per person
Between $19 and $149 per user per month, and it scales with your staff rather than your client list. This is the line item that turns a cheap website into an expensive year, and the guides ranking for this question leave it out entirely. We pulled three of them on 25 August 2026, between 19,000 and 29,000 characters each, and searched the text: "Safeguards" appeared zero times across all three, "multi-factor" zero, "WISP" zero, "encryption" zero, "per user" zero, and "client portal" once, in one page. It does not look like a website expense until you notice that the upload button on your contact page has to point somewhere.
Six platforms in this category publish their rates. Liscio charges $19 per user per month for Intelligent Files, $49 for the Liscio Platform and $99 for Tax Team, all billed annually. Financial Cents charges $19 a month for a single-user Solo plan, then $49 per user for Team and $69 per user for Scale, and requires a minimum of five users for monthly billing. SmartVault charges $55 per user per month for Business Pro with a three-user minimum, $65 for Accounting Pro and $85 for Accounting Unlimited, both with a two-user minimum, and about a third more if you pay monthly rather than annually. Karbon charges $59 per user per month for Team and $89 for Business on annual billing. Canopy charges $74, $109 and $149 per user per month for Standard, Plus and Premium. TaxDome, as above, prices per seat per year.
Two things in that chart are worth more than the headline rates. The first is the minimum. SmartVault's cheapest plan carries a three-user minimum, so the real floor is $165 a month even for a two-person office, and Financial Cents will not bill monthly at all under five users. The second is the gap between the entry tier and the tier the vendor actually markets to tax firms, which runs from $30 a user at Liscio to $75 a user at Canopy. That gap is where the compliance features sit, which is a pattern rather than a coincidence, and the next two sections are about the two clearest examples of it.
Payment processing is the last piece, and the platforms that publish rates charge it separately. Canopy publishes 3.30% plus $0.20 on cards and 1% on ACH capped at $10. Karbon publishes 2.6% plus $0.30 on standard cards, 3.6% plus $0.30 on premium cards, 3.9% plus $0.30 on American Express and 1% plus $0.30 on ACH capped at $5. On a $236 tax return fee, the difference between taking that payment on a premium card through Karbon and taking it by ACH is $6.14, which is worth having across four hundred returns.
The line item that should not be a line item
Encryption in transit is a legal requirement for your firm, and at least one vendor in this niche sells it as an upgrade. On CPA Site Solutions' pricing page, "HTTPS (SSL) Certificate" is listed as a feature of the Diamond tier at $166.50 a month, and further down the same page "Additional HTTPS Website Security" appears in the add-on list at $9.99 a month.

Compare that to the rule the buyer is bound by. 16 CFR 314.4(c)(3) requires a firm to protect customer information by encryption "both in transit over external networks and at rest", with the only escape being a written finding by the Qualified Individual that encryption is infeasible and that compensating controls are in place instead. The FTC's own plain-language guidance puts it as encrypting customer information on your systems and in transit. A login form for a client portal, embedded in a page served without a certificate, is the exact failure that requirement describes.
We checked whether that theoretical failure is a live one. CPA Site Solutions showcases named client sites on its own website, and we tested three of them on 25 August 2026: hmwcpas.com, greysontax.com and glcpas.com. All three answer on plain HTTP with a permanent redirect to HTTPS, which is the correct behavior. So the practice looks better than the price list. That is worth stating plainly rather than implying a scandal that is not there. What remains true is that the page a prospective buyer reads before signing tells a firm with a statutory encryption duty that a certificate belongs in the most expensive tier, and the vendor's own portal feature page advertises "Sarbanes Oxley and Gramm-Leach-Bliley compliance" without mentioning multi-factor authentication anywhere on it.
Who needs multi-factor authentication, and what each platform actually says
You do, for anyone who can reach client information, and the wording your vendor uses tells you how much work is left on your desk. The requirement at 16 CFR 314.4(c)(5) is to "implement multi-factor authentication for any individual accessing any information system", and the FTC's guidance restates it as multi-factor authentication "for anyone accessing customer information on your system". The rule defines the factors: something you know, something you have, something you are, at least two of the three.
Here is what the six platforms say on their own security pages, quoted as printed on 25 August 2026. The differences matter because the obligation is yours, not theirs.
| Platform | What its own security page says about multi-factor authentication | What it says about encryption |
|---|---|---|
| SmartVault | "Multi-Factor Authentication (MFA) Enforced platform-wide" | AES-256, "encrypted at rest and in transit" |
| TaxDome | MFA and role-based access controls "ensure that only authorized users can access the data they need" | TLS 1.2 in transit, AES-256 at rest, keys rotated |
| Canopy | MFA and single sign-on "across all user accounts and client portals" | 256-bit, "both in transit and at rest" |
| Financial Cents | "Multi-factor authentication is provided and recommended to our users" | "All data, regardless of type, is encrypted during transit" |
| Karbon | Login runs through your Microsoft or Google account, so "Multi or two-factor authentication can be set for the user's email account login" | TLS in transit for the web application and Client Portal, AES-256 at rest including backups |
| CPA Site Solutions | Not mentioned on its Secure Firm Portal feature page | "SSL encryption during upload, download, and storage" |
That column describes four different postures, not one feature. Enforced, which is what SmartVault claims, means the vendor has made the decision for you. Available, which is the fair reading of Canopy and TaxDome, means the capability is there across user accounts and portals without the page saying it is mandatory. Provided and recommended, which is Financial Cents' own wording, means a setting exists and somebody at your firm has to turn it on, name that decision in your plan, and check it after every new hire. Delegated, which is how Karbon describes it, means your authentication posture is whatever your Microsoft or Google tenant is doing, which may be excellent and may be a shared password from 2019. And not mentioned means ask, in writing, before you renew.
None of these are accusations. Every one of these platforms is used by real firms and several of them are visibly more careful than the average small business tool. The point is narrower: the regulation puts the duty on the firm, so the sentence on the vendor's page is the start of your work rather than the end of it.
The plan you are required to have, sold as a premium feature
You need a Written Information Security Plan, the IRS gives you a template for nothing, and at least one platform puts its version behind its top tier. SmartVault lists "Compliance Vault (WISP templates)" in the feature set of Accounting Unlimited at $85 per user per month, above Accounting Pro at $65 and Business Pro at $55.

Bundling is a legitimate way to sell software and a WISP that is wired into the tool you actually use may well be worth more than a blank document. But you should know what the alternative costs, because the IRS publishes Publication 5708, Creating a Written Information Security Plan for Your Tax and Accounting Practice, as a free template aimed specifically at smaller practices. If a tier upgrade is being justified to you on compliance grounds, the honest comparison is not template against nothing. It is template against a free template plus whatever the tool does to enforce the plan you wrote.
A plan is also not a purchase. The IRS release says tax professionals "are legally required to have a written, accessible plan and should review, test, and update it regularly", and to adjust it when operations change. Changing your website is an operational change. If you launch a new site with a document upload on it, the plan that described the old intake path is now wrong.
Your contact form stopped being a marketing widget
Treat every field on it as a decision about where regulated data will live, because the moment a prospective client types a Social Security number into a message box you have collected customer information. The Safeguards Rule does not care that you had not signed an engagement letter yet.
Three design decisions follow, and they are the ones we argue about with clients in this category. The first is what you ask for. A contact form on an accounting site should collect enough to call someone back and nothing more, because every extra field is a field somebody will paste a document number into. The second is where submissions land. A form that emails the message to a shared inbox has just made that inbox the system of record for regulated data, and the encryption duty at 314.4(c)(3) covers information at rest as well as in transit. The third is the upload button. If you accept documents on the public website rather than behind a portal login, you have created an intake channel with no authentication at all in front of it, which is the opposite of what 314.4(c)(5) asks for.
There is a fourth decision most firms never make, which is deletion. 16 CFR 314.4(c)(6)(i) requires procedures for the secure disposal of customer information no later than two years after the last date it was used to serve that customer, unless you have a business or legal reason to keep it. Form submissions sitting in a website database from 2021 are covered by that sentence. So are the ones in the inbox.
Your web designer became a service provider you have to supervise
The rule makes your website vendor part of your compliance perimeter, and it asks for three specific things rather than a general feeling of trust. Under 16 CFR 314.4(f) you must take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess them based on the risk they present.
In practice that means three documents you probably do not have. A note on file explaining why you chose this host or platform, in security terms rather than price terms. A contract clause obliging them to maintain safeguards, which most template web design agreements do not contain. And a recurring calendar entry, annual is fine for a small firm, where somebody reads the vendor's current security page and confirms nothing has quietly changed. If your website is on a subscription platform, the platform is the service provider. If it is a custom build, your host is, and so is anyone with deploy access.
This is also where the ownership question becomes a compliance question rather than a commercial one. If your vendor holds the domain, the hosting account and the form data, then your ability to assess them, or to leave them, is theoretical. We wrote a separate piece on what to check before you sign a web design contract, and for a firm in this category the answer to "who has the keys" now has a regulator attached to it.
What happens when it goes wrong
You call a list of people, and the first federal deadline is 30 days. Since 13 May 2024, 16 CFR 314.4(j) has required a covered firm to notify the FTC "as soon as possible, and no later than 30 days after discovery" of a security event involving the unencrypted customer information of at least 500 consumers. The clock starts on the first day the event is known to any employee, officer or agent other than the person who caused it. The notice has to state what kinds of information were involved, the date range if you can determine it, the number of consumers affected, and a general description of what happened.
Five hundred consumers is a low bar for a tax practice. A single-preparer office doing four hundred household returns can clear it with one compromised laptop, because a joint return carries two people.
The federal notice is also the short part. The IRS's own data theft page for tax professionals, last updated 26 March 2026, lists who else to contact: your IRS Stakeholder Liaison, who notifies IRS Criminal Investigation on your behalf and can move to block fraudulent returns filed with your clients' details, your local FBI office, the Secret Service if directed, local police for a report, the state tax agencies for every state you file in through the Federation of Tax Administrators, and the state attorney general in each of those states, because most states require it. Then a security expert to find and close the hole, your insurer, the credit bureaus, and an individual letter to every affected client.
Set that list beside the difference between a $19 portal seat and a $149 one and the arithmetic changes shape. The controls are not what protect you from the fine. They are what keeps the incident from being a notification event in the first place, because the rule's trigger is the acquisition of unencrypted customer information.
What a five-person firm actually pays in year one
Between about $2,200 and $10,000, and the website is the smallest line in every version of it. Here is the arithmetic on the published rates above, at five seats for twelve months on annual billing.
The cheapest combination in that chart, a flat website subscription at $1,080 plus five Liscio Intelligent Files seats at $1,140, comes to $2,220 for the year. The most expensive, the same website plus five Canopy Premium seats at $8,940, comes to $10,020. The spread is $7,800 and almost none of it is the website.
The two middle bars sit closer together than most firms expect: five TaxDome Pro seats on a one-year term come to $5,000, and five SmartVault Accounting Unlimited seats come to $5,100, which is a difference of $100 across the year for two quite different products. Two costs are not in the chart at all, because they are not list prices. Payment processing, at the rates above, is real money on every return you collect by card. And the person who is responsible: the Qualified Individual required by 314.4(a) is a named human being at your firm who owns this program, and their hours are the largest number on the page even though no vendor invoices for them.
Whether any of it pays for itself
It pays if the site brings in roughly three dozen returns a year, which is a target you can check against your own numbers rather than take on faith. Reporting on the National Association of Tax Professionals' 2026 survey data, CPA Trendlines put the average base charge for a Form 1040 with schedules at $236, up from $162 in the same study series two years earlier. At $236 a return, the entire $7,800 gap between the cheapest and most expensive stacks we priced is about 33 returns.
The demand side is public too. The IRS's filing season statistics through 17 April 2026 record 137,618,000 individual returns e-filed, of which 72,821,000 came from tax professionals and 64,796,000 were self-prepared. Professional filings grew 0.4% year over year while self-prepared filings grew 1.7%, and total returns received fell 0.3%, so by our arithmetic the professional share of e-filed returns slipped from 53.2% to 52.9% in a year. Meanwhile the IRS's preparer statistics, current as of 1 August 2026, count 879,698 individuals holding a preparer tax identification number for the year, among them 208,519 certified public accountants, 68,548 enrolled agents and 26,039 attorneys.
Put those together and the competitive position is clear enough. A slowly shrinking share of a flat market, contested by roughly 880,000 people holding a current preparer identification number, most of whom are found the same way you will be. That is an argument for a site that answers the questions a nervous buyer actually has, which in this profession means credentials, jurisdictions, what happens to their documents, and what the first meeting costs.
Our own prices, and the firms we are wrong for
A build from us is $1,499, charged once, and the continuing option is $2,499 a month for a site that keeps being worked on rather than handed over. Both numbers are on the pricing page because we would rather argue about scope than about price. A focused build takes about two weeks once content and access are in hand, though a firm in a regulated category should assume its own review adds time. We do not sell a client portal and we do not want to: we build the site, and we wire it to whichever portal you have chosen from the list above, which keeps the regulated data inside a platform whose whole business is holding it.
Three kinds of firm should buy something else. A solo preparer with fifty clients and no ambition to grow is well served by a template subscription, and the $90 a month tiers above will do more for them than we will. A firm that wants one vendor, one invoice and one support number for the website, the portal and the tax software should buy a platform, because a stitched-together stack means somebody at your firm owns the seams. And a firm whose real problem is that its Google Business Profile is unclaimed and its service pages do not exist should fix those first, at almost no cost, before commissioning anything.
The firms we do well for look different: a practice that has outgrown a template it cannot edit, a multi-partner firm whose specialties are invisible on a site organized around services nobody searches for, or a rebuild where the current vendor holds the domain. If that sounds like your firm, our work for finance and accounting practices is the closest thing we have to a portfolio in your category.
Map the path a W-2 takes
Before you price anything, spend twenty minutes drawing every route by which a client document can reach your firm, and mark what happens to it. Not the routes in your policy. The routes people use. This is the one exercise that turns the whole regulation into a shopping list, and it is also the input the FTC asks for: the risk assessment at 314.4(b) is exactly this drawing, written down.
| Route a document can arrive by | What to establish | What a defensible answer sounds like |
|---|---|---|
| The contact form on your website | Where the submission is stored, and who can read it | It posts over HTTPS into a system with logins, and it does not sit in a shared inbox forever |
| Email attachments from clients | Whether the mailbox is encrypted at rest and who else has access to it | You have stopped asking for documents this way, and you tell clients so in the reply |
| Uploads on your public site | Whether there is any authentication in front of the upload | There is no public upload. Documents go through the portal login |
| The client portal | Whether multi-factor authentication is enforced or merely available, for staff and for clients | Enforced for both, with the setting named in your written plan |
| Text messages and messaging apps | Which staff phones hold client documents, and what happens when one is lost | The channel is either closed or routed into the portal, and devices are encrypted |
| Paper handed over in the office | Where it is stored, and when it is destroyed | A locked cabinet, and a disposal schedule that matches the two-year rule |
Answer the middle column honestly for your own firm and the third column becomes your specification. Every vendor conversation after that is short, because you are no longer asking what a website costs. You are asking whether this vendor can carry six named routes, and what each one adds to the bill.
Do this before you shop and the numbers in this article become useful rather than alarming. Skip it and you will buy a site for $90 a month, feel sensible, and discover in March that the cheapest thing in your firm is the one every client document passes through.
Frequently asked questions
Expect a low four-figure one-time build, or a subscription between $90 and $500 a month from the platforms built for this profession. On 25 August 2026, CPA Site Solutions published tiers at $90.00, $111.00, $137.00 and $166.50 a month; CountingWorks Pro published $150, $200, $300 and $500 a month; MITCO Tech published $499 for a one-time three-page build; and TaxDome folded a managed website into its Pro seat at $1,000 per seat per year on a one-year term. We charge $1,499 once, or $2,499 a month for continuing work. Budget separately for the client portal, which is priced per user and usually costs more.


