A German tax firm works with one of the most unpleasant combinations in the mid-market: client files under professional secrecy per Section 203 of the German Criminal Code, bookkeeping data under GoBD and GDPR, a core application — DATEV — with a very specific storage logic, and a retention period that is rarely below ten years. Solving that with an aging Synology, a Windows file server on RAID5 or even local drives on workstations tends to blow up eventually. Not necessarily on the technical side, but on the audit side. This article covers how a TrueNAS is set up inside a tax firm, how the DATEV storage layout maps cleanly onto it, and which pitfalls we see repeatedly at DATAZONE.
A more foundational take on what GoBD actually requires and what TrueNAS contributes technically is in TrueNAS for Tax Firms: GoBD-Compliant Data Retention. This piece is one step further down the road toward implementation and DATEV practice.
DATEV NAS: What the DATEV Storage Layout Expects from Storage
DATEV is not a single application but an entire product family — from the classic DATEV workstation with Kanzlei-Rechnungswesen and Eigenorganisation through Unternehmen online to DATEV DMS. For the storage layer, three targets matter:
- DATEV Datenbestand — the central working database of the firm, usually hosted on a DATEV server. The Datenbestand lives in a defined folder structure that can be mounted from a NAS share
- DATEV DMS repository — the document management layer with scanned receipts, contracts and client correspondence. This is where most of the volume ends up in practice
- Workstation storage — Excel evaluations, Word templates, firm handbooks, internal notes. Not DATEV in the narrow sense, but still part of the firm’s IT
DATEV itself recommends putting the Datenbestand on a stable SMB share with low latency and a proper backup, not on any random NAS. A TrueNAS server with a decent NVMe pool for the Datenbestand and an HDD pool for the DMS matches that expectation neatly — without the license fees of Windows Storage Server.
Points that matter in practice:
- Latency beats throughput — the DATEV Datenbestand behaves database-like, with lots of small I/O rather than streaming large files. An NVMe-backed dataset is far more pleasant than a large HDD share
- SMB 3 with signing — DATEV clients support SMB 3, and signing protects the traffic inside the firm network from tampering
- One share per purpose — Datenbestand, DMS and workstation storage each get their own dataset with their own share and permissions
For the deeper SMB configuration story, TrueNAS SMB with Active Directory and TrueNAS SMB Multichannel with 10 GbE are worth reading.
GoBD Filing in Practice: WORM, Snapshots and Change History
The GoBD require immutability of posted bookkeeping entries, completeness, traceability and a ten-year retention period. That is primarily a requirement on the bookkeeping software — DATEV enforces immutability at database level by locking postings after they are committed. The storage below still has three important jobs:
- WORM-style filing of DMS documents — receipts filed in DATEV DMS must not be altered afterwards without the change being logged
- Change history through snapshots — even if a file were manipulated outside DATEV, an earlier state must remain recoverable
- Integrity-protected long-term storage — no silent data loss must accumulate over ten years
TrueNAS covers this with three building blocks:
ZFS snapshots as change history. A ZFS snapshot is read-only once taken. Even an admin with full rights cannot alter it — only delete it. For DATEV datasets we recommend a fine-grained snapshot policy: every 15 minutes during working hours for the Datenbestand, daily for the DMS, plus monthly and yearly snapshots with a hold spanning ten years. The scheduling side is covered in TrueNAS Snapshot Schedule Best Practices.
Snapshot hold against accidental or malicious deletion. A snapshot hold on the year-end snapshot prevents deletion at ZFS level for as long as the hold exists. That way even a slipped admin command or a compromised admin account is not an immediate data loss.
Scrub against bit rot. A biweekly or monthly scrub reads the full pool and checks every block against its ZFS checksum. For firm datasets we recommend weekly scrubs on the Datenbestand pool and monthly ones on the DMS pool, both with reports to the IT owners.
What TrueNAS honestly does not replace: a certified archive system in the sense of a Revisionssichere Ablage per IDW PS 880 or a GoBD audit certificate. TrueNAS is the technical storage layer; the audit-proof classification is done by the bookkeeping and DMS software above it. That is not a weakness but an honest division of roles that a Windows file server or a NetApp filer would draw exactly the same way.
Ten-Year Backup: How Retention Actually Works
Ten years sounds harmless but is an athletic timeframe for storage. Hard drives are typically replaced at least twice, the NAS platform once completely, the bookkeeping software cycles through versions and file formats. For firm retention that means:
Active copy inside the firm network. The DATEV Datenbestand and the DMS sit actively on the primary TrueNAS. Snapshots cover the short-term change history — typically 90 days up to one year backward.
Secondary copy in the same building. A second, cheaper TrueNAS with HDDs receives hourly or daily incremental snapshots from the primary via ZFS replication. Advantage: snapshots at the target stay read-only, encrypted datasets stay encrypted. See TrueNAS Replication with ZFS Encryption Key for the mechanics.
Offsite copy outside the firm building. For the disaster case — water damage, fire, burglary that takes both systems — a third copy belongs somewhere else. That can be another TrueNAS in a branch office, a rented server in a data center or a cloud target via Cloud Sync. Options are covered in TrueNAS Cloud Sync for Offsite Backup.
Air gap for ransomware resilience. On top of the replication we recommend an air-gapped target that is only reachable temporarily — either a separate NAS woken on schedule or an LTO tape copy of the year-end snapshots. Details in TrueNAS Replication and Air-Gap Backup and The 3-2-1-1-0 Backup Formula.
The critical point over ten years: snapshots have to travel with every hardware change. ZFS makes that clean via zfs send — from the old pool to the new one. Copying files individually loses the snapshot history and with it the ability to prove earlier states.
Typical Pitfalls in Tax Firms — and How We Fix Them
Several recurring mistakes come up in tax firm projects.
Pitfall 1: DATEV Datenbestand on an HDD share. When latency for opening client bestands is too high, users experience it as sluggish hangs and blame DATEV. An NVMe mirror for the Datenbestand pool and HDDs for the DMS is the pragmatic split — covered in TrueNAS Hybrid Storage from SSD and HDD.
Pitfall 2: A single admin account for everything. If exactly one person has full access to the DATEV server, TrueNAS admin, backup system and firewall, that is both a GoBD risk and a GDPR risk. At DATAZONE we typically separate firm IT administration, snapshot admin and backup admin with documented responsibilities.
Pitfall 3: Snapshots without deletion protection. A snapshot that a compromised admin account can simply delete does not help against ransomware. Snapshot hold on yearly snapshots and replication to a second, administratively separate system are the countermeasures.
Pitfall 4: No documented restore test. A backup that has never been restored is not a backup. We recommend at least one documented restore of a client bestand from the replication target every year, ideally paired with an internal firm runbook.
Pitfall 5: Encryption without key escrow. ZFS native encryption is strong. Too strong when nobody can find the key. The passphrase belongs in a documented key escrow process — at minimum the firm’s safe plus an encrypted password manager with a defined succession rule.
Pitfall 6: Cloud-only storage without a local copy. Cloud-only is convenient but turns into a problem on an abrupt provider change or a contract dispute. We recommend local storage as the primary and cloud as one of several copies.
Hardware Range: Which TrueNAS Fits Which Firm
A reasonable TrueNAS choice depends on three factors: number of workstations, DMS volume and availability requirements. Without concrete prices — hardware prices fluctuate too much for that, we work with ranges and individual quotes — the picture is roughly:
- Small firm up to around 10 workstations — a TrueNAS Mini XL+ or an entry R-Series unit is usually enough. The TrueNAS Mini fits small firms without a dedicated server room particularly well. See TrueNAS Mini X vs. R-Series Buying Guide
- Mid-size firm up to around 40 workstations — an R-Series with NVMe cache and separate pools for Datenbestand and DMS. Add a second, simpler R-Series unit as the secondary copy
- Larger firm or firm group — an F-Series or H-Series unit when HA-level availability is required. When dual-controller pays off is discussed in TrueNAS HA Dual Controller — When Does It Pay Off
For the concrete configuration our TrueNAS Configurator helps — model, pool layout and backup target can be composed without going through individual data sheets. For the wider model discussion the general TrueNAS Buying Guide is a good starting point.
FAQ on TrueNAS in a Tax Firm
Is a TrueNAS on its own GoBD-compliant?
No. GoBD is never a storage property alone but a combination of bookkeeping software — typically DATEV — document management, storage and documented processes. TrueNAS provides the storage building blocks that a tax audit expects: immutable snapshots, integrity-protected filing, encrypted replication and audit logging. The audit-proof classification is done by DATEV and a certified DMS above it.
May the DATEV Datenbestand live on a NAS?
Yes — DATEV itself recommends filing it on a stable SMB share with proper backup. What matters is low latency (SSD or NVMe for the Datenbestand pool), SMB 3 with signing, and a dedicated share only for DATEV. A consumer-style NAS in living-room shape is not the right choice.
How long must DATEV data be retained?
Under German commercial and tax law, receipts, annual statements and comparable documents must be retained for ten years. For commercial letters, order confirmations and similar documents the period is six years. TrueNAS covers this with a snapshot policy that keeps monthly and yearly snapshots with hold across the full ten years, combined with replication to a secondary system and an offsite copy.
How does TrueNAS protect a firm against ransomware?
The core mechanism is the read-only property of ZFS snapshots, combined with snapshot hold and replication to an administratively separated secondary system. An attacker who takes over the Windows layer cannot reach the snapshots on the TrueNAS anymore. On top we recommend an air-gapped target and a clean OPNsense-based network segmentation. See TrueNAS Data Security and Ransomware Resilience.
What happens on a hardware refresh after five years?
The pool is transferred cleanly with zfs send to the new system — with all snapshots and holds intact. Files are not copied one by one; the complete pool including its history moves. That keeps the traceability of earlier states without a break in the retention chain.
Is a second TrueNAS in the same building enough?
No. An administratively separate secondary system in the same building is useful for ransomware isolation but not sufficient on its own. Water damage, fire or burglary require an offsite copy in addition — either at a second firm location, in a data center or in encrypted cloud storage. The 3-2-1-1-0 rule captures that compactly.
What does a TrueNAS for a mid-size firm cost?
We work with individual quotes because hardware prices fluctuate and the concrete configuration — number of pools, SSD share, HA yes or no, backup target included or separate — has a much larger effect on price than the model alone. For a sense of the price range in enterprise storage, TrueNAS Pricing 2026 — What Enterprise Storage Costs is a good read; concrete numbers come from the TrueNAS Configurator or a request to DATAZONE.
More on these topics:
More articles
TrueNAS Sizing Guide: how much storage do I really need?
TrueNAS sizing done honestly: usable baseline, snapshot overhead, compression, growth rate and RAID overhead -- how to get from net capacity to raw capacity.
TrueNAS as Database Storage: Connecting MSSQL, PostgreSQL, and MySQL the Right Way
TrueNAS database storage in practice: iSCSI setup, sync=always, Slog sizing, and ZFS snapshots for MSSQL, PostgreSQL, and MySQL in SMB environments.
TrueNAS vs QNAP in the Enterprise: Where QNAP Ends and ZFS Begins
TrueNAS vs QNAP compared for the enterprise: QuTS hero, OpenZFS, dual-controller HA and support SLAs. An honest look at TrueNAS as a QNAP enterprise alternative.