The IRS WISP Requirement: Written, Implemented, Evidenced

Every PTIN holder signs near it. Form W-12’s Data Security Responsibilities line asks each preparer to confirm awareness of “my legal obligation to have a data security plan.” Behind that checkbox sit two documents: the FTC Safeguards Rule (16 CFR Part 314), which treats professional tax preparers as financial institutions, and IRS Publication 4557, Safeguarding Taxpayer Data, which translates the rule for tax practices. The written information security plan — the WISP — is where both converge.

We handle both halves for CPA firms, tax practices, and enrolled agents: drafting support for the plan itself, and the controls the plan promises — MFA, encryption, monitoring, tested backup (published retention rates), and staff training — implemented and run.

Where the WISP requirement comes from

The chain is short. The Gramm-Leach-Bliley Act obligates financial institutions to safeguard customer information, and the FTC’s Safeguards Rule — 16 CFR Part 314, with its strengthened requirements enforceable since June 9, 2023 — defines what that program must contain. Professional tax return preparers fall under the rule as financial institutions. IRS Publication 4557, Safeguarding Taxpayer Data, is the IRS’s plain-language translation for tax practices: the specific controls, checklists, and reporting steps expected of anyone who prepares returns for compensation.

And since October 2019, the obligation follows your PTIN. Form W-12 — the PTIN application and renewal — includes a Data Security Responsibilities line where each preparer confirms awareness of the legal obligation to have a data security plan and to protect all taxpayer information. The checkbox takes a second to tick; this page is about being able to mean it.

What the Safeguards Rule expects — and what we put in place

The rule’s core expectations, mapped to who does what in a CRC Cloud engagement:

Safeguards Rule expectationHow it gets done
Designate a Qualified IndividualThe rule lets the role sit with your staff or with a service provider — either way we supply the reporting, monitoring dashboards, and documentation it runs on, and a senior person in your firm oversees it
Written risk assessmentA NIST CSF-based assessment of your practice with documented findings, revisited as the practice and the threats change
Access controls, encryption & MFAMulti-factor authentication enforced on every mailbox and login, encryption in transit and at rest, and per-file access controls on client records
Monitor and test safeguards24/7 monitoring, endpoint detection and response (EDR) on managed devices, SIEM log correlation, and recovery testing on a schedule
Oversee service providersWe’re built to be overseen: documented controls, audit-ready records, and hosting in a facility held to published standards (below)
Incident response plan & ongoing reviewA written, rehearsed incident-response plan plus security awareness training (Secure IT), with the program reviewed as your practice grows

What we do, and what we don't. A WISP is a plan your firm writes and owns; nobody issues a WISP certificate. CRC Cloud does not issue compliance certifications — we get your IT ready for the people who do. We build and run the controls, find the gaps and close them, and have the evidence organized before the IRS or your insurer arrives, so the review is a formality rather than a discovery exercise. If they flag something, we remediate it fast. Align, implement and prepare — never certify or guarantee.

Our infrastructure runs in a Southern California facility engineered to a concurrently maintainable, Tier III-standard design, whose operator holds SOC 1 and SOC 2 Type II attestations, ISO 27001 and PCI-DSS certifications and NIST 800-53 (PE) High alignment, with N+1 redundant power and cooling and a 99.9% uptime service level. See our data centers →

Why the IRS keeps asking

A tax office is an identity thief’s shopping list

Social Security numbers, bank accounts, dependents, prior-year returns, e-file credentials — everything needed to file a convincing fraudulent refund claim sits in one practice’s files. The numbers say attackers have noticed:

26%

of small-business breaches start with an exploited vulnerability — the most common way in

Verizon DBIR 2026

$11.5M

average cost of a U.S. data breach — a record high

IBM Cost of a Data Breach 2026

247

days — average time to identify and contain a breach, across all organizations studied

IBM Cost of a Data Breach 2026

A WISP on paper doesn’t shorten a 247-day intrusion — detection does. Secure IT puts a 24/7 SOC on your mailboxes and endpoints through filing season and after it. See how Secure IT responds →

An open guidebook with a clarity lightbulb rising from the page, representing a written security plan that reflects real controls

A WISP is a promise. The controls are the proof.

Plenty of firms download a WISP template, fill in the blanks, and file it away — and a written plan that doesn’t match reality is a liability in an examination and worse after a breach. The document says MFA; is it enforced everywhere? It says encrypted backup; when was recovery last tested? It names an incident-response plan; has anyone rehearsed it?

We close that gap from both ends: drafting support so the plan describes your actual practice, and managed delivery so the practice actually does what the plan says.

  • WISP drafting support built around your workflows, not a generic template
  • MFA, encryption, monitoring, backup, and training — implemented and run
  • Audit-ready evidence, kept current for examiners, insurers, and clients
See the accounting & CPA playbook →

One Safeguards Rule, more than one industry

The WISP a tax practice maintains under IRS Publication 4557 has a sibling: title and settlement companies carry a nearly identical written-program obligation, expressed through ALTA Best Practices Pillar 3. Same GLBA roots, same FTC Safeguards Rule, same controls — MFA, encryption, monitoring, vendor oversight — different regulator asking. If your firm serves both worlds, one properly built security program answers both.

The nine Safeguards elements behind every WISP are in our printable FTC Safeguards checklist — for a tax practice, the two are largely one project.

Our lane is precise: we align your practice to the frameworks, prepare the documentation, and implement and manage the controls. We don’t certify, audit, or guarantee compliance — your firm owns the plan, your advisors keep the sign-off, and we make sure what they’re signing off on is real. Explore every framework we support in the compliance library.

The IRS WISP requirement, asked and answered

Is a written information security plan (WISP) actually required for tax preparers?

Yes. The FTC Safeguards Rule (16 CFR Part 314) treats professional tax return preparers as financial institutions and requires a written information security program. IRS Publication 4557, Safeguarding Taxpayer Data, is the IRS's guide to meeting that obligation, and every PTIN application and renewal on Form W-12 asks you to confirm you're aware of it. This isn't best-practice advice — it's a legal requirement with your signature near it every year.

What is the data-security line on Form W-12, the PTIN renewal form?

Since October 2019, Form W-12 has carried a Data Security Responsibilities line. Each preparer checks a box confirming awareness of "my legal obligation to have a data security plan and to provide data and system security protections for all taxpayer information." Renewing a PTIN while the WISP behind that checkbox doesn't exist is a bad position to explain later — to the IRS, to the FTC, or to clients after a breach.

What does the FTC Safeguards Rule require a WISP to include?

In plain English: a designated Qualified Individual accountable for the program; a written risk assessment; safeguards that address the identified risks — access controls, encryption, multi-factor authentication; regular testing and monitoring of those safeguards; oversight of service providers; and a written incident response plan, with the whole program reviewed and kept current. The strengthened requirements have been enforceable since June 9, 2023.

Will CRC Cloud write the WISP for us?

We provide WISP drafting support — building the written plan around your actual practice instead of a template with the blanks filled in — and then we implement and run the controls the document promises. The plan stays yours: your firm designates the Qualified Individual and owns the program, and your compliance advisors keep any sign-off. We supply the controls and the evidence.

Which WISP controls does CRC Cloud actually run?

The ones a plan is judged by: multi-factor authentication on every mailbox and login, encryption in transit and at rest, endpoint detection and response on managed devices, 24/7 monitoring, encrypted and immutable backup with tested recovery (published retention rates), security awareness training (Secure IT) for staff, and a written, rehearsed incident-response plan. A WISP that lists controls nobody operates is a liability, not a shield.

We're a small tax practice. Does this really apply to us?

The WISP obligation doesn't come with a size pass — a two-person tax office holds the same Social Security numbers, bank details, and prior-year returns an identity thief needs to file a convincing fraudulent return. The requirement scales with your footprint, and so does our delivery. Pricing is published per user and starts on Secure IT at $250 per user per month, including a 24/7 Security Operations Center. Core IT is not an option for a regulated environment, because the frameworks lean on the monitored layer Secure IT adds. The published +10% WISP uplift brings that to $275 per user.

What does the free assessment cover?

Thirty minutes on the phone, NIST CSF-based, no obligation. We look at where taxpayer data lives, which Safeguards Rule controls are actually in place — MFA, encryption, monitoring, backup — and where your written plan and your reality differ. You leave with a gap list you can act on, whether or not you hire us.

Priced openly, like everything else we do. IRS WISP / FTC Safeguards work carries a published uplift of +10% on the per-user plan and per-server management fee — documentation, evidence and audit support are real recurring hours, so we price them instead of hiding them in a quote. Secure IT is the starting point for compliance work — Core IT is not an option for a regulated environment, because the frameworks lean on the monitored layer it adds. On Secure IT that is $275 per user per month. Backup, private cloud resources and add-ons stay at their flat published rates. See the full compliance uplift table →

Get a WISP your signature can stand behind

Book a free 30-minute, NIST CSF-based assessment and see exactly where your written plan and your real-world controls differ. No pitch deck, no obligation.

Book a Free 30-Minute IT Assessment