How Often Does a CPA Firm Need to Update Its WISP?

A CPA firm must review and update its Written Information Security Plan (WISP) at least once a year, and again any time something significant changes — new tax software, new staff, a move to remote work, a new vendor, or a security incident. Both the FTC Safeguards Rule and IRS Publication 4557 treat the WISP as a living […]
IRS WISP: Your Required Written Information Security Plan, Explained

If you’re a paid tax preparer with a PTIN, you are legally required to have a Written Information Security Plan (WISP). This isn’t optional, and it isn’t aspirational — the IRS has been enforcing this since 2023, and the FTC Safeguards Rule expansion put accountants squarely in scope. Yet in nearly every CPA firm we […]