PTIN renewal season is here. Make sure your WISP documentation is current before you complete your renewal attestation.

Check your readiness
Home WISP requirements

Requirements

What a WISP actually has to contain

Every element below comes from published regulatory or IRS text, with the citation attached. Read the sources yourself. That is the point of listing them.

The short version

If you prepare tax returns for compensation, you are a financial institution for the purposes of the FTC Safeguards Rule. The Rule requires you to develop, implement, and maintain a written information security program. The IRS publishes the template structure in Publication 5708 and the practical checklist in Publication 4557. When you apply for or renew your PTIN, Form W-12 asks you to acknowledge the requirement.

“I am aware that paid tax return preparers are required by law to create and maintain a written information security plan.” IRS Form W-12, line 11, Data Security Responsibilities (Rev. October 2025)

Firm size does not change whether the requirement applies. It changes which specific provisions you must satisfy. See the small-firm exemption below.

The federal rule

FTC Safeguards Rule, 16 CFR 314.4

Nine lettered elements. This is the spine of any WISP written for a United States tax or accounting firm.

Required elements of the information security program

16 CFR 314.4(a) through (i)

314.4(a) Qualified individualDesignate a qualified individual responsible for overseeing and implementing the program. The role may sit with an employee, an affiliate, or a service provider, but responsibility for compliance stays with the firm.
314.4(b) Risk assessmentIdentify reasonably foreseeable internal and external risks to customer information, with criteria for evaluating those risks and for how they will be mitigated. Reassess periodically.
314.4(c) SafeguardsAccess controls, an inventory of data, personnel, devices and facilities, encryption of customer information in transit and at rest, secure development practices, multi-factor authentication, secure disposal, change management, and monitoring of authorized user activity.
314.4(d) Testing and monitoringRegularly test the effectiveness of your safeguards. Either continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months and after material changes.
314.4(e) PersonnelSecurity awareness training, qualified security personnel, and ongoing education so staff keep up with current threats.
314.4(f) Service providersSelect providers capable of maintaining safeguards, require those safeguards by contract, and periodically assess them based on risk.
314.4(g) Program evaluationEvaluate and adjust the program in light of testing results, operational changes, and anything else that materially affects it.
314.4(h) Written incident response planGoals, internal processes, roles and responsibilities, communications, remediation, documentation, and revision after an event.
314.4(i) ReportingThe qualified individual reports in writing, at least annually, on program status and material matters, including risk assessment, safeguard decisions, service provider arrangements, testing results, and security events.

The small-firm exemption, stated precisely

A financial institution that maintains customer information concerning fewer than 5,000 consumers is exempt from four specific requirements: the written risk assessment at 314.4(b)(1), the continuous monitoring or penetration testing and vulnerability assessment requirement at 314.4(d)(2), the written incident response plan at 314.4(h), and the annual written report at 314.4(i).

Everything else still applies. The exemption is not a pass on having a program, and the count is of consumers whose information you maintain, not of returns you filed this season.

16 CFR 314.6

Breach notification to the FTC

16 CFR 314.5

Trigger A notification event affecting at least 500 consumersUnauthorized acquisition of unencrypted customer information.
Deadline As soon as possible, and no later than 30 days after discoveryFiled electronically with the FTC.
Contents Firm name and contact, types of information involved, dates, number of consumers affected, a description of the eventPlus any law enforcement determination that public disclosure should be delayed.

The IRS structure

Publication 5708: the seven-section framework

The IRS publishes a template for exactly this document. Its structure is what an examiner will recognize, which is why ProtPTX generates to it.

Sections of the plan

IRS Publication 5708, Creating a Written Information Security Plan for your Tax and Accounting Practice

1ObjectiveThe compliance statement, citing the Gramm-Leach-Bliley Act and the FTC requirement.
2PurposeHow client data protection is actually carried out in your firm.
3ScopeWhat the plan covers and where its boundaries are.
4Responsible officialsNamed individuals and their duties.
5Inside the firm, risk mitigationData collection and retention, personnel accountability, disclosure of personally identifiable information, reportable events.
6Outside the firm, risk mitigationNetwork protection, user access, electronic exchange, wireless, remote access, connected devices, security training.
7ImplementationFormal adoption, with signatures and dates.

Data Security Coordinator

Named in the plan. Oversees daily security operations, monitors compliance, runs training, manages third-party vendor safeguards, and reviews the plan annually.

IRS Pub. 5708

Public Information Officer

The single voice for external communication during an incident, handling client notification and contact with law enforcement.

IRS Pub. 5708

Publication 5708 also supplies sample attachments: record retention policy, rules of conduct for handling personally identifiable information, breach procedures, employee acknowledgment forms, hardware inventory, and the authorized user access list. ProtPTX generates each of these populated with your firm's answers rather than left blank.

The IRS checklist

Publication 4557: what the plan has to be true about

Publication 4557 is the operational companion. It groups safeguards into three areas and tells you what to do after a theft.

Employee management and training

Background checks, confidentiality agreements, access limited to job need, strong passwords, multi-factor authentication, password-activated screen savers, mobile device policy, security training and reminders, telecommuting policy, and a stated disciplinary measure for violations.

Information systems

Secure storage with both physical and digital protection, encryption of sensitive data in transit, secure disposal of records and electronic media, and a maintained equipment inventory.

Detecting and managing failures

Monitoring vendor advisories, keeping security software and firewalls current, intrusion detection, audit logs that would reveal unauthorized access, and a breach response procedure.

If client data is stolen

Publication 4557 directs practitioners to report data losses or thefts immediately, and to contact the IRS Stakeholder Liaison, the FBI if the IRS directs it, local police, relevant state tax agencies, and your security and insurance providers. This is a sequence you want written down in advance, with the phone numbers already in the file.

IRS Pub. 4557

Consequences

What we will and will not claim about penalties

Fear numbers circulate freely in this market and most of them cannot be traced to a source. Here is the one figure we will stand behind, and the reason we leave the rest alone.

What is verifiable

The FTC's most recently published maximum civil penalty for violations of Section 5(m)(1)(A) of the FTC Act is $53,088 per violation, set in the agency's 2025 inflation adjustment.

FTC, Inflation-Adjusted Civil Penalty Amounts for 2025, published February 2025.

What we do not repeat

Per-day penalty figures widely quoted in WISP marketing, along with breach cost averages attributed to no primary source. We could not verify them, so they do not appear on this site.

If a vendor quotes you a number, ask which document it comes from. It is a fair question and the answer tells you something.

Penalty exposure depends on the statute invoked, the conduct, and the enforcing authority. Nothing here is a prediction about your firm. Ask your attorney.

State law sits on top of all of this

Federal requirements are the floor. If you hold information about residents of certain states, additional duties apply, and they are not satisfied by a plan written only to the federal rule. Massachusetts is the clearest example, and it has no firm-size threshold at all.

Find out which of these you can actually evidence

Knowing the rule and being able to prove you follow it are different things. The assessment asks about the second one.