Skip to main content

For CPA and tax firms with 20 to 200 users

Your security plan, ready before busy season.

At every PTIN renewal, each of your preparers acknowledges that the law requires a written information security plan. Find out in 10 minutes whether yours would hold up across your partners, staff, and offices. Then let us get it written and running in 30 days.

Free. 13 yes-or-no questions. No sales pitch. Not an audit.

Busy Season Ready Check

Get your Busy Season Ready score

  • Your score out of 13, as soon as you finish
  • The gaps to close first, mapped to 16 CFR 314.4 and IRS Pubs 5708 and 4557
  • If you want it: a KairosIT security lead walks your answers with you in 30 minutes and sends a written top-three list within 2 business days
  • Managed IT
  • Cybersecurity on the NIST framework
  • Microsoft 365
  • Backup & recovery
  • WISP and Safeguards readiness
Get my readiness score

Busy Season Ready Check

12 questions plus one on AI. About 10 minutes.

Answer for the whole firm: every partner, staff member, office, and seasonal hire. Honest answers give you a useful score.

Prefer paper? Download the printable checklist

Question 1 of 13

One person owns it

Have you named someone in writing to run your security program, and do they report to the partners in writing at least once a year?

Also worth doing during filing season: check your e-File application and PTIN account weekly for the number of returns filed under your EFIN and PTINs (IRS Pub. 4557).

† Under 16 CFR 314.6, firms that hold customer information on fewer than 5,000 consumers are exempt from 314.4(b)(1) (the written risk assessment), (d)(2) (the continuous monitoring or pen test and scan schedule), (h) (the written incident response plan), and (i) (the annual written report). Count every consumer whose information you hold, not only this year's clients. Firms with 20 to 200 users are often above 5,000.

* KairosIT recommended practice or a state law check, not FTC or IRS rule text. Florida breach notice duties (Fla. Stat. 501.171) apply separately; confirm with counsel.

Sources: 16 CFR Part 314, sections 314.4 and 314.6; FTC Safeguards Rule notification requirement; IRS Pub. 5708 (Rev. 8-2024); IRS Pub. 4557 (Rev. 6-2024); IRS Pub. 5293; Instructions for Form W-12, line 11; Fla. Stat. 501.171.

Why now

Busy season is the real deadline

The rules do not change in January. Your capacity does. Here is what the check measures and why it is worth closing the gaps this fall. For the full picture, see our FTC Safeguards Rule and WISP services for CPA firms.

Who it covers

The FTC Safeguards Rule (16 CFR Part 314) treats firms that prepare tax returns as financial institutions, regardless of size. That includes CPA firms, tax practices, and enrolled agents.

What you need

A written information security plan (WISP) that a named Qualified Individual runs and reports on to the partners every year. IRS Pub. 5708 provides a sample WISP, and IRS Pub. 4557 covers tax preparer data security.

Where it comes up

At each PTIN application and renewal, Form W-12 line 11 asks every preparer to acknowledge that paid preparers are required by law to have a WISP. Cyber insurers and larger clients ask too.

When to act

PTIN renewal opens in mid-October. To have a WISP written and running before busy season, start by mid-November. A breach involving 500 or more consumers must be reported to the FTC within 30 days of discovery.

Who this helps

Managing partners and firm administrators at CPA and tax firms with 20 to 200 users

Most firms your size know they need a WISP. The gaps are usually behind it:

  • A template filed once and never updated after a merger, a new office, or new software
  • MFA and encryption that stop short of every login and every laptop
  • Seasonal staff who start in January without training or same-day offboarding
  • No security review of tax software, portal, and cloud vendors
  • No written incident response plan with names and numbers
  • Hard questions from PTIN renewal, your cyber insurer, or clients

What you get in 30 days

WISP Done in 30 Days, fixed fee.

Risk assessment, data and vendor inventory, a WISP tailored from IRS Pub. 5708, an incident response plan with your IRS, FTC, and insurer call tree, an AI use policy, and signed staff training. Done before January.

A Qualified Individual named

A partner or firm administrator owns the program, with KairosIT behind them.

16 CFR 314.4(a)

Written risk assessment

What could go wrong, and how the firm handles each risk.

16 CFR 314.4(b)

Client data and device inventory

Every device, system, portal, and cloud app that holds client data, across all offices.

16 CFR 314.4(c)(2)

Technical check

MFA coverage, encryption, access, logging, and backups, verified from Microsoft 365 and endpoint reports.

16 CFR 314.4(c)

Vendor review

Contracts and safeguards for your top vendors: tax software, portal, cloud, and IT.

16 CFR 314.4(f)

Your WISP, tailored

Built from the IRS Pub. 5708 outline around your people, offices, and systems. Word and PDF.

IRS Pub. 5708

Incident response plan

A call tree with your IRS Stakeholder Liaison, the FTC, Florida notice checks with counsel, and your cyber insurer.

16 CFR 314.4(h), (j); IRS Pub. 4557

AI use policy

One page on which AI tools staff may use and what client data stays out of them.

KairosIT recommended practice

Staff training, signed

A 45-minute session for partners and staff, with signed, dated acknowledgments.

16 CFR 314.4(e); IRS Pub. 5708

First report to the partners

The written yearly report, ready for your partner meeting.

16 CFR 314.4(i)

90-day roadmap

The fixes that matter most, prioritized around filing season.

Planning

Then, Keep It Current

The ongoing option: yearly WISP review, training and acknowledgments, the partner report, regular vulnerability scans, and a tabletop exercise before each busy season.

Ongoing

Busy season timeline

Start by mid-November. Be done before January.

Once returns start coming in, partners and staff have no time for this. Here is how the 30 days run.

1

Now

Take the Busy Season Ready Check and walk your answers with a KairosIT security lead.

2

Weeks 1 and 2

Kickoff, Qualified Individual named, risk assessment, data and vendor inventory, technical check.

3

Weeks 3 and 4

Your WISP, incident response plan, AI use policy, and staff training across every office.

4

Before January

Signed acknowledgments on file, first report to the partners, and a 90-day roadmap.

What matters

What the rule asks for, and how we help

01

Controls

What the FTC Safeguards Rule requires:

  • A written security program (your WISP)
  • A designated Qualified Individual
  • A written risk assessment
  • Access controls, encryption, and MFA
  • Secure disposal and change management
  • Continuous monitoring, or annual penetration testing plus vulnerability scans every 6 months
  • Staff security training
  • Service provider oversight
  • A written incident response plan
  • A yearly written report to leadership
  • FTC notice within 30 days of discovering a notification event involving 500 or more consumers

For tax firms, also: report client data theft to your IRS Stakeholder Liaison (IRS Pub. 4557). Florida breach notice rules (Fla. Stat. 501.171) may also apply; confirm with counsel.

Based on 16 CFR Part 314 and IRS Publications 5708 and 4557.

02

Operations

How KairosIT helps:

  • Support for your Qualified Individual
  • Written risk assessment and updates
  • WISP writing and annual review
  • MFA, encryption, EDR, and patching
  • Microsoft 365 and email security
  • Vendor security reviews
  • Incident response planning
  • Help preparing the annual report to the partners
  • Security awareness training

Security on the NIST framework

The WISP is the policy. We run the security behind it.

KairosIT positions your security program on the NIST Cybersecurity Framework: Identify, Protect, Detect, Respond, and Recover, across the systems your partners and staff use every day.

  • Identify client data, devices, vendors, and risks across every office
  • Protect with MFA, encryption, patching, and same-day offboarding
  • Detect with endpoint detection, logging, and regular vulnerability scans
  • Respond with a plan that has names, numbers, and people who pick up
  • Recover from backups kept separate and restores actually tested
< 30 minAvg. response target
24/7Monitoring & alerting
M365 + AzureCloud security work
NIST CSFFramework behind every plan

FAQ

Questions about the Ready Check and WISP Done in 30 Days

What is the Busy Season Ready Check?

A free, 10-minute self-check for CPA and tax firms. You answer 13 questions (12 drawn from the FTC Safeguards Rule, 16 CFR 314.4, and IRS Pubs 5708 and 4557, plus one on AI tools) and get a score out of 13 with the gaps to close first. One point for each yes you could show proof of today. 11 to 13 is in good shape, 8 to 10 means a few gaps, and 7 or less means get the plan written and running before busy season.

Does my CPA or tax firm need a WISP?

If your firm prepares tax returns, almost certainly. The FTC Safeguards Rule treats tax preparers as financial institutions, regardless of size, and requires a written information security program. The IRS calls it a WISP. The PTIN application and renewal (Form W-12, line 11) asks each preparer to acknowledge awareness that paid preparers are required by law to create and maintain a WISP.

What must a WISP include under 16 CFR 314.4?

A Qualified Individual who runs the program and reports to the partners in writing every year; a written risk assessment; safeguards for access control, a data and systems inventory, encryption, MFA, secure disposal, change management, and activity monitoring; continuous monitoring or annual penetration testing plus vulnerability scans every 6 months; staff training; vendor oversight; and a written incident response plan. IRS Pub. 5708 gives a sample outline you tailor to your firm.

When do we have to notify the FTC about a breach?

Within 30 days of discovering a notification event involving the information of 500 or more consumers, using the FTC online form (16 CFR 314.4(j)). If client tax data is stolen, also contact your IRS Stakeholder Liaison right away (IRS Pub. 4557). Florida breach notice rules (Fla. Stat. 501.171) may also apply; confirm with counsel.

We have fewer than 5,000 consumers. Are we exempt?

Only partly. Below 5,000 consumers, four items drop off: the written risk assessment, the specific continuous monitoring or annual penetration test and twice-yearly vulnerability scan schedule, the written incident response plan, and the annual written report. You still need to regularly test or monitor your safeguards, and your WISP, Qualified Individual, MFA, encryption, access controls, training, and vendor oversight still apply. Count every consumer whose information you hold, not only this year's clients. Firms with 20 to 200 users are often above 5,000.

Is the IRS WISP template in Publication 5708 enough?

It is a solid starting point. Publication 5708 is a sample you must tailor to your people, offices, systems, and vendors, and the controls it describes have to actually run. KairosIT helps turn the template into a WISP that matches your firm.

How long does it take to get a WISP written and running?

With WISP Done in 30 Days, about 30 days from kickoff for a firm with 20 to 200 users: risk assessment, inventories, a tailored WISP, an incident response plan, an AI use policy, and signed staff training. To be done before January, start by mid-November.

Does KairosIT replace our counsel?

No. KairosIT does the IT, security, and documentation work, and legal questions stay with your counsel.

Sources: 16 CFR Part 314 (eCFR), FTC Safeguards Rule guidance, IRS Pub. 5708, IRS Pub. 4557, IRS Form W-12, and Fla. Stat. 501.171.

Last reviewed October 6, 2026 by the KairosIT security team.

Before busy season

Find your gaps now, while there is time to fix them.

Take the 10-minute check first. If you want a second set of eyes, we walk your answers with you in 30 minutes.

Get my readiness score