A Qualified Individual named
A partner or firm administrator owns the program, with KairosIT behind them.
16 CFR 314.4(a)For CPA and tax firms with 20 to 200 users
At every PTIN renewal, each of your preparers acknowledges that the law requires a written information security plan. Find out in 10 minutes whether yours would hold up across your partners, staff, and offices. Then let us get it written and running in 30 days.
Free. 13 yes-or-no questions. No sales pitch. Not an audit.
Busy Season Ready Check
Busy Season Ready Check
Answer for the whole firm: every partner, staff member, office, and seasonal hire. Honest answers give you a useful score.
One person owns it
Have you named someone in writing to run your security program, and do they report to the partners in writing at least once a year?
Your Busy Season Ready score
Gaps to close first
Also worth doing during filing season: check your e-File application and PTIN account weekly for the number of returns filed under your EFIN and PTINs (IRS Pub. 4557).
† Under 16 CFR 314.6, firms that hold customer information on fewer than 5,000 consumers are exempt from 314.4(b)(1) (the written risk assessment), (d)(2) (the continuous monitoring or pen test and scan schedule), (h) (the written incident response plan), and (i) (the annual written report). Count every consumer whose information you hold, not only this year's clients. Firms with 20 to 200 users are often above 5,000.
* KairosIT recommended practice or a state law check, not FTC or IRS rule text. Florida breach notice duties (Fla. Stat. 501.171) apply separately; confirm with counsel.
Sources: 16 CFR Part 314, sections 314.4 and 314.6; FTC Safeguards Rule notification requirement; IRS Pub. 5708 (Rev. 8-2024); IRS Pub. 4557 (Rev. 6-2024); IRS Pub. 5293; Instructions for Form W-12, line 11; Fla. Stat. 501.171.
Why now
The rules do not change in January. Your capacity does. Here is what the check measures and why it is worth closing the gaps this fall. For the full picture, see our FTC Safeguards Rule and WISP services for CPA firms.
The FTC Safeguards Rule (16 CFR Part 314) treats firms that prepare tax returns as financial institutions, regardless of size. That includes CPA firms, tax practices, and enrolled agents.
A written information security plan (WISP) that a named Qualified Individual runs and reports on to the partners every year. IRS Pub. 5708 provides a sample WISP, and IRS Pub. 4557 covers tax preparer data security.
At each PTIN application and renewal, Form W-12 line 11 asks every preparer to acknowledge that paid preparers are required by law to have a WISP. Cyber insurers and larger clients ask too.
PTIN renewal opens in mid-October. To have a WISP written and running before busy season, start by mid-November. A breach involving 500 or more consumers must be reported to the FTC within 30 days of discovery.
Who this helps
Most firms your size know they need a WISP. The gaps are usually behind it:
What you get in 30 days
Risk assessment, data and vendor inventory, a WISP tailored from IRS Pub. 5708, an incident response plan with your IRS, FTC, and insurer call tree, an AI use policy, and signed staff training. Done before January.
A partner or firm administrator owns the program, with KairosIT behind them.
16 CFR 314.4(a)What could go wrong, and how the firm handles each risk.
16 CFR 314.4(b)Every device, system, portal, and cloud app that holds client data, across all offices.
16 CFR 314.4(c)(2)MFA coverage, encryption, access, logging, and backups, verified from Microsoft 365 and endpoint reports.
16 CFR 314.4(c)Contracts and safeguards for your top vendors: tax software, portal, cloud, and IT.
16 CFR 314.4(f)Built from the IRS Pub. 5708 outline around your people, offices, and systems. Word and PDF.
IRS Pub. 5708A call tree with your IRS Stakeholder Liaison, the FTC, Florida notice checks with counsel, and your cyber insurer.
16 CFR 314.4(h), (j); IRS Pub. 4557One page on which AI tools staff may use and what client data stays out of them.
KairosIT recommended practiceA 45-minute session for partners and staff, with signed, dated acknowledgments.
16 CFR 314.4(e); IRS Pub. 5708The written yearly report, ready for your partner meeting.
16 CFR 314.4(i)The fixes that matter most, prioritized around filing season.
PlanningThe ongoing option: yearly WISP review, training and acknowledgments, the partner report, regular vulnerability scans, and a tabletop exercise before each busy season.
OngoingBusy season timeline
Once returns start coming in, partners and staff have no time for this. Here is how the 30 days run.
Take the Busy Season Ready Check and walk your answers with a KairosIT security lead.
Kickoff, Qualified Individual named, risk assessment, data and vendor inventory, technical check.
Your WISP, incident response plan, AI use policy, and staff training across every office.
Signed acknowledgments on file, first report to the partners, and a 90-day roadmap.
What matters
What the FTC Safeguards Rule requires:
For tax firms, also: report client data theft to your IRS Stakeholder Liaison (IRS Pub. 4557). Florida breach notice rules (Fla. Stat. 501.171) may also apply; confirm with counsel.
Based on 16 CFR Part 314 and IRS Publications 5708 and 4557.
How KairosIT helps:
A WISP your partners and staff can actually run, with clear owners and evidence.
Related: IT services for accounting and CPA firms and regulated IT compliance services.
Security on the NIST framework
KairosIT positions your security program on the NIST Cybersecurity Framework: Identify, Protect, Detect, Respond, and Recover, across the systems your partners and staff use every day.
FAQ
A free, 10-minute self-check for CPA and tax firms. You answer 13 questions (12 drawn from the FTC Safeguards Rule, 16 CFR 314.4, and IRS Pubs 5708 and 4557, plus one on AI tools) and get a score out of 13 with the gaps to close first. One point for each yes you could show proof of today. 11 to 13 is in good shape, 8 to 10 means a few gaps, and 7 or less means get the plan written and running before busy season.
If your firm prepares tax returns, almost certainly. The FTC Safeguards Rule treats tax preparers as financial institutions, regardless of size, and requires a written information security program. The IRS calls it a WISP. The PTIN application and renewal (Form W-12, line 11) asks each preparer to acknowledge awareness that paid preparers are required by law to create and maintain a WISP.
A Qualified Individual who runs the program and reports to the partners in writing every year; a written risk assessment; safeguards for access control, a data and systems inventory, encryption, MFA, secure disposal, change management, and activity monitoring; continuous monitoring or annual penetration testing plus vulnerability scans every 6 months; staff training; vendor oversight; and a written incident response plan. IRS Pub. 5708 gives a sample outline you tailor to your firm.
Within 30 days of discovering a notification event involving the information of 500 or more consumers, using the FTC online form (16 CFR 314.4(j)). If client tax data is stolen, also contact your IRS Stakeholder Liaison right away (IRS Pub. 4557). Florida breach notice rules (Fla. Stat. 501.171) may also apply; confirm with counsel.
Only partly. Below 5,000 consumers, four items drop off: the written risk assessment, the specific continuous monitoring or annual penetration test and twice-yearly vulnerability scan schedule, the written incident response plan, and the annual written report. You still need to regularly test or monitor your safeguards, and your WISP, Qualified Individual, MFA, encryption, access controls, training, and vendor oversight still apply. Count every consumer whose information you hold, not only this year's clients. Firms with 20 to 200 users are often above 5,000.
It is a solid starting point. Publication 5708 is a sample you must tailor to your people, offices, systems, and vendors, and the controls it describes have to actually run. KairosIT helps turn the template into a WISP that matches your firm.
With WISP Done in 30 Days, about 30 days from kickoff for a firm with 20 to 200 users: risk assessment, inventories, a tailored WISP, an incident response plan, an AI use policy, and signed staff training. To be done before January, start by mid-November.
No. KairosIT does the IT, security, and documentation work, and legal questions stay with your counsel.
Sources: 16 CFR Part 314 (eCFR), FTC Safeguards Rule guidance, IRS Pub. 5708, IRS Pub. 4557, IRS Form W-12, and Fla. Stat. 501.171.
Last reviewed October 6, 2026 by the KairosIT security team.
Related KairosIT services
Before busy season
Take the 10-minute check first. If you want a second set of eyes, we walk your answers with you in 30 minutes.
Not legal advice, an audit, or a certification. Legal questions stay with your counsel.
KairosIT, LLC | 1280 SW 36th Ave #101, Pompano Beach, FL 33069 | Human-Focused IT. Period.