Skip to content

Journal

Written for the people who build the software.

Security and HMRC compliance notes for tax and accounting software vendors. Every figure sourced, nothing gated, no sales call needed to read a date.

BEFORE HMRC LETS YOUR SOFTWARE GO LIVEHMRC REQUIRESHMRC CHECKSYour API calls are formed correctlyYesYour fraud prevention headers are sent, and accurateYesYou tested for security vulnerabilities before go liveNoYou do regular penetration testingNoYour security controls still workNoSOURCE: HMRC DEVELOPER HUB TERMS OF USE, AND THE MTD PRODUCTION APPROVAL PROCESS
HMRC6 min read

HMRC requires penetration testing. It has never checked whether you did one.

HMRC's Terms of Use require MTD software providers to test for security vulnerabilities before going live, including regular penetration testing. At production approval HMRC verifies your fraud prevention headers, with a specialist team reading your sandbox logs, and asks nothing about the security testing. One requirement is policed. The other is a box you tick.

3 August 2026Read
WHO ACTUALLY MANDATES CRESTFRAMEWORK OR BUYERCREST REQUIREDCBEST, Bank of EnglandYesSTAR-FS, FCA and PRA regulated firmsYesUK Government and MoD contractsYesDORA, EU financial entitiesYesSome cyber insurance policiesSometimesISO 27001NoSOC 2NoHMRC Terms of Use, MTD softwareNoSOURCES: FORTBRIDGE (CREST ACCREDITED), AND THE HMRC DEVELOPER HUB TERMS OF USE
Compliance7 min read

Do you need a CREST accredited tester for your tax software?

In the ordinary case, no. HMRC's Terms of Use require regular penetration testing but name no accreditation scheme. Fortbridge, itself a CREST accredited firm, states that ISO 27001 and SOC 2 do not mandate CREST specifically. CREST is mandatory for CBEST, STAR-FS, government and MoD contracts, and DORA. Here is who genuinely needs it, and what to ask a supplier instead.

27 July 2026Read
UK PRICE BANDS // WHAT EACH ONE BUYSUnder £1,500An automated scan with a report attached£2,500 to £8,000Human led web application test£8,000 to £15,000Complex platform, customer financial data£15,000 upwardTechnical due diligence for an acquirerSOURCES: PRECURSOR, AARDWOLF, FORTBRIDGE, SECFORCE
Pricing7 min read

What a penetration test costs in the UK, and what each price band buys

A UK web application penetration test costs roughly £2,500 to £8,000, rising to £8,000 to £15,000 where customer financial data is involved. Below about £500 a day you are buying an automated scan with a report attached. What moves the number, and the one question people forget to ask.

20 July 2026Read
WHERE THE DEAL STOPSDemowent wellPricingagreedProcurementquestionnaireSignaturewaitingTWO TO FOUR WEEKS ADDED
Security6 min read

The security questionnaire that stalled your deal, and the one question behind it

Vendor security questionnaires are one of the most common reasons a B2B software deal stops just before signature. Usually one question does it: attach your most recent independent penetration test report. What to say when you have not got one, and how to stop it happening again.

13 July 2026Read
WHAT IT SAYS // WHAT THEY EXPECTSTANDARDTHE TEXT SAYSTHE AUDITOR EXPECTSISO 27001Never uses the wordsAnnual, in practiceSOC 2Not formally requiredMost auditors want onePCI DSS 4.0Required, Req 11.4Annual and after changeNHS DTACRequiredWithin last 12 monthsNONE OF THESE REQUIRE A CREST ACCREDITED TESTER
Compliance8 min read

Do you need a penetration test for ISO 27001, SOC 2, PCI DSS or NHS DTAC?

ISO 27001 never uses the words. SOC 2 does not formally require one. PCI DSS v4.0 genuinely does, under Requirement 11.4, annually and after significant change. NHS DTAC wants a test within 12 months. What each standard says, what auditors actually expect, and whether CREST matters.

6 July 2026Read
FRAUD PREVENTION HEADERS // SANCTIONS PATHHeaders wrongor missingHMRC gets in touchdiscussions£3,000penaltyAPI accessblockedSOURCE: HMRC DEVELOPER HUB, FRAUD PREVENTION GUIDANCE
HMRC7 min read

HMRC fraud prevention headers: what they are, and what happens when you get them wrong

MTD software is required by law to send fraud prevention headers with every HMRC API call. A £3,000 penalty applies to developers who fail to support the requirement, and continued non compliance can get your software blocked from HMRC's APIs entirely. HMRC checks them once, at production approval, and never again.

29 June 2026Read
WHO CHECKS THE WORKCONSTRUCTIONBuilder buildsBuilding control checksSOFTWAREAgency buildsAgency checks itselfThe dashed line is where the money goes missing.
Security6 min read

Your development agency marks its own homework. Here is what that costs.

If an outside agency built your platform, the only people who can tell you whether it is secure are the people you paid to build it. That is a conflict of interest rather than dishonesty, and it produces a specific class of error. Five questions to ask them, and when an independent check is worth it.

22 June 2026Read
WHAT GETS TESTEDAccess controlCan one customer reach anotherPayment gatesCan an unpaid account reach paid featuresHMRC integrationHeaders, tokens, agent authorityInjection and uploadsWhat reaches the database or diskSession and authReset, lockout, token lifetimeDisclosureStack traces, versions, internal pathsOWASP TESTING GUIDE // PTES // NIST SP 800-115
Security8 min read

What a security review of tax software actually covers

Tax software combines personal financial records, a payment gate and a live government API. A review that treats it as a generic web application misses the two surfaces that matter most. The six surfaces worth testing, what a report should contain, and what it costs in the UK.

15 June 2026Read
YOUR FIRMThe workflow it runs onBUYOff the shelf. Fast to start. Priced per seat.BUILDShaped to your workflow. Yours to keep.
Ownership7 min read

Build vs buy: when should an accountancy firm build its own practice software?

Most firms should buy off the shelf practice software first. But once you are paying for several tools, working around rigid workflows, and adding staff just to keep admin moving, building the workflow you own becomes the simpler, cheaper option. Here is how to tell which side of the line your firm is on.

8 June 2026Read
MTD FOR INCOME TAX // YEAR ONE6 Apr 2026Records start7 Aug 2026Q1 updateFIRST DEADLINE7 Nov 2026Q2 update7 Feb 2027Q3 update7 May 2027Q4 update31 Jan 2028Tax return
MTD8 min read

Making Tax Digital for Income Tax: every deadline a UK practice needs in 2026

MTD for Income Tax starts on 6 April 2026 for sole traders and landlords with qualifying income over £50,000. The first quarterly update is due by 7 August 2026. Here is the full timeline, who is in scope, and what it does to a practice's workload.

1 June 2026Read
RENTED£/mo£/mo£/moPer seat. Every year. Their roadmap.OWNEDBuilt once. You hold the keys.
Ownership7 min read

Rented vs owned: what per-seat practice software really costs a growing firm

Per-seat practice software is rented: you pay every year, the price rises with headcount, and the roadmap is not yours. A custom platform you own costs more up front and less over time. Here is the honest comparison, including when renting is the right call.

25 May 2026Read