PTIN renewal season is here. Make sure your WISP documentation is current before you complete your renewal attestation.

Check your readiness

WISP compliance for tax and accounting firms

A WISP is not a one-time document. It is an ongoing compliance obligation.

ProtPTX builds your firm-specific Written Information Security Plan, then helps keep it current as your firm, systems, vendors and regulatory requirements change.

Nine questions. Instant gap analysis. Download the report or have it sent to you.

FTC Safeguards Rule Gramm-Leach-Bliley Act IRS Pub. 4557 IRS Pub. 5708

Compliance activity log · Example firm

Current

2026-08-04 Two new cloud tools recorded Vendor oversight updated, plan revised Logged
2026-08-11 Staff security training completed, 4 of 4 Completion records filed Logged
2026-08-19 Laptop added to device inventory Encryption and MFA confirmed Logged
2026-09-01 Monthly compliance check-in Scheduled Scheduled
2026-10-15 Annual review, ahead of PTIN renewal Documentation current before the attestation Scheduled
Twelve months on record · no gaps

Why this matters

The obligation is ongoing, and a static template does not meet it.

A Written Information Security Plan is legally required for tax professionals handling taxpayer data. The obligation is connected to the FTC Safeguards Rule, the Gramm-Leach-Bliley Act, and IRS guidance including Publications 4557 and 5708. When you renew your PTIN, you are asked to attest that you maintain one.

The requirement is not satisfied by having a file. The plan must be current, implemented and reviewed over time. A static template does not address what happens next: staff join and leave, devices are replaced, vendors change, software is added, security controls shift, and requirements are updated.

Where a plan no longer describes the firm, that exposure is real. Noncompliance can expose a firm to PTIN, licensing, civil-penalty, professional-liability and reputational risks. What applies to your firm depends on its size, services and circumstances.

Template versus program

The difference is what happens after you download it.

 A static template ProtPTX
Written plan producedYesYes
Describes your actual devices, staff and software GenericBuilt from your intake
Names your Data Security Coordinator Blank to fill inDocumented
Risk assessment for your firm You write itCompleted with you
Updated when staff or vendors change NoPrompted monthly
Regulatory change monitoring NoIncluded
Annual review scheduled You remember itScheduled and reminded
Training records organised NoTracked
Dated compliance activity log NoMaintained
Device charges Unlimited devices, no per-device charges

Two parts

A custom build, then ongoing checks.

01

One-time tailored setup

We build a Written Information Security Plan specific to your firm's actual devices, staff, software and vendors. It starts with a structured intake that takes under ten minutes and covers all ten parts a plan is expected to have, from program scope through to the annual review schedule.

What your firm-specific WISP includes

02

Ongoing monthly checks

We monitor for relevant regulatory and guidance changes, run a monthly compliance check-in, prompt the updates your changes require, schedule the annual review, organise training records, track vendor oversight, and maintain a dated compliance activity log.

What the monthly service delivers

03

The result

Documentation that stays current and a firm that stays audit-ready, without you tracking any of it yourself. That is compliance peace of mind rather than a document download.

Pricing

Flat-rate coverage without per-device pricing.

Three plans banded by firm size. Choose annual and the setup fee is waived.

Flat rate Unlimited devices No per-device charges

Solo

For a single preparer or sole practitioner

Save $255 a year

$412per year

$34.33 a month, billed annually

Setup fee waived $199

Flat rate · Unlimited devices · No per-device charges

Start with the readiness check
  • Firm-specific WISP built from your intake, not a template
  • Covers 1 preparer
  • Unlimited devices at no extra charge
  • Monthly compliance check-ins and update prompts
  • Regulatory and guidance change monitoring
  • Annual review scheduling and reminders
  • Maintained compliance activity log and audit trail
  • Current plan documents and full update history

Multi-office

For firms with 11 or more staff or multiple locations

Save $1,057 a year

$1,890per year

$157.50 a month, billed annually

Setup fee waived $799

Flat rate · Unlimited devices · No per-device charges

Start with the readiness check
  • Firm-specific WISP built from your intake, not a template
  • Covers 11+ staff or multiple locations
  • Unlimited devices at no extra charge
  • Monthly compliance check-ins and update prompts
  • Regulatory and guidance change monitoring
  • Annual review scheduling and reminders
  • Maintained compliance activity log and audit trail
  • Current plan documents and full update history

Full pricing, the billing toggle and what the setup fee covers

Refer a firm, take 20% off your own renewal. Five and yours is free.

No cash changes hands and there is nothing to invoice. Every firm that signs up with your code takes 20% off your own next renewal, stacking to free at 5. On the Firm plan that is $188 off, and $940 a year saved outright.

20%off your own renewal
per confirmed referral
5referrals and your
subscription is free
$0no cash, no invoicing,
no payout to chase

Not ready yet

We will check in before renewal season.

Leave an email and we will send the readiness check, a reminder before the October to December PTIN renewal window, and one follow-up in January. Nothing else.

No client data. Unsubscribe any time. Handled by send.php on your own server.

Start with the free readiness check

Nine questions drawn from the FTC Safeguards Rule and IRS Publications 4557 and 5708. You get a readiness outcome and a gap list on screen, then download the report or have it sent to you.