A CPA firm must review and update its Written Information Security Plan (WISP) at least once a year, and again any time something significant changes — new tax software, new staff, a move to remote work, a new vendor, or a security incident. Both the FTC Safeguards Rule and IRS Publication 4557 treat the WISP as a living document, not a one-time filing. A plan written in 2021 and never touched since is not compliant, no matter how thorough it was originally.
Most firms get the “create a WISP” part done and then file it away. That’s the mistake. The requirement isn’t just to have a plan—it’s to keep it current. Here’s exactly when and how often a Miami CPA or tax firm needs to update it.
What the rules actually say about updating a WISP
The obligation comes from two overlapping sources. The FTC Safeguards Rule (16 CFR Part 314), which classifies tax preparers as financial institutions under the Gramm-Leach-Bliley Act, requires firms to “evaluate and adjust” their information security program in response to operational changes, the results of testing, security incidents, and shifts in the threat environment. IRS Publication 4557 reinforces this, and the IRS’s own guidance describes the WISP as an evergreen document that should be reviewed and adjusted regularly as the firm’s size, scope, and operations change.
In plain terms, that translates to two triggers: a scheduled annual review, and event-driven updates whenever your environment changes.
The baseline: review at least once a year
At a minimum, your firm should conduct a documented annual review of the WISP—and the documentation matters as much as the review itself. Auditors look for signatures and dates showing the plan was actually revisited, not just written once. A common audit failure isn’t the absence of a WISP; it’s a WISP that exists on paper but no longer reflects how the firm actually operates.
For most firms, the natural rhythm is to schedule the review after tax season—late spring or summer—when staff have capacity and you can honestly assess what worked, what broke, and what changed during the busy months. Setting a recurring calendar reminder for this review isn’t an optional tip; treating it as a fixed annual obligation is what keeps you compliant.
The triggers: update whenever your firm changes
Beyond the annual review, certain events should prompt an immediate update—because waiting until next year’s review leaves a documented gap between your plan and your reality. Update your WISP when you:
- Add or change software — adopting new tax prep software, a new client portal, a document management system, or cloud storage.
- Change your team — hiring new staff (including seasonal preparers), losing staff, or changing who has access to client data. Offboarding procedures belong in the WISP.
- Shift how or where people work — adding remote workers, opening a second office, or changing devices.
- Change vendors — any new third party that touches client data requires documented oversight under the Safeguards Rule.
- Experience a security incident — even a near-miss phishing attempt should prompt a review of whether your safeguards held.
- Face new regulatory requirements — major updates to IRS guidance can change what your plan must contain.
Why this matters more for the 2026 filing season
WISP currency isn’t just a paperwork formality—it’s tied directly to your ability to file. The IRS now requires WISP certification as part of PTIN renewal, and a false certification on that federal form carries serious consequences. Updated IRS guidance heading into the 2026 filing season also tightened technical expectations, including removing the prior exception that let in-office staff skip multi-factor authentication. If your WISP still reflects older rules, it’s out of date by definition.
There’s a financial dimension too. Most cyber liability insurers now expect a current, documented WISP—and after a breach, they audit your security program before paying a claim. An outdated plan can become the reason a claim is denied at the worst possible moment.
The practical takeaway for Miami CPA firms
Build the annual review into your post-tax-season routine, and update the plan immediately whenever your software, staff, vendors, or work arrangements change. The goal isn’t the thickest possible document—it’s a plan that genuinely matches how your firm operates today, with the evidence to prove it. That’s what holds up under an audit, satisfies your insurer, and actually protects your clients’ data.
If you’re not sure whether your current WISP still reflects your firm—or you’ve never formally reviewed it—we can help. ITva builds and maintains WISPs for Miami CPA and tax firms as part of our managed security service. Learn more on our IT support for CPA firms page, or book a free assessment and we’ll tell you exactly where you stand. You can also call us at (305) 629-5925.
This article is general information, not legal or compliance advice. Your firm’s specific obligations depend on its size, operations, and the data it handles.
Written by Giancarlo Ramirez, CTO of ITva Technologies. Giancarlo brings 18+ years of systems engineering across healthcare, accounting, and aviation, is Cisco-certified, and holds advanced cybersecurity training from the NYU Tandon School of Engineering. He leads ITva’s security and compliance work for Miami’s regulated businesses. Last updated June 2026.
Sources: IRS Publication 5709, “Creating a Written Information Security Plan”; FTC Safeguards Rule (16 CFR Part 314); IRS Publication 4557. Update-frequency guidance corroborated by the National Association of Tax Professionals (NATP).





