A fillable Written Information Security Plan for a US tax, accounting or bookkeeping practice of roughly 3 to 25 people. Every requirement cites the section it comes from, so you can check it against the regulation instead of trusting a template.
Email it to yourself, or skip the form and download it directly — the file is the same either way.
We email you the template and occasional notes on the Safeguards Rule. No sharing, no reselling, unsubscribe in one click.
Saved. The template is below — bookmark this page, the link does not expire.
Fourteen sections following the structure of the FTC Safeguards Rule, plus the six appendices that turn a document into a working program.
If your firm holds information on fewer than 5,000 consumers, four requirements do not apply to you (16 CFR 314.6). They are labelled, so you can delete them instead of pretending to do them.
Appendix A is the part almost no firm has: every application that touches client data, where it stores it, who can reach it, and whether MFA is on. Half the work of compliance is this table.
Where is our data stored, who at your company can read it, how long does a full export take. Ask them before you sign, not after a breach.
Who to call, in what order, with the deadlines attached — including the FTC's 30-day rule for events involving 500 or more consumers.
The IRS's short list — anti-virus, firewall, MFA, backup, drive encryption, VPN — as a table you tick, with room for the product names an examiner will ask for.
Training log, disposal log, incident log, off-boarding checklist. Training that was not written down did not happen.
Checked against the primary sources on 8 September 2026, not recalled from a blog post. All of these are free to read.
| Statement in the template | Source |
|---|---|
| Tax and accounting professionals are financial institutions regardless of size | IRS Pub 5708 |
| The nine program elements | 16 CFR 314.4 |
| Dispose of customer information no later than two years after last use | 16 CFR 314.4(c)(6) |
| Notify the FTC of events involving 500+ consumers within 30 days | 16 CFR 314.4(j)(1) |
| Fewer than 5,000 consumers: four requirements do not apply | 16 CFR 314.6 |
| PTIN holders attest to the WISP requirement | Form W-12, line 11 |
Because filling in Appendix A is how most firms discover where their client data actually lives — and that is the question Ettex exists to answer. Ettex is a local-first office suite for small practices: documents, spreadsheets, mail and storage that keep working when the internet does not, from $9 per seat. No obligation, and the template is complete without us. See what it is →