
A WISP for tax preparers, a Written Information Security Plan, is the documented security program that the FTC Safeguards Rule and IRS require any tax practice to maintain. Tax professionals handle Social Security numbers, bank account details, income records, and complete family financial histories, which makes small tax firms a consistent target for ransomware operators and identity thieves. Federal law has treated this as a legal obligation, not a best practice, since 1999, when the Gramm-Leach-Bliley Act (GLBA) classified tax preparation businesses as financial institutions subject to mandatory data safeguards. Every tax preparer who holds a PTIN needs a written plan on file, whether the practice files 11 returns a year or 11,000. This guide breaks down what the plan must include for the 2026 filing season, including the mandatory multi-factor authentication requirement the IRS added in August 2024.
Quick Answer
A WISP for tax preparers is a written document required by the FTC Safeguards Rule (16 CFR Part 314) and IRS Publication 4557 that describes how a practice protects client data. Every tax preparer with a PTIN must have one on file. At minimum, it needs a designated security coordinator, a written risk assessment, administrative and technical safeguards including mandatory multi-factor authentication (MFA) as of August 2024, physical safeguards, vendor oversight, and an incident response plan with IRS 24-hour breach notification procedures.
Three overlapping federal rules require a written security plan for a small tax firm: the Gramm-Leach-Bliley Act, the FTC Safeguards Rule, and IRS enforcement tied to PTIN and EFIN licensing.
GLBA, passed in 1999, defined 'financial institution' broadly enough to include tax preparation businesses, which put solo preparers and small CPA firms under the same data protection standard as banks and credit unions.
The FTC implements that law through the Safeguards Rule (16 CFR Part 314). The December 2022 amendments turned general principles into specific, documented requirements: a designated qualified individual overseeing the program, a periodic written risk assessment, administrative and technical safeguards, ongoing testing, and an incident response plan.
The IRS adds enforcement weight through its Security Summit initiative. IRS Publication 4557, Safeguarding Taxpayer Data, sets the IRS's expectations, and Form W-12 PTIN renewal applications now require practitioners to confirm they have a written plan in place. The IRS can revoke PTIN and EFIN credentials for noncompliant practitioners, which ends their ability to prepare returns professionally. Our PTIN renewal guide covers what to expect at renewal time, and our IRS Security Six checklist covers the related baseline controls the IRS recommends.
2026 Filing Season Requirement
IRS Form W-12 PTIN renewal applications require tax professionals to confirm active WISP implementation. The August 2024 update to IRS Publication 5708 made multi-factor authentication mandatory for all information system access, not just remote connections. Confirm your plan reflects this before the 2026 filing season opens.
The FTC Safeguards Rule identifies six interconnected components: governance (who is responsible), a risk assessment (what threats exist), administrative safeguards (how people handle data), technical safeguards (how technology protects data), physical safeguards (how facilities and equipment are secured), and incident response (how you detect, contain, and report events).
IRS Publication 4557 offers a useful checklist for orientation, but your actual document has to go further: describe your specific systems, vendors, employees, and risk assessment findings. Generic language that could describe any firm will not hold up if a regulator reviews your plan after a breach.
Your risk assessment, required by both the Safeguards Rule and the NIST Cybersecurity Framework, should inventory every system touching taxpayer data and document why you chose each safeguard. Regulators are assessing whether your controls are reasonable for your firm's actual risk, not whether you reached theoretical perfection.
WISP Compliance Checklist for Small Tax Firms
- Designate a security coordinator responsible for the plan and its annual review
- Inventory every system that stores or processes taxpayer data, including cloud services
- Complete a written risk assessment covering internal and external threats
- Enable multi-factor authentication on all tax software, email, and cloud accounts
- Deploy endpoint protection with behavioral monitoring on every device that touches client data
- Turn on full-disk encryption on all devices that store or access taxpayer information
- Write access control and employee onboarding and termination procedures
- Document vendor security assessments for every third-party provider
- Set incident response procedures with IRS 24-hour and FTC 30-day notification timelines
- Schedule annual security awareness training and document attendance
- Document physical security: locked storage, visitor sign-in, screen locks, and shredding
Administrative safeguards are the policy rules your WISP documents and enforces, covering employee management, vendor oversight, and operational procedures. Regulators look at these first because they show whether security is actually managed or just claimed on paper.
The Safeguards Rule requires appointing a coordinator with the expertise to run the program. In a solo practice, that is usually the owner. In a multi-professional firm, it might be an office manager or outside IT consultant. Our guide to the qualified individual requirement covers what regulators expect from this role, including specific timelines like an annual review date and quarterly access reviews, so the responsibility has real accountability instead of aspirational language.
Access control should follow least privilege: employees reach only what their job requires. Document what training is required before access is granted, who approves requests, and how you confirm permissions stay appropriate over time. Termination procedures deserve equal attention. Revoke system access on the employee's last day, collect devices and physical credentials, change any shared passwords they knew, and review recent access logs for unusual activity. Your WISP should name who performs each step and by when, not just that it happens.
Technical safeguards are the technology controls that prevent, detect, and respond to unauthorized access. Your plan should specify which controls are deployed, where, and who maintains them. Regulators expect documented, reasonable protection calibrated to your firm's size, not perfection.
Every device that touches taxpayer data needs endpoint protection beyond traditional antivirus. Endpoint Detection and Response (EDR) tools add behavioral monitoring and automated response that signature-based antivirus misses, and IRS Publication 4557 specifically recommends EDR-class protection. Outsourcing that monitoring to a managed provider can satisfy the Safeguards Rule's ongoing-monitoring requirement more affordably than building an internal security team; our protection plan comparison breaks down what different levels of managed coverage include. Document whichever approach you use, including the vendor's name and your contractual incident-notification terms.
Encrypt every device that stores or accesses taxpayer information. Windows BitLocker and macOS FileVault both provide AES-256 encryption at no added cost, so document which is active on each device category and who verifies it stays on. For data in transit, confirm your tax software and client portal use TLS 1.2 or higher.
The August 2024 Publication 5708 update made MFA mandatory for all system access, not just remote logins. Turn it on for tax software, email, cloud storage, VPN, and any administrative interface touching client data. Authenticator apps are preferred over SMS, which is vulnerable to SIM-swapping. Our IRS Tax Pro Account MFA setup guide and two-factor authentication resource walk through configuration for the accounts tax preparers use most.
How to Build a WISP: 6 Implementation Steps
Appoint your security coordinator
Designate who is responsible and document their authority in writing before any other step begins.
Complete a written risk assessment
Inventory every system touching taxpayer data, identify threats, and document why you chose each safeguard.
Deploy technical controls
Turn on EDR, full-disk encryption, MFA on every system, and email filtering.
Write your policies into the document
Put access control, onboarding and termination, vendor management, and incident response procedures into the WISP itself with names and timelines.
Train employees and test controls
Run initial and annual security awareness training, then test with a backup restore, a phishing simulation, and a vulnerability scan.
Review and update annually
Revise the risk assessment and controls each year, and date and sign the updated version.
Bellator Builds Your WISP for You
A custom WISP for your practice starts at $749 for up to 5 users. Practices with more than 5 users get a custom quote. Firms typically save 20 to 40 billable hours compared with writing and maintaining the document in-house.
A strong digital security program can be undone by an unlocked server room, documents left out during a client visit, or paper thrown away unshredded. The Safeguards Rule calls out physical safeguards specifically, and treating them as secondary to technical controls is a common gap regulators notice.
Lock doors to server rooms, records storage, and back-office areas. Require visitors to sign in and stay escorted, which matters most during the high-traffic weeks of filing season. Set screen locks to activate after five to ten minutes of inactivity, position monitors away from client sightlines, and use a clean-desk policy so documents go into locked drawers whenever an employee steps away.
Document disposal is not optional. The IRS has documented identity theft cases that started with improperly discarded paperwork. Put cross-cut shredders in every area where staff handle client documents, and use a certified destruction service for high-volume shredding. Your WISP should name the destruction standard, the equipment or vendor, and how you record that destruction happened.
Tax practices rely on a range of vendors: tax software, cloud storage, email hosting, practice management systems, IT support, and document management. Every vendor with access to taxpayer data extends your attack surface and your regulatory exposure. The Safeguards Rule requires selecting qualified providers and contractually obligating them to safeguard client data, which makes vendor management a documented requirement, not a courtesy.
Start with an inventory: who the vendor is, what data they can reach, what security commitments they've made, and when you last reviewed their posture.
Vendor Due Diligence Checklist
- Request a SOC 2 Type II audit report from any vendor storing or processing client data
- Review vendor answers on encryption, access controls, and incident response
- Confirm relevant certifications, such as PCI DSS for anyone processing payments
- Require breach notification to your firm within a defined window in the contract
- Require audit rights and a data return or destruction clause when the relationship ends
- Note any vendor that won't agree to these terms in writing as a risk in your assessment
Preventive controls reduce risk, they don't eliminate it. Regulators treat a firm with a documented, imperfect response plan more favorably than one with no plan at all, because the plan shows good faith.
Define what counts as an incident in your WISP: confirmed or suspected unauthorized access, malware or ransomware, lost or stolen devices, compromised employee credentials, and vendor breaches affecting your clients' data. Clear definitions stop delay caused by uncertainty about whether to escalate.
Response follows a sequence: detect and report to your designated security officer (list the contact and after-hours procedure), contain by isolating affected systems and disabling compromised accounts, investigate what was accessed and how, and recover by restoring from clean backups and patching before returning to operations.
Multiple notification clocks start running at once. The IRS requires reporting confirmed breaches to its Data Security Office within 24 hours through the Stakeholder Liaison process listed in Publication 4557. The FTC Safeguards Rule requires notifying the FTC within 30 days when an incident affects 500 or more consumers. All 50 states also have their own breach notification statutes, with different timelines and definitions of covered data, so document which state obligations apply based on where your clients live, since one incident can trigger several states' rules at once.
A WISP Is a Living Document
A WISP that sits untouched after year one will not hold up to a regulator's review. Update the risk assessment, revise controls that didn't work, and reflect changes in staff, vendors, and technology at least once a year, with a dated and signed version for your records.
Talk with a cybersecurity expert
Get a straightforward assessment of what your practice's WISP needs before the next filing season.
Frequently Asked Questions
Yes. The FTC Safeguards Rule and IRS PTIN requirements apply regardless of firm size. A solo preparer filing a small number of returns has the same written plan obligation as a firm with dozens of staff.
The IRS can revoke PTIN and EFIN credentials for noncompliant preparers, which ends the ability to prepare returns professionally. The FTC Safeguards Rule also carries civil penalty exposure for financial institutions that fail to maintain required safeguards. Talk to counsel about your firm's specific legal exposure.
At least annually, and any time you add a major system, change vendors, or hire or lose staff with access to client data. The Safeguards Rule expects ongoing monitoring and testing, not a document written once and filed away.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



