Free checklist · for tax & accounting offices

WISP-readiness
checklist.

If you prepare tax returns, federal law expects your office to keep a written information security plan — a WISP. Tick off what's already in place, print the rest as your to-do list, and put the vendor questions to everyone who touches client data. Us included.

Questions for your vendors

It applies at any size

The FTC's Safeguards Rule names tax preparers as "financial institutions," and IRS Publication 5708 says that holds "regardless of size." A sole practitioner's plan can be shorter than a 10-partner firm's — but it has to be written.3,4

The IRS keeps asking

The PTIN application and renewal form (Form W-12, line 11) asks you to acknowledge that paid preparers must create and maintain a WISP. The IRS Office of Professional Responsibility's July 2026 article warns that skipping it can bring Safeguards Rule liability and, if willful, Circular 230 discipline.9,11

Breaches now have a 30-day clock

Since May 13, 2024, an incident involving 500 or more people's unencrypted information must be reported to the FTC within 30 days of discovery. New York's breach law gives you 30 days to notify affected New Yorkers, and the state must be told too.7,13

Each item shows where it comes from: the FTC Safeguards Rule (16 CFR 314.4) and IRS Pub 5708, the IRS's free WISP template. Items marked ★ don't apply to firms holding information on fewer than 5,000 consumers (16 CFR 314.6) — they're still good practice.

The plan and who owns it

Know what you hold

Logins and access

Protect the data

Watch and test

Train your people

Your vendors

When something goes wrong

★ Not required if you keep customer information on fewer than 5,000 consumers (16 CFR 314.6). Multi-factor authentication, encryption, vendor oversight and FTC notification apply regardless.

Vendor oversight · 314.4(f)

Questions for every vendor
— including us.

Ask any software, IT or AI provider that will touch client data. Get the answers in writing, keep them with your WISP, and ask again once a year.

  1. Where is our data stored?Which companies host it, and in which country?
  2. Is our data kept separate from your other customers' data?Its own database, or shared tables?
  3. Who at your company can see our data?How is that access controlled, and is it logged?
  4. Is multi-factor authentication required for your staff?On every system that touches our data — and can our own staff turn it on?
  5. Is data encrypted in transit and at rest?Including uploaded files and backups.
  6. Is our data used to train AI models?By you, or by the AI providers you send it to? What do their terms say about retention?
  7. Which subprocessors do you use?Hosting, database, email, AI, payments — and will you tell us before adding one?
  8. How quickly will you tell us about a security incident?Your own FTC and New York clocks are 30 days; a vendor's delay eats into them.
  9. How are changes to the software approved and tested?Can a bad change be rolled back quickly?
  10. What backups do you keep?How often, for how long — and when did you last test restoring one?
  11. When we leave, how do we get our data back?In what format, how fast, and when is it deleted — including from backups?
  12. Will you sign a written security addendum?Do you carry cyber insurance? Any independent audit, such as SOC 2 — and if not, what can you show instead?
Red flags: "we're compliant, so you don't need to worry"; no written answer on AI training; no named person accountable; won't sign anything; can't say where backups live.
Asking us? We'll answer all twelve in writing with our one-page vendor security sheet, gaps included. Request the vendor security sheet · and for your clients, the free client document checklist.
General information, not legal advice. Your obligations depend on your firm, its size and where your clients live. This list doesn't make anyone compliant — your plan and the work behind it do. Check with your own counsel or compliance advisor. Last checked October 10, 2026.

Sources

  1. FTC Safeguards Rule, 16 CFR 314.4 — elements of an information security program (eCFR, current as of Oct 7, 2026). ecfr.gov
  2. 16 CFR 314.6 — exceptions for institutions with customer information on fewer than 5,000 consumers. ecfr.gov
  3. 16 CFR 314.2 — definitions, incl. (h)(2)(viii) tax preparation services and (m) "notification event." ecfr.gov
  4. IRS Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice (Rev. 8-2024). irs.gov
  5. IRS Publication 4557, Safeguarding Taxpayer Data (Rev. 6-2024). irs.gov
  6. IRS Publication 1345, Handbook for Authorized IRS e-file Providers (Rev. 12-2025). irs.gov
  7. FTC, "Safeguards Rule notification requirement now in effect" (May 14, 2024). ftc.gov
  8. FTC, "FTC Safeguards Rule: What Your Business Needs to Know." ftc.gov
  9. IRS Office of Professional Responsibility, "How to Be a Careful WISP(er)," Issue 2026-22 (July 22, 2026). irs.gov
  10. IRS News Release IR-2026-92, IRS and Security Summit remind tax pros they need a written information security plan (Aug 18, 2026). irs.gov
  11. IRS Form W-12, PTIN Application and Renewal (Rev. October 2025), line 11, and its instructions. Form · Instructions
  12. IRS, "Data theft information for tax professionals" (updated Mar 26, 2026). irs.gov
  13. New York General Business Law §899-aa (breach notification; amended Dec 21, 2024, ch. 647). nysenate.gov
  14. New York General Business Law §899-bb (data security protections; small-business provision). nysenate.gov

Sources opened and checked October 10, 2026. Rules change — follow the links for the current text.

Want this handled for you?

Pyxeon builds and runs the software around it.

We're a small Long Island team that builds client portals and office software for tax and accounting firms around how you already work, then hosts it and keeps improving it. Every change you ask for starts with a plan you approve, is tested and reviewed before it goes live, and can be undone. And we'll answer the twelve questions above in writing, gaps included.

A two-minute form about your office. A person — usually Timmy — replies within one business day. No pitch deck.