
What Is a Written Information Security Plan (WISP)?
A written information security plan (WISP) is a documented cybersecurity program that tax preparers must maintain under the Gramm-Leach-Bliley Act (GLBA), the federal law that treats tax preparation businesses as financial institutions for data security purposes. The FTC Safeguards Rule turns that classification into a specific obligation: any preparer who files 11 or more federal tax returns in a year must keep a written information security plan describing the administrative, technical, and physical safeguards used to protect client data.
Who needs one: every tax preparer, CPA firm, and accounting practice handling taxpayer data counts as a financial institution under this rule, regardless of size. That covers solo preparers working from a home office as well as multi-partner firms. The IRS makes the same point directly in Publication 4557, Safeguarding Taxpayer Data, which tells preparers a written security plan is not optional.
What to do next: if you don't have a WISP yet, start with IRS Publication 5708, a sample plan built for tax practices, run a risk assessment of the systems that touch client data, and document the safeguards you already have. Waiting isn't a low-risk shortcut. According to IBM's 2025 Cost of a Data Breach Report, the average data breach now costs $4.88 million, and the FTC can separately pursue civil penalties for Safeguards Rule violations, currently up to roughly $46,517 per violation per day and adjusted for inflation each year.
Quick Answer
A written information security plan (WISP) is a document required under the FTC Safeguards Rule and IRS Publication 4557 that spells out the administrative, technical, and physical safeguards a tax practice uses to protect client data. Any preparer filing 11 or more returns a year needs one, regardless of firm size. The IRS offers free starting templates through Publications 5708 and 5709, but they have to be customized to match your actual systems, staff, and vendors. Firms that skip this step risk FTC penalties, IRS scrutiny, and gaps in coverage if a breach happens.
WISP Compliance By the Numbers
Federal WISP Requirements for Tax Professionals
The WISP requirement doesn't come from one rule. It comes from two federal frameworks that overlap but aren't identical, and tax preparers need to satisfy both.
Gramm-Leach-Bliley Act and the FTC Safeguards Rule
The FTC Safeguards Rule (16 CFR Part 314) implements GLBA's data security requirements for financial institutions, a category that includes tax preparers. The version of the rule that took effect June 9, 2023 added specific technical requirements instead of a general duty to be reasonably secure:
- Multi-factor authentication on any system that accesses customer information
- Encryption for data at rest and in transit, using current standards such as AES-256 and TLS 1.2 or higher
- Annual penetration testing and vulnerability assessments twice a year for firms holding records on 5,000 or more consumers, or continuous monitoring as an alternative
- A written incident response plan and FTC notification within 30 days when an incident affects 500 or more people
For a full walkthrough of these technical requirements, see our FTC Safeguards Rule checklist for tax preparers.
IRS Security Standards and Publications
The IRS lays out its own expectations in Publication 4557, Safeguarding Taxpayer Data, which states plainly that tax professionals must create a written security plan. Two companion documents make the process easier: Publication 5708, a sample WISP built for tax practices, and Publication 5709, a worksheet-based guide for building a plan from scratch.
These aren't competing requirements. The FTC rule sets the legal floor, and the IRS publications tell you how to document that you're meeting it. Satisfying one doesn't automatically satisfy the other. Our related guide on Publication 4557 requirements covers this in more depth.
2026 Filing Season Reminder
IRS Publication 4557 directs every tax professional to maintain a written security plan. Ahead of the 2026 filing season, confirm your WISP is current, matches your actual systems, and can be produced if a preparer review or PTIN renewal asks for it. Check the current PTIN renewal instructions directly, since certification requirements can change year to year.
Administrative Safeguards: Policies and Training
Administrative safeguards are the policies and personnel practices that govern how your firm handles security day to day. This is usually the largest section of a WISP, because it sets expectations for everyone on staff, not just IT.
Core Policies Every WISP Should Include
At minimum, your WISP needs to document the following policies:
WISP Core Policies Checklist
- Acceptable use policy covering firm technology, internet access, and personal devices
- Access control policy applying least-privilege, role-based permissions
- Password and authentication policy, including MFA requirements
- Data classification policy that sets handling rules by sensitivity level
- Encryption policy specifying how client tax data is protected
- Remote work policy covering VPN use and other controls for distributed staff
- Vendor management policy with security provisions for third parties
- Data retention policy (IRS guidance points to a 7 year retention period for tax records)
Employee Security Awareness Training
According to Verizon's 2025 Data Breach Investigations Report, a human element was involved in 68% of confirmed breaches. A WISP without a training program only exists on paper. At minimum, training should cover phishing recognition and reporting, proper handling of sensitive taxpayer data, password hygiene, physical security basics like clean desks, and who staff should contact if something looks wrong.
Run this training at onboarding and at least once a year after that, and keep records of who attended and how they performed. That documentation, not the policy alone, is what an examiner or insurer will ask to see. Our IRS Security Six checklist covers the baseline controls this training should reinforce.
How to Build a WISP: 7 Steps
Conduct a risk assessment
Inventory every system that stores or touches taxpayer data and identify internal and external threats to that data.
Designate a security coordinator
Assign one person, even in a solo practice this can be the owner, to run the security program and keep it current.
Document current controls
Catalog the administrative, technical, and physical safeguards you already have in place.
Identify gaps and remediate
Compare what you have against FTC and IRS requirements and fix what's missing.
Write the policies
Put every policy, procedure, and training requirement into the formal WISP document.
Train staff and test the plan
Run security awareness training and walk through incident response with a tabletop exercise.
Review and update annually
Revisit the WISP at least once a year, and any time staff, systems, or vendors change.
Technical and Physical Safeguards
Technical safeguards are the technology controls protecting your electronic systems from unauthorized access. Physical safeguards keep unauthorized people away from the equipment and paper files that hold that same data.
Essential Technical Controls
Endpoint protection: Modern endpoint detection and response (EDR) tools use behavioral analysis to catch attacks that legacy antivirus signatures miss, which matters most during filing season when your systems are handling the highest volume of sensitive data all year. If you're comparing options, our EDR comparison guide walks through what to look for.
Network security: A properly configured firewall combines packet filtering with intrusion prevention and should default to denying unnecessary connections rather than allowing them.
Encryption: The FTC Safeguards Rule requires encryption of customer information. That means full-disk encryption on workstations, AES-256 or equivalent for databases, TLS 1.2 or higher for data in transit, encrypted email for sensitive documents, and backup encryption with keys stored separately from the backups themselves.
Access controls: Unique accounts for every user, MFA on all tax systems, automatic session timeouts, and immediate access revocation when someone leaves the firm.
Physical Security Measures
Your WISP should also document facility access controls (keyed locks or electronic systems), visitor management procedures, workstation security such as screen locks and clean desk practices, secured server equipment in locked rooms, and document disposal through cross-cut shredding.
Security Maturity Levels for Tax Practices
Endpoint Protection
- Basic
- Legacy antivirus only
- Standard
- EDR with behavioral analysis
- Advanced
- EDR on every endpoint with zero-day defense
Data Backup
- Basic
- Basic backup copies
- Standard
- Encrypted backups
- Advanced
- Encrypted backups with keys stored separately
Monitoring
- Basic
- Periodic reviews only
- Standard
- Biannual vulnerability assessments
- Advanced
- Continuous monitoring with centralized logging
Incident Response
- Basic
- No formal plan
- Standard
- Documented response procedures
- Advanced
- Formal plan with assigned team roles
Compliance Documentation
- Basic
- Template only, self-managed
- Standard
- Annual review and training records
- Advanced
- Penetration testing plus annual reporting
| Feature | Basic | Standard | Advanced |
|---|---|---|---|
| Endpoint Protection | Legacy antivirus only | EDR with behavioral analysis | EDR on every endpoint with zero-day defense |
| Data Backup | Basic backup copies | Encrypted backups | Encrypted backups with keys stored separately |
| Monitoring | Periodic reviews only | Biannual vulnerability assessments | Continuous monitoring with centralized logging |
| Incident Response | No formal plan | Documented response procedures | Formal plan with assigned team roles |
| Compliance Documentation | Template only, self-managed | Annual review and training records | Penetration testing plus annual reporting |
Incident Response and Breach Notification
No set of controls stops every incident, which is why your WISP needs a documented response plan covering preparation, detection and analysis, containment, eradication, recovery, and a post-incident review.
Breach Notification Timelines
- IRS: contact your local Stakeholder Liaison as soon as you discover a breach, typically within 24 hours
- FTC: notify within 30 days if the incident affects 500 or more individuals
- State: most states require notification within 30 to 60 days, and requirements vary by state law
- Affected individuals: notify according to your state's breach notification law
- Law enforcement: report to the FBI's Internet Crime Complaint Center and local authorities
For a step-by-step breakdown of the first 24 hours after discovering an incident, see our small business data breach response plan, and our ransomware protection guide covers how to prepare specifically for a ransomware event.
Advantages of an IRS Template
- Free and IRS-sanctioned, so you're starting from an accepted framework
- Publications 5708 and 5709 include worksheets that walk through the process step by step
- A reasonable fit for solo preparers with simple, well-understood systems
Considerations
- A generic template doesn't document your actual systems, vendors, or staff until you customize it
- No one updates it for you as regulations or your technology change
- It documents requirements but doesn't implement them; MFA, encryption, and monitoring still have to be set up separately
- Larger practices with more systems and staff usually need more customization than the worksheets provide
Want a WISP built around your actual firm instead of a blank template?
Bellator's custom WISP service documents your real systems, staff, and vendors instead of leaving you to adapt a generic worksheet. It starts at $749 for firms with up to 5 users, with larger practices quoted separately, and most firms save an estimated 20 to 40 billable hours compared to building one from scratch.
WISP Requirements by Practice Size
Every tax professional needs a WISP, but how much time and detail that takes scales with the complexity of your practice.
Solo Practitioners and Small Firms (1 to 5 Employees)
Small practices can implement WISP requirements proportionally. The owner typically serves as the security coordinator. IRS Publications 5708 and 5709 provide templates scaled for small practices, and cloud-based tax software with built-in encryption and MFA can cover several technical requirements at once.
Mid-Size and Larger Firms (6 or More Employees)
Larger practices face the full scope of the Safeguards Rule: a designated qualified individual with documented expertise, annual penetration testing and biannual vulnerability assessments once you cross the 5,000-consumer-record threshold, a formal incident response plan with assigned team roles, a vendor risk management program, and regular reporting to firm leadership on the security program's status. See our tax preparer security plan resources for more on scaling these requirements, and our privileged access management guide if you're setting up role-based access for the first time.
Book a Free Tax Cybersecurity Assessment
Get an evaluation of your current security posture against FTC Safeguards Rule and IRS WISP requirements, with concrete next steps for your practice.
Frequently Asked Questions
A WISP is a document required under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule for tax professionals handling taxpayer data. It spells out the administrative, technical, and physical safeguards a firm uses to protect personally identifiable information from unauthorized access, disclosure, or loss.
Any tax preparer, accounting firm, or financial service provider handling taxpayer data is treated as a financial institution under federal law and must maintain a WISP. This applies to solo practitioners, CPA firms, and multi-office practices once they file 11 or more returns a year, regardless of firm size.
The FTC can pursue civil penalties for Safeguards Rule violations, currently up to roughly $46,517 per violation per day and adjusted annually for inflation. The IRS can also take action against a preparer's PTIN or e-file privileges for security failures, and unaddressed gaps can complicate your standing with a professional liability insurer. IBM's 2025 Cost of a Data Breach Report put the average breach cost at $4.88 million, which puts the potential downside in perspective.
Review and update your WISP at least once a year, and any time you have a significant change to systems, staff, or vendors. The FTC Safeguards Rule also expects annual risk assessments and ongoing monitoring of how well the security program is actually working.
Yes. The IRS provides templates through Publications 5708 and 5709, and they're a legitimate starting point. But a generic, unmodified template that doesn't reflect your actual systems and procedures won't hold up to scrutiny. Firms that would rather not build and maintain it themselves can use a paid service that documents their specific practice instead.
Follow the notification timeline in your WISP: contact the IRS Stakeholder Liaison within roughly 24 hours, notify the FTC within 30 days if 500 or more individuals are affected, comply with your state's breach notification law (typically 30 to 60 days), and notify affected taxpayers as required.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



