16 CFR Part 314 · IRS Publication 5708

A WISP template you can actually finish this afternoon

A fillable Written Information Security Plan for a US tax, accounting or bookkeeping practice of roughly 3 to 25 people. Every requirement cites the section it comes from, so you can check it against the regulation instead of trusting a template.

10 pages, 6 appendices Under-5,000 exemptions marked PDF and editable DOCX

Get the template

Email it to yourself, or skip the form and download it directly — the file is the same either way.

We email you the template and occasional notes on the Safeguards Rule. No sharing, no reselling, unsubscribe in one click.

Here it is

Saved. The template is below — bookmark this page, the link does not expire.

What is in it

Fourteen sections following the structure of the FTC Safeguards Rule, plus the six appendices that turn a document into a working program.

The exemptions, marked

If your firm holds information on fewer than 5,000 consumers, four requirements do not apply to you (16 CFR 314.6). They are labelled, so you can delete them instead of pretending to do them.

A system inventory

Appendix A is the part almost no firm has: every application that touches client data, where it stores it, who can reach it, and whether MFA is on. Half the work of compliance is this table.

Seven questions for vendors

Where is our data stored, who at your company can read it, how long does a full export take. Ask them before you sign, not after a breach.

An incident page worth having

Who to call, in what order, with the deadlines attached — including the FTC's 30-day rule for events involving 500 or more consumers.

The Security Six checklist

The IRS's short list — anti-virus, firewall, MFA, backup, drive encryption, VPN — as a table you tick, with room for the product names an examiner will ask for.

Logs that prove it happened

Training log, disposal log, incident log, off-boarding checklist. Training that was not written down did not happen.

Where every claim comes from

Checked against the primary sources on 8 September 2026, not recalled from a blog post. All of these are free to read.

Statement in the templateSource
Tax and accounting professionals are financial institutions regardless of sizeIRS Pub 5708
The nine program elements16 CFR 314.4
Dispose of customer information no later than two years after last use16 CFR 314.4(c)(6)
Notify the FTC of events involving 500+ consumers within 30 days16 CFR 314.4(j)(1)
Fewer than 5,000 consumers: four requirements do not apply16 CFR 314.6
PTIN holders attest to the WISP requirementForm W-12, line 11
This template is general information, not legal advice. The IRS publishes its own sample plan inside Publication 5708; this is a companion to it, adding the inventories, logs and vendor questions that the sample leaves to you.

Why a software company is giving this away

Because filling in Appendix A is how most firms discover where their client data actually lives — and that is the question Ettex exists to answer. Ettex is a local-first office suite for small practices: documents, spreadsheets, mail and storage that keep working when the internet does not, from $9 per seat. No obligation, and the template is complete without us. See what it is →