WISP compliance checklist Connecticut CPA firms

WISP Compliance Checklist for Connecticut CPA Firms — 2026 Guide

Every CPA firm that handles client tax data is legally required to have a Written Information Security Plan — and most don’t. This WISP compliance checklist for CPA firms breaks down exactly what the FTC Safeguards Rule and IRS Publication 4557 require — in plain English, without the legal jargon. Use this checklist to assess your firm’s current compliance status and identify exactly what needs to be fixed. At MR. Computer, LLC we help CPA firms implement every item on this list through our managed IT and compliance services.

What Is a WISP and Who Needs One?

A Written Information Security Plan is a formal document that describes how your firm protects client financial data. Under the FTC Safeguards Rule and IRS Publication 4557 — every tax preparer and CPA firm that handles client financial information is required to have one — regardless of firm size. When you renew your PTIN each year you are confirming awareness of this requirement. Falsely claiming compliance is considered perjury and can result in PTIN suspension.

The consequences of non-compliance are serious — FTC fines up to $100,000 per violation per day, personal liability up to $10,000 for firm partners, PTIN suspension, and public breach reports that clients can find on Google. If your firm suffers a breach affecting 500 or more clients — you must notify the FTC within 30 days and that report becomes publicly available.

WISP Compliance Checklist for CPA Firms — 2026

Work through each section below. Every unchecked item is a compliance gap that needs to be addressed.

Section 1 — Governance & Qualified Individual

  • ☐ A specific person is designated as the Qualified Individual (QI) responsible for your information security program
  • ☐ The QI’s name and role is documented in writing in your WISP
  • ☐ Your WISP document exists, is signed, dated and stored securely
  • ☐ Your WISP has been reviewed and updated within the past 12 months

Section 2 — Risk Assessment

  • ☐ A written risk assessment has been completed within the past 12 months
  • ☐ The assessment identifies where client data is stored and transmitted
  • ☐ The assessment identifies internal and external threats to client data
  • ☐ Risk management decisions are documented in writing

Section 3 — The IRS Security Six

The IRS requires every CPA firm to implement these six specific technical controls:

  • Antivirus software — installed and actively updated on ALL devices
  • Firewall — protecting your network perimeter
  • Multi-factor authentication (MFA) — enabled on ALL systems handling client data including email, tax software and remote access
  • Drive encryption — all devices containing client data are fully encrypted
  • Encrypted data backup — automated backups running and tested regularly
  • VPN — required for all remote access to firm systems

Section 4 — Access Controls

  • ☐ Access to client data is limited to staff with a legitimate business need
  • ☐ Access rights are reviewed when staff join, change roles or leave the firm
  • ☐ Strong password policies are enforced across all systems
  • ☐ All default passwords on devices and software have been changed
  • ☐ Administrative privileges are limited to necessary personnel only

Section 5 — Data Backup & Recovery

  • ☐ Backups are encrypted both at rest and in transit
  • ☐ Backup restoration has been tested within the past 6 months with documented results
  • ☐ Backups are stored offsite or in the cloud — not only on local devices
  • ☐ A data retention and secure destruction policy is documented and followed

Section 6 — Employee Training

  • ☐ All staff have received security awareness training within the past 12 months
  • ☐ Training records are documented — dates, attendees and topics covered
  • ☐ Staff know how to recognize phishing emails and social engineering attacks
  • ☐ Staff know who to contact if they suspect a security incident

Section 7 — Vendor Oversight

  • ☐ All vendors with access to client data are identified in your WISP
  • ☐ Written contracts with vendors require them to maintain appropriate security
  • ☐ Vendor security practices are reviewed at least annually

Section 8 — Incident Response & FTC Breach Notification

  • ☐ Your WISP includes a breach response procedure with specific steps
  • ☐ Staff know who to contact internally if a breach is suspected
  • ☐ FTC breach notification procedures are documented — 30 day window for 500+ affected clients
  • ☐ Your firm knows how to submit a breach report at ftc.gov

Small Firm Exemption — Under 5,000 Client Records

Good news for smaller CPA practices — firms with fewer than 5,000 consumer records qualify for the small firm exemption under Section 314.6 of the FTC Safeguards Rule. This means you are exempt from four specific requirements:

  • Annual penetration testing
  • Bi-annual vulnerability scans
  • Formal written incident response plan
  • Annual written report to board or senior officer

However — small firms still must have a WISP document, MFA on all systems, encrypted backup, access controls, employee training, vendor oversight and FTC breach notification procedures. The exemption removes the most complex requirements — but the core security controls are still mandatory.

How Did Your Firm Score?

Count up your unchecked items:

  • 0 gaps — congratulations! Your firm is fully compliant.
  • 1-5 gaps — your firm has minor compliance gaps that should be addressed soon.
  • 6-10 gaps — your firm has significant compliance exposure. Address these before your next PTIN renewal.
  • 10+ gaps — your firm needs immediate attention. The risk of FTC enforcement, data breach, and PTIN suspension is real.

The Most Common WISP Gaps We Find In CPA Firms

After working with accounting firms throughout Connecticut we consistently see the same compliance gaps:

  • No MFA on email — the single most common gap and the easiest for hackers to exploit
  • Untested backups — having a backup isn’t enough — it must be tested and documented
  • Generic WISP template — a downloaded template that doesn’t reflect your actual systems won’t pass an audit
  • No vendor documentation — most firms can’t name all their vendors with access to client data
  • WISP never updated — a WISP from 2022 with no revision history will not satisfy a 2026 audit

Get a Professional WISP Compliance Assessment

Working through this checklist is a great first step — but a self-assessment can only go so far. MR. Computer, LLC offers a professional $250 WISP Compliance Assessment specifically designed for CPA firms and accounting practices. Here’s what it includes:

  • Complete IT security audit of your firm’s technology environment
  • Review of your existing WISP — or creation of a new one if needed
  • IRS Security Six compliance check
  • Gap analysis identifying exactly what’s missing
  • Written Report of Findings — a professional document you can keep on file
  • Recommended remediation plan with clear next steps

Based in Wallingford, CT — we serve CPA firms and accounting practices throughout Connecticut and surrounding states. Most assessments are completed within one week.

Call us at (203) 269-1739 to schedule your WISP compliance assessment. We help CPA firms get compliant quickly, affordably and without the headache.