For tax preparers, CPAs, EAs and bookkeepers
Your Written Information Security Plan, scored, documented and kept current.
WISP readiness check
Sample result5of 9 elements in place
Scored against the elements the regulations enumerate.
Written plan on file16 CFR 314.3
In placeData Security Coordinator named16 CFR 314.4(a)
In placeDocumented risk assessment16 CFR 314.4(b)
GapTraining log with dates16 CFR 314.4(e)
GapFind your gaps in nine questions, then let the plan stay current as your firm changes.
Why this matters
The obligation is ongoing, and a static template does not meet it.
The plan has to be current, implemented and reviewed over time. Having a file is not the same as meeting the requirement.
A template stops describing your firm the moment any of this changes:
- Staff join or leave
- A device is replaced
- A vendor is added
- Software changes
- Controls shift
- Requirements are updated
The obligation sits under the FTC Safeguards Rule and IRS Publications 4557 and 5708. What the rules actually require
Template versus program
The difference is what happens after you download it.
| A static template | ProtPTX | |
|---|---|---|
| Written plan produced | Yes | Yes |
| Describes your actual devices, staff and software | Generic | Built from your intake |
| Names your Data Security Coordinator | Blank to fill in | Documented |
| Risk assessment for your firm | You write it | Completed with you |
| Updated when staff or vendors change | No | Prompted monthly |
| Regulatory change monitoring | No | Included |
| Annual review scheduled | You remember it | Scheduled and reminded |
| Training records organised | No | Tracked |
| Dated compliance activity log | No | Maintained |
| Device charges | — | Unlimited devices, no per-device charges |
Two parts
A custom build, then ongoing checks.
A plan built from your intake
Your actual devices, staff, software and vendors. Ten minutes of questions, all ten parts a plan is expected to have. What it includes
Checks that keep it true
Monthly vendor and change review, training records, the scheduled annual review, and a dated log of every one. What arrives monthly
A record you can show
Twelve dated entries a year, ready before you answer line 11 on Form W-12.
Who it is for
Tax preparers, CPAs, EAs and bookkeepers
The obligation is similar across these firms. The gaps are not, because the systems and the staffing are different.
Tax preparers
You attest at PTIN renewal that you maintain a WISP. This is what stands behind it.
Read more →Bookkeepers
No PTIN, and still handling data that brings obligations with it.
Read more →CPA and EA firms
More systems and more turnover means the plan drifts faster than anyone expects.
Read more →MSPs and partners
Run it for your own practice and cut your bill with every client you refer.
Read more →Pricing
Flat rate, per firm.
Unlimited devices. No per-user or per-device charges. Three bands by firm size.
From
$39/month
plus $199 setup
Refer a firm, take 20% off for as long as they stay. Five and yours is free.
No cash changes hands and there is nothing to invoice. Every firm that signs up with your code takes 20% off your own subscription, at every renewal, for as long as that firm stays with us. It stacks to free at 5. On the Firm plan one referral is $188 off a year, every year they stay.
per active referral
subscription stays free
no payout to chase
Not ready yet
We will check in before renewal season.
Leave an email and we will send the readiness check, a reminder before the October to December PTIN renewal window, and one follow-up in January. Nothing else.
No client data. Unsubscribe any time. Handled by send.php on your own server.
Start with the free readiness check
Nine questions drawn from the FTC Safeguards Rule and IRS Publications 4557 and 5708. You get a readiness outcome and a gap list on screen, then download the report or have it sent to you.