
Tax professionals handle some of the most sensitive personal data in existence: Social Security numbers, bank account details, income records, and complete family financial histories. That concentration of high-value data makes small tax firms consistent targets for cybercriminals, ransomware operators, and identity thieves.
Federal law has required written data security programs for tax preparers since 1999, when the Gramm-Leach-Bliley Act (GLBA) classified tax preparation businesses as financial institutions subject to mandatory safeguards. A Written Information Security Plan (WISP) for your small tax firm is the documented security program that satisfies those requirements and shields your practice from regulatory penalties and client harm.
This is a federal legal obligation enforced by both the FTC and IRS. Since the 2023 filing season, IRS Form W-12 PTIN renewal applications have required tax professionals to confirm active WISP implementation. The August 2024 update to IRS Publication 5708 expanded requirements to include mandatory multi-factor authentication (MFA) and defined breach notification timelines that apply to every firm, regardless of size. Whether you prepare 11 returns or 11,000 annually, the same federal obligations apply.
This guide covers every WISP component required by the FTC Safeguards Rule (16 CFR Part 314) and IRS data security standards, so you can build a plan that protects your clients and satisfies regulators in 2026.
Quick Answer
A WISP for a small tax firm is a written document required by the FTC Safeguards Rule and IRS Publication 4557 that describes how your practice protects client data. Every tax preparer holding a PTIN must have one. Your WISP must cover a designated security coordinator, a written risk assessment, employee policies, technical controls (including mandatory MFA as of August 2024), physical safeguards, vendor management, and an incident response plan with IRS 24-hour breach notification procedures.
Tax Firm Cybersecurity By The Numbers
IBM Cost of Data Breach Report 2024
Verizon Data Breach Investigations Report 2024
Required under IRS Publication 4557 and Publication 5708
Legal and Regulatory Framework: Who Requires a WISP and Why
Three overlapping federal authorities require small tax firms to maintain written information security plans: the Gramm-Leach-Bliley Act, the FTC Safeguards Rule, and IRS enforcement mechanisms tied to PTIN and EFIN licensing.
The Gramm-Leach-Bliley Act, enacted in 1999, established the foundational obligation. Title V of GLBA requires financial institutions to develop, implement, and maintain safeguards protecting customer records. Congress defined "financial institution" broadly enough to include any business providing financial services, including tax preparation. That classification subjects solo practitioners and small CPA firms to the same data protection standards applied to banks and credit unions.
The FTC implements GLBA through the FTC Safeguards Rule (16 CFR Part 314). The December 2022 amendments transformed what had been general principles into specific, documented requirements. Your WISP for small tax firm compliance must now address:
- A designated qualified individual overseeing your information security program
- A periodic risk assessment identifying internal and external threats to taxpayer data
- Administrative, technical, and physical safeguards addressing identified risks
- Ongoing monitoring and testing of security control effectiveness
- A detailed incident response plan with breach notification procedures
The IRS adds enforcement weight through its Security Summit initiative, a partnership between federal and state tax agencies and the private tax software industry. IRS Publication 4557, Safeguarding Taxpayer Data, documents the IRS's data security expectations, and Form W-12 PTIN renewals now require practitioners to affirmatively confirm they have implemented written data security plans. The IRS can revoke PTIN and EFIN credentials for non-compliant practitioners, effectively ending their ability to prepare tax returns professionally. For a full breakdown of how PTIN renewal ties to WISP compliance, see our guide on PTIN and WISP requirements for tax preparers.
2026 WISP Compliance Requirement
IRS Form W-12 PTIN renewal applications require tax professionals to confirm active WISP implementation. The August 2024 IRS Publication 5708 update made multi-factor authentication mandatory for all information system access, not just remote connections. Verify your current requirements against IRS Publication 5708 before the 2026 filing season begins.
Essential WISP Components for Small Tax Firms
The FTC Safeguards Rule identifies the minimum elements your WISP must address. Think of it as a security management system with six interconnected components: governance (who is responsible), risk assessment (what threats exist), administrative safeguards (how people handle data), technical safeguards (how technology protects data), physical safeguards (how facilities and equipment are secured), and incident response (how you detect, contain, and report security events).
IRS Publication 4557 reinforces this structure with practical implementation guidance for tax professionals. The Publication 4557 checklist is a useful orientation point, but your actual WISP documentation must go further, describing your specific systems, vendors, employees, and risk assessment findings in detail. Generic language that could apply to any firm will not satisfy regulators examining a breach response.
If you need a starting framework, the Bellator free WISP template for 2026 is built around the FTC Safeguards Rule requirements and IRS Publication 4557 structure, pre-formatted for tax firms and updated for current regulatory requirements including the mandatory MFA provisions from Publication 5708.
Your risk assessment, required by both the FTC Safeguards Rule and the NIST Cybersecurity Framework, should identify every system that touches taxpayer data, evaluate likely threats and vulnerabilities, and document your rationale for the safeguards you select. Regulators use this documentation to assess whether your controls are reasonable given your firm's actual risk profile, not whether you achieved theoretical perfection.
WISP Compliance Checklist for Small Tax Firms
- Designate a security coordinator responsible for the WISP and annual review
- Inventory all systems that store or process taxpayer data, including cloud services
- Complete a written risk assessment identifying internal and external threats
- Implement multi-factor authentication on all tax software, email, and cloud accounts
- Deploy endpoint protection with behavioral monitoring on all devices accessing client data
- Enable full-disk encryption on all devices that store or access taxpayer information
- Establish written access control and employee onboarding and termination procedures
- Create vendor management policies with documented security assessments for each provider
- Document incident response procedures with IRS 24-hour and FTC 30-day notification timelines
- Schedule annual employee security awareness training and document attendance
- Plan quarterly vulnerability assessments and annual penetration testing
- Document physical security controls: locks, visitor sign-in, screen locks, and shredding policy
Administrative Safeguards: Policies That Govern People and Processes
Administrative safeguards establish the policy framework governing how your firm handles taxpayer information through employee management, vendor oversight, and operational procedures. These are the written rules your WISP documents and enforces. Regulators examine administrative safeguards first when evaluating compliance because they reveal whether security is genuinely managed or merely claimed.
Security Officer Designation and Responsibilities
The FTC Safeguards Rule explicitly requires appointing a coordinator with appropriate expertise to manage your information security program. In a solo tax practice, that is typically the owner. In multi-professional firms, you might assign this responsibility to an office manager, senior staff member, or external IT consultant with relevant technical knowledge.
The designated security officer's responsibilities should be documented in your WISP to include: creating and maintaining all WISP documentation; conducting annual risk assessments; evaluating vendor security practices; coordinating employee security training; managing incident response activities; and monitoring ongoing compliance with FTC and IRS requirements. Document specific timelines, such as annual review by a specific calendar date and quarterly access reviews, so the role has accountability built in rather than aspirational language.
Access Control and the Principle of Least Privilege
Access control procedures ensure employees can only reach the information necessary for their specific job functions. Document your process for granting system access when employees join: what training must be completed before access is granted, who must approve access requests, and how you verify that permissions remain appropriate for each role over time.
Termination procedures deserve equal attention in your WISP. Revoke all system access on the employee's last day, collect physical credentials and devices, change any shared passwords the departing employee knew, and review recent access logs for unusual activity. Your WISP should define who performs each step and the timeline for completion, not just that it happens, but how it happens and who is accountable for confirming completion.
Technical Safeguards: The Technology Controls Your WISP Must Document
Technical safeguards are the technology controls that prevent, detect, and respond to unauthorized access to electronic taxpayer information. Your WISP must specify which controls are deployed, where they are implemented, and who is responsible for maintaining them. Regulators do not expect perfection; they expect documented, reasonable protections calibrated to your firm's size and actual risk exposure.
Endpoint Protection and Network Security
Every workstation, laptop, and server accessing taxpayer information needs endpoint protection that goes beyond traditional antivirus software. Endpoint Detection and Response (EDR) solutions provide behavioral monitoring, threat detection, and automated response capabilities that signature-based antivirus cannot match. The IRS explicitly recommends EDR-class protection in Publication 4557, and the FTC Safeguards Rule requires safeguards that address the actual threat environment facing financial institutions, which in 2026 includes ransomware, business email compromise, and credential theft attacks that legacy antivirus routinely misses.
For small firms evaluating their options, our comparison of EDR vs. MDR vs. XDR solutions breaks down which tier fits a small tax practice. Outsourcing endpoint monitoring to a qualified managed detection and response (MDR) provider satisfies the FTC's requirement for ongoing monitoring and can be more cost-effective than building internal security operations capacity. Your WISP should document whichever approach you use, including the vendor's name, their security certifications, and your contractual obligations regarding incident notification.
Network firewalls controlling traffic between your practice network and the internet provide a necessary perimeter control. Email security gateways filter phishing attempts, malware attachments, and business email compromise attacks before they reach employee inboxes. Phishing remains the most common entry point for tax firm breaches according to IRS Security Summit reporting, making email filtering a required control, not an optional upgrade.
Encryption: Protecting Data at Rest and In Transit
The IRS requires encryption for all taxpayer information stored on portable devices and transmitted across public networks. Implement full-disk encryption on every device that stores or accesses taxpayer information: desktop computers, laptops, tablets, and smartphones used for work purposes. Modern operating systems include built-in encryption: BitLocker for Windows and FileVault for macOS both provide AES-256 protection with minimal performance impact. Your WISP should document which encryption solution is deployed on each device category and who verifies that encryption remains active.
For data in transit, ensure your tax software and client portal solutions use TLS 1.2 or higher for all data transmission. Our guide to tax client portal security covers what to evaluate before trusting a portal with sensitive client data, including how to verify the encryption standard a vendor actually applies.
Multi-Factor Authentication: Mandatory for All System Access
The August 2024 IRS Publication 5708 update made MFA mandatory for all information system access, not just remote connections. Multi-factor authentication (MFA) requires users to verify their identity through at least two independent factors before gaining access to any system containing taxpayer data. This single control prevents the vast majority of credential-based attacks, which account for the largest share of tax firm breaches tracked by the IRS Security Summit.
Enable MFA on all systems containing sensitive information: tax preparation software accounts, email accounts, cloud storage platforms, VPN and remote desktop solutions, accounting and practice management software, and administrative interfaces for network equipment. Authenticator apps are preferred over SMS codes, which are vulnerable to SIM-swapping attacks. Your WISP should document which MFA method is used for each system category so you can demonstrate a specific, intentional choice to regulators.
WISP Implementation Steps for Small Tax Firms
Appoint Your Security Coordinator
Designate a qualified individual responsible for your WISP. Document their specific responsibilities, authority, and reporting structure in writing before any other step begins.
Complete a Written Risk Assessment
Inventory every system that stores or processes taxpayer data. Identify internal and external threats, evaluate vulnerabilities, and document the rationale for each safeguard you select.
Deploy Technical Controls
Implement EDR on all endpoints, enable full-disk encryption on all devices, configure MFA on every system accessing client data, and set up email security filtering.
Document Policies and Procedures
Write your access control, employee onboarding and termination, acceptable use, vendor management, and incident response procedures into the WISP document itself with specific names and timelines.
Train All Employees
Conduct initial security awareness training for all staff before they access client systems. Document attendance and schedule annual refresher training with the same documentation.
Test Your Controls
Run a backup restore test, conduct a phishing simulation, and complete a vulnerability scan. Document findings and remediate gaps before the filing season.
Review and Update Annually
Update your risk assessment, revise any controls that proved ineffective, and reflect changes in staff, technology, and vendors. Date and sign each updated version for your records.
Physical Safeguards: Securing Facilities, Devices, and Documents
Physical security controls prevent unauthorized individuals from accessing facilities, equipment, and documents containing taxpayer information. A technically sophisticated digital security program can be undermined by an unlocked server room, documents left on a desk during a client visit, or paper records disposed of without shredding. The FTC Safeguards Rule's physical safeguard requirements are specifically called out in federal tax information security guidance, and treating them as less important than technical controls is a common compliance gap that regulators notice.
Facility Access Controls
Implement locked doors with key or card access for areas containing sensitive information, particularly server rooms, records storage areas, and back-office workspaces. Visitor management procedures should require guests to sign in and be escorted by staff members at all times, an important control during the busy filing season when client traffic through the office is highest. Security cameras at entry points and sensitive areas provide both deterrence and forensic evidence when incidents occur. Your WISP should document the specific controls in place for each area of your facility, not just state that access controls exist.
Workstation and Screen Security
Require automatic screen locks activating after no more than five to ten minutes of inactivity, with password or PIN authentication to resume. Position monitors to prevent viewing by clients or unauthorized staff walking through office areas, a particularly relevant control in open-plan offices and reception areas where clients may wait. Clean desk policies requiring employees to secure documents in locked drawers when leaving workspaces, even briefly, prevent opportunistic information theft during client visits, vendor service calls, and after-hours cleaning services. Document these requirements in your WISP with specific standards so employees understand what is expected.
Document Disposal
Dumpster diving remains a productive attack vector for criminals seeking taxpayer information, and the IRS has documented cases where tax-related identity theft originated from improperly disposed documents. Provide cross-cut shredders in all areas where employees handle sensitive documents. Establish a shredding policy requiring destruction of all documents containing client information before disposal, and consider certified document destruction services for high-volume shredding. Your WISP should specify the destruction standard, the equipment or vendor used, and how you document that destruction occurred for compliance purposes.
Vendor Management: Extending Your Security Program to Third Parties
Tax practices depend on a substantial number of third-party vendors: tax preparation software, cloud storage, email hosting, practice management systems, IT support providers, document management platforms, and payroll services. Each vendor that accesses, stores, or transmits taxpayer information extends your attack surface and your regulatory exposure. The FTC Safeguards Rule explicitly requires selecting qualified service providers and contractually obligating them to implement appropriate safeguards, making vendor management a documented WISP requirement rather than just a best practice.
Vendor Inventory and Due Diligence
Start by inventorying all service providers with access to taxpayer information. Common categories for tax firms include: tax preparation software vendors, cloud storage and backup services, email hosting providers, practice management and client portal systems, IT support and managed service providers, and document management and scanning services. For each vendor, your WISP should document who the vendor is, what data they can access, what security commitments they have made, and when you last reviewed their security posture.
Before engaging any vendor with access to client data, conduct formal due diligence. Request SOC 2 Type II audit reports documenting independently verified security controls. Review security questionnaires addressing encryption practices, access controls, incident response capabilities, and business continuity planning. Verify compliance certifications relevant to financial services: payment processors should carry PCI DSS certification. Document your due diligence process and findings in your WISP so you can demonstrate to regulators that vendor selection was reasoned rather than arbitrary.
Contractual Requirements
Your vendor agreements should require the vendor to implement appropriate security measures, notify you of any breach affecting your client data within a defined timeframe, allow you to audit their security practices, and return or destroy your data when the relationship ends. Generic vendor agreements often lack these provisions. Review your contracts and seek amendments where needed. A vendor that will not agree to minimum security obligations in writing is itself a risk signal worth documenting in your WISP risk assessment.
Need Help Building Your WISP?
Our security team has helped thousands of tax professionals create compliant Written Information Security Plans that satisfy FTC Safeguards Rule and IRS Publication 4557 requirements. Download a free 2026 template built specifically for tax firms.
Incident Response: What to Do When Something Goes Wrong
Preventive controls reduce risk but cannot eliminate it. A WISP for small tax firm operations without working incident response procedures is incomplete from both a regulatory and practical standpoint. Regulators impose more severe consequences on firms that lack documented response procedures than on firms with plans that prove imperfect under pressure, because a documented plan demonstrates good faith while the absence of any plan demonstrates indifference to client data security.
Defining Security Incidents
Start by establishing clear definitions of what constitutes a security incident requiring a formal response. Your incident response plan should address: confirmed or suspected unauthorized access to taxpayer information; malware infectionsransomware, or system compromises; lost or stolen devices containing client data; successful phishing attacks compromising employee credentials; suspicious system activities suggesting potential compromise; insider threats or unauthorized data disclosure; and vendor breaches affecting taxpayer data stored with third parties. Clear definitions prevent delays caused by uncertainty about whether an event requires formal escalation.
Response Procedures: Detect, Contain, Investigate, Recover
Effective incident response follows a structured sequence. Detection and reporting procedures allow any employee to trigger response activation by contacting designated security officers; your WISP should include the specific contact information and after-hours procedures. Containment isolates affected systems: disconnect compromised devices from networks, disable compromised user accounts, and preserve system state for forensic investigation before attempting recovery. Investigation determines what data was accessed, which systems were affected, how attackers gained entry, and whether vulnerabilities remain. Recovery restores systems from clean backups, applies security patches, and validates that the threat is fully removed before returning to operations.
For a deeper look at building out these procedures, our guide on incident response planning for tax practices walks through each phase with tax-firm-specific examples.
Federal and State Breach Notification Requirements
When incidents result in unauthorized access to taxpayer data, multiple notification obligations apply simultaneously. The IRS requires tax professionals to report confirmed breaches to the IRS Data Security Office within 24 hours using the Stakeholder Liaison reporting process; a contact list is maintained in IRS Publication 4557. The August 2024 FTC Safeguards Rule update added mandatory FTC notification within 30 days when incidents affect 500 or more consumers.
State breach notification laws add a further layer of complexity. All 50 states have enacted breach notification statutes with varying requirements, timelines, and covered data definitions. Your WISP should document applicable state obligations based on where your clients reside, not just where your firm is located. For firms handling clients across multiple states, this means tracking a matrix of different notification timelines and requirements, and your WISP must account for each jurisdiction.
Testing, Validation, and Annual WISP Updates
A WISP that documents controls but never validates them provides limited practical protection and weakened regulatory standing. The FTC Safeguards Rule requires regular testing and monitoring of implemented safeguards. When regulators investigate a breach, they examine testing records as evidence of whether the firm took its security program seriously. Incidents at firms with documented but untested controls typically result in more severe consequences than incidents at firms with actively maintained security programs.
Technical Control Validation Schedules
Backup and restore testing should occur quarterly, simulating various failure scenarios including ransomware encryption to confirm actual data recovery capability, not just that backups are running. Firms that have never tested recovery often discover during an actual incident that their backups are incomplete, corrupted, or incompatible with their current systems.
Monthly automated vulnerability scanning identifies security weaknesses in systems, applications, and network infrastructure before attackers discover them. Annual penetration testing by qualified security professionals tests defenses against real-world attack techniques under controlled conditions. Quarterly phishing simulations test employee ability to recognize social engineering attempts, with targeted follow-up training for individuals who engage with simulated attacks. This is not punitive; it is the most effective way to identify and close the human element of your security program. Access control reviews should also occur quarterly to verify that user permissions match current job responsibilities and confirm that former employees' access has been fully revoked.
Annual Review Requirements
The FTC Safeguards Rule requires annual review and updating of your written information security plan. Annual reviews should update risk assessments based on emerging threats, revise controls that proved ineffective during the year, incorporate lessons from any security incidents experienced, and reflect changes in your technology stack, staffing, vendors, or office locations. A WISP that was accurate in 2024 but has not been updated to reflect a new cloud storage vendor, a staff change, or a new remote work policy is non-compliant even if the original document was thorough.
The NIST Cybersecurity Framework provides a structured methodology for ongoing risk assessment that aligns with both FTC and IRS expectations. Organizing your annual review around the NIST CSF's Identify-Protect-Detect-Respond-Recover structure ensures you address each security domain systematically rather than revisiting only the areas that caused problems during the year. For firms that want support through this processBellator's IRS Publication 4557 compliance services include annual WISP review and updating as part of managed security programs for tax professionals.
Bottom Line
Every tax professional holding a PTIN must maintain a written information security plan that describes their firm's specific systems, vendors, and controls. A generic or template document that has never been reviewed, customized, or tested will not satisfy FTC or IRS examiners following a breach. Build it once, update it annually, and test it quarterly. The documentation you create now is the evidence that protects your practice if something goes wrong.
Book a Free Tax Cybersecurity Assessment
Our security experts will evaluate your current WISP compliance and provide actionable recommendations to meet FTC Safeguards Rule and IRS Publication 4557 requirements before the 2026 filing season.
Frequently Asked Questions
A Written Information Security Plan (WISP) is a documented security program that describes how a business protects sensitive customer data. The FTC Safeguards Rule requires any business classified as a financial institution under the Gramm-Leach-Bliley Act to maintain one. Tax preparers, CPAs, and accounting firms qualify as financial institutions because they provide financial services, so every tax professional holding a PTIN must have a current, documented WISP regardless of firm size or the number of returns prepared.
The FTC Safeguards Rule requires at least annual review and updating. You should also update your WISP whenever material changes occur: adding a new software vendor, changing your office location, hiring or terminating staff with system access, or adopting new technology. A WISP with an outdated risk assessment or vendor list is non-compliant even if it was thorough when originally written. Date and sign every updated version.
Operating without a WISP exposes your firm to IRS PTIN and EFIN revocation, FTC enforcement actions, and state regulatory penalties. PTIN renewal applications now require affirmative confirmation of WISP implementation. If a breach occurs and you cannot produce a WISP, regulators treat the absence of a written plan as evidence of indifference to client data security, which typically results in more severe enforcement outcomes than a breach at a firm with a documented but imperfect plan.
Yes, a template is a valid starting point. The IRS Security Summit and organizations like Bellator Cyber Guard publish templates designed for tax firms. The key requirement is customization: your WISP must describe your specific systems, employees, vendors, and risk assessment findings. A template that has not been customized with your firm's actual details will not satisfy regulators examining a breach response. Use a template to ensure you cover every required element, then fill in the specifics for your practice.
Yes. The August 2024 update to IRS Publication 5708 made MFA mandatory for all information system access, not just remote connections. Your WISP must document MFA implementation across all systems that store or process taxpayer data, including tax preparation software, email accounts, cloud storage, and practice management platforms. Authenticator apps are preferred over SMS-based codes because SMS codes are vulnerable to SIM-swapping attacks.
Tax firms face two federal notification timelines. The IRS requires reporting confirmed breaches to the IRS Data Security Office within 24 hours of discovery using the Stakeholder Liaison contact process documented in IRS Publication 4557. The FTC Safeguards Rule requires notifying the FTC within 30 days when a breach affects 500 or more consumers. State breach notification laws apply separately, with timelines typically ranging from 30 to 90 days depending on the state. Your WISP should document all applicable requirements based on where your clients reside.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



