Skip to main content

Network Essentials

Your WISP Is Not Optional: What Charlotte CPA Firms Must Have in Writing

Federal law requires every paid tax preparer to keep a written information security plan. What the WISP must contain, what happens without one, and how managed IT covers it, mapped to NIST CSF 2.0.
CPA firm partner in Charlotte reviewing her firm's written information security plan

If your firm prepares tax returns for a fee, federal law already requires you to have a written information security plan, a WISP. It is not a best practice and it is not new. It comes from the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, which treat tax preparation firms as financial institutions. When you renew your PTIN on Form W-12, you check a box acknowledging that requirement. The IRS publishes a template, Publication 5708, and a companion guide, Publication 4557.

A WISP is a document. Most of what it promises is technology and process that a firm of ten or forty people cannot run on its own. This guide covers what the plan must say, what happens if it is missing, and which parts of it a managed IT provider should be delivering for you, organized by the six functions of the NIST Cybersecurity Framework so you can hand it to an auditor, an insurer or a client who asks.

Why the WISP is required

The law behind it

  • The Gramm-Leach-Bliley Act requires financial institutions to protect customer information. The FTC’s Safeguards Rule, 16 CFR Part 314, says how, and its own list of covered businesses includes tax preparation firms.
  • The rule was strengthened in 2021, with most new requirements in force since June 2023. Since May 2024, a breach involving the unencrypted information of 500 or more consumers must be reported to the FTC within 30 days of discovery.
  • The IRS restates it to every preparer: paid tax return preparers are required by law to create and maintain a written information security plan. The PTIN renewal form asks you to acknowledge it.

What the plan must contain

The Safeguards Rule lists the elements of an information security program. Firms that hold information on fewer than 5,000 consumers are exempt from a few of them, noted below, but the core applies to every covered firm.

  1. A designated Qualified Individual who owns the program. A partner, an employee, or a service provider, but someone must be named.
  2. A risk assessment that identifies what data you hold, where it lives, and what could go wrong. Firms with 5,000 or more consumers must have it in writing.
  3. Safeguards that address the risks: access controls, a data inventory, encryption in transit and at rest, multi-factor authentication for anyone accessing customer information, secure disposal, change management, and monitoring of user activity.
  4. Regular testing of those safeguards: continuous monitoring, or annual penetration testing plus vulnerability scans every six months. The testing cadence is one of the exempted items for firms under 5,000 consumers.
  5. Security awareness training for staff, and qualified people running the program.
  6. Oversight of service providers, including your IT provider, through contracts and periodic review.
  7. A written incident response plan. Exempted below 5,000 consumers, but the FTC breach notice still applies to everyone.
  8. An annual written report from the Qualified Individual to the partners. Also exempted below 5,000 consumers.
  9. Keeping the program current as the firm and the threats change.

What happens without one

  • A breach at a firm with no WISP is a breach with no defense. The FTC can bring an enforcement action, and the incident becomes public record.
  • Cyber insurers now ask for the WISP, proof of MFA, and evidence of tested backups at renewal. Missing any of the three is a common reason for a declined renewal or a higher premium.
  • Clients ask. Larger clients’ vendor questionnaires increasingly require the firm to show a written program.
  • After a data theft the IRS asks the firm to report it to its Stakeholder Liaison, and affected clients’ returns get flagged for identity theft. That work lands in filing season, on top of the season.

How managed IT covers it, mapped to NIST CSF 2.0

The NIST Cybersecurity Framework 2.0, published February 2024, organizes security into six functions. The FTC does not require NIST, but auditors, insurers and larger clients speak that language, so Network Essentials builds every CPA client’s program on it. Each row shows what the function means, which Safeguards element it satisfies, and what our managed IT and cybersecurity service does for you under it.

NIST function In plain words Safeguards Rule element What Network Essentials delivers
Govern Who owns security, what the policy is, how vendors are held to it Qualified Individual named; written program; service-provider oversight; annual report Quarterly security review with your Qualified Individual; the technical evidence for the annual report; our own controls documented for your vendor file
Identify Know what you have and what could go wrong Written risk assessment; data inventory Asset and data inventory kept current; risk assessment refreshed annually and after major changes; findings written in plain language for the WISP appendix
Protect Stop most incidents before they start Access controls, MFA, encryption, secure disposal, change management, training Phishing-resistant MFA on every account; least-privilege access; full-disk and email encryption; patching; zero trust access for remote work; monthly phishing simulations and role-based training
Detect Notice an intrusion quickly Continuous monitoring of user activity and systems 24/7 monitoring by a managed security operations center; alerts on unusual logins, mass downloads and new forwarding rules; managed detection and response on every endpoint
Respond Contain it and meet the reporting clock Written incident response plan; FTC notice within 30 days for 500+ consumers A written, tested incident response plan you can attach to the WISP; after-hours emergency support for clients; evidence preservation and the timeline your counsel and the FTC filing need
Recover Get back to work without paying a ransom Business continuity, backup and restore Encrypted, immutable backups with tested restores and defined recovery times; documented restore drills, which is the proof insurers ask for

Two things are deliberately not on that list. We do not name the security operations center or other vendors we use, because those change as the market changes and the outcome is what you are buying. And we do not sign as your Qualified Individual. The rule allows a service provider to fill that role, but a firm that outsources ownership of its own security program has learned nothing from it. We make the partner who holds that title effective, with the evidence and the technical work done for them.

What your firm still owns

  • Naming the Qualified Individual and signing the WISP.
  • Deciding what client data the firm keeps and for how long, so the data inventory reflects real policy.
  • Telling your IT provider within the hour when something looks wrong. The 30-day FTC clock starts at discovery.
  • Making training mandatory. We run it; partners have to require it.
  • Reviewing the annual report and signing it.

What an engagement looks like

  1. Free IT audit: a review of your current environment against the nine Safeguards elements. You get a written gap list, whether or not you hire us.
  2. Onboarding: on day one we collect the credentials, lock out the old provider and start taking support requests. Over the next two to four weeks we document the environment and put MFA, encryption, monitoring, backups and the incident response plan in place, written up in a form that drops straight into Publication 5708’s template.
  3. Ongoing: 24/7 monitoring, help desk staffed Monday to Friday 6am to 6pm, after-hours emergency support for clients, quarterly security reviews, annual risk assessment refresh and the annual report package.

Engagements are a flat monthly fee with a minimum of $2,000 per month and no long-term lock-in. Network Essentials is CISSP-led, independently owned in Charlotte since 2002, and has been named to the CRN MSP 500 Pioneer 250 five times since 2021. See our IT services for financial and accounting firms, or read why tax season is the wrong time to find out your IT is broken. To start with the audit, call (704) 206-8900 or request a free IT audit.

Frequently asked questions

Is a WISP really required for a small CPA firm?

Yes. The FTC Safeguards Rule applies to any firm that prepares tax returns for a fee, and it requires a written information security program. Firms holding information on fewer than 5,000 consumers are exempt from the written risk assessment, the written incident response plan, the testing cadence and the annual report, but not from the program itself, the safeguards, or the FTC breach notice.

Can my IT provider be the Qualified Individual?

The rule allows a service provider to fill the role, but the firm stays responsible for compliance and must oversee that provider. Network Essentials recommends a partner hold the title and we supply the evidence and technical work behind it.

Does the FTC require NIST?

No. NIST CSF 2.0 is a voluntary framework. It is useful because insurers, auditors and larger clients recognize it, and because its six functions map cleanly onto the Safeguards Rule’s required elements.

What do I have to report after a breach?

Since May 2024, a breach involving the unencrypted information of 500 or more consumers must be reported to the FTC within 30 days of discovery. The IRS also asks preparers to report client data theft to their IRS Stakeholder Liaison, and state breach laws may apply as well. Confirm the full list with counsel.

Smart Technology to Maximize Productivity