Independent. Not affiliated with the FTC or the IRS. Every figure cites its primary source, with an as-of date.
WISP and FTC Safeguards Rule compliance, from the primary sources.
Safeguards Monitor is an independent publication for US tax professionals: solo preparers, CPA firms, enrolled agents, and bookkeepers. We cover the Written Information Security Plan (WISP) requirement and the FTC Safeguards Rule (16 CFR Part 314), and we cite the regulator for every figure we publish.
From the primary record
The rule that requires a written information security plan names tax preparers directly. This is the text.
Primary record
An accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution because tax preparation services is a financial activity listed in 12 CFR 225.28(b)(6)(vi) and referenced in section 4(k)(4)(G) of the Bank Holding Company Act, 12 U.S.C. 1843(k)(4)(G).
Verified July 13, 2026
The re-check log
Recently verified
Every figure on this site is pulled from the primary record on a schedule. This is the log of the most recent pulls.
- 2026-07-1316 CFR 314.2(h)(2)(viii) scope (eCFR)re-checked, unchanged
- 2026-07-1216 CFR 314.6 (eCFR)re-checked, unchanged
- 2026-07-1016 CFR 1.98 annual-adjustment cycle (eCFR)re-checked
- 2026-07-07IRS Publication 3112 (Rev. 11-2025) sanction levelsverified
- 2026-07-07Zirin Tax Co. v. United States, E.D.N.Y. No. 24-cv-01511docket verified
Guides
Start with your question.
Understand the rule
What 16 CFR Part 314 actually requires of a tax practice, who it covers, and who is exempt.
Build your WISP
The written information security plan the rule requires: what it must say, who imposes it, and how to build one.
Protect your EFIN
The IRS sanction chain, a real case, and the monitoring routine that catches EFIN theft early.
How we verify
Precision is the whole point.
- Primary sources only
- Every regulatory claim on this site is quoted from the primary source: the eCFR, the FTC, the IRS, or the Federal Register. Never paraphrased from memory.
- Dated and re-checked
- Every figure carries the date we last confirmed it and a re-verification schedule, because a rule or a number can change after it publishes.
- Honest about enforcement
- Where we can find no public record of an action, we say so plainly. We never inflate a penalty figure to make a point.
All guides
The Safeguards Rule
- 01
FTC Safeguards Rule for Tax Preparers
The FTC Safeguards Rule (16 CFR Part 314) applies to tax preparers as financial institutions under GLBA. What its nine elements require, who is covered, and who is exempt.
Checked July 17, 2026
- 02
FTC Safeguards Rule Exemptions
The FTC Safeguards Rule exemption for firms under 5,000 consumers (16 CFR 314.6): the exact four waived items, what stays required, and how the count works.
Checked July 17, 2026
- 03
IRS MFA Requirement for Tax Pros
The IRS MFA requirement for tax professionals: what 16 CFR 314.4(c)(5) actually requires, which systems it covers, and the Qualified Individual's written exception.
Checked July 18, 2026
WISP and IRS guidance
- 04
Who Needs a WISP? Written Information Security Plan
Who needs a WISP? The FTC Safeguards Rule covers any firm in the business of completing income tax returns. The full map: EAs, CPAs, bookkeepers, payroll, VITA.
Checked July 18, 2026
- 05
WISP for Tax Preparers: Written Information Security Plan
The WISP requirement for tax preparers: the FTC Safeguards Rule requires the written plan and the IRS presses it. What it says, who imposes it, how to build one.
Checked July 17, 2026
- 06
Free WISP Template: Written Information Security Plan
A free Written Information Security Plan template for tax preparers, adapted from IRS Publication 5708. Direct download in Word or PDF, no email required.
Checked July 17, 2026
- 07
IRS Publication 4557: What It Requires
IRS Publication 4557, Safeguarding Taxpayer Data: what the guide covers, what is legally binding behind it, how to work the checklist, and where the Security Six stands.
Checked July 17, 2026
- 08
IRS Publication 5708 Walkthrough
IRS Publication 5708, section by section: what the IRS WISP template asks, what it deliberately leaves blank, honest time estimates, and what changed in Rev. 8-2024.
Checked July 17, 2026
- 09
PTIN Renewal and Form W-12 Line 11
Form W-12 Line 11, the PTIN renewal data security checkbox: the exact language, its evolution since 2019, and what the awareness attestation does and does not certify.
Checked July 20, 2026
EFIN and incidents
- 10
EFIN Suspension & Data Security
The IRS can suspend or revoke your EFIN over data-security failures, at its own discretion. How the sanction chain works, and what protects your EFIN.
Checked July 10, 2026
- 11
Tax Preparer Data Breach: What to Do
Who a tax preparer calls after a data breach, in what order, and the deadlines that actually exist. The IRS liaison first; then police, states, the FTC, and clients.
Checked July 18, 2026
State law and insurance
- 12
Massachusetts 201 CMR 17.00 Explained
What 201 CMR 17.00 requires, who it reaches, and what it adds beyond a federal WISP. One Massachusetts client is enough, and every regulatory claim here cites the primary text.
Checked July 19, 2026
- 13
NY SHIELD Act for Tax Preparers
The NY SHIELD Act for tax preparers: what GBS 899-bb requires, the small-business test read correctly, and the GLBA deemed-compliance shortcut, from the statute.
Checked July 19, 2026
- 14
Cyber Insurance and Your Written Information Security Plan
Do cyber carriers require a WISP? What applications ask in writing, what the Travelers rescission case shows, and how to answer an application you can stand behind.
Checked July 19, 2026