CPA & Financial Firms

The IRS WISP Requirement: What Your Firm Needs to Know

Every firm handling taxpayer data must maintain a Written Information Security Plan. Most were written once and never opened again.

August 2026  ·  6 minute read  ·  All articles

Here is a question worth asking at your next partner meeting: has our WISP been updated since we added cloud storage or remote work?

It is a fair question, not an accusation. Most firms we talk to in Pittsburgh have a Written Information Security Plan somewhere. It was created a few years ago, probably from a template, probably to satisfy a checkbox. Then the firm moved files to the cloud, added a remote work policy, changed tax software, hired three people, and let two go. The WISP did not change at all.

That gap is the entire problem. And it matters most on the one day you hope never comes.

What the Requirement Actually Says

Under the FTC Safeguards Rule, and reinforced through IRS Publication 4557 and the annual PTIN renewal process, any firm that handles taxpayer data is required to create and maintain a Written Information Security Plan. This is not guidance. It is a federal requirement, and it applies to a three person practice in Dormont exactly as it applies to a hundred person firm downtown.

A compliant WISP is expected to cover, at minimum:

That last item is the one nearly everyone misses. A WISP is required to be a living document. A plan that describes a network you retired in 2022 is not a plan. It is a filing cabinet artifact.

Why It Matters Most After a Breach

Firms tend to think of the WISP as a compliance chore. The more useful way to think about it is as the document that determines what happens to your firm after something goes wrong.

A current WISP does not prevent a breach. It changes who is responsible for one.

When taxpayer data is exposed, three separate conversations begin almost immediately, and your WISP is central to all three.

The Regulatory Conversation

The IRS and FTC will want to know what reasonable steps your firm took to protect the data. A current, specific, honestly maintained WISP is your evidence of due diligence. Its absence, or a version that clearly does not describe your actual environment, is evidence of the opposite.

The Insurance Conversation

Cyber liability policies increasingly require documented security practices as a condition of coverage. Read your policy carefully. If it requires a written plan and you cannot produce a current one, you have created an opening for a claim denial at the exact moment you need the policy to work.

The Client Conversation

Your clients handed you their most sensitive financial information. When you have to tell them it may have been exposed, the difference between “we had a documented plan, we followed it, and here is exactly what we are doing” and “we are still figuring out what happened” is the difference between a firm that keeps its clients and one that does not.

The Ten Second Version

If you take one thing from this article, make it the diagnostic question at the top. Ask your partners, or ask yourself:

Has our WISP been updated since we added cloud storage or remote work?

If the answer is no, or if nobody is certain, that is not a crisis. It is a project, and a manageable one. Most firms can get a genuinely useful plan in place in a few weeks of honest work.

What Good Looks Like

A WISP that actually protects your firm tends to share a few traits. It is specific to your firm rather than a downloaded template with the name changed. It names real people and real systems. It gets reviewed on a calendar, ideally after tax season when the firm has capacity to think. And it is written in language your staff can follow, because a security plan nobody reads is a security plan nobody follows.

We also tell firms this plainly: a WISP is a document, not a defense. The plan should describe safeguards that genuinely exist, which usually means multifactor authentication, encrypted storage, tested backups, endpoint protection, and staff training that happens more than once. Writing down controls you do not have is worse than having no plan at all.

Where We Fit

We work with CPA and financial firms across Pittsburgh and the South Hills on exactly this. Not selling a template, but sitting down, documenting where your data actually lives, identifying the honest gaps, closing them, and building a plan that reflects reality and stays current as your firm changes.

If the question at the top of this article gave you pause, that is worth a conversation.

Have Questions About Your Own Setup?

Thirty minutes, no pressure and no pitch. We will talk through your business, your technology, and whether we are the right fit.

Schedule a Free Consultation