WISP proof check for CPA and tax firms

Before you sign, make sure your answers hold up.

Your PTIN renewal, your cyber insurance application and the cyber supplement to your E&O renewal all ask about your firm's security. This check scans your email domain, asks the 10 questions those forms turn on, grouped the way insurers group them, and shows which answers you can prove today, sized to your firm. Then take home a written security plan marked where you fall short.

WISP proof checkSAMPLE
6/10
Provable today
Hard to prove
MFA everywhereGap
Payment call-backsGap
Incident deadlinesNot sure
Staff trainingProven
10 questions · 2 scans

We use this to send your results and the tracker. No newsletter sign-up. Privacy policy

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
What the rules require

What a CPA firm has to be able to show in 2026

Dec 31
PTINs expire. Renewal asks you to confirm you know a written security plan is required by law.
Next business day
to report a security incident to the IRS if you are an authorized e-file provider
30 days
to notify the FTC after discovering a breach affecting 500 or more consumers
Immediately
Texas CPAs must notify affected clients in writing after a loss of client records, including a cyber breach (Board Rule 501.75)

Tax and accounting firms are financial institutions under the FTC Safeguards Rule. That means a written security program, a named person responsible for it, multi-factor authentication for anyone who accesses your systems, encryption, training and vendor oversight. Firms holding data on fewer than 5,000 consumers are excused from four items, not from the rest.

In Texas, a 2025 law (Business and Commerce Code chapter 542) protects firms under 250 employees from punitive damages after a breach, but only if they can show they implemented and maintained a qualifying cybersecurity program at the time. What qualifies depends on headcount. Cyber insurers ask the same questions, and the answers matter: in Travelers v. International Control Services (2022), the parties agreed the policy was void from the start after the application said MFA was in place and a ransomware attack showed otherwise.

How the check works: Yes means you could show the proof today. No and Not sure both count as gaps. If you are not sure, assume you could not prove it. The scans use public sources and your company domain only, and nothing is sent to anyone at your firm.

Your answers stay in your browser. If you ask for the proof pack, it arrives as a Word document built from your answers: your result, the rules for a firm your size, the deadlines, and a written security plan you can edit. This is a readiness tool, not legal advice.

FAQ

CPA firm security questions, answered

Yes. The rule defines "an accountant or other tax preparation service that is in the business of completing income tax returns" as a financial institution (16 CFR 314.2). It applies regardless of firm size.

Form W-12, line 11 asks you to confirm you are aware that paid tax return preparers are required by law to create and maintain a written information security plan. The whole form is signed under penalties of perjury. The IRS points preparers to Publications 5708 and 4557 for what the plan should contain.

Partly. Firms that hold customer information on fewer than 5,000 consumers are excused from four FTC requirements: the written risk assessment, penetration testing and vulnerability scans, the written incident response plan and the annual report. MFA, encryption, a Qualified Individual, training, vendor oversight and FTC breach notice still apply.

The Texas State Board of Public Accountancy amended Rule 501.75, effective April 1, 2026. As amended, it requires written client permission before disclosing client information to third parties, including contractors, subcontractors, subsidiaries and affiliates within or outside the United States, and it requires firms to notify affected clients in writing immediately after a loss of confidential client records, including a cybersecurity breach.

In June 2026 the IRS Office of Professional Responsibility warned that uploading client data to public AI tools risks unauthorized disclosure under IRC sections 6713 and 7216, and told practitioners to use secure, firm-approved AI. Check with your advisor on client consent before client data goes into any AI tool.

Your answers stay in your browser unless you ask for the proof pack. If you do, we keep your answers with your request so we can send it, and we never share them. The scans use public sources and your company domain only.

Ground truth. Not story.

Insurers and regulators ask for proof, not policies. We test the controls in your actual systems and show what holds up.

Since May 1, 2026, our forensic audits have prevented $2.2M in wire fraud, none of it flagged first by the client's IT team, managed service provider, bank or security tools.