Requirements
What a WISP actually has to contain
Every element below comes from published regulatory or IRS text, with the citation attached. Read the sources yourself. That is the point of listing them.
The short version
If you prepare tax returns for compensation, you are a financial institution for the purposes of the FTC Safeguards Rule. The Rule requires you to develop, implement, and maintain a written information security program. The IRS publishes the template structure in Publication 5708 and the practical checklist in Publication 4557. When you apply for or renew your PTIN, Form W-12 asks you to acknowledge the requirement.
Firm size does not change whether the requirement applies. It changes which specific provisions you must satisfy. See the small-firm exemption below.
The federal rule
FTC Safeguards Rule, 16 CFR 314.4
Nine lettered elements. This is the spine of any WISP written for a United States tax or accounting firm.
Required elements of the information security program
16 CFR 314.4(a) through (i)
The small-firm exemption, stated precisely
A financial institution that maintains customer information concerning fewer than 5,000 consumers is exempt from four specific requirements: the written risk assessment at 314.4(b)(1), the continuous monitoring or penetration testing and vulnerability assessment requirement at 314.4(d)(2), the written incident response plan at 314.4(h), and the annual written report at 314.4(i).
Everything else still applies. The exemption is not a pass on having a program, and the count is of consumers whose information you maintain, not of returns you filed this season.
16 CFR 314.6Breach notification to the FTC
16 CFR 314.5
The IRS structure
Publication 5708: the seven-section framework
The IRS publishes a template for exactly this document. Its structure is what an examiner will recognize, which is why ProtPTX generates to it.
Sections of the plan
IRS Publication 5708, Creating a Written Information Security Plan for your Tax and Accounting Practice
Data Security Coordinator
Named in the plan. Oversees daily security operations, monitors compliance, runs training, manages third-party vendor safeguards, and reviews the plan annually.
IRS Pub. 5708Public Information Officer
The single voice for external communication during an incident, handling client notification and contact with law enforcement.
IRS Pub. 5708Publication 5708 also supplies sample attachments: record retention policy, rules of conduct for handling personally identifiable information, breach procedures, employee acknowledgment forms, hardware inventory, and the authorized user access list. ProtPTX generates each of these populated with your firm's answers rather than left blank.
The IRS checklist
Publication 4557: what the plan has to be true about
Publication 4557 is the operational companion. It groups safeguards into three areas and tells you what to do after a theft.
Employee management and training
Background checks, confidentiality agreements, access limited to job need, strong passwords, multi-factor authentication, password-activated screen savers, mobile device policy, security training and reminders, telecommuting policy, and a stated disciplinary measure for violations.
Information systems
Secure storage with both physical and digital protection, encryption of sensitive data in transit, secure disposal of records and electronic media, and a maintained equipment inventory.
Detecting and managing failures
Monitoring vendor advisories, keeping security software and firewalls current, intrusion detection, audit logs that would reveal unauthorized access, and a breach response procedure.
If client data is stolen
Publication 4557 directs practitioners to report data losses or thefts immediately, and to contact the IRS Stakeholder Liaison, the FBI if the IRS directs it, local police, relevant state tax agencies, and your security and insurance providers. This is a sequence you want written down in advance, with the phone numbers already in the file.
IRS Pub. 4557Consequences
What we will and will not claim about penalties
Fear numbers circulate freely in this market and most of them cannot be traced to a source. Here is the one figure we will stand behind, and the reason we leave the rest alone.
What is verifiable
The FTC's most recently published maximum civil penalty for violations of Section 5(m)(1)(A) of the FTC Act is $53,088 per violation, set in the agency's 2025 inflation adjustment.
FTC, Inflation-Adjusted Civil Penalty Amounts for 2025, published February 2025.
What we do not repeat
Per-day penalty figures widely quoted in WISP marketing, along with breach cost averages attributed to no primary source. We could not verify them, so they do not appear on this site.
If a vendor quotes you a number, ask which document it comes from. It is a fair question and the answer tells you something.
Penalty exposure depends on the statute invoked, the conduct, and the enforcing authority. Nothing here is a prediction about your firm. Ask your attorney.
State law sits on top of all of this
Federal requirements are the floor. If you hold information about residents of certain states, additional duties apply, and they are not satisfied by a plan written only to the federal rule. Massachusetts is the clearest example, and it has no firm-size threshold at all.
Find out which of these you can actually evidence
Knowing the rule and being able to prove you follow it are different things. The assessment asks about the second one.