HomePoliciesInformation securityWritten Information Security Plan

Policy  required document  US

Written Information Security Plan (WISP)

A WISP is the one document a tax preparer, CPA firm, or any business holding Massachusetts residents’ personal data must be able to produce on request. It names who is responsible, what data you hold, what safeguards protect it, and what happens when something goes wrong. Below: who requires it, what an examiner asks to see, and every tool, consultant and service in this directory that produces or maintains one.

Also called: Written Information Security Program  Data Security Plan  Safeguards Rule program
Share

Obligation ledger

Who requires a WISP, and what each one actually says.

Same document, three regulators, three slightly different lists. The ledger records the source, the trigger, and the last date this site confirmed the text.

SourceApplies whenWhat it requiresStatusConfirmed
FTC Safeguards Rule
16 CFR Part 314
You are a non-bank “financial institution” under GLBA. Tax preparers and CPAs doing tax work qualify.A written program with a designated “qualified individual,” written risk assessment, specified safeguards (MFA, encryption, access controls), staff training, vendor oversight, written incident response plan, annual report to the board or senior officer.MandatoryAug 28, 2026 verify
FTC breach notification amendment
16 CFR 314.4(j)
A “notification event” affecting 500 or more consumers.Notify the FTC within 30 days of discovery. Your WISP’s incident response section should reference it.MandatoryAug 28, 2026 verify
IRS Publication 4557
Safeguarding Taxpayer Data
You hold a PTIN or EFIN.Points preparers to the Safeguards Rule and states a data security plan is required. Publication 5708 supplies a sample WISP template.MandatorySep 1, 2026 verify
PTIN renewal attestationAnnual PTIN renewal.Preparer confirms awareness of data security responsibilities. Not a WISP upload, but an on-record statement.AttestationSep 1, 2026 verify
Massachusetts data security regulation
201 CMR 17.00
You own or license personal information of a Massachusetts resident, in any state.The original “WISP” requirement: designated employee, risk identification, employee policies and discipline, third-party contracts, annual review, computer security requirements including encryption of portable devices.MandatoryAug 20, 2026 verify
New York SHIELD Act
GBL § 899-bb
You hold private information of a New York resident.“Reasonable safeguards” with listed administrative, technical and physical measures. A WISP is the customary way to evidence them; not named as such.ImpliedAug 20, 2026 verify
Cyber insurance applicationsApplying for or renewing a cyber policy.Most carriers’ questionnaires ask whether a written security policy exists and who owns it. Not law, but a “no” prices the policy.MarketJul 2026 sample of 6 forms

Sources 16 CFR Part 314 §314.4(j) 86 FR 70272 IRS Pub 4557 IRS Pub 5708 PTIN requirements 201 CMR 17.00 GBL §899-bb

Further reading

  1. IRS and Security Summit remind tax pros they must have a WISPThe IRS states the mandate in plain words and points to the Pub 5708 template. Read this before the template itself.IRS newsroom
  2. Safeguards Rule notification requirement now in effectThe FTC’s own post on the 30-day breach notice, the section most WISPs written before 2024 are missing.FTC business blog
  3. NIST Cybersecurity Framework 2.0 for small businessIf you want the safeguards section of your WISP to follow a recognised structure, this is the shortest route in.NIST

What examiners ask for

The document, and the proof around it.

A WISP fails review more often on the evidence around it than on its content. Left: the sections every source expects. Right: what an FTC investigator, IRS agent or state AG asks to see, sorted by who in the market produces each item.

Required sections

Union of the FTC, IRS Pub 5708 and 201 CMR 17.00 lists. A section in only one source is marked.

  • Named responsible individual (FTC: “qualified individual”; MA: “designated employee”)
  • Inventory of the personal and taxpayer data held, where, and who can reach it
  • Written risk assessment, repeated on a schedule
  • Safeguards in force: access control, MFA, encryption at rest and in transit, secure disposal
  • Employee policies, training, and discipline for violations (MA names discipline explicitly)
  • Service-provider oversight and contract terms
  • Incident response plan, including the 30-day FTC notice trigger
  • Annual review, change log, and report to the owner or board (FTC)
  • Staff acknowledgment of the plan (best practice in all three; required by none in those words) verify

Evidence requested

Four classes. The class tells you which lane of the directory you need.

1  Written planThe current WISP, its version history, who approved it, and the date of last annual review. Consultants write it  policy tools control it
2  AttestationWhich named staff acknowledged which version, and when. Departed staff still on record. Policy tools
3  Operational recordsTraining completions, risk assessment reports, vendor contracts, the annual report to the owner. MSPs, LMS, the firm itself
4  Technical controlsMFA enforcement, encryption settings, backup logs, endpoint protection. MSPs and vCISOs  compliance automation
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedWISP 2026by name, on record
Pub 4557 Handledwith AllyMatter
Plan It the Modern WayThe six-element plan, acknowledged by everyone with a client file
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every preparer and admin on record
Version-bound, re-collected each season
03
Produce the record for the IRS in one export
From $29/mo, 20 editors, unlimited staff (published)

Assessors

Who assesses the WISP

Government enforcement only. The FTC investigates and brings enforcement actions; there is no certification or third-party audit requirement. Institutions may commission independent assessments voluntarily or under a consent order; No routine inspection or certification. The FTC enforces the Safeguards Rule; the IRS can revoke a PTIN or EFIN for false renewal statements and runs e-file provider monitoring visits. State boards of accountancy and licensing bodies may act on data security failures.

No firm has claimed a the WISP assessor listing yet. Claim yours →

Consultants

Who helps with the WISP

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a the WISP consultant listing yet. Claim yours →

Software

Tools for the WISP

Tools that name this framework in their own material.

What changed

Change log for this obligation.

May 2024 verifyFTC breach-notification amendment takes effect: 30-day notice to the FTC for events affecting 500+ consumers.
Jun 9, 2023 verifyAmended Safeguards Rule fully in force after the extension: MFA, encryption, qualified individual, written incident plan.
2022 filing season verifyIRS begins stating in Pub 4557 that a written data security plan is required for preparers; Pub 5708 template published.
Mar 1, 2010201 CMR 17.00 in force; the term “WISP” enters common use.

Subscribe to changes on this page →

Related

Policies that usually travel with it.

Need a hand implementing it?

Find a Consultant for Written Information Security Plan (WISP)

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Manage This Document in AllyMatter

Route it for approval, keep every version, and record a named acknowledgment from everyone who has to read it.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

Questions

Cost, ownership, and what counts.

Is the IRS Pub 5708 template enough on its own?

It produces the document. It does not produce a dated approval, an annual review record, staff acknowledgments, or proof the safeguards exist. An examiner asks for all of those. Most firms pair the template with either a consultant or a policy tool, often both.

How much does a WISP cost to get done?

Published prices in this directory run from free (the template) to about $1,800 one-time for a consultant-drafted plan, plus a managed retainer if the same firm implements the technical safeguards. Law-firm drafting for 201 CMR 17.00 is quote-only in every listing we hold.

Does a staff acknowledgment need to be a signature?

None of the three sources say “signature.” A dated, attributable acknowledgment of a specific version is the customary evidence. Some firms want an e-signature anyway for their insurer. Tool profiles state which of the two they capture.

We are not in Massachusetts. Does 201 CMR 17.00 apply?

If you hold a Massachusetts resident’s personal information, yes, regardless of where you are. A tax office in Ohio with one Massachusetts client is in scope.

Who owns this site?

AllyMatter, one of the tools listed above. It is labeled every time it appears, is excluded from picks, and receives no lead from the matching form unless you name it. Because it supports the policy layer of the WISP, this page’s one labeled Sponsored slot carries its ad, placed by the publisher at no charge. On frameworks it does not support, that slot shows a house ad or another vendor. Method on the methodology page.

Sources

  1. FTC, Standards for Safeguarding Customer Information, 16 CFR Part 314, as amended; final rule at 86 FR 70272. Fetched live at publish.
  2. IRS Publication 4557, Safeguarding Taxpayer Data; IRS Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice; PTIN requirements.
  3. Massachusetts 201 CMR 17.00, Standards for the Protection of Personal Information of Residents of the Commonwealth.
  4. New York General Business Law § 899-bb (SHIELD Act).
  5. Six cyber insurance application forms sampled July 2026. Held on file, not published, so no link.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.