IRS WISP Requirements for 2026: The Complete Guide for Tax Professionals
If you prepare tax returns for compensation, you are legally required to have a Written Information Security Plan (WISP). Not next year. Not eventually. Right now.
The IRS and FTC have made this non-negotiable. Yet thousands of tax professionals are still operating without one — putting their practice, their clients, and their PTIN at risk.
This guide breaks down exactly what the IRS requires, who needs a WISP, what goes in it, and how to create one without hiring a $1,500 consultant.
What Is a WISP?
A Written Information Security Plan is a formal document that describes how your tax practice protects sensitive client data — Social Security numbers, financial records, tax returns, and other personally identifiable information (PII).
Think of it as your firm's security playbook. It covers what you do to prevent a data breach, how you train your staff, who has access to what, and what happens if something goes wrong.
The IRS provides guidance through Publication 5708 (Creating a Written Information Security Plan for Your Tax & Accounting Practice) and Publication 4557 (Safeguarding Taxpayer Data).
Who Needs a WISP?
If any of the following apply to you, a WISP is required:
- You hold a PTIN (Preparer Tax Identification Number)
- You are a CPA, Enrolled Agent, or tax preparer who files returns for compensation
- You run a bookkeeping firm that handles client financial data
- You are an ERO (Electronic Return Originator)
It doesn't matter if you're a solo practitioner working from a home office or a 50-person firm. The Gramm-Leach-Bliley Act (GLBA) classifies all tax professionals as "financial institutions" — and the FTC Safeguards Rule requires every financial institution to maintain a written security program.
Bottom line: If you touch taxpayer data, you need a WISP.
The Legal Foundation: Why the IRS and FTC Require a WISP
The WISP requirement comes from two federal mandates:
1. The Gramm-Leach-Bliley Act (GLBA)
This federal law requires financial institutions to protect customer data. Under the GLBA, tax preparers and CPAs are legally classified as financial institutions — regardless of firm size.
2. The FTC Safeguards Rule (16 CFR Part 314)
The FTC enforces the GLBA through the Safeguards Rule, which was significantly updated in June 2023. The rule requires every covered business to:
- Designate a Qualified Individual to oversee the security program
- Conduct risk assessments identifying threats to client data
- Implement safeguards including encryption, access controls, and multi-factor authentication
- Train employees on security awareness
- Monitor and test your security measures regularly
- Oversee service providers who access client data
- Maintain a written plan documenting all of the above
Penalties for non-compliance can reach $53,000 per violation.
PTIN Renewal and Your WISP
When you renew your PTIN using IRS Form W-12, Line 11 asks you to attest that you are aware of your data security responsibilities. While the IRS doesn't currently audit WISPs during PTIN renewal, the expectation is clear: you need one.
The IRS Security Summit has repeatedly emphasized that a WISP is not optional. Having no WISP when you file returns for compensation means you are operating outside federal law.
What Must a WISP Include? (IRS Publication 5708)
IRS Publication 5708 outlines the key components. Your WISP should address:
1. Designate a Security Coordinator
Name a specific person responsible for your firm's security program. For solo practitioners, that's you.
2. Conduct a Risk Assessment
Identify where client data lives — paper files, computers, cloud storage, email — and assess the threats to each.
3. Written Security Policies
Document your policies for:
- Password requirements and multi-factor authentication (MFA)
- Data encryption (at rest and in transit)
- Physical security (locked offices, secure disposal)
- Remote access and mobile device security
4. Employee Training
Every person who touches client data must be trained on your security procedures. Document the training and keep records.
5. Vendor and Service Provider Management
Identify every third party with access to client data (cloud storage, tax software, IT providers) and ensure they maintain adequate security.
6. Incident Response Plan
Document what you'll do if a breach occurs: who to notify, how to contain the damage, and how to report it to the IRS and FTC.
7. Annual Review
Your WISP must be reviewed and updated at least annually. Document each review.
Three Ways to Create a WISP
Option 1: DIY with IRS Templates (Free, but time-consuming)
Download IRS Publication 5708, read through 28 pages, and adapt the sample template to your practice. Cost: $0. Time: 8-20+ hours depending on your technical comfort level.
Option 2: Hire a Consultant ($500-$2,000+)
A cybersecurity consultant or IT firm can create a custom WISP for you. Thorough but expensive, especially for solo practitioners.
Option 3: Use an AI-Powered WISP Platform (Fast and affordable)
Platforms like WISP Creator use artificial intelligence to generate a customized, IRS-aligned WISP based on your specific practice. Answer questions about your firm, and the AI generates all required policy sections, risk assessments, and documentation — in minutes, not hours.
| Approach | Cost | Time | Customization | Ongoing Updates |
|---|---|---|---|---|
| DIY (IRS Template) | Free | 8-20+ hours | Manual | Manual |
| Consultant | $500-$2,000+ | 1-4 weeks | High | Additional fees |
| AI Platform | $199-$399/year | Minutes | AI-customized | Included |
What Happens If You Don't Have a WISP?
- FTC penalties up to $53,000 per violation
- Loss of PTIN — inability to prepare returns for compensation
- Insurance issues — cyber liability insurers increasingly require a documented WISP
- Client lawsuits in the event of a data breach
- Reputational damage that can end a practice
Key Deadlines and Dates for 2026
- Now: The WISP requirement is already in effect. There is no grace period.
- PTIN Renewal: Your WISP should be current before renewing your PTIN
- Annual Review: Update your WISP at least once per year
- Breach Reporting: Security events affecting 500+ people must be reported to the FTC within 30 days
Start Building Your WISP Today
You don't need to be a cybersecurity expert to create a compliant WISP. Whether you use the IRS template, hire a consultant, or leverage an AI-powered platform like WISP Creator, the important thing is to get started.
Every day without a WISP is a day your practice operates outside federal law — and a day your clients' data is unprotected.
Get started with WISP Creator →
This guide is for informational purposes and does not constitute legal advice. Consult with a qualified attorney or compliance professional for guidance specific to your practice.