IRS WISP Requirements for 2026: The Complete Guide for Tax Professionals

If you prepare tax returns for compensation, you are legally required to have a Written Information Security Plan (WISP). Not next year. Not eventually. Right now.

The IRS and FTC have made this non-negotiable. Yet thousands of tax professionals are still operating without one — putting their practice, their clients, and their PTIN at risk.

This guide breaks down exactly what the IRS requires, who needs a WISP, what goes in it, and how to create one without hiring a $1,500 consultant.


What Is a WISP?

A Written Information Security Plan is a formal document that describes how your tax practice protects sensitive client data — Social Security numbers, financial records, tax returns, and other personally identifiable information (PII).

Think of it as your firm's security playbook. It covers what you do to prevent a data breach, how you train your staff, who has access to what, and what happens if something goes wrong.

The IRS provides guidance through Publication 5708 (Creating a Written Information Security Plan for Your Tax & Accounting Practice) and Publication 4557 (Safeguarding Taxpayer Data).


Who Needs a WISP?

If any of the following apply to you, a WISP is required:

It doesn't matter if you're a solo practitioner working from a home office or a 50-person firm. The Gramm-Leach-Bliley Act (GLBA) classifies all tax professionals as "financial institutions" — and the FTC Safeguards Rule requires every financial institution to maintain a written security program.

Bottom line: If you touch taxpayer data, you need a WISP.


The Legal Foundation: Why the IRS and FTC Require a WISP

The WISP requirement comes from two federal mandates:

1. The Gramm-Leach-Bliley Act (GLBA)

This federal law requires financial institutions to protect customer data. Under the GLBA, tax preparers and CPAs are legally classified as financial institutions — regardless of firm size.

2. The FTC Safeguards Rule (16 CFR Part 314)

The FTC enforces the GLBA through the Safeguards Rule, which was significantly updated in June 2023. The rule requires every covered business to:

Penalties for non-compliance can reach $53,000 per violation.


PTIN Renewal and Your WISP

When you renew your PTIN using IRS Form W-12, Line 11 asks you to attest that you are aware of your data security responsibilities. While the IRS doesn't currently audit WISPs during PTIN renewal, the expectation is clear: you need one.

The IRS Security Summit has repeatedly emphasized that a WISP is not optional. Having no WISP when you file returns for compensation means you are operating outside federal law.


What Must a WISP Include? (IRS Publication 5708)

IRS Publication 5708 outlines the key components. Your WISP should address:

1. Designate a Security Coordinator

Name a specific person responsible for your firm's security program. For solo practitioners, that's you.

2. Conduct a Risk Assessment

Identify where client data lives — paper files, computers, cloud storage, email — and assess the threats to each.

3. Written Security Policies

Document your policies for:

4. Employee Training

Every person who touches client data must be trained on your security procedures. Document the training and keep records.

5. Vendor and Service Provider Management

Identify every third party with access to client data (cloud storage, tax software, IT providers) and ensure they maintain adequate security.

6. Incident Response Plan

Document what you'll do if a breach occurs: who to notify, how to contain the damage, and how to report it to the IRS and FTC.

7. Annual Review

Your WISP must be reviewed and updated at least annually. Document each review.


Three Ways to Create a WISP

Option 1: DIY with IRS Templates (Free, but time-consuming)

Download IRS Publication 5708, read through 28 pages, and adapt the sample template to your practice. Cost: $0. Time: 8-20+ hours depending on your technical comfort level.

Option 2: Hire a Consultant ($500-$2,000+)

A cybersecurity consultant or IT firm can create a custom WISP for you. Thorough but expensive, especially for solo practitioners.

Option 3: Use an AI-Powered WISP Platform (Fast and affordable)

Platforms like WISP Creator use artificial intelligence to generate a customized, IRS-aligned WISP based on your specific practice. Answer questions about your firm, and the AI generates all required policy sections, risk assessments, and documentation — in minutes, not hours.

Approach Cost Time Customization Ongoing Updates
DIY (IRS Template) Free 8-20+ hours Manual Manual
Consultant $500-$2,000+ 1-4 weeks High Additional fees
AI Platform $199-$399/year Minutes AI-customized Included

What Happens If You Don't Have a WISP?


Key Deadlines and Dates for 2026


Start Building Your WISP Today

You don't need to be a cybersecurity expert to create a compliant WISP. Whether you use the IRS template, hire a consultant, or leverage an AI-powered platform like WISP Creator, the important thing is to get started.

Every day without a WISP is a day your practice operates outside federal law — and a day your clients' data is unprotected.

Get started with WISP Creator →


This guide is for informational purposes and does not constitute legal advice. Consult with a qualified attorney or compliance professional for guidance specific to your practice.