← EasyWayIT.com
EasyWayIT — Tampa Bay

The 8-Point WISP &
FTC Safeguards Readiness Check

The 8 controls behind the WISP you certified on Form W-12 Line 11 — score yourself in 4 minutes, before an examiner, an insurer, or a breach finds out for you.

Applies to: CPA firms, tax preparers, EAs, bookkeepers (2–25 staff) Updated: 2026 Standards: IRS Form W-12 Line 11, IRS Pub 5708, FTC Safeguards Rule (16 CFR 314)
When you renew your PTIN on Form W-12, Line 11, you certify under penalty of perjury that your firm maintains a Written Information Security Plan — the IRS calls it a WISP (Publication 5708). Separately, the FTC Safeguards Rule (in force since June 9, 2023) classifies every tax-prep firm as a "financial institution" and requires specific, named security controls. Most firms signed Line 11 without actually having the controls behind it. Tick each box you can honestly say yes to — score 1 point each.
1
Named Qualified Individual
  • One specific, named person owns your data-security programAn employee or an outside provider you've designated in writing. "Everybody kind of watches it" = No.
2
Written Risk Assessment
  • A written document maps where client tax data (NPI) lives and how it's protectedIdentifies where NPI lives, how it could be exposed, and what you do about each risk. A plan in your head doesn't count.
3
Multi-Factor Authentication — everywhere NPI lives
  • MFA is on for tax software/portal, email, remote access, and cloud storageIf even one is a password alone, that's a direct Safeguards Rule violation.Most common gap
4
Encryption at Rest and in Transit
  • Client data is encrypted on devices/servers (AES-256) and when sent (TLS 1.2+)Includes laptops, the file server, and anything synced to the cloud.Most common gap
5
Written Incident-Response Plan
  • A written, tested plan covers who you call, how you contain it, and how you notifyIf breached tomorrow: clients and the IRS notified within required timelines.Often missing
6
Documented Staff Security Training
  • Everyone who touches client data completed security-awareness training this yearWith a record you could hand an examiner.
7
Vendor / Service-Provider Oversight
  • You've verified in writing that vendors holding client data meet Safeguards-equivalent standardsCloud storage, software vendors, your IT provider.
8
The WISP Document + Annual Review
  • A current, written WISP is on file with a dated review log from the last 12 monthsNot a downloaded template you never finished.The signature item
What's at stake — put it on the ledger. This isn't about a fine.
  • PTIN suspension = 100% of the season's revenue — you can't legally file.
  • A denied cyber-insurance claim — premiums spent on coverage that won't pay if the controls weren't actually in place.
  • False-certification exposure on a document you signed under penalty of perjury (FTC enforcement under GLBA).
Self-Assessment Score
Checked items
__ / 8
MFA on everything?
Yes  /  No
Date completed
___________
Closing the gaps without becoming an IT expert. Items 1, 3, 4, 6, 7 and 8 are exactly what a managed security provider delivers as a package — the controls and the paperwork that proves them — a fixed $99/computer a month plus $75/month for the documented WISP (about $370/month for a 3-person firm), against a downside measured in your whole revenue. A Clearwater accounting & tax firm we work with was running on an on-premises network that couldn't meet Safeguards; we moved them to a fully compliant cloud environment — MFA, encryption, vendor oversight, and the documented WISP, all in place. Scored below 8? Book a 15-minute gap review — no system access; we work from your answers.