PTIN renewal season is here. Make sure your WISP documentation is current before you complete your renewal attestation.

Check your readiness
Home Setup

The one-time custom build

What Your Firm-Specific WISP Includes

This is not template generation. The setup documents your firm's actual devices, staff, software, vendors and data practices, and maps them to the structure a Written Information Security Plan is expected to have.

Built from your intake Unlimited devices Setup waived on annual plans

The ten parts of your plan

Each one is completed with your firm's own answers, not left as a blank to fill in later.

Plan structure

Designed around IRS and FTC expectations, including IRS Publications 4557 and 5708 and the FTC Safeguards Rule

01Program objective, purpose and scopeWhat the plan is for, which taxpayer information it covers, which locations and systems fall inside it, and where its boundaries sit.
02Designated responsible individualsYour Data Security Coordinator and Public Information Officer named in the document, with their duties written out rather than assumed.
03Written risk assessmentInternal, external and accidental disclosure risks identified and evaluated for your firm, with how each is mitigated.
04Hardware and software inventoryDevices, storage locations, cloud platforms and data access points. Unlimited devices, documented, at no extra charge.
05Data encryption and access control policiesPassword requirements, least-privilege access, multi-factor authentication, and how remote-work access is granted and removed.
06Security safeguardsAntivirus, firewall, multi-factor authentication, encryption, backup and software-update practices, described as your firm actually runs them.
07Incident, breach and notification proceduresWhat happens in the first hours, who decides, who is contacted, in what order, and what has to be recorded.
08Employee code of conduct and trainingConfidentiality expectations, acceptable use, security training and the records that show it happened.
09Service-provider and vendor oversightWhich third parties reach taxpayer information, what diligence was done, and the safeguards your contracts carry.
10Implementation, review schedule and update processThe implementation clause, effective date, annual review schedule and the process for updating the plan when your firm changes.

How the build runs

From intake to a plan that describes your firm

Structured intake, under ten minutes

Firm and entity type, staff numbers, devices, remote or hybrid arrangements, the software you run, vendors with access, storage and backup practices, existing controls and policies, physical office security, and your designated coordinators.

We document your real environment

Your answers become the inventory, the risk assessment and the access-control policies. Where you already have controls in place, the plan records them as they are rather than prescribing something you do not use.

Gaps become recommendations

Where an expected element is missing, the plan says so and sets out what would address it. Often that is a setting in software you already pay for.

Delivery and implementation

You receive the plan with its implementation clause, effective date and annual review schedule, ready for signature, along with the supporting policies and records.

The monthly service begins

From that date the plan is maintained rather than filed. See what that involves below.

After setup

Compliance Does Not End at Setup

A plan is only useful while it still describes your firm. Here is the specific work the monthly subscription performs, month by month.

Regulatory and guidance monitoring

We watch for changes to the FTC Safeguards Rule, IRS guidance including Publications 4557 and 5708, and related requirements, and tell you when something affects your plan.

Monthly compliance check-ins

A scheduled check each month that asks what changed in your firm and records the answer, so nothing accumulates unnoticed until renewal season.

Change prompts

When you add employees, contractors, devices, cloud tools, vendors, offices or remote-work arrangements, we prompt the plan updates those changes require.

Annual review scheduling

The annual review is scheduled and reminded rather than remembered, and it produces a dated record when it is done.

WISP revision prompts

When business conditions change enough to affect the plan, we prompt the revision and keep the previous version in the history.

Training records

Reminders when training is due, and organisation of the completion records so they can be produced on request.

Service-provider oversight tracking

Your vendor list kept current, with the diligence and contract position recorded against each one.

Compliance activity log and audit trail

A maintained, dated record of the reviews, updates, training and checks performed, which is what being audit-ready actually consists of.

Documents and history, always available

Ongoing access to your current plan documents and the full update history, so you can show not just what the plan says but when it changed and why.

Know another firm in the same position?

Most people who buy this can name three peers who signed the same attestation and quietly know their plan is out of date. Every one of them that signs up with your code takes 20% off your own renewal, and at 5 your subscription costs you nothing.

20%off your own renewal
per confirmed referral
5referrals and your
subscription is free
$0no cash, no invoicing,
no payout to chase

What this service does and does not do

What ProtPTX does

  • Builds a Written Information Security Plan specific to your firm
  • Documents your devices, staff, software, vendors and data practices
  • Monitors for relevant regulatory and guidance changes
  • Prompts the updates your changes require
  • Maintains a dated compliance activity log
  • Helps keep your documentation current and your firm audit-ready

What ProtPTX does not do

  • Guarantee legal compliance
  • Prevent breaches or act as a security product
  • Provide legal advice, or act as your law firm
  • File anything with the IRS or the FTC on your behalf
  • Replace your IT provider, your attorney or your own judgment
  • Determine what the law requires of your specific firm

Requirements are not identical for every firm. What applies to yours depends on its size, services and circumstances. Where that matters, talk to your own attorney.

Start with the free readiness check

Nine questions, an instant gap analysis, and a report you can download or have sent to you with recommended next steps.