Skip to main content
Framework library
Framework module · irs-publication-1075

IRS Publication 1075

The IRS's safeguard requirements for any agency, contractor, or state/local entity that receives federal tax information — relevant to any government contractor or CMS-adjacent SaaS vendor handling federal tax data.

Rev. 11-2021 · Internal Revenue Service · published 2022-06-10

Standing today
Directory entry

00Answer

from the registry record
What is IRS Publication 1075?
The IRS's safeguard requirements for any agency, contractor, or state/local entity that receives federal tax information — relevant to any government contractor or CMS-adjacent SaaS vendor handling federal tax data.
Who does IRS Publication 1075 apply to?
IRS Publication 1075 applies to government, CMS contractors, state and local government, US, per Internal Revenue Service.
What is the current version of IRS Publication 1075?
The current edition is Rev. 11-2021, issued by Internal Revenue Service and published 2022-06-10. Source: https://www.irs.gov/pub/irs-pdf/p1075.pdf.
What does an assessment under IRS Publication 1075 require?
No control catalog has been ingested for IRS Publication 1075 yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

IRS Publication 1075 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Named and tracked only; safeguard requirements not modelled as a control catalog.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Recordkeeping · Secure storage · Restricting access · Reporting requirements · Disposal
Applies to
government · CMS contractors · state and local government · US
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
Pending change
A successor, Rev. 12-2026, exists only as a draft on the IRS's draft-forms page (marked 'DRAFT — NOT FOR FILING'); Rev. 11-2021 remains the current, effective version.Expected: Draft not yet finalized

03Version ledger

1 edition
Rev. 11-2021Current edition2022-06-10

03aCoexisting versions

1 other version in force
  1. Rev. 12-2026 (draft)

    Applies to: No population yet — marked "DRAFT — NOT FOR FILING" on the IRS's own draft-forms page; not effective for any agency or contractor

    No scheduled end date — The IRS has not announced a finalization date for the draft.

    Source (opens in a new tab)

06Related frameworks

scored from registry facts
  1. Also applies to government · The FBI's security requirements for any agency or vendor that touches criminal justice information — the gate for public-safety software.

  2. Also applies to CMS contractors · CMS's minimum security and privacy control baseline for CMS information systems and CMS contractors. It is distinct from the Marketplace-focused ARC-AMPE baseline.

  3. Also applies to state and local government · A standardized assessment, authorization, and continuous-monitoring program for cloud services used by state and local governments, built on NIST SP 800-53 Rev. 5. Core, Ready, and Authorized are service-offering statuses—not company-wide certifications. StateRAMP rebranded to GovRAMP on 2025-02-14; StateRAMP, Inc. remains the legal entity operating under the GovRAMP name.

  4. ASD Essential EightMaturity Model (November 2023)

    Also applies to government · The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.

IRS Publication 1075 | ControlFrame