Skip to content
Bellator Cyber Guard
Tax17 min readDeep Dive

CPA WISP Requirements for 2026: What the IRS Actually Checks

WISP requirements for CPAs and tax preparers in 2026: the nine FTC Safeguards Rule elements, the IRS Publication 5708 updates, and what reviewers check.

By Bellator Cyber Guard Security Team
Ultimate WISP Requirements Guide 2025: Essential Compliance Steps for Tax Professionals - wisp requirements 2025

WISP requirements apply to every tax preparer, CPA, enrolled agent, and accounting firm that handles client data, not just larger firms. The requirement traces back to the Gramm-Leach-Bliley Act (GLBA), a 1999 federal law that classifies tax professionals as financial institutions subject to customer data protection rules. The FTC enforces that obligation through the Safeguards Rule (16 CFR Part 314), and the IRS reinforces it through Publication 4557. A Written Information Security Plan (WISP) is the documentation regulators expect to see during a Preparer Tax Identification Number (PTIN) renewal, an IRS audit, or after a data breach.

Heading into the 2026 filing season, the August 2024 update to IRS Publication 5708 adds specific technical requirements, including universal multi-factor authentication (MFA) and longer minimum password lengths, that were previously optional or ambiguous. This guide covers the nine mandatory WISP elements, the 2026 changes to act on now, and the documentation gaps that show up most often in compliance reviews.

Quick Answer

A compliant WISP covers nine elements under FTC Safeguards Rule 16 CFR §314.4: a designated Qualified Individual, a written risk assessment, documented administrative and technical safeguards, service provider oversight, monitoring and testing, employee training, a systems inventory, a written incident response plan, and an annual program review. Every tax preparer handling client data needs one, regardless of firm size. For the 2026 filing season, IRS Publication 5708 also requires universal MFA, 12-character minimum passwords, and documented breach notification procedures.

WISP Compliance by the Numbers

$4.88M
Average cost of a data breach
9
Mandatory WISP elements
72 hours
Breach notification expectation for affected parties

Who Must Comply: The 5,000-Consumer Myth

The 5,000-consumer threshold in the FTC Safeguards Rule does not exempt small tax practices from WISP requirements. It only reduces documentation for specific subsections, such as written risk assessment records and incident response testing logs, for firms below that threshold. Every tax professional who handles customer information, including a solo preparer with a single client, still has to implement all nine elements of an information security program.

The enforcement point with the most immediate consequence is PTIN renewal. Tax professionals certify compliance with security requirements each time they renew a Preparer Tax Identification Number, and a false certification is fraud under 18 U.S.C. § 1001. See our PTIN renewal next steps guide for what the attestation covers, and our WISP penalties breakdown for the range of civil and state-level exposure beyond PTIN risk.

2026 Filing Season Deadline

The IRS expects an updated WISP in place before the 2026 filing season opens. A practice without a compliant plan risks PTIN suspension, and a false PTIN compliance certification carries federal fraud exposure under 18 U.S.C. § 1001.

The Nine Mandatory WISP Elements

FTC Safeguards Rule §314.4 lists nine required components of an information security program. Regulators evaluate all nine during a review, and a gap in one element undermines the rest of the plan.

The Nine FTC Safeguards Rule Elements

  • Designated Qualified Individual who oversees and enforces the program (solo preparers serve as their own)
  • Written risk assessment covering internal and external threats, updated annually
  • Administrative, technical, and physical safeguards sized to the risks identified
  • Service provider oversight with contracts that name specific security obligations
  • Ongoing monitoring and periodic testing of key controls, with documented results
  • Employee security training with signed attendance records
  • Inventory of information systems, including secure disposal procedures
  • Written incident response plan, tested at least annually
  • Annual review of the program's effectiveness, reported to practice leadership

Two elements draw the most findings in compliance reviews: service provider oversight and physical security. A generic vendor agreement without specific cybersecurity language no longer satisfies the requirement. Physical safeguards, locked file storage, screen privacy filters, and controlled visitor access, are easy to document and easy to skip. See our Qualified Individual requirement guide for how to structure and document that first element, whether you fill the role yourself or engage an outside specialist.

2026 Updates to IRS Publication 5708

The August 2024 update to IRS Publication 5708 is the most significant WISP change since the FTC's 2021 Safeguards Rule amendments. Four changes affect every practice preparing for the 2026 filing season.

The password change is worth flagging because it runs opposite to older habits. NIST SP 800-63B found that frequent forced password changes tend to produce weaker passwords, since people fall back on predictable patterns. Practices still enforcing 90-day rotations should update the written password policy before the 2026 season starts, not just the technical setting. For the MFA piece, see our two-factor authentication guide for tax pros.

Common WISP Mistakes That Draw Scrutiny

Compliance reviews increasingly focus on the gap between what a WISP says and what a practice actually does. Four gaps come up most often:

  • Treating the WISP as a one-time document instead of reviewing it annually and after any technology or operational change.
  • Using a generic template without naming actual systems, vendors, and physical locations.
  • Skipping employee training or failing to keep signed attendance records, which counts as no training during a review.
  • Leaving physical security out of the plan, unattended client files, unlocked cabinets, uncontrolled visitor access, even when technical controls are strong.

Undocumented security activity carries no compliance value during a review. The IRS's standard five-year records retention period is a reasonable minimum for WISP documentation, incident response plans, training logs, and vendor contract reviews included. If a breach does happen, our tax professional data breach response guide walks through the notification steps regulators expect.

Bottom Line

Every tax preparer handling client data needs a WISP, regardless of practice size. The 5,000-consumer threshold reduces documentation for some subsections; it does not remove the underlying security obligation. A false PTIN compliance certification carries federal fraud exposure under 18 U.S.C. § 1001, so the plan on file needs to match the controls actually in place before the 2026 filing season begins.

Build the Expertise or Bring In a Specialist

The FTC Safeguards Rule allows a practice to engage a qualified outside specialist to fill the Qualified Individual role and handle service provider oversight, as long as the relationship is documented in a written agreement. That is a legitimate path for a practice without in-house security staff. The requirement is that this expertise exists and gets applied to the program, not that a practice builds it internally.

A WISP built for your practice, not a template

Bellator Cyber Guard builds a custom Written Information Security Plan starting at $749 for practices with up to 5 users, with larger practices quoted separately. Most firms recoup the cost through 20 to 40 billable hours saved versus building the documentation from scratch.

Talk with a cybersecurity expert

Get your current WISP and security controls reviewed against IRS Publication 5708 and FTC Safeguards Rule requirements before the 2026 filing season.

Frequently Asked Questions

A Written Information Security Plan (WISP) documents how a practice protects client data from unauthorized access, disclosure, and misuse. Every tax preparer, CPA, enrolled agent, and accounting firm that handles customer information needs one under the FTC Safeguards Rule (16 CFR Part 314) and IRS Publication 4557. Practice size does not exempt a firm from the core requirement.

No. The threshold creates limited exemptions for specific documentation requirements within certain subsections, but it does not eliminate the obligation to maintain a security program. Every tax professional, including a solo preparer, still has to implement all nine WISP elements.

The FTC Safeguards Rule requires an annual review at minimum, and the plan must also be updated whenever the technology environment changes materially, a new service provider is added, regulations change, or after a security incident. Reviewers look for evidence the WISP reflects current systems, not a snapshot from the year it was first written.

The most immediate risk is PTIN suspension, since tax professionals certify compliance during PTIN renewal and a false certification is fraud under 18 U.S.C. § 1001. The FTC can also pursue civil penalties for Safeguards Rule violations, and a breach without a documented program can expose a practice to civil liability from affected clients.

Yes. The August 2024 update to IRS Publication 5708 removed the ambiguity around local network access. MFA is now required for all users accessing systems that contain customer information, whether they connect from inside or outside the office network.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.