Free WISP Readiness Check
Find your gaps before your renewal attestation does.
9 questions, drawn from the FTC Safeguards Rule and IRS Publications 4557 and 5708. You get a readiness outcome and a gap list on screen straight away, then you can download the full report or have it sent to you with recommended next steps.
This is a self-assessment, not a WISP. It will not produce a plan for you, and it is not a determination of your compliance status.
Question 1
Do you have a written Written Information Security Plan today?
The plan has to exist in writing. A verbal understanding of how the office handles data is not a plan, and PTIN renewal asks you to attest that you maintain one.
16 CFR 314.3 · IRS Pub. 5708
Question 2
Have you identified a Data Security Coordinator for your firm?
A named individual has to be responsible for the program. In small firms this role is often assumed rather than assigned, which means in practice it belongs to nobody.
16 CFR 314.4(a) · IRS Pub. 5708
Question 3
Have you completed a documented risk assessment?
Internal, external and accidental disclosure risks have to be identified and evaluated, and the assessment has to exist as a document rather than as a conversation.
16 CFR 314.4(b)
Question 4
Do you maintain a current inventory of your devices and software?
You cannot protect what you have not listed. This is the item most firms discover is out of date the moment they check it.
16 CFR 314.4(c)(2)
Question 5
Do you use multi-factor authentication on systems containing taxpayer information?
Multi-factor authentication is named specifically in the Safeguards Rule, and it applies to every person and every system that reaches taxpayer information, email included.
16 CFR 314.4(c)(5)
Question 6
Do you have an incident-response process?
What happens in the first hours, who decides, who is contacted and in what order. Publication 4557 also sets out the reporting sequence to follow after a data theft.
16 CFR 314.4(h) · IRS Pub. 4557
Question 7
Do you review vendors and service providers with access to client data?
Service providers have to be selected for their ability to maintain safeguards, and those safeguards have to be required by contract. This includes software vendors and contractors.
16 CFR 314.4(f)
Question 8
Have you conducted employee security training?
Security awareness training is an explicit requirement, and the evidence a reviewer asks for is the completion record rather than the intention.
16 CFR 314.4(e)
Question 9
Have you reviewed or updated your WISP in the past twelve months?
The plan has to be current, implemented and reviewed over time. Staff, devices, vendors, software and requirements all change, and a plan that no longer describes the firm is the problem this check is designed to surface.
IRS Pub. 5708 · 16 CFR 314.4(g)
How to read your result
A gap is not a violation
It means you could not confirm the element. Often the control exists and the evidence does not, which is usually the easier problem to fix.
Not sure is a useful answer
Most firms hit several. Each one is a question somebody in the building, or your IT provider, can already answer.
Your circumstances matter
Requirements are not identical for every firm. What applies to you depends on your size, your services and the data you hold. Treat this as a starting point.
What this is not
This is a self-assessment against published IRS and FTC guidance. It is not legal advice, an audit, a certification, or a determination that your firm does or does not comply. ProtPTX is not a law firm. Your firm remains responsible for its own program and for every attestation it signs.
Turn the gap list into a plan
The readiness check tells you what is missing. The one-time setup documents your real environment and closes the list in a stated order.