Guides & Resources  ›  Tax & Accounting Compliance

The WISP Rule: What Every Texas Tax Preparer Must Have Before PTIN Renewal

Other Guys ITUpdated July 20269 min read

If you prepare tax returns for a living, the IRS already assumes you have a written data security plan. On your next PTIN renewal, you sign a form that says so — whether or not the plan is real.

Most preparers first hear the word “WISP” the week renewal opens, download a template, save it, and check the box. That satisfies the paperwork. It does not satisfy the rule — and the gap between the two is exactly where an examiner, a breach, or a false-attestation problem lives.

Here’s what a WISP actually is, why it’s mandatory, what you’re attesting to on Form W-12, the nine elements a compliant plan has to contain, and the honest distance between downloading the IRS template and running the controls it describes.

What a WISP is — and why it isn’t optional

A WISP is a Written Information Security Plan: a documented description of how your firm protects taxpayer data, who’s responsible, and what happens when something goes wrong. Two separate authorities make it mandatory, and they reinforce each other.

First, the FTC Safeguards Rule — the Standards for Safeguarding Customer Information, 16 CFR Part 314, issued under the Gramm-Leach-Bliley Act (GLBA). The rule classifies tax preparers and accounting firms as “financial institutions,” which surprises most people the first time they read it. The updated Safeguards Rule became fully effective June 9, 2023, and it requires a written security program with specific, named elements. Enforcement carries civil penalties reaching roughly $100,000 per violation, with potential personal liability for the responsible individuals.

Second, the IRS. Publication 4557 (Safeguarding Taxpayer Data) tells preparers they are required to have a written data security plan, and Publication 5708 gives them a fill-in-the-blank WISP template to build one. The IRS didn’t invent a second standard — it pointed the whole preparer community at the FTC’s.

A WISP isn’t a best practice you get to when you find the time. It’s a federal requirement with two enforcers behind it.

The Form W-12 attestation — the part people miss

Every PTIN holder renews annually on IRS Form W-12. Renewal now includes a data-security responsibility item: by renewing, you confirm you’re aware of your obligations under the FTC Safeguards Rule and that you have a data security plan in place.

Read that carefully, because it’s the sentence that trips firms up. You are not attesting that you downloaded a template. You are attesting that a plan is in place — that the controls it describes are real and running. Checking the box with a PDF named “WISP” sitting unread in a folder is a false attestation on a federal form. That’s a different category of problem than being behind on your security work. It’s signing your name to something that isn’t true.

The practical test: if the IRS or the FTC asked you to show the plan working — MFA enforced, backups tested, access logs, training records — could you produce it? If the answer is “we have the document but not the evidence,” the attestation is exposed.

The nine elements a compliant WISP must contain

Between IRS Pub 4557 and the FTC Safeguards Rule, a compliant plan has to cover nine things. Miss one and the plan is incomplete on its face — before anyone even checks whether the controls are live.

ElementWhat it actually requires
1. Designated security leadA named, accountable person — the Safeguards Rule’s “Qualified Individual” — who owns the program. It can be an owner or an outside provider, but it has to be a specific person, not “the office.”
2. Risk assessmentA written inventory of where client data lives (email, tax software, cloud, laptops, paper) and how it could be exposed. This is the foundation the rest of the plan is built on.
3. Access controlsLeast-privilege access: each person can reach only the data their job requires, and access is removed the day someone leaves.
4. EncryptionTaxpayer data protected both at rest (drives, backups) and in transit (email, file transfer, remote sessions).
5. Multi-factor authenticationMFA on email, remote access, and every system that touches taxpayer data — explicitly named in the updated Safeguards Rule.
6. Vendor oversightDocumented diligence that your software, cloud, and service providers protect data too — their security is part of yours.
7. Incident response planA written, tested procedure for a suspected breach, including the IRS Stakeholder Liaison and state notification steps.
8. Employee trainingDocumented security-awareness training for everyone who handles client data — with records that it happened.
9. Annual reviewThe plan reviewed and updated at least yearly, and after any material change to systems, staff, or vendors.

Notice how many of those are technical (encryption, MFA, access controls, EDR-backed monitoring, tested backups) and how many are organizational (the named lead, the training records, the annual sign-off). A real WISP needs both halves. Which is where most firms hit the wall.

Downloading Pub 5708 is the easy 10%

The IRS template is genuinely useful, and it’s free. You open Pub 5708, fill in your firm’s name, tick the sections, and you have a document. For a lot of firms, that’s where the project ends.

The problem is that the template is a description of controls, and the rule requires the controls. You can type “we enforce multi-factor authentication” into the template in thirty seconds. Actually turning MFA on across every mailbox, every remote session, and every application that touches a return — then proving it stayed on — is the real work. The sentence takes a minute. The system takes a project.

That distance is the whole point of this article. Here’s the same idea as a checklist: what the template lets you write, versus what it takes to make each line true.

What the template saysWhat running it actually takes
“We enforce MFA.”MFA enforced across Microsoft/Google, remote access, and tax software; legacy sign-in blocked; a documented break-glass account so you don’t lock yourself out.
“Data is encrypted.”Full-disk encryption confirmed on every laptop and workstation, TLS on mail, and backups encrypted — then verified, not assumed.
“Access is limited to those who need it.”Per-user permissions mapped to roles, admin rights audited, and same-day removal when someone leaves — with a log that shows it.
“We use endpoint protection.”Real EDR on every endpoint (behavior-based, not signature antivirus), with alerts actually monitored by someone.
“Backups are in place.”Ransomware-resistant backups with restores tested on a schedule — because an untested backup is a guess, not a recovery.
“Staff are trained.”Scheduled security-awareness training with completion records you can hand an examiner.
“We have an incident response plan.”A written runbook with contacts, notification steps, and roles — rehearsed before the day you need it, not during.
“Vendors are vetted.”A documented review of each provider’s security posture, kept current as you add tools.

Left column: lines you can complete in the Pub 5708 template in an afternoon. Right column: the implemented, evidenced controls the FTC Safeguards Rule actually requires.

Where Other Guys IT comes in

Every item in that right-hand column is technical implementation and documentation — which is our half of the job. We configure the controls, keep them running, and hand you the evidence that backs your attestation.

WISP technical controls — implemented and documented

$125/ workstation / month

Servers $275/month. Licenses at cost. Everything below is inside that number.

This is IT-implementation guidance, not legal advice. Other Guys IT implements and documents the technical controls behind your WISP. Your firm — with its attorney or compliance advisor — owns the written plan and signs the Form W-12 attestation. We make the controls real and the evidence exist so that signature is true.

If you’re weighing what this kind of coverage should cost against the walk-up quotes floating around Houston, read How much managed IT really costs in Houston — it reconstructs where the “cheap” number actually lands. And for how we work with tax and accounting firms specifically, see our IT for tax & accounting firms page.

Renewal season is a fixed date on the calendar. The controls behind that attestation take longer to stand up than the box takes to check — which is the whole argument for starting before the deadline is on top of you.

One more 2026 reality: your staff is already pasting client documents into free AI chatbots, and your WISP is supposed to account for it. We fold an AI-usage policy into every WISP we stand up — which tools are allowed, what data never leaves the firm, and the Google Workspace controls that enforce it instead of hoping.

Sources: IRS Publication 4557 (Safeguarding Taxpayer Data) and Publication 5708 (Creating a Written Information Security Plan); FTC Standards for Safeguarding Customer Information — the Safeguards Rule — 16 CFR Part 314, issued under the Gramm-Leach-Bliley Act (GLBA), fully effective June 9, 2023; IRS Form W-12 PTIN renewal. Regulatory points are summarized for IT-implementation guidance and are not legal advice; confirm your firm’s specific obligations with qualified counsel.

Not sure your WISP would survive a second look?

15 minutes with the founder — a straight read on which of the nine elements are actually running, where the gaps are, and what it takes to close them before renewal. Plain English, no 40-page scare report.

Get Free IT Assessment →
BOOK
15
Grab a free 15-minute assessment
Pick a time straight on Kareem's calendar — no phone tag.
Pick a Time →
Scheduling by TidyCal

Or call (972) 244-3009 or email support@otherguys.tech — same-day response, in writing.

Serving The Woodlands, Spring, Conroe, Kingwood, Tomball & Magnolia.

When your I.T. can’t fix it, the Other Guys can.

Humility  |  Excellence  |  Innovation