Skip to content
Bellator Cyber Guard
Tax52 min readDeep Dive

IRS Publication 4557 & WISP Requirements Explained

IRS Publication 4557 requires tax preparers with 11+ returns to maintain a compliant WISP. Learn the required elements, FTC penalties, and 2026 compliance steps.

By Bellator Cyber Guard Security Team
IRS Publication 4557 & WISP Requirements Explained - irs publication 4557 safeguarding taxpayer data wisp requirements

What IRS Publication 4557 Actually Requires from Tax Professionals

IRS Publication 4557Safeguarding Taxpayer Data, is the IRS's definitive guidance on data security obligations for every tax preparer in the United States. If you prepare federal tax returns professionally, understanding the IRS Publication 4557 safeguarding taxpayer data WISP requirements is not optional. It is your legal duty under the Gramm-Leach-Bliley Act (GLBA) and the Federal Trade Commission (FTC) Safeguards Rule to protect the sensitive financial data you handle every day.

At its core, Publication 4557 requires every tax professional or firm, regardless of size, to implement a formal, written data security program called a Written Information Security Plan (WISP). If you handle 11 or more federal returns annually, the FTC Safeguards Rule mandates you have one in place. The IRS reinforces this obligation through Publication 4557 and IRS Publication 5708, which provides a sample WISP template tailored to tax preparers. For Bellator's full breakdown of meeting these standards, see our Publication 4557 compliance resources.

This guide breaks down exactly what Publication 4557 covers, what your WISP must include, and practical steps to achieve and maintain compliance in 2026. For a broader view of security obligations specific to your profession, see our guide on cybersecurity requirements for tax professionals.

IRS WISP Compliance: Key Numbers

$50,120
FTC Penalty Per Violation Per Day

Maximum civil penalty for Safeguards Rule non-compliance, assessed per violation, per day

11+
Returns Triggers WISP Requirement

Tax preparers filing 11 or more federal returns annually must maintain a written, compliant WISP

24-48 hrs
IRS Data Theft Reporting Window

Time window to report confirmed taxpayer data theft to your IRS Stakeholder Liaison after discovery

The Legal Foundation: GLBA, the FTC Safeguards Rule, and IRS Guidance

Tax preparers operate at the intersection of three overlapping regulatory frameworks, all of which converge on the same core requirement: protect taxpayer data with a documented security program.

Gramm-Leach-Bliley Act (GLBA)

The GLBA classifies tax preparers as "financial institutions" because they receive nonpublic personal financial information. This classification makes you subject to the FTC's implementing regulations, specifically the Safeguards Rule under 16 CFR Part 314, which was significantly updated in 2023.

FTC Safeguards Rule (Updated 2023)

The revised Safeguards Rule requires covered financial institutions, including tax preparers filing 11 or more returns, to maintain a written information security program that includes:

  • A designated qualified individual responsible for the program
  • A written risk assessment identifying reasonably foreseeable threats
  • Safeguards addressing identified risks, including encryption, access controls, and multi-factor authentication (MFA)
  • Annual testing or monitoring of those safeguards
  • Oversight of service providers who handle taxpayer data
  • An incident response plan
  • Annual reporting to the board or governing body

IRS Publication 4557

Publication 4557 translates these regulatory requirements into actionable IRS guidance. It maps directly to the FTC Safeguards Rule while adding IRS-specific expectations around reporting data theft, responding to identity theft on filed returns, and securing e-file credentials including your Electronic Filing Identification Number (EFIN) and Preparer Tax Identification Number (PTIN). The IRS updates this publication periodically; the current version reinforces that a WISP is mandatory for any practicing tax professional.

Non-compliance carries real consequences. The FTC can impose civil penalties up to $50,120 per violation per day. State attorneys general can also bring independent enforcement actions. Beyond regulatory penalties, a breach of taxpayer data exposes your firm to civil liability and reputational damage that few small practices can survive. Review our page on tax safeguard compliance solutions for additional enforcement context.

Is Your WISP Current Under the 2023 Safeguards Rule?

If your WISP was drafted before the 2023 FTC Safeguards Rule amendments, it may not satisfy current encryption, MFA, or incident response requirements, even if it was once compliant. A stale WISP can expose your firm to the same penalties as having no WISP at all. Review and update it before your next filing season opens.

What Must Be in Your WISP: The Required Elements

The FTC Safeguards Rule and IRS Publication 4557 together define the minimum elements your WISP must address. These IRS Publication 4557 safeguarding taxpayer data WISP requirements apply to every covered preparer, regardless of firm size. A compliant WISP is not a one-page acknowledgment; it is a living document that describes your actual security environment and how you manage risk within it.

1. Designated Qualified Individual

You must name a specific person, whether internal or an external service provider, responsible for overseeing, implementing, and enforcing the security program. For sole practitioners, this is typically the preparer themselves. For larger firms, it may be an office manager, IT director, or a managed security services partner.

2. Risk Assessment

Before you can protect data, you need to know what threats it faces. Your WISP must document a formal risk assessment that identifies where taxpayer data lives (workstations, servers, cloud storage, email), who can access it, and what realistic threats exist including phishing, ransomware, insider misuse, and physical theft. For guidance on assessing cloud exposure specifically, see our article on the security of tax client portals.

3. Safeguards Proportionate to Risk

Based on the risk assessment, your WISP must specify the controls you use to mitigate each identified threat. The FTC Safeguards Rule prescribes several controls explicitly:

  • Encryption of taxpayer data in transit and at rest
  • Multi-factor authentication (MFA) for any system accessing taxpayer data, or a documented equivalent compensating control
  • Access controls limiting data access to those who need it
  • Secure disposal of data and devices no longer needed
  • Patch management keeping systems current against known vulnerabilities
  • Anti-malware protection on all endpoints handling taxpayer data

4. Testing and Monitoring

Safeguards must be tested. For firms with fewer than 5,000 customer records, annual penetration testing is not mandated, but vulnerability assessments are. Larger firms must conduct annual penetration testing and bi-annual vulnerability scans. All firms must monitor systems for unauthorized access or anomalous activity.

5. Service Provider Oversight

If you use cloud tax software, hosted servers, or any vendor who accesses taxpayer data, your WISP must identify those providers and document how you verify their security practices. This is typically accomplished through written contracts requiring service providers to implement appropriate safeguards.

6. Incident Response Plan

Your WISP must include a written incident response plan describing how your firm will detect, contain, assess, notify, and recover from a security event. The IRS requires you to report data theft to the IRS Stakeholder Liaison within 24-48 hours of discovery. Our guide on incident response planning for tax practices provides a step-by-step framework you can incorporate directly into your WISP.

How to Build a Compliant WISP for Your Tax Practice

1

Inventory Your Data Environment

Document every location where taxpayer data lives: local workstations, external drives, cloud tax software, email servers, client portals, and paper files. Include data in transit, such as email attachments and file transfers.

2

Conduct a Written Risk Assessment

Identify realistic threats to each data location, including phishing, ransomware, insider misuse, and physical theft. Document the probability and potential impact of each threat against your specific environment.

3

Name a Qualified Individual

Formally designate a specific person, whether an internal staff member or an external security partner, to own, implement, and enforce the security program. Document this person's responsibilities in the WISP.

4

Define Proportionate Safeguards

Select controls that address your identified risks: encryption, MFA, access controls, anti-malware, patch management, and secure disposal. Match control complexity to your firm's actual size and risk profile.

5

Write Your Incident Response Plan

Document who to contact, in what order, within what timeframes, and what evidence to preserve after a security event. Include IRS Stakeholder Liaison reporting procedures and client notification protocols.

6

Train Staff and Document Completion

Conduct security awareness training annually for all staff with access to taxpayer data. Export completion records and store them with your WISP as supporting documentation.

7

Review and Update at Least Annually

Tie your WISP review to your annual board reporting cycle. Also update after any material change: new software, new staff, new service providers, a new office location, or a security incident.

Building a WISP That Passes Scrutiny: Practical Guidance

Many tax preparers have a WISP on file that was written once, filed away, and never updated. That approach may satisfy the letter of the requirement at the moment of creation, but it fails almost immediately because your technology, staff, and threat environment all change. Regulators and auditors look for evidence that your WISP reflects your current operations, not a snapshot from three filing seasons ago.

Start With IRS Publication 5708

The IRS published IRS Publication 5708, which includes a sample WISP template tailored specifically for tax professionals. It is the most practical starting point available and is structured to satisfy both FTC Safeguards Rule requirements and IRS-specific expectations. Use it as a framework, not a finished product. Your WISP must reflect your actual environment, not a generic template. You can also download our free WISP template for 2026 to get started quickly, or explore the all-in-one compliance package for a fully guided approach.

Match Controls to Actual Risk

A two-person firm operating on a single network with three workstations faces different risks than a 20-person regional CPA firm with remote staff. Your controls and your WISP should reflect that reality. Overengineered controls that staff do not follow are worse than simpler controls that are actually implemented. For detailed implementation guidance, review our WISP implementation guide for small tax firms.

Address Phishing Explicitly

Phishing is consistently the leading initial access vector in tax sector breaches, and the IRS issues annual warnings about targeted campaigns against preparers. Your WISP should describe your email security controls, employee training schedule, and procedures for verifying suspicious client communications. Our analysis of phishing attacks and how to recognize them covers current threat patterns worth including in your risk assessment.

Do Not Overlook Physical Security

Publication 4557 covers physical as well as digital safeguards. Unlocked file cabinets containing client folders, unattended workstations, and unsecured printers storing tax returns in memory are all within scope. Your WISP should address office access controls and paper document handling procedures alongside your digital controls.

Ransomware is a particular concern for tax practices during filing season, when attackers know you cannot afford downtime. Our guide on ransomware prevention and recovery covers strategies aligned with Publication 4557 requirements.

WISP Compliance Checklist for Tax Preparers

  • Designate a named qualified individual responsible for the security program
  • Complete and document a written risk assessment covering all systems that store or process taxpayer data
  • Enable MFA on all systems and accounts that access taxpayer data
  • Encrypt taxpayer data in transit (TLS 1.2 or higher) and at rest (AES-256)
  • Document all service provider agreements requiring data security safeguards from vendors
  • Maintain a written incident response plan with IRS Stakeholder Liaison reporting procedures
  • Complete and document annual security awareness training for all staff with data access
  • Conduct annual vulnerability assessments (or penetration testing if you hold 5,000 or more customer records)
  • Address physical security controls, including office access procedures and paper document handling
  • Review and update your WISP at least annually and after any material change to your environment

IRS Publication 4557 and the Broader Compliance Picture

Publication 4557 does not exist in isolation. Tax professionals increasingly face overlapping obligations from state-level data security laws, professional licensing bodies, and cyber insurance underwriters, all of which align with or exceed IRS and FTC requirements. Understanding how these frameworks interact lets you build a security program that satisfies all of them at once, rather than patching gaps after the fact.

State-Level Requirements

At least 11 states have enacted their own data security laws for tax preparers or financial service providers, with requirements that may exceed the federal baseline. Massachusetts (201 CMR 17.00), New York (SHIELD Act and 23 NYCRR 500), and California (CCPA/CPRA) are among the most demanding. Your WISP should be reviewed against any state requirements applicable to your practice location and your clients' states of residence.

FTC Safeguards Rule vs. IRS Publication 4557

These two frameworks are complementary, not duplicative. The FTC Safeguards Rule is the enforceable regulation with civil penalty authority. IRS Publication 4557 is the IRS's interpretive guidance that applies the Safeguards Rule to the specific context of tax preparation and adds IRS-specific reporting requirements around data theft and identity theft on filed returns. Compliance with Publication 4557 generally satisfies the FTC Safeguards Rule for tax preparers, but verify compliance with both frameworks independently. For a detailed breakdown of how these rules differ, see our dedicated guide on the FTC Safeguards Rule for tax preparers.

For firms that also handle payroll, benefits administration, or financial planning, additional framework obligations specific to those services may apply. Firms exploring a zero trust security architecture will find that approach well-aligned with Publication 4557's access control and least-privilege requirements.

Cyber Insurance Requirements

Insurers writing cyber coverage for tax practices increasingly require documented WISP existence as a condition of coverage, and some require evidence of specific controls, including MFA, Endpoint Detection and Response (EDR), and encrypted backups, before binding a policy. A well-maintained WISP is not just a compliance document; it directly affects your insurability and premium. For more on endpoint protection requirements and their relationship to cyber insurability, see our guide on EDR vs. MDR vs. XDR for small businesses.

Bottom Line

A WISP is not a document you file once and forget. The IRS Publication 4557 safeguarding taxpayer data WISP requirements demand a living security program that reflects your current technology, staff, and risk environment. Regulators look for evidence that your plan is both accurate and actively maintained, not just that a document exists somewhere in a filing cabinet.

Common WISP Failures and How to Avoid Them

Having a WISP is necessary. Having a compliant, current WISP is what actually matters. The following are the most frequently observed failures in tax preparer security programs, along with practical ways to address each one.

Using a Generic Template Without Customization

The IRS sample WISP in Publication 5708 is a starting point, not a finished document. A WISP that lists security controls your firm does not actually use, or omits controls you do use, is both inaccurate and potentially misleading to regulators. Every section should reflect your real environment. Our WISP template for tax preparers includes customization guidance for every required section.

Not Updating After Material Changes

Adding a new staff member, switching tax software, or moving to cloud-based storage all change your risk profile. Each of these events should trigger a WISP review. Build a recurring calendar reminder tied to your tax season wind-down to conduct an annual full review, and use a change log section within your WISP to document each revision with the date and reason.

Missing the Incident Response Component

The incident response plan is the most commonly omitted section in small-firm WISPs. It is also the most operationally important one because in the stress of a breach, you need a documented playbook, not improvisation. At minimum, document who to call, in what order, within what timeframe, and what evidence to preserve. If you experience a breach and need to know what comes next, see our guide on what to do after a data breach.

No Documentation of Training

Training requirements without records do not count toward compliance. Maintain a log of all security awareness training completed, including dates, topics covered, and who attended. If you use an online training platform, export completion certificates and store them with your WISP as supporting documentation.

Ignoring Remote and Mobile Work

If any staff member accesses taxpayer data outside the office, whether from home, a client site, or a mobile device, your WISP must address those access points. Home networks represent a frequent entry point for attackers targeting tax practices. Our guide on remote work security for small teams covers controls that integrate directly into WISP documentation, including VPN requirements and device management policies.

Core Security Controls Required by IRS Publication 4557

Publication 4557 does not mandate specific technology products, but it prescribes security outcomes that your controls must achieve. The table below maps each required outcome to the control category and a typical implementation approach that satisfies the requirement.

Required Outcome

Control Category

Example Implementation

Prevent unauthorized access to taxpayer data

Access Controls

Role-based access, unique user accounts, least-privilege permissions

Protect data in transit

Encryption

TLS 1.2 or higher for email and web; VPN for remote access

Protect data at rest

Encryption

AES-256 disk encryption on workstations and servers

Verify user identity

Authentication

MFA via authenticator app or hardware token on all systems with taxpayer data

Detect and block malware

Endpoint Protection

EDR software with real-time behavioral detection on all endpoints

Identify vulnerabilities before attackers do

Vulnerability Management

Annual vulnerability scans; patch deployment within 30 days of vendor release

Respond to security events

Incident Response

Written IRP with IRS reporting procedures and client notification protocols

Train staff to recognize threats

Security Awareness

Annual phishing simulations and security training with documented completion records

For tax professionals looking to go beyond the Publication 4557 baseline, the NIST Cybersecurity Framework (CSF) 2.0 provides a more detailed control catalog that maps well to IRS requirements. Our guide to creating a WISP aligned with IRS requirements covers specific threat scenarios that should inform your risk assessment.

What Changed in 2023: FTC Safeguards Rule Updates That Affect Your WISP

The 2023 amendments to the FTC Safeguards Rule introduced the most significant changes to tax preparer data security requirements in over a decade. If your WISP was drafted before these amendments, it may not satisfy current requirements even if it was once compliant. These changes are the reason the IRS Publication 4557 safeguarding taxpayer data and WISP requirements now look meaningfully different from what many small firms originally documented.

Key changes that affect tax preparers include:

  • Encryption is now mandatory, previous versions allowed encryption as one option among several; the 2023 rule requires it for data in transit and at rest unless a documented exception is justified in writing
  • MFA is required by default, all systems containing taxpayer data must use MFA; any alternative requires a written compensating control justification approved by the qualified individual
  • Penetration testing timelines are now specified, firms above the 5,000-record threshold must conduct annual pen tests and bi-annual vulnerability scans
  • Board reporting is now mandatory, the qualified individual must provide a written annual report to firm leadership on the state of the security program
  • Breach notification thresholds were added, breaches affecting 500 or more customers in a single state trigger mandatory FTC notification in addition to IRS reporting

For PTIN-specific compliance obligations, review our article on PTIN and WISP requirements for tax preparers. For identity theft prevention strategies that go beyond the WISP baseline, see our resource on identity theft prevention for tax professionals.

The IRS also coordinates annual threat advisories through its Security Summit program, a joint initiative with state tax agencies and the private tax industry that publishes updated best practices for tax preparer security programs each year. Following Security Summit guidance alongside Publication 4557 gives your WISP the broadest possible regulatory and threat coverage. For answers to the most common compliance questions from tax preparers, see our tax security FAQ page.

Not Sure Where to Start With Your WISP?

Our team has helped over 4,000 tax professionals build WISP documents that satisfy IRS Publication 4557, the FTC Safeguards Rule, and state-level data security requirements.

Get a Free Tax Cybersecurity Assessment

Our experts will evaluate your current security program against IRS Publication 4557 requirements and provide actionable recommendations to close any gaps before your next filing season.

Frequently Asked Questions

IRS Publication 4557, Safeguarding Taxpayer Data, is the IRS's primary guidance document for tax professionals on data security obligations. It translates the Gramm-Leach-Bliley Act (GLBA) and FTC Safeguards Rule requirements into IRS-specific guidance, covering Written Information Security Plans (WISPs), data theft incident reporting, EFIN and PTIN security, and procedures for handling identity theft on filed returns.

Any tax preparer or firm that files 11 or more federal tax returns annually is required to maintain a Written Information Security Plan under the FTC Safeguards Rule, which the IRS reinforces through Publication 4557. This applies to sole proprietors, partnerships, S-corporations, and multi-partner CPA firms alike. There is no small-firm exemption based on revenue or employee headcount.

Operating without a WISP exposes your firm to FTC civil penalties up to $50,120 per violation per day under the Safeguards Rule. State attorneys general can bring independent enforcement actions under state data security laws. Beyond regulatory penalties, a taxpayer data breach without a documented security program can result in civil liability, reputational damage, and potential PTIN or EFIN suspension. Cyber insurers may also deny claims if no WISP was in place at the time of a covered incident.

There is no minimum or maximum length requirement. A compliant WISP must address all required elements: a designated qualified individual, a written risk assessment, defined safeguards, testing and monitoring procedures, service provider oversight, an incident response plan, and a provision for annual reporting. For most small tax practices, a thorough WISP runs 15-30 pages once all required elements are documented with practice-specific details. Accuracy and completeness matter more than length.

IRS Publication 4557 explains your legal requirements and what you must do to protect taxpayer data. IRS Publication 5708 provides a sample WISP template that tax preparers can use as a starting framework. They work together: read Publication 4557 to understand your obligations, then use Publication 5708 as a template to document how you fulfill them. Your final WISP must reflect your actual environment, not simply replicate the Publication 5708 template without customization.

The FTC Safeguards Rule requires your qualified individual to report to firm leadership at least annually on the state of the security program, and your WISP should be reviewed and updated as part of that cycle. You must also update your WISP after any material change to your environment, including new staff, new software, new service providers, a new office location, or a security incident. Tying your update to the post-filing-season wind-down each spring is a practical scheduling approach.

Yes. The FTC Safeguards Rule and IRS Publication 4557 apply to all tax preparers filing 11 or more federal returns annually, including sole proprietors. As a sole practitioner, you are both the qualified individual and the security program owner. The controls required scale with firm size and risk profile, so a one-person practice will have a simpler WISP than a 20-person firm, but the WISP itself is still required under the law.

The 2023 FTC Safeguards Rule explicitly requires tax preparers to implement: encryption of taxpayer data in transit and at rest; multi-factor authentication (MFA) on all systems with taxpayer data; access controls based on least privilege; a written incident response plan; annual security awareness training; vulnerability assessments (and penetration testing for firms with 5,000 or more records); secure disposal of data and devices; and written oversight of service providers. These are the requirements your WISP must document and demonstrate in practice.

A template is a valid starting point, but it cannot be used as-is to achieve compliance. The IRS's own sample in Publication 5708 is the recommended starting framework. Any template, including our free 2026 WISP template, must be customized to reflect your actual technology environment, staff roles, service providers, and risk profile before it qualifies as a compliant WISP under IRS Publication 4557 and the FTC Safeguards Rule.

Report confirmed or suspected taxpayer data theft to your IRS Stakeholder Liaison within 24-48 hours of discovery. You will also need to contact your state tax agency and notify affected clients according to your state's breach notification law. Preserve all system logs and evidence before making any changes to affected systems. Your incident response plan, which must be part of your WISP under IRS Publication 4557, should document these steps so your team can act without improvising under pressure. For a full walkthrough, see our guide on what to do after a data breach.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.