Your firm's ATX installation works, but the workday doesn't always stay in the office. A preparer needs to review a return from home, a partner wants access while traveling, or a local server becomes unavailable just as electronic filing volume peaks. Moving ATX to the cloud can solve the location problem, but it doesn't remove operational responsibility. It changes where the application runs, who maintains the infrastructure, and how the firm must manage access, backups, connectivity, and support.
The important question isn't whether hosted ATX sounds convenient. It's which failures the host covers, how recovery works, and who resolves an ATX-specific problem. This guide focuses on those boundaries, with the practical requirements and trade-offs firms should evaluate before migrating.
A tax office can still run ATX on a local PC or server, but the filing environment around that setup is now heavily digital. In fiscal year 2025, the Internal Revenue Service processed 271.4 million federal tax returns and supplemental documents. More than 224.2 million returns and other forms were filed electronically, representing 82.6% of all filings, while 93.7% of individual income tax returns were filed electronically through the same period.
Paid preparers handled a large share of that volume, electronically filing 86.7 million individual returns in fiscal year 2025, according to the same IRS data. Those figures do not measure ATX usage or hosted deployment rates. They do show the operating conditions firms work under. When filing, review, and client response all depend on digital systems, downtime is no longer a side issue.
The main pressure point is recovery under deadline. If ATX is tied to one office machine or one small server, a hardware failure, corrupted backup, or remote-access issue can stall preparation, review, and e-filing at the same time. The question is not only whether staff can log in from somewhere else. The question is how fast the environment can be restored, what the host is responsible for fixing, and who takes over when the problem is specific to ATX rather than Windows access.
Cloud hosting shifts that boundary. The application and data run in a managed remote environment, and staff connect to that hosted desktop instead of depending on a specific office workstation. That can reduce single-machine dependence and make remote work practical, but it also means the provider's backup scope, recovery process, access controls, and support limits become part of the firm's day-to-day operating model.
That is why a cloud-based tax software environment should be reviewed as production infrastructure. Remote access is only one piece. Firms also need clear answers on restoration testing, peak-season capacity, user accountability, and whether the host will address an ATX-specific failure or stop at the server layer.
ATX remains a Windows-oriented desktop application. Hosting it in the cloud usually doesn't turn it into a native browser application. Instead, the provider installs ATX on a hosted Windows server, stores the application data in that environment, and gives each authorized user access through a remote desktop session.
The user sees and operates the application remotely. The server performs the calculations and accesses the shared data, while the local device mainly displays the session and sends keyboard, mouse, print, and file-transfer instructions. This architecture can reduce the need for powerful office workstations, but it makes session stability, latency, peripheral redirection, and server sizing important.
Published ATX requirement guidance identifies Windows 10 or Windows 11, at least 8 GB of RAM for a baseline workstation, approximately 3–10 GB of available storage, .NET Framework 4.8, and a high-speed internet connection for installation, updates, and electronic filing. Those requirements describe a local workstation baseline. In a hosted deployment, they become inputs for designing the server environment.
The provider should account for:
A hosted application environment can be a sensible way to host applications in the cloud, but the migration should begin with compatibility testing. Validate the ATX version, supported Windows environment, licensing, remote-session behavior, printer and scanner redirection, Microsoft Office integration, backup restoration, and access to shared files before moving production work.
The architecture works well when the provider treats ATX as a business-critical application rather than an ordinary installed program. It works poorly when the host provisions generic remote desktops without testing the firm's actual workflows.
Hosting taxpayer information changes the security perimeter. The firm no longer protects only office computers and a local server. It must govern the remote-access gateway, user identities, endpoints, administrative privileges, session behavior, backups, and support access.
The IRS recommends that tax professionals enable multifactor authentication wherever it's available, including tax software, cloud storage, email, and other systems containing client information. MFA limits the value of a stolen password because an attacker also needs an independent factor, such as a device-generated code or biometric credential.
A hosted ATX environment should enforce MFA at the remote-access layer and assign every employee a unique account. Shared logins make it difficult to determine who accessed a return, changed a configuration, or initiated an electronic filing.
The firm should verify that the environment provides:
Tax-industry security guidance also describes a 30-minute inactivity timeout for tax-related professional software, followed by reauthentication. The control needs workflow testing. A session should lock as required, but firms must confirm that an interrupted calculation or electronic-filing process won't create confusion or duplicate work after reauthentication.
Practical rule: Security claims are less useful than evidence. Ask to see the access policy, backup-retention terms, restoration process, support escalation path, and activity logs that apply to your environment.
Compliance should be assessed in context. A resource such as IT compliance requirements 2026 can help teams organize broader technology obligations, but it doesn't replace a provider-specific review. Similarly, a label such as SOC compliance doesn't answer who restores a damaged client directory or fixes an ATX update that disrupts e-file connectivity.
The right deployment model depends on which responsibilities the firm can manage consistently. Local hosting gives the practice direct control over its hardware and network, but that control also includes patching, monitoring, backup verification, recovery planning, physical security, and replacement decisions. Cloud hosting shifts much of the infrastructure work to a provider while increasing dependence on remote access and contractual service commitments.
| Dimension | Local Hosting | Cloud Hosting |
|---|---|---|
| Upfront investment | The firm purchases and configures server hardware, storage, networking, and supporting equipment. | The firm avoids maintaining its own application server but pays for hosted infrastructure and agreed services. |
| Maintenance | Internal staff or an IT provider manages operating-system maintenance, hardware, monitoring, and application support coordination. | The host manages the infrastructure and operating system within the agreed scope. ATX-specific troubleshooting still needs a defined support path. |
| Backup responsibility | The firm must configure backups, protect backup copies, monitor jobs, and test restoration. | The host may operate backups, but the firm must verify retention, recovery terms, access, and restoration testing. |
| User access | Access usually depends on the office network and the firm's remote-access setup. | Users connect through a remote desktop environment from approved devices and locations. |
| Scalability | Capacity is constrained by installed hardware until the firm expands or replaces it. | CPU, memory, storage, and session capacity can be adjusted through the hosting arrangement. |
| Connectivity risk | Office users may continue working locally during an external internet interruption, depending on the setup. | A stable internet connection is required to reach the hosted application and files. |
| Recovery | The firm owns the recovery process and must maintain replacement equipment or alternate capacity. | Recovery depends on the provider's backups, recovery objectives, support escalation, and documented procedures. |
Firms comparing these models can also benefit from broader guidance on cloud modernization for engineering leaders, particularly around ownership boundaries and change management. The same principle applies to tax software: a migration is successful only when technical responsibility matches operational expectations.
Cloud hosting is often a strong fit for firms with distributed staff, limited internal infrastructure capacity, or a need for centralized access. Local hosting may remain appropriate where the firm has mature IT operations and a tested recovery environment. Neither option is automatically secure or reliable. The controls and procedures matter more than the location alone.
A controlled migration starts with a responsibility matrix. Before anyone moves a client directory, document what ATX requires, what the hosting provider manages, and what the firm must continue to own.
ATX is still desktop-oriented, so hosting generally relocates the application and its data to a remote Windows environment. It doesn't eliminate the need to validate licensing, annual updates, e-file connectivity, printer and scanner redirection, local-drive access, Microsoft Office integration, and the behavior of shared folders. Guidance on ATX setup and cloud hosting supports this distinction.
The host should own infrastructure provisioning, Windows maintenance within scope, monitoring, agreed backup operations, and the availability of the remote-access environment.
The firm should own user permissions, passwords, endpoint protection, employee procedures, client-data handling, ATX workflow decisions, and verification that backups can be restored.
Both parties should define who handles ATX updates, licensing questions, e-file failures, printer issues, Microsoft Office behavior, data corruption, and emergency escalation. “Contact support” isn't a recovery plan unless the contract identifies the support boundary and response process.
Use a representative pilot rather than an empty test environment. Select returns and workflows that reflect actual work, then verify:
A tax-specific control list should sit alongside the firm's wider compliance calendar. For example, a 2026 VAT compliance checklist can help teams coordinate tax obligations beyond the ATX migration, even though the hosting project itself requires a separate U.S. tax-workflow review.
Use a documented cloud migration checklist to keep technical tasks, user acceptance, backup verification, and sign-off in one place. Don't schedule the cutover immediately before a critical filing deadline.
Cloud hosting reduces the hardware burden at the desk, but it doesn't remove the network from the workflow. ATX installation, updates, and electronic filing require a high-speed connection, and users still need a stable remote desktop session to work effectively.
Raw download speed isn't the only consideration. A connection with inconsistent latency can make ATX feel slow even when the server is technically available. Printing may work while scanning fails. The application may open while a shared directory or e-file connection performs poorly. Firms should measure usability from each major office and from representative remote locations rather than accepting a generic uptime statement.
During the 2025 filing season, the IRS received 144.8 million individual income tax returns by the week ending May 3, 2025, and nearly 96% were filed electronically, according to TIGTA's filing-season analysis. Individual e-filed returns were generally processed within 21 calendar days, which reinforces the practical need for timely transmission, status monitoring, and issue resolution.
That environment creates two different performance questions:
A provider can meet an availability target while the firm still experiences slow sessions or a broken integration. The service agreement should address the metrics that matter to the firm, not only whether the server responds to a basic monitoring check.
Before relying on hosted access during deadlines, use server capacity planning to match resources to simultaneous preparers, return complexity, PDF workloads, storage growth, and expected seasonal demand. Ask how capacity changes are approved, tested, and billed, and whether the provider can add resources without an unplanned migration.
Run a pilot from every important location. Disconnect a test session, reconnect it, and verify that users understand what happens to unsaved work. Test a printer failure, an unavailable scanner, and a temporary local internet outage. The firm should also maintain an offline contingency plan that identifies alternate connectivity, emergency contacts, data-access procedures, and the point at which work pauses rather than risking inconsistent files.
The most common evaluation mistake is treating “cloud hosted” as the complete answer. A provider may offer remote access, backups, encryption, and MFA, yet the firm still needs to know who resolves an ATX update failure, who restores a damaged directory, who investigates a failed e-file connection, and how quickly the escalation begins.
Generic claims such as “IRS compliant” or “SOC compliant” aren't decision-grade evidence on their own. Request the operating details:
A firm with hosted ATX begins a filing deadline by checking that each preparer can authenticate through MFA and open the shared client environment. The partner confirms that the previous backup completed and that the support contact knows which issues require escalation. Preparers work through remote sessions, save returns centrally, and use a documented process for reconnecting if a home connection drops.
When a printer fails, the firm doesn't assume the entire hosting environment is unavailable. The user switches to the approved PDF workflow while support investigates the redirection issue. When an ATX update causes unexpected behavior, the firm follows the change-control procedure, preserves affected files, and escalates to the party responsible for the application rather than asking the infrastructure host to guess at an ATX defect.
A good hosting decision doesn't promise that failures won't happen. It proves that the firm knows how failures are detected, contained, escalated, and recovered.
Hosted ATX is a strong fit when the firm needs centralized access, has distributed preparers, wants to reduce local server maintenance, and is prepared to manage identity, endpoints, procedures, and testing. Slow or undocumented support, unclear backup terms, untested peripherals, and vague recovery commitments are warning signs. A phased migration with a representative pilot is safer than moving every client workflow at once.
Cloudvara hosts tax and accounting applications in remote desktop environments with dedicated-server options, automated backups, multifactor authentication, and support for hosted applications including ATX Tax. Review how the environment fits your responsibility matrix, then visit Cloudvara to discuss a practical migration and hosting setup.