PTIN renewal season is here. Make sure your WISP documentation is current before you complete your renewal attestation.

Check your readiness
Home FAQ

FAQ

Questions, answered plainly

Where a question has a legal answer we give the citation. Where it does not, we say so.

Do I really need a WISP if I am a one-person practice?

Firm size does not change whether the requirement applies. If you prepare tax returns for compensation, you are a financial institution for the purposes of the FTC Safeguards Rule, and the Rule requires a written information security program. Form W-12 asks you to acknowledge that when you apply for or renew your PTIN.

Size does change which specific provisions you must satisfy. Under 16 CFR 314.6, a firm maintaining information on fewer than 5,000 consumers is exempt from four requirements: the written risk assessment at 314.4(b)(1), the testing requirement at 314.4(d)(2), the written incident response plan at 314.4(h), and the annual written report at 314.4(i). Everything else still applies. In Massachusetts, 201 CMR 17.00 has no size threshold of any kind.

Is ProtPTX a law firm?

No. ProtPTX is a compliance documentation and workflow service. We do not provide legal advice, we do not guarantee legal compliance, we do not prevent breaches, and we do not act as your professional of record. Your firm remains responsible for its own program and for every attestation it signs.

What we do is structure the published requirements, assemble your documentation from your own answers with each clause cited, and keep the required actions on a calendar. Bringing your attorney into the file is a feature, not a workaround.

How is this different from downloading the IRS template?

The IRS template in Publication 5708 is genuinely good, and we build to its structure. The difference is what happens after you fill it in.

A template is a snapshot. Your program has to be true on the day someone asks about it, not on the day you wrote it. ProtPTX keeps it current through a monthly change review, produces the annual review as a document, logs training completions, maintains the vendor register, and leaves a dated record behind all of it. That record is the part a template cannot give you.

What if I already have a WISP?

Bring it. The intake will surface where it has drifted from how the firm actually works now, and the quiz will tell you which elements it does not address. Many existing plans are structurally fine and simply out of date, in which case the work is smaller than you expect.

Does ProtPTX store my clients' data?

No. The program file describes where client information lives, who can reach it, and how it is protected. It does not contain the information itself. We do not want your clients' returns and we have no reason to hold them.

See our own security program for how we handle the firm-level information you do give us.

Can my IT provider or attorney use it too?

Yes, and it is free. ProtPTX is priced per firm, so advisor seats do not change your bill. Each advisor sees the section they were invited to, their answers are attributed and dated, and access can be revoked in one click. See advisor access.

What happens to my documents if I cancel?

You export everything, in Word and PDF, and it remains yours. Nothing is held back. The one real consequence is that the dated record stops on the day you stop, and months cannot be bought back later. That is a property of a calendar, not a lock we put on your files.

Do you cover states other than Massachusetts?

The federal requirements in the Safeguards Rule and the IRS publications apply nationally, and they are the base every program is built on. Massachusetts is mapped in full because 201 CMR 17.00 is unusually specific and has no size threshold. Other state overlays are being added. Ask us which are live today rather than assuming from this page.

Is an AI assistant really a vendor I have to document?

If it receives client information, then yes, on the plain text of rules you are already subject to. 16 CFR 314.4(f) requires you to select service providers capable of maintaining appropriate safeguards and to require those safeguards by contract. 201 CMR 17.03(2)(f) says the same. Whether a given tool is in scope depends on what your staff actually put into it, which is why the intake asks.

How long does the intake take?

Roughly twenty minutes for a solo practice if you have your software list handy. Longer for a firm with multiple locations, remote staff, or an outsourced team. You can stop and come back. Most firms need one short follow-up with their IT provider to answer three or four technical questions, which is what advisor access is for.

What penalties am I actually exposed to?

We will not give you a number for your firm, because it depends on the statute invoked, the conduct, and the enforcing authority. The one figure we cite is the FTC's most recently published maximum civil penalty for violations of Section 5(m)(1)(A) of the FTC Act, $53,088 per violation in the agency's 2025 inflation adjustment.

We deliberately do not repeat the per-day figures and breach cost averages common in this market, because we could not trace them to a primary source. Ask any vendor quoting a number which document it comes from.

What does it cost?

There are three plans, banded by firm size. Each has a one-time setup fee and a flat subscription. Choose annual and the setup fee is waived.

  • Solo (1 preparer): $199 setup, $39 a month, or $412 a year with setup waived. Annual saves $255.
  • Firm (2 to 10 staff): $399 setup, $89 a month, or $940 a year with setup waived. Annual saves $527.
  • Multi-office (11+ staff or multiple locations): $799 setup, $179 a month, or $1,890 a year with setup waived. Annual saves $1,057.

Every plan is flat rate with unlimited devices and no per-device charges. Full pricing

Am I charged per device or per user?

No. Devices are unlimited on every plan and there are no per-device charges. Plans are banded by firm size, so a Solo plan covers a sole practitioner and the Firm plan covers 2 to 10 staff, but neither counts your computers, phones or tablets.

What does the setup fee actually buy?

A custom build, not an onboarding charge. It covers tailoring your Written Information Security Plan to your firm's staff, devices, software, vendors, data practices and operating environment, across all ten parts a plan is expected to have.

It starts with a structured intake questionnaire that takes under ten minutes. What your firm-specific WISP includes

Why is annual cheaper than paying monthly?

Two reasons stack. Annual plans are priced at the full twelve-month value less a 12% signup discount, and the one-time setup fee is waived. On the Firm plan that is $128 off the twelve-month list price of $1,068, plus the $399 setup, which is $527 in total.

How does the referral discount work?

There is no cash payment. Every firm that signs up using your code takes 20% off your own next renewal, stacking to free at 5 referrals. On the Firm plan one referral is $188 off, and 5 means you pay nothing that year.

If you pay monthly, the same value is pro-rated across the months left in your cycle. You need an active subscription for the discount to apply to, and your code lives in your portal. Full terms

Do I have to take the quiz before buying?

No, but it is free and it is the sensible first step. It runs in your browser, takes a few minutes, and gives you a readiness outcome and a gap list whether or not you go any further.

The paid setup begins with a fuller intake questionnaire that collects the detail needed to build the plan itself. What that covers

Know another firm that needs this? Each one that signs up with your code takes 20% off your own renewal. Five and you pay nothing.

How the discount works →

Still have a question

Ask it directly. We answer from the regulations, and we say so when the honest answer is that it depends on your facts.