When you renew your PTIN on Form W-12, Line 11, you certify under penalty of perjury that your firm maintains a Written Information Security Plan — the IRS calls it a WISP (Publication 5708). Separately, the FTC Safeguards Rule (in force since June 9, 2023) classifies every tax-prep firm as a "financial institution" and requires specific, named security controls. Most firms signed Line 11 without actually having the controls behind it. Tick each box you can honestly say yes to — score 1 point each.
A written document maps where client tax data (NPI) lives and how it's protectedIdentifies where NPI lives, how it could be exposed, and what you do about each risk. A plan in your head doesn't count.
MFA is on for tax software/portal, email, remote access, and cloud storageIf even one is a password alone, that's a direct Safeguards Rule violation.Most common gap
A written, tested plan covers who you call, how you contain it, and how you notifyIf breached tomorrow: clients and the IRS notified within required timelines.Often missing
What's at stake — put it on the ledger. This isn't about a fine.
- PTIN suspension = 100% of the season's revenue — you can't legally file.
- A denied cyber-insurance claim — premiums spent on coverage that won't pay if the controls weren't actually in place.
- False-certification exposure on a document you signed under penalty of perjury (FTC enforcement under GLBA).
MFA on everything?
Yes / No
Date completed
___________
- 8 / 8Rare. You're genuinely defensible. Keep the annual review log current and you're done.
- 5–7Partially covered — but the gaps are exactly the ones that void a cyber-insurance claim and that an examiner flags first. Most are a few days of work to close.
- 2–4Typical. Your Line 11 attestation is, candidly, exposed. Fixable — but not by Friday; it needs a real plan.
- 0–1High risk. If a client's data is lost right now, there is no defensible position. Priority.
Closing the gaps without becoming an IT expert. Items 1, 3, 4, 6, 7 and 8 are exactly what a managed security provider delivers as a package — the controls
and the paperwork that proves them — a fixed
$99/computer a month plus $75/month for the documented WISP (about
$370/month for a 3-person firm), against a downside measured in your whole revenue. A Clearwater accounting & tax firm we work with was running on an on-premises network that couldn't meet Safeguards; we moved them to a fully compliant cloud environment — MFA, encryption, vendor oversight, and the documented WISP, all in place. Scored below 8?
Book a 15-minute gap review — no system access; we work from your answers.