
Every tax preparer, CPA, enrolled agent, and accounting firm operating in the United States must maintain a Written Information Security Plan (WISP). Tax professionals looking up WISP requirements 2025 guidance often encounter conflicting information about who is covered, which exemptions actually apply, and how much changed heading into the 2026 filing season. This guide addresses all of it: every element regulators examine, the recent updates you must act on now, and the documentation gaps most commonly cited in enforcement reviews.
The legal foundation runs through two parallel regulatory tracks. The Gramm-Leach-Bliley Act (GLBA), enacted in 1999, classified tax professionals as financial institutions subject to the same data protection obligations as banks and investment firms. GLBA Section 501(b) requires these institutions to establish administrative, technical, and physical safeguards to protect customer information. The FTC translates this obligation into enforceable rules through the Standards for Safeguarding Customer Information (16 CFR Part 314), commonly called the FTC Safeguards Rule. The 2021 amendments strengthened enforcement significantly by mandating specific technical controls, including multi-factor authentication (MFA) and encryption, that were previously recommended but not required.
The IRS reinforces these mandates through IRS Publication 4557 and the Security Summit initiative, a public-private partnership launched in 2015 between the IRS, state tax agencies, and the private tax industry. The August 2024 update to IRS Publication 5708 introduced material changes applying to the 2026 filing season, making compliance more stringent than at any previous point in the program's history. This guide covers every element regulators examine, the 2026 updates you must act on now, and the implementation mistakes most commonly cited in enforcement actions.
WISP Compliance: Key Numbers
IBM Cost of Data Breach Report 2024
Required under FTC Safeguards Rule 16 CFR §314.4
Federal expectation under updated IRS Publication 5708 guidance
Who Must Comply: Clearing Up the 5,000-Consumer Myth
A persistent and dangerous misconception circulates among small tax practices: that firms serving fewer than 5,000 clients are fully exempt from WISP requirements. This misreading of FTC regulations exposes thousands of solo practitioners and small practices to significant compliance violations and real security gaps.
The FTC Safeguards Rule's 5,000-consumer threshold creates only limited exemptions for specific subsections of the rule. It does not eliminate the obligation to maintain an information security program. Every tax professional handling customer information, including solo practitioners preparing returns for a single client, must document and implement security programs covering all fundamental safeguard categories.
Firms with fewer than 5,000 consumers may have reduced requirements for written risk assessment documentation and incident response testing records, but they must still conduct these activities and implement the controls they identify. The exemption lightens paperwork on certain subsections; it does not remove the underlying security obligations. For a thorough breakdown of what applies at different practice sizes, see our dedicated guide for WISP compliance at small tax firms.
The enforcement mechanism with the sharpest teeth is Preparer Tax Identification Number (PTIN) renewal. Tax professionals must certify compliance with security requirements when renewing their PTINs. A false certification constitutes federal fraud subject to criminal prosecution under 18 U.S.C. § 1001. For a full breakdown of what this attestation requires, see our guide to PTIN and WISP requirements for tax preparers.
2026 Filing Season Compliance Deadline
The IRS requires all tax preparers to have an updated WISP in place before the 2026 filing season begins. Firms without a compliant plan risk PTIN suspension. A false PTIN compliance certification is subject to federal fraud prosecution under 18 U.S.C. § 1001. Verify your current posture with our IRS Publication 4557 compliance assessment before your next PTIN renewal.
The Nine Mandatory WISP Elements Under 16 CFR §314.4
The FTC Safeguards Rule section 314.4 enumerates nine required components of a compliant information security program. Understanding these WISP requirements 2025 standards means recognizing that every covered entity must address all nine with policies, procedures, and technical controls proportionate to their size and risk profile. Weakness in any single element undermines the entire program, and regulators evaluate all nine during audits.
1. Designated Qualified Individual
Every covered entity must designate a qualified individual to oversee, implement, and enforce the information security program. This person coordinates all security activities, manages vendor relationships, oversees incident response, and reports to practice leadership. For solo practitioners, you serve as your own qualified individual. Formal documentation of your responsibilities is essential for compliance verification during an audit.
2. Risk Assessment
Risk assessments form the analytical foundation of your WISP. They identify threats to customer information and evaluate whether existing safeguards adequately address those threats. Assessments must examine internal threats, such as employee errors, inadequate training, system misconfigurations, and insider access abuse, alongside external threats including phishing campaigns, malware infections, physical theft, and social engineering attacks. The assessment must be repeated annually and whenever your technology or operations change materially.
3. Safeguard Design and Implementation
Based on risk assessment findings, design and implement administrative, technical, and physical safeguards proportionate to identified risks. Technical safeguards include firewalls, intrusion detection systems, encryption protocols, access controls, and security monitoring. Administrative safeguards cover policies, procedures, and employee training programs. Physical safeguards, frequently overlooked by practices focused on technology, include locked document storage, screen privacy filters, and visitor access restrictions. All three categories must appear in your written WISP.
4. Service Provider Oversight
Select and retain service providers that maintain appropriate safeguards for customer information they access or process on your behalf. Contracts with these providers must include specific, enforceable security commitments. Generic service agreements without security language no longer satisfy this element under updated IRS guidance. This applies to tax software vendors, cloud storage providers, payroll processors, and any other third party that touches client data.
5. Monitoring, Testing, and Evaluation
Continuously monitor your information systems and periodically test the effectiveness of key controls. Testing methods include penetration testing, vulnerability scanning, and access control reviews. Results must be documented and used to update your safeguards. Regulators specifically look for evidence that monitoring outputs influenced program changes, not just that monitoring occurred.
6. Employee Training
Train employees consistent with your information security program and keep records of all training activity. Annual training is the regulatory floor; quarterly reinforcement addresses how quickly attack techniques evolve. Training content must cover phishing recognition, safe data handling, password hygiene, and internal reporting procedures for suspected incidents. Undocumented training sessions carry no compliance value.
7. Information Systems Inventory and Lifecycle Management
Maintain an accurate inventory of information systems and implement controls governing their entire lifecycle, from procurement through secure disposal. This includes how hardware is retired, how software is decommissioned, and how storage media is sanitized before disposal. Many practices focus on active systems and neglect the disposal phase, which creates both compliance gaps and real security exposure.
8. Incident Response Planning
Develop and implement a written incident response plan that defines roles, internal communication procedures, external notification requirements, and post-incident review processes. The plan must be tested at least annually through tabletop exercises and must include documented notification procedures with specific contact information for your state's IRS Stakeholder Liaison office.
9. Annual Program Review
Conduct an annual review of your information security program's effectiveness. Review results must be documented and presented to practice leadership. The review should assess changes in your risk environment, evaluate safeguard performance, and drive updates to the written WISP document itself.
Building a Compliant WISP: Implementation Steps
Designate Your Qualified Individual
Assign a named person to own and enforce the security program. For solo practitioners, document your own responsibilities in writing with your specific duties listed.
Conduct a Written Risk Assessment
Identify internal and external threats to client data. Document findings and use them to select and design your safeguards.
Design and Document Your Safeguards
Specify the administrative, technical, and physical controls you will implement. Name specific systems, tools, and procedures rather than using generic language.
Evaluate and Update Service Provider Contracts
Review all vendors that access client data. Update agreements to include explicit cybersecurity language before the 2026 filing season.
Conduct Employee Security Training
Train all staff on phishing recognition, data handling, passwords, and incident reporting. Collect and retain signed attendance records for every session.
Test and Monitor Your Controls
Run vulnerability scans and access control reviews. Document results and use findings to update your written WISP.
Review and Update Annually
Review the entire program each year and update whenever technology, operations, or regulatory requirements change. Present results to practice leadership.
Need a Starting Point for Your WISP?
Our free 2026 WISP template is pre-structured for all nine FTC Safeguards Rule elements with tax-practice-specific customization prompts for each section.
2026 Regulatory Updates Every Tax Preparer Must Act On Now
The August 2024 update to IRS Publication 5708 introduced the most significant changes to WISP requirements since the FTC's 2021 Safeguards Rule amendments. Four changes carry particular weight for practices entering the 2026 filing season. Review the full updated guidance in our IRS Publication 5708 WISP walkthrough.
Universal MFA Eliminates the In-Office Exception
Previous guidance created ambiguity about whether MFA was required for local network access or only remote connections. The updated Publication 5708 resolves that ambiguity: MFA is required for all users accessing systems containing customer information, regardless of whether access originates inside or outside the office network. Every in-office workstation used to access tax software, client portals, or any system storing Personally Identifiable Information (PII) now falls under this requirement.
Password Standards Align With NIST SP 800-63B
Password management requirements shifted from mandatory 90-day change cycles to minimum 365-day intervals, reflecting NIST SP 800-63B guidance that frequent forced changes often produce weaker passwords as employees resort to predictable patterns. Minimum length requirements are now 12 characters with complexity requirements including uppercase letters, lowercase letters, numbers, and special characters. Practices still enforcing 90-day rotations must update their written password policies before the 2026 filing season to close this documentation gap.
Breach Notification Timelines Are Now Explicit
Updated guidance clarifies that tax professionals must notify the IRS, affected clients, and potentially state regulators when data breaches occur. Meeting the 72-hour notification expectation described above requires documented procedures in your incident response plan, including the specific contact information for your state's IRS Stakeholder Liaison office, not just generic language about notifying regulators. For a step-by-step response plan, see our guide on what to do after a data breach.
Service Provider Security Documentation Requirements Tightened
The updated IRS guidance makes clear that written contracts with service providers must explicitly address cybersecurity obligations. Generic service agreements without specific security language no longer satisfy this element. Review all vendor contracts, particularly with tax software providers and cloud storage vendors, to confirm they contain enforceable security commitments before the 2026 season begins.
Common WISP Implementation Mistakes That Draw Regulatory Scrutiny
Regulatory audits focus increasingly on the gap between what a WISP says and what a practice actually does. The deficiencies below are the most common findings in enforcement reviews, each representing a breakdown between documented security posture and real-world controls.
Treating the WISP as a One-Time Document
Filing a WISP and never revisiting it is the most widespread failure. Plans must be reviewed annually and updated whenever technology, operations, regulatory requirements, or the threat environment changes. A WISP describing systems you no longer use, or omitting software added since the last update, fails on its face. Auditors compare WISP documentation against your actual technology inventory and will identify discrepancies immediately.
Using Generic Templates Without Customization
Template language that does not reflect your specific software applications, network architecture, vendor relationships, and physical locations fails to satisfy the regulatory requirement. A WISP referencing "the firm's network" without identifying specific systems, or listing generic vendor categories without naming actual providers, is a documentable compliance gap. A starting-point template is valuable, and our free 2026 WISP template includes section-by-section customization guidance, but every element must be completed with your real environment in mind.
Skipping Ongoing Employee Security Training
Tax firms are high-value targets precisely because they hold Social Security numbers, financial records, and bank routing information for large client bases. Training must cover recognition of phishing attempts, safe handling of client data, password hygiene, and the internal procedure for reporting suspected security incidents. Undocumented training sessions carry no compliance value. Keep signed attendance records for every session.
Failing to Document Security Activities
During a regulatory audit or legal proceeding following a breach, undocumented activities are treated as if they never occurred. Document risk assessments, testing results, training completions, vendor evaluations, incident investigations, and program reviews without exception. The standard IRS records retention period of five years is a reasonable minimum for WISP documentation. Our all-in-one compliance package includes documentation templates for every FTC Safeguards Rule element.
Neglecting Physical Security Controls
Many practices deploy thorough technical controls while overlooking physical threats. Client files left unattended on desks, unlocked filing cabinets, uncontrolled visitor access to workstations, and inadequate screen privacy all represent WISP compliance gaps. Physical safeguards must be documented alongside technical controls. Practices handling Federal Tax Information (FTI) face additional physical security requirements under IRS Publication 1075.
WISP Compliance Checklist for Tax Professionals
- Designate a named Qualified Individual responsible for the WISP and document their specific duties
- Complete a written risk assessment covering internal and external threats to client data
- Inventory all systems, software, and vendors that store or process Personally Identifiable Information
- Enable multi-factor authentication on all workstations accessing tax software, client portals, or PII systems
- Update password policies to require 12-character minimum and annual rotation per NIST SP 800-63B
- Review and update vendor contracts to include explicit, enforceable cybersecurity language
- Conduct annual employee security awareness training and keep signed attendance records
- Write an incident response plan with specific IRS Stakeholder Liaison contact information for your state
- Test your incident response plan with at least one tabletop exercise per year
- Document all security activities and retain records for a minimum of five years
- Conduct an annual WISP review and update the document whenever technology or operations change
Bottom Line
All tax preparers handling client data must have a Written Information Security Plan, regardless of practice size. The 5,000-consumer threshold does not exempt smaller practices from the core security program obligation. PTIN certification of compliance creates federal fraud exposure under 18 U.S.C. § 1001 if you attest to having a program you do not actually maintain. Address all nine FTC Safeguards Rule elements and incorporate the 2026-specific IRS updates before the filing season begins.
Building a Durable, Audit-Ready Security Program
Meeting WISP requirements 2025 standards is the floor, not the ceiling. Annual WISP reviews become genuine opportunities to assess whether controls remain effective as your technology changes. Vendor contract reviews surface providers whose security posture has degraded since onboarding. Incident response tabletop exercises build the procedural memory that determines whether a breach becomes a recoverable event or a practice-ending one.
If building internal security expertise is not feasible for your practice size, the FTC Safeguards Rule permits you to engage a qualified external specialist. Doing so simultaneously satisfies the qualified individual requirement and the service provider oversight element, provided you document the relationship in a written security agreement. The regulation does not require you to build this expertise in-house; it requires you to ensure it exists and is applied to your program.
Tax practices facing the 2026 season also need to think beyond the WISP itself. Strong endpoint security, identity theft prevention protocols, and documented FTC Safeguards Rule compliance work together with your written plan to create a defensible security posture. The IRS's Security Summit guidance emphasizes that the WISP is a living document embedded in an active security program, not a form you file and forget.
Practices that want to verify their current posture against the 2026 requirements can start with our IRS Publication 4557 compliance assessment, which maps your existing controls against each regulatory element and identifies documentation gaps before they become audit findings.
Get Your WISP Reviewed Before the 2026 Filing Season
Our security experts will evaluate your Written Information Security Plan against IRS Publication 5708 and FTC Safeguards Rule requirements, then identify every gap before regulators do.
Frequently Asked Questions
A Written Information Security Plan (WISP) is a documented cybersecurity program that covers how your practice protects client data from unauthorized access, disclosure, and misuse. Every tax preparer, CPA, enrolled agent, and accounting firm that handles customer information is required to maintain one under both the FTC Safeguards Rule (16 CFR Part 314) and IRS Publication 4557. Practice size does not exempt you from the core requirement.
The WISP requirements 2025 tax preparers and firms must satisfy include all nine elements under FTC Safeguards Rule §314.4: a designated Qualified Individual, written risk assessment, administrative and technical safeguards, service provider oversight with enforceable contracts, monitoring and testing, employee training with documentation, information systems inventory, a written incident response plan, and an annual program review. The August 2024 IRS Publication 5708 update added specific requirements for universal MFA, 12-character minimum passwords, a 72-hour breach notification timeline, and explicit vendor contract language that apply to the 2026 filing season.
No. The 5,000-consumer threshold under the FTC Safeguards Rule creates limited exemptions for specific documentation requirements within certain subsections, but it does not eliminate the obligation to maintain a security program. Every tax professional, including solo practitioners preparing a single return, must implement all nine WISP elements. Smaller practices may have reduced written documentation requirements for some subsections, but the underlying security controls are still required.
The FTC Safeguards Rule requires an annual review at minimum. You must also update your WISP whenever your technology environment changes materially, when you add new service providers, when regulations change, or after any security incident. Auditors specifically look for evidence that the WISP reflects your current systems and operations, not just a snapshot from the year you first created it.
The most immediate enforcement risk is PTIN suspension. Tax professionals certify compliance with security requirements during PTIN renewal; a false certification is subject to federal fraud prosecution under 18 U.S.C. § 1001. Beyond PTIN risk, the FTC can pursue civil penalties for Safeguards Rule violations. State regulators and data protection authorities may have additional enforcement authority depending on your jurisdiction. A breach without a documented security program also exposes your practice to civil liability from affected clients.
Templates are a legitimate starting point, and the IRS itself provides sample WISP language in Publication 5708. However, regulators require that your WISP reflect your specific practice, including named systems, actual vendors, and real physical locations. A generic template submitted without customization does not satisfy the requirement. Our free 2026 WISP template includes section-by-section customization prompts to guide you through completing each element for your actual environment.
Yes. The August 2024 update to IRS Publication 5708 eliminated the ambiguity that existed around local network access. MFA is now required for all users accessing systems containing customer information, regardless of whether access originates inside or outside the office network. Every workstation used to access tax software, client portals, or any system storing Personally Identifiable Information must have MFA enabled.
Updated IRS guidance establishes a 72-hour notification expectation. You must notify the IRS, affected clients, and potentially state regulators following a breach involving client data. Your written incident response plan must include the specific contact information for your state's IRS Stakeholder Liaison office. Generic language about notifying regulators no longer satisfies this element. For a step-by-step guide, see our resource on what to do after a data breach.
The IRS standard records retention period of five years is a reasonable minimum for WISP documentation. This includes the written WISP itself, risk assessment records, training attendance logs, testing results, vendor evaluations, incident investigation records, and annual review documentation. Retaining records for at least five years provides a compliance history that demonstrates your program's continuity if an incident surfaces after the fact.
The FTC Safeguards Rule (16 CFR Part 314) is the primary federal regulation establishing the nine-element security program requirement for financial institutions, including tax professionals. IRS Publication 4557 and IRS Publication 5708 translate those obligations into tax-preparer-specific implementation guidance and address how the WISP integrates with PTIN renewal and IRS Security Summit commitments. The two frameworks are complementary. Meeting the IRS publication guidance generally satisfies the FTC Safeguards Rule requirements for tax practices. See our detailed breakdown in the FTC Safeguards Rule guide for tax preparers.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



