For tax preparers & PTIN holders
IRS Written Information Security Plan (WISP) for Tax Preparers
We scan your firm first, then write the plan around what we actually found — and, if you want it, run the ongoing work that keeps the plan true. The scan is free, takes about a minute, and you keep the result whether or not you buy anything.
- ✓ Built to the FTC Safeguards Rule, 16 CFR Part 314 — the rule IRS Pub 4557 and Form W-12 point to
- ✓ Risk assessment written from a scan of your firm, not from a questionnaire you fill in yourself
- ✓ From $897 · five business days from completed intake
- ✓ Richfield, Utah. One named technician. 435-201-2646
Already know you need the plan? Book the WISP — $897 · See pricing
No obligation, and you keep the result either way.
Start with what’s actually exposed
Enter your firm’s email domain — the part after the @ in your email, like smithtax.com. You don’t need a website; most firms out here don’t have one.
In about a minute we check whether your email can be spoofed (SPF, DKIM, DMARC), what of your firm is reachable from the open internet, whether what’s exposed is encrypted, and whether your addresses show up in known breach data. It’s passive. We don’t touch anything — we look at what is already visible from outside and write it down. It is a scan, not a penetration test, and there’s a section below explaining why that distinction matters.
You keep the result either way. If it comes back clean, that’s a real answer and we’ll tell you so.
Free, instant, and passive — we only read public information, the same as an attacker or insurance auditor would.
What this free scan can’t see — and why that matters more
Everything above is your public face. Here is what no external scan can reach, ours included:
Whether MFA is actually enforced on your tax software, or merely available. Whether the laptop that goes home at night is encrypted. Whether anything at all is logging who opened which return. Whether last year’s clients are still sitting on a share nobody has reviewed. Whether the multifunction copier in the corner has been writing scanned 1040s to an internal drive since 2019.
Those are §314.4(c) — access control, encryption, MFA, disposal, logging — and they are the parts of the rule a small firm is least likely to have running and most likely to describe inaccurately in a plan.
So the free scan is a real answer to a narrow question. The engagement is how you get an answer to the rest of it: we add DKIM, a certificate-transparency inventory of the hosts and subdomains your firm forgot it had, and a credential-breach check — and then we come look at the inside.
Where the requirement actually comes from (it isn’t the IRS)
The obligation is the Federal Trade Commission’s, at 16 CFR Part 314 — the Safeguards Rule under Gramm-Leach-Bliley. A firm “in the business of completing income tax returns” is a financial institution under §314.2(h)(2)(viii). That is how a five-person office in central Utah ends up inside a banking regulation.
IRS Publication 4557 is the IRS explaining that rule to preparers. Form W-12 is the IRS asking whether you know about it. Neither is the source of the requirement, and neither approves anything. There is no IRS-approved WISP and no IRS-approved vendor — including us.
Now the sentence the market skates past. §314.3(a) requires you to “develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts.” Three verbs. And §314.2(i) defines that program as “the administrative, technical, or physical safeguards you use.”
The program is the safeguards. The written plan describes them. Pub 4557 puts it in plainer words: preparers must “create and enact” security plans.
A document is the first verb. A plan describing controls your office does not run has documented a gap rather than closed one.
What Form W-12 Line 11 actually says
Line 11 is captioned Data Security Responsibilities. It reads: “I am aware that paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information.” You check Yes or No, and the instructions point you to FTC 16 CFR Part 314.
It attests that you are aware of the obligation. It does not certify that you have a plan. There is nothing to attach, and nobody at the IRS reads your WISP.
You will find pages telling you the IRS now verifies that box against your actual plan, or that checking it without a WISP is per se perjury. Neither is what the form says, and we would rather you bought from us for a reason that survives you looking it up.
What is true: the application is signed under penalties of perjury. Once you have checked that box, “nobody told me” is no longer available to you. That is enough — it doesn’t need dressing up.
PTIN renewal opens in mid-October and closes December 31.
If you’re under 5,000 clients, look closely at what you’re excused from
§314.6 is one sentence: “Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.”
That is four things:
- (b)(1) — that your risk assessment be written in a specified format
- (d)(2) — the annual penetration test and six-month vulnerability scan schedule
- (h) — the written incident response plan
- (i) — the Qualified Individual’s annual written report to your governing body
Three of those four are paperwork. The fourth is a testing schedule.
Now what §314.6 does not touch. It does not touch §314.3(a) — the written program requirement lives there, not in §314.4, so it is never waived by size. It does not touch §314.4(a), designating a Qualified Individual. Not any of §314.4(c): access controls, asset inventory, encryption in transit and at rest, MFA for any individual accessing any information system, secure disposal, change management, or logging user activity. Not (d)(1), “regularly test or otherwise monitor the effectiveness” of your safeguards. Not (e) training, (f) service-provider oversight, or (g) evaluate and adjust. And not (j) — notifying the FTC within 30 days of a security event involving at least 500 consumers — which was added after §314.6 was written and is not in its list.
So the small-firm relief is real, and it lands almost entirely on documents. The controls stay.
One caution, and we mean it. Don’t assume you’re under the line. It counts consumers whose information you still maintain, not returns you filed this season. §314.4(c)(6) contemplates holding data up to two years after last use — and it carves out information you still need for business operations, or that other law or your own retention obligations require you to keep — so retained prior-year files count while you hold them. That is a number you have to actually work out. We’ll work it out with you. We won’t tell you the answer before we’ve seen your retention.
What a questionnaire can’t do
A template — the free one in IRS Publication 5708, the one your tax software vendor sends, the one your E&O carrier attached to a renewal email — asks you to list your antivirus, your backup, your training, your encryption.
Those are good documents. The IRS wrote one of them. Preparers write perfectly serviceable plans from them every year, and the ones who have written up how long it took land around two working days.
The limit isn’t quality. It’s that the format has no way to check whether the answers are true. If you write “MFA is required for remote access” because you believe it is, the template accepts it. So does any plan built from an intake form — the questions are the same questions either way, and the answers are still yours.
We do it in the other order. We scan, we look, we ask you about what we couldn’t see, and the risk assessment is written from findings that have dates on them.
Same document type. Different evidentiary weight.
And you can absolutely do this yourself. If two days of your time in October is worth less to you than $897, use Pub 5708 — and call me if the free scan turns up something you’d like a second opinion on.
The half a document can’t do
Most of §314.4 is not paperwork. Read the verbs:
- (c)(1) implementing and periodically reviewing access controls
- (c)(2) identify and manage the data, personnel, devices, systems and facilities — an inventory that goes stale the day a laptop is replaced
- (c)(3) encryption of customer information in transit over external networks and at rest
- (c)(5) MFA for any individual accessing any information system
- (c)(6) secure disposal, and periodic review of your retention policy
- (c)(8) monitor and log the activity of authorized users, and detect unauthorized access
- (d)(1) regularly test or otherwise monitor the effectiveness of your safeguards
- (e) training, updated as the risk assessment changes
- (f)(3) periodically assessing your service providers
- (g) evaluate and adjust the program as things change
Every one of those is work somebody performs on a schedule. A five-person office almost never has (c)(8) — a record of who touched what — without an agent running on the machines.
The rule does not say who performs that work. You can. An employee can. A service provider can. It does not require you to hire an IT company, and anyone telling you it does is selling. What the rule doesn’t contemplate is nobody performing it while the plan says otherwise.
That is the only reason there is a managed IT tier on this page. When your plan says MFA is enforced, disk encryption is on, and user activity is logged, we would rather that be true because we turned it on and we watch it than because you told us it was, on a phone call, in October.
Be exact about what that does and does not buy you. Running the controls does not make you compliant, any more than the document does. Compliance is a determination someone makes about your firm’s actual practices, and no vendor gets to declare it in advance. What we can do is make the sentences in your plan true on the day they are written, still true six months later, and backed by a dated record of when we checked.
What we send you
- A findings report
- The external scan — DNS, SPF, DKIM, DMARC, TLS, security headers, certificate-transparency inventory, credential-breach exposure — plus what we saw on site. In English, with the severity of each item and what it would take to fix.
- The risk assessment
- Written from those findings. This is the element the blank template leaves for you.
- The WISP itself
- With each section mapped to the element of §314.4 it answers — and where §314.6 lifts an element for your firm, we mark it covered, not required, rather than let you believe the rule demanded it of you.
- An incident response plan
- §314.6 excuses this one below 5,000 consumers. We include it anyway, at no extra cost, because the version of this you want is the one that already exists at 6 p.m. on a Friday.
- A Qualified Individual designation letter
- Naming both the QI and the senior person at your firm who oversees that role.
- A vendor oversight addendum
- You can send it to your tax software, portal, backup and hosting providers.
- An evidence log
- Every element tied to either a scan observation or a dated attestation from your intake, with the history kept. Under pressure, what someone asks you for is evidence, not prose. That’s why we build it from a pipeline instead of a Word file.
Five business days from completed intake. Intake is a short form, a photo checklist of your equipment and workspace, and about forty-five minutes on the phone. If your office is on the corridor between Richfield and Spanish Fork, I’ll do that walkthrough in person instead — it’s faster, and I’ll catch things a photo checklist won’t.
Annual update $297/yr, or kept current for you while monitoring or managed IT is active.
One note worth having, since this audience counts. §314.4 now runs (a) through (j) — a tenth lettered paragraph, the FTC notification duty, was added in November 2023 and took effect May 13, 2024. If a WISP page still advertises nine, it was written before the amendment.
Pricing
These are the published prices. They’re the same numbers on the rest of the site, and they don’t change because you arrived through an ad. If a price on your quote doesn’t match a price on this page, ask me why before you sign it.
You can buy the WISP by itself, and we’d rather you did that than take a bundle you don’t want. A plan built from a scan of your firm is still the most accurate one you can get, and everything else can be added later or never. If the IT isn’t for you, say so and I’ll write the plan around what you actually run — including, in plain language, the ongoing work in §314.4(c) and (d)(1) you’re taking on yourself, and a written spec your own IT person can work from, at no charge. A plan that honestly describes a firm doing its own maintenance is worth more than one that quietly describes a firm doing none.
WISP
from $897
one-time, quoted per firm · annual update $297/yr
The findings report, the risk assessment written from it, the plan, the incident response plan, the QI designation letter, the vendor oversight addendum, and the evidence log. Five business days from completed intake.
For a firm that wants the most accurate document it can get and intends to run its own IT, or already has someone who does.
WISP + Security Monitoring
$1,497
first year, then $99/mo (or $990/yr)
The packet, plus recurring external scanning of your public-facing posture, with every rescan dated into your evidence log, and the annual update kept current for you.
Honest scope, because you’ll check it: §314.4(d)(1) requires you to “regularly test or otherwise monitor the effectiveness of the safeguards’ key controls, systems, and procedures, including those to detect actual and attempted attacks on, or intrusions into, information systems.” Recurring external scanning is real evidence toward the first half of that sentence for your externally reachable systems. It does not address the intrusion-detection half — that needs something running on your machines, which is the next tier. And it is not the “continuous monitoring” alternative in §314.4(d)(2), which contemplates detecting changes across your information systems rather than your public face. We’d rather scope it than let you assume.
For a firm whose day-to-day IT is genuinely handled, but that wants the plan re-checked rather than reframed.
WISP + Managed IT
What I’d recommend$897 one-time
plus Managed IT from $299/mo
Tiny Office $299/mo flat, up to 5 devices · Essentials $125/user/mo, $500/mo minimum · Complete $165/user/mo, $750/mo minimum. The minimum is a floor for offices of four or fewer; above that you pay the per-user rate. Month to month, no long-term contract.
The packet, plus we run the machines: patching, managed antivirus, verified backups, MFA rollout, and endpoint logging. That is the §314.4(c) work your plan describes — (c)(2) inventory that stays current, (c)(3) encryption verified rather than asserted, (c)(5) MFA enforced as staff and software change, and (c)(8) logging who touched what, which a five-person office almost never has without an agent on the endpoints. The plan and the controls come from the same place, so the sentences in it are checkable and dated. Complete adds scheduled on-site visits and vendor management, including your copier company.
I’m calling this a recommendation, not a bestseller. Pairing the two is new here and I’m not going to invent a popularity claim.
For a firm that read §314.4(c), looked at its own office, and concluded honestly that it cannot currently say those sentences are true.
Qualified Individual retainer — $297/mo
The rule requires every covered firm to designate a Qualified Individual under §314.4(a), and it expressly allows that person to work for a service provider — so a three-person firm doesn’t have to invent one internally. We’ll fill the role: overseeing and enforcing the program, running the periodic reassessment under (b)(2), and producing the written report.
The limit, stated plainly because a careful partner will ask: §314.4(a)(1) keeps responsibility for compliance with your firm and requires you to designate a senior member of your own staff to direct and oversee us. Nothing we sell moves that off your firm, and any vendor implying otherwise is describing an arrangement the rule doesn’t permit. It goes in the engagement letter in writing. Note also that §314.6 excuses the QI’s annual report below 5,000 consumers — so if you’re under it, treat that report as evidence you’d otherwise not have, not a box the rule makes you tick.
The argument our first tax-firm client made before we did
The first tax firm we did this for is our first paying FTC Safeguards engagement.
Partway through the draft, the senior partner stopped and said he was not willing to accept risk on paper. If the plan was going to say his firm did something, he wanted the firm to actually be doing it. He asked for the IT side — monitoring and backup — specifically so the written plan would be true on the day he signed it.
Nobody pitched him that. He got there himself, reading the same rule you’re reading.
We’re not going to tell you that firm is now “compliant.” That isn’t a thing a vendor gets to declare, and you’d be right not to believe us. We’re telling you what happened.
Who you’re dealing with
Kendall Sorenson. Richfield, Utah. Kovyr is one technician, and the technician is me.
Weekdays I’m a copier technician, which means I’m already inside offices like yours most weeks — under the desk, behind the machine, looking at the network closet nobody has opened since the last guy retired. It’s an unglamorous credential and it’s the one no national WISP vendor and no remote MSP has.
Two things I notice because I’m standing there. The multifunction copier in your file room very likely stores images of what it scans and prints on an internal drive; most models do. Whether yours does — and what happens to that drive when the lease ends and the machine goes back on a truck — is a §314.4(c)(6) disposal question, and I can answer it off the model number on the front of it. And nobody writing your plan from a phone call is going to notice where your shared drive physically lives or who set up the router.
Now the honest side of one person, because you’re going to ask and I’d rather answer first.
There is no bench behind me. If you need someone at 6 a.m. on March 15 and I’m already at another office, you’re waiting — and I’ll tell you you’re waiting instead of opening a ticket and going quiet. What I can control is that being tied to me is never a trap. You hold your own administrator credentials. Your plan, risk assessment and inventory are delivered as files you own, in formats any other provider can pick up. There is no portal. If you outgrow me, or you don’t like me, you leave with everything.
I built the scanner and the document pipeline that produce your packet. If something in your plan is wrong, there is one person to call, and he answers his own phone.
Remote works fine for the plan itself and we do it for firms across the state. If you’re anywhere between Richfield and Spanish Fork, I’d rather come to you.
What we are not
Because you’re going to ask, and because you should.
- Not IRS-approved.
- Neither is anyone else. The IRS approves no vendor and reviews no plan, and there is nothing about a WISP to submit with your PTIN renewal. Any page advertising an “IRS-approved” or “IRS-certified” WISP, or a “certificate of compliance,” is describing something that does not exist.
- Not legal advice.
- Kovyr produces compliance documentation reflecting your firm’s information and our external observations. Reading a regulation to you carefully is not the same as advising you on it, and where the two diverge you should talk to your own counsel.
- Not a penetration test.
- §314.2(n) reserves that term for a methodology where assessors “attempt to circumvent or defeat the security features of an information system.” We enumerate what’s exposed. We’ll keep calling it a scan.
- Not a compliance guarantee.
- No document we write and no service we run makes your firm compliant. What we produce is an accurate plan and a dated record.
- Not insured or audited the way a large vendor would be.
- Kovyr does not carry bound errors-and-omissions coverage and is not SOC 2 audited. If either is a hard requirement for your firm’s vendors, tell me now and I’ll say so rather than waste a meeting. §314.4(f) makes assessing your service providers your job, so you’d have arrived at this question anyway — and once you hire us, that includes us. Send the questionnaire; we’ll answer it.
- Not taking your liability.
- §314.4(a)(1) is explicit: where the Qualified Individual works for a service provider, your firm “shall retain responsibility for compliance with this part,” and you designate a senior member of your own staff to direct and oversee us.
- Not quoting you a fine.
- You’ll see per-violation dollar figures on other pages. There are at least four different ones circulating, they contradict each other, and the FTC’s own Safeguards Rule guidance page prints none of them — so we’re not going to sell you with a number we can’t source.
- Not able to tell you about your state.
- Some states impose their own written-program obligations keyed to where your clients live rather than where your office sits. If you file across state lines, that’s worth checking before you assume this is the whole picture. I’d rather tell you I don’t know.
Questions
- Is this IRS-approved?
- No, and neither is anyone else. The IRS approves no vendor and no plan — there is nothing to submit and nothing to certify. Our packet is built to the FTC Safeguards Rule at 16 CFR Part 314, which is the rule Publication 4557 and Form W-12 point you to.
- I’m a sole practitioner with 40 clients. Do I really need one?
- Yes. There is no size floor anywhere in the rule. §314.2(h)(2)(viii) makes an accountant or tax preparation service a financial institution, §314.3(a) requires the written program, and §314.4(a) requires you to designate a Qualified Individual — none of which §314.6 waives. What size changes is the content: §314.3(a) scales safeguards to “your size and complexity.” A one-person plan is genuinely shorter. It still has to exist.
- Am I under the 5,000-consumer threshold?
- Possibly, and it’s worth working out rather than assuming — I’m not going to hand you an exemption on a web page. It counts consumers whose information you still maintain, not returns you filed this season, and prior-year files count while you hold them. Bring your retention practices to the call and we’ll count it together. Either way it never reaches §314.3(a): the written program is required at any size, and §314.6 waives exactly four sub-provisions of §314.4.
- Can I just use the free IRS template?
- Yes, genuinely. Publication 5708 has a real template starting on page 6, it’s free, and preparers write serviceable plans from it every year — most report it taking about two days. We’re not going to tell you it’s bad; the IRS wrote it. What it cannot do is check whether the sentences you put in it are true at your firm. That’s not a flaw, it’s what a template is. If you’d rather spend the two days, spend the two days.
- What’s the fine if I don’t have one?
- We won’t quote you one. There are at least four different per-violation figures circulating on vendor sites, they contradict each other, and the FTC’s own Safeguards Rule guidance page prints none of them. I also can’t point you to an FTC enforcement action against a five-person firm in central Utah, and I won’t pretend I can. The exposure that actually shows up for firms your size is your carrier and your clients — see the next question.
- What does this have to do with my cyber insurance?
- Your cyber or E&O application asks whether your firm requires multi-factor authentication. Your WISP will say you do. If both are true, you’re fine, and you now have two documents that agree with each other. If neither was ever checked against your actual systems, you’ve made the same statement twice and verified it zero times. In 2022 an insurer sued to rescind a cyber policy from inception, alleging the policyholder had represented on its application that it required MFA across email, remote access and endpoints when MFA in fact protected only the firewall; the parties stipulated to an order voiding the policy. That’s a real, public dispute over the accuracy of an application answer — not a prediction about your carrier, and I’m not going to make one. It is also the argument that closed our first tax client.
- Does the rule require an annual penetration test?
- For most firms this page reaches, no. That schedule lives in §314.4(d)(2), which §314.6 removes outright for firms under 5,000 consumers — and even where it applies it’s an either/or with continuous monitoring, not both. What survives at every size is §314.4(d)(1): regularly test or otherwise monitor whether your safeguards work, including detecting attacks and intrusions. Separately, what we run is a scan, not a penetration test, and §314.2(n) is the reason we’re careful about the word.
- What does the annual update cover, and is it worth $297?
- A re-scan, a review of what changed in your firm, and an adjustment of the program under §314.4(g), which requires you to evaluate and adjust in light of what your testing and monitoring found. Which is the catch, and it’s worth saying against our own interest: an annual update is worth very little if nothing re-checked the facts during the year — it just re-dates last year’s assumptions. That’s the honest case for monitoring, and the honest limit of an annual-only relationship.
- How long does it take, and what do you need from me?
- Five business days from a completed intake. The scan takes a minute, the intake form is short, and the call runs about forty-five minutes. If you’re on the corridor between Richfield and Spanish Fork, I’ll come to your office for the walkthrough.
- How many of these have you done?
- Not many, and I’m not going to inflate it. One tax firm has paid for the full engagement. What that buys you is my attention and a person who will answer for every sentence in your plan. What it doesn’t buy you is a long track record, and if that’s what you need, you should say so now.
- What happens if you’re sick, or busy, or gone?
- You wait, and I’ll say so rather than going quiet. I’m one person and there’s no bench behind me — that’s a real limitation and I’m not going to dress it up. What I can control is that you’re never stuck: you keep your own administrator credentials, your plan and inventory are files you own in portable formats, there’s no portal, and another provider can pick up where I left off. Ask me this on the call. You should.
- Do I have to buy the managed IT to get the WISP?
- No, and we’d tell you if the answer changed. $897 gets you the scan and the plan, and that’s a complete purchase. If you already have someone running your machines, we’ll write them a plain-language spec of exactly what the plan requires, at no charge. The IT tier exists because a document can’t perform (c)(5) MFA, (c)(8) logging, or (d)(1) monitoring on your behalf — not because we’ve bolted it to the front door.
- Does managed IT mean you can see my clients’ returns?
- Managed IT means administrative access to machines where client data lives. I don’t need to open returns and I won’t. Be precise about it rather than trusting me: I become one of your service providers under §314.4(f), so the access terms go in writing, they go in your plan, and you reassess me the same way you reassess your portal vendor. I’ll hand you the language to do it with.
PTIN renewal opens in October
Renewal opens in mid-October and your PTIN expires December 31. That’s the real deadline, and it’s the only one on this page. I’m not going to invent a second one.
Five business days from completed intake means a firm that starts now checks Line 11 with a plan that is already true.
Start with the scan if you’d rather — it’s free, it takes about a minute, you keep the result either way, and it’s the only honest way to find out whether this is urgent for you or not. Or if you already know, use this and I’ll call you.
Or call 435-201-2646 and ask me the hardest question you have about the rule. If I don’t know, I’ll tell you that too.
Kovyr Technology LLC produces compliance documentation reflecting your firm’s information and our external observations. It is not legal advice, not a penetration test, and not a certification. The IRS does not endorse or approve any vendor. Kovyr does not carry bound errors-and-omissions coverage and is not SOC 2 audited.
Kovyr Technology LLC · Richfield, Utah · 435-201-2646 ·kendall@kovyr.com