5 min read
How to Write a WISP for Your Tax or CPA Firm, Using IRS Publications 5708 and 4557
The short answer
Every paid tax preparer needs a written information security plan (WISP). The FTC Safeguards Rule requires one, and the PTIN application asks you to confirm you know that. Start from the free IRS template in Publication 5708, use Publication 4557 for the safeguards to describe, and keep it to what your firm really does, reviewed once a year.

In August 2026 the IRS and its Security Summit partners reminded tax professionals that they need a written information security plan. Plenty of firms have something on file: a template from a few years ago, a plan written for a different office, or a folder somebody meant to finish. What counts is a plan that describes your firm as it works today, and you can write that yourself with two free IRS publications.
Every paid preparer needs one, whatever the firm’s size
The FTC counts tax preparers as financial institutions under the Gramm-Leach-Bliley Act, so its Safeguards Rule applies. The rule asks for a written information security program, with ten parts it has to cover. The IRS calls the same document a WISP, so a single plan can answer to both.
The IRS also asks about it directly. Line 11 of Form W-12, the PTIN application and renewal, is headed “Data Security Responsibilities”. It asks you to confirm you’re aware that paid preparers are required by law to create and keep a written information security plan.
Firms that hold information on fewer than 5,000 consumers can skip four parts of the FTC rule, but the written plan, the person in charge of it, multi-factor authentication (MFA) and encryption all still apply. Our plain-English guide to the FTC Safeguards Rule covers the rule part by part.
What the IRS template in Publication 5708 gives you
Publication 5708, “Creating a Written Information Security Plan for your Tax & Accounting Practice”, was written by the Security Summit with smaller practices in mind. It includes:
- A short explanation of the requirements and how to get started
- An outline of what a WISP covers
- A sample plan with placeholders for your firm’s details
- Extra detail on each section, such as listing risks and documenting the safeguards you have
- Sample attachments: record retention, rules of behavior for staff, steps to follow after a security breach, a hardware inventory, and a list of the people allowed to see client data
- A glossary of the terms it uses
Its companion, Publication 5709, is a short summary of how to create a plan. It suggests keeping the finished WISP in a format anyone can open, such as PDF or Word, and storing a copy off site or in the cloud in case something happens to the office.
Publication 4557 tells you which safeguards to describe
The template gives you the shape. Publication 4557, “Safeguarding Taxpayer Data”, fills in what you should be protecting and how. It covers security software, passwords and MFA, Wi-Fi, stored client data, spotting data theft, phishing, and what to do after a data loss. For remote access, it treats MFA and a VPN as the minimum.
The IRS’s Taxes-Security-Together Checklist boils the technical side down to what it calls the “Security Six”:
- Anti-virus software
- A firewall
- MFA wherever it’s offered
- Backup software or services
- Drive encryption
- A virtual private network (VPN) for remote access
The same checklist points to key areas a plan should cover, such as employee management and training, information systems, and detecting and managing system failures. If you want everything the IRS publishes on data security in one place, Publication 5293 collects it.
Writing your first draft, step by step
Open the Publication 5708 template and work through it in this order. Describe what’s true today. If something is still on the to-do list, say so and give it a date, rather than writing it up as if it’s done.
- Name your Qualified Individual. The template calls this person the Data Security Coordinator. It can be a partner, the office manager or an outside provider supervised by someone at the firm.
- List the client information you hold and where it lives: the tax software, document storage, email, the client portal, paper files and backups.
- List your devices and where each one is: computers, laptops, phones, servers, and the printers and scanners that store copies.
- Describe your safeguards using Publication 4557 as the checklist: MFA, encryption, backups, security software, the firewall, Wi-Fi and remote access. For the tax software itself, see setting up Drake, Lacerte, UltraTax CS or ProSeries.
- List the vendors that handle client data, such as your tax software, portal, cloud storage, shredding company and IT provider, and how you check that they protect it. The FTC rule expects you to choose them carefully and keep an eye on them.
- Record who can see client data, and how you remove access the day someone leaves.
- Write the incident steps: who notices, who decides, who calls the IRS, the insurer and your attorney, and in what order.
- Plan staff training, and have everyone sign that they’ve read the plan. The template suggests the owners sign too, so the whole office is held to the same standard.
- Sign and date it, and write down when it will next be reviewed.
Keep it current with a yearly review
Publication 5709 describes a WISP as an evergreen document. The FTC rule expects you to adjust your program when your business or its technology changes, and the IRS template suggests reviewing it at least once a year.
In practice that means a short review whenever something changes (a new hire, new software, a new vendor, a move), plus a full read-through each fall. Our tax season IT checklist puts the WISP review alongside the other jobs worth finishing before January.
What to do if client data is stolen
The plan earns its keep on a bad day, so make the incident steps specific. The IRS says to contact your local IRS Stakeholder Liaison right away, and the August 2026 reminder adds that you can report to state tax agencies through the Federation of Tax Administrators.
If 500 or more people’s unencrypted information is taken, the FTC rule gives you 30 days from discovery to tell the FTC, and California’s own rules on telling clients apply too, so put your attorney’s number in the plan. For the first hour of a ransomware attack or a hacked mailbox, see what to do first after ransomware or a hacked email account.
How we help with yours
We help tax and CPA firms across Orange County write their WISP in plain language and look after the safeguards it describes: MFA, encryption, tested backups and monitoring around the clock. If you’re not sure where your firm stands, our 7 signs your accounting firm’s IT needs attention is a quick way to check.
To talk it through, book a free IT check-in, or read more about our IT support for accounting and CPA firms.
This guide is general information, not legal advice. For questions about your firm’s specific obligations, talk to your attorney or compliance advisor.
Sources
- IRS Publication 5708: Creating a Written Information Security Plan for Your Tax and Accounting Practice
- IRS Publication 4557: Safeguarding Taxpayer Data
- IRS Publication 5709: How to Create a Written Information Security Plan for Data Safety
- IRS Publication 5293: Data Security Resource Guide for Tax Professionals
- IRS Form W-12: PTIN Application and Renewal (line 11, Data Security Responsibilities)
- IR-2026-92: IRS, Security Summit remind tax pros they need a Written Information Security Plan to protect client data
- IRS: Tax Security 2.0, the Taxes-Security-Together Checklist
- eCFR: 16 CFR 314.4, Elements of an information security program
- FTC: FTC Safeguards Rule, What Your Business Needs to Know

