Skip to content
Bellator Cyber Guard
Tax29 min readDeep Dive

Written Information Security Plan: What Tax Pros Must Know

A written information security plan (WISP) is required under the FTC Safeguards Rule and IRS Pub. 4557. See what tax preparers must include and how to build one.

By Bellator Cyber Guard Security Team
Written Information Security Plan: What Tax Pros Must Know - written information security plan

What Is a Written Information Security Plan (WISP)?

A written information security plan (WISP) is a documented cybersecurity program that tax preparers must maintain under the Gramm-Leach-Bliley Act (GLBA), the federal law that treats tax preparation businesses as financial institutions for data security purposes. The FTC Safeguards Rule turns that classification into a specific obligation: any preparer who files 11 or more federal tax returns in a year must keep a written information security plan describing the administrative, technical, and physical safeguards used to protect client data.

Who needs one: every tax preparer, CPA firm, and accounting practice handling taxpayer data counts as a financial institution under this rule, regardless of size. That covers solo preparers working from a home office as well as multi-partner firms. The IRS makes the same point directly in Publication 4557, Safeguarding Taxpayer Data, which tells preparers a written security plan is not optional.

What to do next: if you don't have a WISP yet, start with IRS Publication 5708, a sample plan built for tax practices, run a risk assessment of the systems that touch client data, and document the safeguards you already have. Waiting isn't a low-risk shortcut. According to IBM's 2025 Cost of a Data Breach Report, the average data breach now costs $4.88 million, and the FTC can separately pursue civil penalties for Safeguards Rule violations, currently up to roughly $46,517 per violation per day and adjusted for inflation each year.

Quick Answer

A written information security plan (WISP) is a document required under the FTC Safeguards Rule and IRS Publication 4557 that spells out the administrative, technical, and physical safeguards a tax practice uses to protect client data. Any preparer filing 11 or more returns a year needs one, regardless of firm size. The IRS offers free starting templates through Publications 5708 and 5709, but they have to be customized to match your actual systems, staff, and vendors. Firms that skip this step risk FTC penalties, IRS scrutiny, and gaps in coverage if a breach happens.

WISP Compliance By the Numbers

$4.88M
Average cost of a data breach
$46,517
Maximum FTC fine per violation, per day
68%
Breaches involving a human element
11+
Returns filed per year that trigger the WISP requirement

Federal WISP Requirements for Tax Professionals

The WISP requirement doesn't come from one rule. It comes from two federal frameworks that overlap but aren't identical, and tax preparers need to satisfy both.

Gramm-Leach-Bliley Act and the FTC Safeguards Rule

The FTC Safeguards Rule (16 CFR Part 314) implements GLBA's data security requirements for financial institutions, a category that includes tax preparers. The version of the rule that took effect June 9, 2023 added specific technical requirements instead of a general duty to be reasonably secure:

  • Multi-factor authentication on any system that accesses customer information
  • Encryption for data at rest and in transit, using current standards such as AES-256 and TLS 1.2 or higher
  • Annual penetration testing and vulnerability assessments twice a year for firms holding records on 5,000 or more consumers, or continuous monitoring as an alternative
  • A written incident response plan and FTC notification within 30 days when an incident affects 500 or more people

For a full walkthrough of these technical requirements, see our FTC Safeguards Rule checklist for tax preparers.

IRS Security Standards and Publications

The IRS lays out its own expectations in Publication 4557, Safeguarding Taxpayer Data, which states plainly that tax professionals must create a written security plan. Two companion documents make the process easier: Publication 5708, a sample WISP built for tax practices, and Publication 5709, a worksheet-based guide for building a plan from scratch.

These aren't competing requirements. The FTC rule sets the legal floor, and the IRS publications tell you how to document that you're meeting it. Satisfying one doesn't automatically satisfy the other. Our related guide on Publication 4557 requirements covers this in more depth.

2026 Filing Season Reminder

IRS Publication 4557 directs every tax professional to maintain a written security plan. Ahead of the 2026 filing season, confirm your WISP is current, matches your actual systems, and can be produced if a preparer review or PTIN renewal asks for it. Check the current PTIN renewal instructions directly, since certification requirements can change year to year.

Administrative Safeguards: Policies and Training

Administrative safeguards are the policies and personnel practices that govern how your firm handles security day to day. This is usually the largest section of a WISP, because it sets expectations for everyone on staff, not just IT.

Core Policies Every WISP Should Include

At minimum, your WISP needs to document the following policies:

WISP Core Policies Checklist

  • Acceptable use policy covering firm technology, internet access, and personal devices
  • Access control policy applying least-privilege, role-based permissions
  • Password and authentication policy, including MFA requirements
  • Data classification policy that sets handling rules by sensitivity level
  • Encryption policy specifying how client tax data is protected
  • Remote work policy covering VPN use and other controls for distributed staff
  • Vendor management policy with security provisions for third parties
  • Data retention policy (IRS guidance points to a 7 year retention period for tax records)

Employee Security Awareness Training

According to Verizon's 2025 Data Breach Investigations Report, a human element was involved in 68% of confirmed breaches. A WISP without a training program only exists on paper. At minimum, training should cover phishing recognition and reporting, proper handling of sensitive taxpayer data, password hygiene, physical security basics like clean desks, and who staff should contact if something looks wrong.

Run this training at onboarding and at least once a year after that, and keep records of who attended and how they performed. That documentation, not the policy alone, is what an examiner or insurer will ask to see. Our IRS Security Six checklist covers the baseline controls this training should reinforce.

How to Build a WISP: 7 Steps

1

Conduct a risk assessment

Inventory every system that stores or touches taxpayer data and identify internal and external threats to that data.

2

Designate a security coordinator

Assign one person, even in a solo practice this can be the owner, to run the security program and keep it current.

3

Document current controls

Catalog the administrative, technical, and physical safeguards you already have in place.

4

Identify gaps and remediate

Compare what you have against FTC and IRS requirements and fix what's missing.

5

Write the policies

Put every policy, procedure, and training requirement into the formal WISP document.

6

Train staff and test the plan

Run security awareness training and walk through incident response with a tabletop exercise.

7

Review and update annually

Revisit the WISP at least once a year, and any time staff, systems, or vendors change.

Technical and Physical Safeguards

Technical safeguards are the technology controls protecting your electronic systems from unauthorized access. Physical safeguards keep unauthorized people away from the equipment and paper files that hold that same data.

Essential Technical Controls

Endpoint protection: Modern endpoint detection and response (EDR) tools use behavioral analysis to catch attacks that legacy antivirus signatures miss, which matters most during filing season when your systems are handling the highest volume of sensitive data all year. If you're comparing options, our EDR comparison guide walks through what to look for.

Network security: A properly configured firewall combines packet filtering with intrusion prevention and should default to denying unnecessary connections rather than allowing them.

Encryption: The FTC Safeguards Rule requires encryption of customer information. That means full-disk encryption on workstations, AES-256 or equivalent for databases, TLS 1.2 or higher for data in transit, encrypted email for sensitive documents, and backup encryption with keys stored separately from the backups themselves.

Access controls: Unique accounts for every user, MFA on all tax systems, automatic session timeouts, and immediate access revocation when someone leaves the firm.

Physical Security Measures

Your WISP should also document facility access controls (keyed locks or electronic systems), visitor management procedures, workstation security such as screen locks and clean desk practices, secured server equipment in locked rooms, and document disposal through cross-cut shredding.

Security Maturity Levels for Tax Practices

Endpoint Protection

Basic
Legacy antivirus only
Standard
EDR with behavioral analysis
Advanced
EDR on every endpoint with zero-day defense

Data Backup

Basic
Basic backup copies
Standard
Encrypted backups
Advanced
Encrypted backups with keys stored separately

Monitoring

Basic
Periodic reviews only
Standard
Biannual vulnerability assessments
Advanced
Continuous monitoring with centralized logging

Incident Response

Basic
No formal plan
Standard
Documented response procedures
Advanced
Formal plan with assigned team roles

Compliance Documentation

Basic
Template only, self-managed
Standard
Annual review and training records
Advanced
Penetration testing plus annual reporting

Incident Response and Breach Notification

No set of controls stops every incident, which is why your WISP needs a documented response plan covering preparation, detection and analysis, containment, eradication, recovery, and a post-incident review.

Breach Notification Timelines

  • IRS: contact your local Stakeholder Liaison as soon as you discover a breach, typically within 24 hours
  • FTC: notify within 30 days if the incident affects 500 or more individuals
  • State: most states require notification within 30 to 60 days, and requirements vary by state law
  • Affected individuals: notify according to your state's breach notification law
  • Law enforcement: report to the FBI's Internet Crime Complaint Center and local authorities

For a step-by-step breakdown of the first 24 hours after discovering an incident, see our small business data breach response plan, and our ransomware protection guide covers how to prepare specifically for a ransomware event.

Advantages of an IRS Template

  • Free and IRS-sanctioned, so you're starting from an accepted framework
  • Publications 5708 and 5709 include worksheets that walk through the process step by step
  • A reasonable fit for solo preparers with simple, well-understood systems

Considerations

  • A generic template doesn't document your actual systems, vendors, or staff until you customize it
  • No one updates it for you as regulations or your technology change
  • It documents requirements but doesn't implement them; MFA, encryption, and monitoring still have to be set up separately
  • Larger practices with more systems and staff usually need more customization than the worksheets provide

Want a WISP built around your actual firm instead of a blank template?

Bellator's custom WISP service documents your real systems, staff, and vendors instead of leaving you to adapt a generic worksheet. It starts at $749 for firms with up to 5 users, with larger practices quoted separately, and most firms save an estimated 20 to 40 billable hours compared to building one from scratch.

WISP Requirements by Practice Size

Every tax professional needs a WISP, but how much time and detail that takes scales with the complexity of your practice.

Solo Practitioners and Small Firms (1 to 5 Employees)

Small practices can implement WISP requirements proportionally. The owner typically serves as the security coordinator. IRS Publications 5708 and 5709 provide templates scaled for small practices, and cloud-based tax software with built-in encryption and MFA can cover several technical requirements at once.

Mid-Size and Larger Firms (6 or More Employees)

Larger practices face the full scope of the Safeguards Rule: a designated qualified individual with documented expertise, annual penetration testing and biannual vulnerability assessments once you cross the 5,000-consumer-record threshold, a formal incident response plan with assigned team roles, a vendor risk management program, and regular reporting to firm leadership on the security program's status. See our tax preparer security plan resources for more on scaling these requirements, and our privileged access management guide if you're setting up role-based access for the first time.

Book a Free Tax Cybersecurity Assessment

Get an evaluation of your current security posture against FTC Safeguards Rule and IRS WISP requirements, with concrete next steps for your practice.

Frequently Asked Questions

A WISP is a document required under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule for tax professionals handling taxpayer data. It spells out the administrative, technical, and physical safeguards a firm uses to protect personally identifiable information from unauthorized access, disclosure, or loss.

Any tax preparer, accounting firm, or financial service provider handling taxpayer data is treated as a financial institution under federal law and must maintain a WISP. This applies to solo practitioners, CPA firms, and multi-office practices once they file 11 or more returns a year, regardless of firm size.

The FTC can pursue civil penalties for Safeguards Rule violations, currently up to roughly $46,517 per violation per day and adjusted annually for inflation. The IRS can also take action against a preparer's PTIN or e-file privileges for security failures, and unaddressed gaps can complicate your standing with a professional liability insurer. IBM's 2025 Cost of a Data Breach Report put the average breach cost at $4.88 million, which puts the potential downside in perspective.

Review and update your WISP at least once a year, and any time you have a significant change to systems, staff, or vendors. The FTC Safeguards Rule also expects annual risk assessments and ongoing monitoring of how well the security program is actually working.

Yes. The IRS provides templates through Publications 5708 and 5709, and they're a legitimate starting point. But a generic, unmodified template that doesn't reflect your actual systems and procedures won't hold up to scrutiny. Firms that would rather not build and maintain it themselves can use a paid service that documents their specific practice instead.

Follow the notification timeline in your WISP: contact the IRS Stakeholder Liaison within roughly 24 hours, notify the FTC within 30 days if 500 or more individuals are affected, comply with your state's breach notification law (typically 30 to 60 days), and notify affected taxpayers as required.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.