Issue Number: 2026-11
If your organization handles Foreign Account Tax Compliance Act (FATCA) reporting, there is an upcoming technical deadline you need to add to your calendar. The IRS has announced that the public key currently used for encrypting FATCA filings is nearing its expiration date, and a replacement will be issued soon.
Here is a breakdown of what is changing, when it happens, and what you need to do to ensure your filings continue without interruption.
The Key Change and Timeline
To securely exchange FATCA data, Financial Institutions and Host Country Tax Authorities use the International Data Exchange Service (IDES). Because IDES requires all data transmissions to be strictly encrypted, public/private key pairs are a critical part of the reporting process.
Like most security credentials, the IRS Public Key has a set expiration date. To maintain security standards, the IRS will be replacing the existing key on Wednesday, September 24, 2026.
The transition will take place at 9:00 am EDT.
What You Need to Do
If you submit FATCA reports, you cannot simply use the old key indefinitely. Your action items are:
-
Pause Submissions During Transition: Be aware of the cutoff time. Do not attempt to use the old key or submit reports right around the 9:00 am EDT transition window to avoid encryption errors or rejected filings.
-
Download the New Key: After 9:00 am EDT on September 24, 2026, log into IDES and download the newly issued IRS Public Key.
-
Update Your Systems: Ensure your internal systems and encryption software are updated to use the new public key for all future FATCA file submissions.
A Crucial Reminder Regarding Digital Certificates
The IRS announcement also included an important reminder for organizations that might be renewing or purchasing their own digital certificates.
To communicate securely on the IDES platform, users must have a digital certificate. When purchasing a new digital certificate or replacing one that is about to expire, remember that IDES only recognizes and accepts digital certificates issued by IRS-approved Certificate Authorities (CAs).
If you use a non-approved CA, your certificate will not be accepted, and you will be unable to successfully transmit your FATCA data. Always verify your vendor against the IRS’s approved list before making a purchase.
Staying Compliant
Maintaining up-to-date encryption keys and valid digital certificates is essential for smooth FATCA reporting. We recommend notifying your IT and compliance teams immediately so they can prepare to download and implement the new IRS Public Key on September 24 2026.