
A WISP, short for Written Information Security Plan, is the written data-security plan the IRS expects every paid tax preparer to keep, and the WISP requirements in 2026 have real teeth: your plan is tied to your PTIN, and a careless attestation can cost you. It is not a form you file once. It is a living document that describes, in plain terms, how your firm protects client data, who is responsible, and what happens if something goes wrong. If you have been treating “we have antivirus” as a WISP, this is the gap to close before the next filing season. Below is what a WISP actually has to contain, who needs one, and where hosting can and cannot help.
What a WISP actually is
A WISP is your firm’s written plan for safeguarding taxpayer data. It exists because two things require it. The FTC Safeguards Rule, which treats tax and accounting firms as financial institutions, mandates a written security program. And the IRS, through Publication 4557 and the sample framework in Publication 5708, expects every preparer to maintain one. The plan does not have to be long or full of jargon. A small practice can keep a short, clear WISP. What it cannot be is missing, or a folder of good intentions nobody wrote down. The point is that your security is documented, assigned, and reviewed, so it holds up when a client, an insurer, or the IRS asks.
What a WISP must include in 2026
Strip it to the essentials, and a WISP has eight moving parts. The IRS sample plan in Publication 5708 walks through each one.
Two of these carry the most weight in practice. The Data Security Coordinator makes someone accountable rather than leaving security as everyone’s job and no one’s. And the incident response plan is the part firms skip until they need it, which is the worst possible time to be writing one.
Getting started is less daunting than it sounds. The IRS sample WISP in Publication 5708 gives you a fill-in framework, so much of the work is describing what you already do and deciding what to fix. A short, honest plan you actually follow beats a long one that sits in a drawer.
Who needs one, and the PTIN connection
Every paid preparer with a PTIN. Not just large firms. The requirement follows the PTIN, not your headcount, so a solo preparer working from a spare room needs a WISP the same as a fifty-person office does. The plan simply scales to the size of the practice. The connection people underestimate is the attestation: when you renew your PTIN on Form W-12, you confirm that you have a data security plan in place, and you do it under penalty of perjury. Answering yes without a real WISP is not a paperwork shortcut. It is a false statement on a federal form.
How hosting helps you meet it
Hosting your tax and accounting software covers a real chunk of the safeguards a WISP calls for, without making the plan itself for you. A hosted environment supplies encryption, multi-factor authentication, managed backups, and access controls, and it gives you a documentable service provider for the oversight requirement. What it does not do is name your Data Security Coordinator, run your risk assessment, train your staff, or write your incident response plan. Those stay with your firm. Think of hosting as covering the technical safeguards and the vendor line, while you own the program around them. We walk through the vendor-oversight side in our guide on documenting your host in your WISP, and you can see how the security is built on our QuickBooks Desktop hosting page. Common questions are covered in our hosting FAQ.
This article is general information, not legal or compliance advice. Confirm your obligations against the current IRS Publication 4557 and 5708 and a qualified advisor.
WISP questions from tax pros
What is a WISP?
A Written Information Security Plan, a document describing how your firm protects client data. The IRS expects every paid preparer to keep one, and the FTC Safeguards Rule requires a written security program for firms that handle financial data.
Is a WISP legally required in 2026?
Yes. It comes from the FTC Safeguards Rule and IRS guidance, and it applies regardless of firm size. Your PTIN renewal on Form W-12 asks you to attest that you have one, so it is not optional for a paid preparer.
Do solo preparers really need one?
Yes. The requirement follows the PTIN, not the number of employees, so a one-person practice needs a WISP too. It can be short and scaled to your setup, and the IRS provides a sample framework in Publication 5708 to start from.
Does hosting satisfy my WISP?
No. Hosting supplies several of the technical safeguards and a documentable vendor, which covers part of the plan. You still name your Data Security Coordinator, run the risk assessment, train staff, and keep the incident response plan. The WISP stays yours.
How often should I update it?
At least once a year, and any time your systems, staff, or service providers change in a meaningful way. A WISP that never changes is a sign it is not being used, which is exactly what a reviewer will notice.
Need the technical side of your WISP handled?
A 15-minute call is enough to see which safeguards hosting can cover for your practice, and how to document them.
Book a 15-min consult

Leave a Reply