Get your WISP started today
IRS Publication 4557 requires every tax preparer to have a Written Information Security Plan. We make it easy.
- Covers IRS Publication 4557, FTC Safeguards Rule & GLBA
- Includes a free Incident Response Plan
- Updated for 2026 requirements
- Used by 4,000+ tax professionals
AICPA Certified | A+ BBB Rating | No credit card required
Download Your Free WISP
What Is a Written Information Security Plan?
A Written Information Security Plan (WISP) is a comprehensive document that outlines how your tax practice protects sensitive client information from unauthorized access, use, or disclosure.
It serves as your blueprint for data security, documenting the administrative, technical, and physical safeguards you implement to protect taxpayer data.
Under the FTC Safeguards Rule and enforced through IRS regulations, every tax professional who handles non-public personal information must maintain a compliant WISP that addresses nine specific components mandated by federal law.
Why It Matters
- ✓ Demonstrates professionalism and commitment to client data protection
- ✓ Provides clear procedures for your team to follow
- ✓ Satisfies insurance requirements and protects your practice from devastating penalties
- ✓ Transforms security from an abstract concept into actionable policies
Federal WISP requirements and guidance
The FTC Safeguards Rule requires covered financial institutions to maintain a written information security program appropriate to their size, activities, and customer information. IRS Publication 4557 explains safeguards for tax professionals, while IRS Publication 5708 provides a WISP outline. Current Form W-12 instructions say Line 11 acknowledges awareness that paid preparers are required by law to create and maintain a WISP; it is not described as a certification that the IRS reviewed or approved a particular plan.
- FTC Safeguards Rule small-entity compliance guide
- IRS Publication 4557: Safeguarding Taxpayer Data
- IRS Publication 5708: Creating a Written Information Security Plan
- Current IRS Form W-12 instructions
Review date: July 22, 2026. Requirements can change; obtain legal advice for your practice and jurisdiction.
Three steps to a compliant WISP
Download the template
Get our free, professionally written WISP template — pre-filled with IRS-required sections and plain-English guidance.
Customize for your practice
Fill in your firm's details, employee count, systems, and data handling procedures. Our instructions walk you through every section.
Implement & maintain
Activate the security controls listed in your WISP. We offer managed services to handle this for you — endpoint protection, monitoring, and annual updates.
State privacy and breach rules vary
Notification deadlines, affected-person thresholds, regulator filings, and available remedies depend on the state, the data involved, and the facts of the incident. Do not rely on a nationwide “24-hour” rule. For example, California Civil Code section 1798.82, as amended effective January 1, 2026, generally calls for notice within 30 calendar days, subject to stated exceptions. Build the incident plan around prompt legal review rather than a single universal deadline.
- California Civil Code §1798.82
- Massachusetts 201 CMR 17.00
- New York SHIELD Act information
- Texas Attorney General breach-reporting guidance
Review date: July 22, 2026. This overview is not legal advice.
Common WISP Mistakes to Avoid
Using Generic Templates
A WISP must reflect YOUR actual practices, not theoretical ones. Generic templates fail audits because they don't match your operations. Customize every section to your specific technology, procedures, and client base.
Missing Annual Updates
Creating a WISP isn't one-and-done. The FTC requires annual reviews and updates. Failing to document regular reviews suggests your WISP is abandoned, not actively implemented.
No Training Documentation
Employee training is mandatory, not optional. Without documented training records, you can't prove compliance. Keep signed acknowledgments, training dates, and materials covered.
Ignoring Vendor Management
Every service provider with data access needs oversight. Failing to assess vendor security or update contracts leaves you liable for their breaches. Document all vendor reviews.
WISP Implementation Options
“I downloaded the free WISP template and had it customized for my practice in under an hour. When I was ready for full protection, Bellator handled everything — EDR, monitoring, the works.”
WISP frequently asked questions
Yes. The template is completely free to download and use. We created it because every tax professional deserves access to a compliant WISP, regardless of budget. If you want us to customize it or add managed security services, those are paid — but the template itself is always free.
Our template covers all requirements outlined in IRS Publication 4557 (Safeguarding Taxpayer Data), the FTC Safeguards Rule, and relevant sections of NIST SP 800-171. It includes sections for data classification, access controls, incident response, employee training, and physical security.
The IRS expects your WISP to be a living document — updated at least annually, and whenever you make significant changes to your technology, staff, or processes. Our professional plan includes automatic annual updates.
Absolutely. The template scales from solo practitioners to firms with 50+ employees. Larger firms may want our professional customization service to ensure every department and role is properly covered.
A WISP is your overall security policy — it describes how you protect data day-to-day. An incident response plan is a specific section within your WISP that details what to do when a breach or security event occurs. Our template includes both.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.
- Common question: WISP penalties and noncomplianceUnderstand the cost of missing safeguardsReview enforcement, professional, and operational consequences before they become urgent.
Protect your tax practice from cyber threats
Schedule a free consultation to assess your firm's security posture.
