FOR TAX, ACCOUNTING & BOOKKEEPING FIRMS
FTC Safeguards Rule Readiness Review for CPA, Tax and Accounting Firms
The work is vendor-neutral and focused on what leadership can verify. You receive a clear view of where the firm stands, what the evidence supports, and what needs attention.
THE PROBLEM
A WISP on File Is Not the Same as a Program That Holds Up
Many firms have a written security plan somewhere. It may have come from a template, a software tool, an industry association, or a one-time purchase, but when was the last time it was compared against the systems, procedures, contracts, training, and safeguards the firm currently uses.
That gap often stays invisible until someone asks for evidence. The request may come from a cyber insurer, a client, a regulator, a business partner, or an investigation following a security incident.
For paid tax return preparers, the current Form W-12 also asks whether the applicant is aware that paid preparers are legally required to create and maintain a written information security plan. It does not ask the preparer to certify that every safeguard is in place, but it places the responsibility directly in front of the applicant.
The question this review answers is practical and direct. Does your written program match what your firm actually does, and what can the available evidence support?
THE THRESHOLD TRUTH
Fewer Than 5,000 Consumers Does Not Mean Fully Exempt
A covered financial institution that maintains customer information concerning fewer than 5,000 consumers is exempt from four specific Safeguards Rule provisions. It is not exempt from the Rule as a whole.
The exception applies to the following:
- Detailed written risk assessment requirements
- The prescribed information-system testing requirements
- The written incident response plan requirement
- The written annual Qualified Individual reporting requirement.
The firm remains responsible for the other applicable parts of the Rule.
Smaller covered firms still need:
- An accountable Qualified Individual
- A risk-based written information security program with appropriate safeguards
- Employee security training
- Service provider oversight
- Ongoing testing or monitoring
- A program that is reviewed and adjusted as circumstances change
Individual requirements may also contain alternatives or exceptions that must be evaluated based on the firm’s circumstances.
This review examines the firm’s activities, customer information, consumer count, and current program to identify the provisions that appear applicable. Questions requiring a legal interpretation are clearly identified for review with qualified counsel.
TWO LEVELS OF READINESS
Which Engagement Fits Your Firm?
The Safeguards Rule does not apply identically to every covered firm. The requirements change when a firm maintains customer information concerning 5,000 or more consumers, which is why I offer two clearly defined engagement paths.
Both begin with an independent review of your written program, current safeguards, responsibilities, vendors, and supporting evidence. The full-scope program adds the detailed documentation, incident response, technical testing, and annual reporting requirements that apply at the higher threshold.
Fewer than 5,000 Consumers
FTC Safeguards Rule Readiness Review
This engagement is designed for covered tax preparation firms and other accounting or bookkeeping practices that maintain customer information concerning fewer than 5,000 consumers.
Being below the threshold does not make a covered firm exempt from the Safeguards Rule. It removes four specific provisions: the detailed written risk assessment requirements, the prescribed penetration testing and vulnerability assessment requirements, the written incident response plan requirement, and the written annual Qualified Individual reporting requirement. The remaining applicable requirements still need to be addressed through a written, risk-based information security program.
The readiness review examines whether your WISP reflects your firm as it operates today. I compare the document with your systems, vendors, responsibilities, policies, training, and the safeguards that can actually be verified.
The goal is not to add unnecessary complexity to a smaller firm. The goal is to give leadership an honest, documented understanding of what is already working, what cannot currently be supported by evidence, and what should be addressed next.
What the review includes
- Applicability and threshold summary based on your firm’s activities, customer information, systems, and estimated consumer count. Questions that require a legal determination are identified for review with qualified counsel.
- WISP-to-practice comparison examining whether the written program accurately reflects the technology, procedures, vendors, responsibilities, and safeguards currently in use.
- Qualified Individual and leadership responsibility review confirming who is accountable for overseeing the program, what authority that person has, and how leadership remains involved.
- Evidence-based safeguard review covering the applicable administrative, technical, and physical requirements, including access controls, multi-factor authentication, encryption or approved alternatives, data retention, secure disposal, user activity monitoring, employee training, and change management.
- Data and system inventory review identifying where customer information is collected, stored, transmitted, accessed, and retained.
- Service provider oversight review examining whether key vendors are appropriately selected, contractually required to protect customer information, and periodically evaluated.
- Testing and monitoring review examining how the firm currently evaluates whether its safeguards are working. Smaller firms are exempt from the prescribed testing schedule, but they are not exempt from regularly testing or otherwise monitoring the effectiveness of their safeguards.
- Security event notification readiness review examining whether leadership understands the process for identifying and reporting a notification event involving the information of at least 500 consumers.
- Written risk assessment documenting the risks identified during the engagement and the safeguards currently relied upon. Although firms below the threshold are exempt from the Rule’s detailed written risk assessment provision, a documented assessment gives the WISP a clearer factual foundation and supports informed leadership decisions.
- Prioritized remediation roadmap organizing the findings by urgency, risk, and practical sequence so leadership can decide what should happen first.
- Leadership findings meeting where I walk through the results in plain language and answer questions about what the evidence supports, what remains uncertain, and which responsibilities need clearer ownership.
What you receive
You receive a point-in-time readiness report documenting the scope of the review, the evidence examined, the status of each applicable requirement, and the limitations of the assessment.
The report includes the written risk assessment, identified gaps, recommendations, and a prioritized roadmap. It gives leadership a clear record of what was reviewed and what the available evidence supported at that time.
What this engagement does not include
This review is not a certification, compliance guarantee, or legal opinion. It does not replace management’s responsibility for the firm’s information security program.
Technical remediation, penetration testing, vulnerability assessments, development of a written incident response plan, and ongoing Qualified Individual services are not included unless they are separately scoped. Those services may still be valuable because of risk, cyber insurance, client requirements, or the firm’s own governance standards, even when the specific full-scope provisions do not apply.
5,000 or More Consumers
FTC Safeguards Full-Scope Readiness and Testing Program
This engagement is designed for covered tax preparation firms and other accounting or bookkeeping practices that maintain customer information concerning 5,000 or more consumers.
At this threshold, the firm is subject to the complete set of Safeguards Rule provisions. In addition to the core program requirements, the firm must address the detailed written risk assessment, prescribed information-system testing, written incident response planning, and written annual Qualified Individual reporting requirements.
Because these responsibilities include recurring testing, annual reporting, program adjustments, and assessments following certain changes, this is structured as a 12-month program rather than a one-time document review.
The program combines independent governance and evidence review from N.O. IT Strategy with specialized technical testing performed through a cybersecurity testing partner. I remain responsible for coordinating the engagement, connecting the technical findings to the risk assessment and WISP, and helping leadership understand what the results mean for the information security program.
What the program includes
The Full-Scope Readiness and Testing Program includes every element of the Fewer Than 5,000 Consumers Readiness Review, along with the following expanded requirements.
- Detailed written risk assessment documenting the criteria used to evaluate and categorize security risks, the criteria used to assess the confidentiality, integrity, and availability of customer information and information systems, and how identified risks will be mitigated or accepted.
- Periodic risk reassessment process establishing when risks, safeguards, systems, vendors, and business changes will be reevaluated.
- Written incident response plan addressing the goals of the response, internal processes, roles and decision-making authority, internal and external communications, remediation, documentation, reporting, recovery, and post-incident review.
- Continuous-monitoring evaluation determining whether the firm has effective systems that detect, on an ongoing basis, changes that may create vulnerabilities.
- Risk-based annual penetration testing when the firm does not have effective continuous monitoring or another ongoing system that satisfies the Rule. The scope is determined each year using the risks identified in the written risk assessment.
- Vulnerability assessments at least every six months when the continuous-monitoring alternative is not satisfied. The testing plan also addresses the requirement for additional assessments after material operational or business changes, or when circumstances may materially affect the information security program.
- Technical findings coordination connecting penetration testing and vulnerability assessment results to the firm’s risk assessment, WISP, remediation priorities, and leadership decisions.
- Remediation tracking documenting how significant findings are assigned, addressed, accepted, transferred, or deferred by management.
- Written annual Qualified Individual reporting support organizing the status of the program, material risks, control decisions, service provider arrangements, testing results, security events, management responses, and recommended program changes.
- Leadership and governing-body review presenting the annual report to the appropriate board, equivalent governing body, or responsible senior officer.
- Annual governance and testing calendar documenting when risk reassessments, technical testing, vendor reviews, training, WISP updates, incident response reviews, and leadership reporting should occur.
- How the technical testing works
The program first determines whether the firm has effective continuous monitoring or another ongoing system capable of detecting changes that may create vulnerabilities.
When that alternative is not satisfied, the program includes an annual penetration test and vulnerability assessments at least twice during the year. The penetration test and scheduled vulnerability assessments are performed by a specialized cybersecurity testing partner under a documented scope.
Additional vulnerability assessments required because of material changes or new circumstances cannot always be predicted at the beginning of the year. The program identifies when an additional assessment may be necessary, and any testing beyond the scheduled scope is separately authorized before work begins.
Qualified Individual reporting
The Rule requires the Qualified Individual to report in writing, regularly and at least annually, to the board, an equivalent governing body, or the senior officer responsible for the information security program.
The report must address the overall status of the program and material matters such as risk assessment, risk management decisions, service provider arrangements, testing results, security events, management responses, and recommended changes. I organize the findings and supporting evidence so the firm’s designated Qualified Individual can make that report based on documented information.
When N.O. IT Strategy is separately engaged to serve as the Qualified Individual, that authority, accountability, reporting relationship, and ongoing scope are documented in a separate agreement. The firm and its leadership continue to retain responsibility for compliance and oversight of the program.
What you receive
You receive the readiness assessment, detailed written risk assessment, WISP-to-practice findings, technical testing reports, written incident response plan, remediation roadmap, testing and governance calendar, and annual Qualified Individual reporting package.
Leadership also receives scheduled findings reviews that connect the technical results to business risk, responsibility, and the decisions required to keep the program current.
What this engagement does not promise
This program is not a certification, legal opinion, or guarantee that a regulator, insurer, client, or court will reach a particular conclusion.
It provides an independent, evidence-based process for assessing the program, performing the applicable testing, documenting findings, and helping leadership make informed decisions. Questions that require legal interpretation are identified for review with qualified counsel, and management remains responsible for the firm’s compliance decisions.
INVESTMENT
A Readiness Review Sized to Your Firm
The Safeguards Rule applies to firms of very different sizes, from solo tax preparers to multi-location accounting practices. The investment should reflect the size and complexity of the firm rather than forcing every business into the same engagement.
The number of consumers whose information your firm maintains determines which regulatory requirements apply. The number of people, systems, locations, and service providers involved determines the scope and price of the review.
Firms Maintaining Information on Fewer Than 5,000 Consumers
Firms Maintaining Information on 5,000 or More Consumers
For firms maintaining information on fewer than 5,000 consumers, the readiness review is priced primarily by the number of people who can access customer information. This includes owners, employees, seasonal staff, and regular contractors.
Firms maintaining information on 5,000 or more consumers have additional requirements, including a written incident-response plan, regular penetration testing and vulnerability assessments, and annual reporting by the Qualified Individual.
Because the scope depends on the firm’s systems, locations, existing documentation, testing arrangements, and current security program, these engagements are priced after an initial discovery conversation.
Solo Practitioner
$1,500
Designed for a one-person practice with a relatively straightforward technology environment.
2–5 People
$2,500
Designed for small firms where several people share access to tax, accounting, payroll, or customer information.
6–10 People
$3,500
Designed for established firms with more user accounts, systems, vendors, and internal processes to evaluate.
11–20 People
Starting at $5,000
Firms of this size typically require a broader review of access controls, responsibilities, service providers, documentation, and data-handling practices.
More Than 20 People
Custom Scope
A short discovery conversation is used to confirm the environment and establish the appropriate scope.
Each engagement includes a structured intake, review of the firm’s existing Written Information Security Plan, evaluation of its principal systems and service providers, identification of material gaps, and a prioritized readiness report.
Initial Year
Generally $15,000–$20,000
Full-scope first-year engagements generally start at $15,000, with most falling between $15,000 and $20,000.
The initial year establishes the foundation of the program. It includes the readiness assessment, detailed written risk assessment, WISP-to-practice review, incident response plan, testing and governance calendar, remediation roadmap, technical findings coordination, and annual Qualified Individual reporting package.
The final investment depends on the firm’s systems, locations, existing documentation, service providers, testing arrangements, and the current condition of its information security program.
Following Years
Generally $8,000–$12,000 Annually
After the initial program has been established, subsequent-year engagements generally range from $8,000 to $12,000.
The annual scope focuses on keeping the program current. This includes reviewing material changes, updating the risk assessment and written program, coordinating the required testing cycle, tracking significant findings, reviewing service provider oversight, and preparing the annual Qualified Individual reporting package.
The exact annual investment depends on how much the firm and its technology environment have changed, the condition of the program, the findings from technical testing, and the amount of coordination required during the year.
Separately Priced Services
Third-party penetration testing and vulnerability assessments are priced separately based on the systems, locations, applications, and environments included in the approved testing scope.
Serving as the firm’s named Qualified Individual is also a separate ongoing engagement. The full-scope program can support an existing internal Qualified Individual without automatically transferring that accountable role to N.O. IT Strategy.
Technical remediation, software implementation, managed IT services, legal review, and testing required after unplanned material changes are not included unless specifically identified in the approved scope.
What the Listed Pricing Assumes
The listed pricing for firms maintaining information on fewer than 5,000 consumers assumes one legal entity, one principal location, a completed intake questionnaire, an existing Written Information Security Plan available for review, and no known active security incident.
The final investment may change when the firm has multiple locations, affiliated businesses, on-premises infrastructure, extensive contractor access, missing documentation, numerous service providers, or a more complicated technology environment.
A solo practitioner may still maintain information on more than 5,000 consumers, particularly when records have been retained for many years. Consumer count and firm headcount are evaluated separately during the intake process so the engagement follows the correct regulatory path.
WHAT THE REVIEW INCLUDES
What You Actually Get
- Applicability and scope summary based on your firm’s activities, customer information, systems, and consumer count. Questions that require a legal determination are identified for counsel rather than presented as settled legal conclusions.
- WISP-to-practice comparison examining whether the written program reflects the firm’s current systems, responsibilities, vendors, procedures, and safeguards.
- Evidence-based control review against the applicable FTC Safeguards Rule requirements, documenting what is implemented, what is partially supported, what could not be verified, and what appears to be missing.
- Written risk assessment documenting identified risks and providing a factual foundation for the firm’s information security program, even when the firm may qualify for the fewer-than-5,000-consumers exception to the Rule’s detailed written-assessment provision.
- Prioritized roadmap identifying what leadership should address first and organizing the work into a practical sequence.
- Leadership findings review where we walk through the results in plain language so decision-makers understand the firm’s current position, limitations, and next steps.
Each finding includes its status, the evidence reviewed, the relevant business context, and the applicable requirement or reference point. The report is designed to give leadership a clear record of what was reviewed and what the available evidence supported at that point in time.
CLEAR BOUNDARIES
What This Review Is Not
- It is not a guarantee of compliance and not a certification.
- It is not a legal opinion or a substitute for qualified legal counsel.
- It is not technical remediation, managed IT service, or software licensing.
- It is not a penetration test or vulnerability assessment unless that work is separately scoped.
- It is not an ongoing Qualified Individual service unless that responsibility is separately defined and contracted.
- It does not transfer management’s responsibility for the firm’s information security program.
This is an independent readiness assessment. It documents what the evidence supports, identifies gaps and limitations, and gives leadership a practical roadmap for deciding what happens next.
The firm remains responsible for its compliance decisions and information security program. Where coverage or interpretation is genuinely uncertain, the report recommends confirming the matter with qualified counsel.
INDEPENDENT OVERSIGHT
Your MSP May Already Be Doing the Work. This Verifies It.
Think of this review the same way you think about an independent financial audit. The person responsible for maintaining the books should not also be the person providing the independent opinion on whether they hold up. Your MSP may be doing excellent work, but leadership still benefits from someone outside that relationship verifying what is documented, what is actually being done, and what the evidence supports. Your IT provider may already handle much of the technical work described in your program. This review is not a replacement for the MSP, and it is not an assumption that the provider has failed.
The purpose is to determine whether the work being performed matches the written program and whether leadership has evidence supporting the safeguards it relies on. That can confirm that controls are working, identify documentation gaps, or uncover responsibilities that were never clearly assigned.
N.O. IT Strategy does not sell hardware or software, and the review is not conditioned on replacing your IT provider or purchasing a managed-services contract. The findings are based on the firm’s program, evidence, risks, and leadership responsibilities.
TIMING
The Time to Check Is Before Renewal Season
PTIN renewal open season generally begins in mid-October each year, and PTINs expire on December 31. The current Form W-12 asks paid tax return preparers to answer whether they are aware of the legal requirement to create and maintain a written information security plan.
The form does not ask applicants to certify that every safeguard is implemented. It does require the applicant to provide an accurate answer and to sign the complete application as true, correct, and complete.
A readiness review turns that annual reminder into a practical examination of the program behind the WISP. Firms that begin before fall have more time to collect evidence, clarify responsibilities, and address priority gaps before tax season.
RECOGNIZED REQUIREMENTS AND FRAMEWORKS
Built on the Rule, Supported by Recognized Standards
This review is anchored to the FTC Safeguards Rule in 16 CFR Part 314. IRS Publications 4557 and 5708 are used as tax-professional guidance for safeguarding taxpayer information and developing a WISP.
NIST Cybersecurity Framework 2.0 is used to organize cybersecurity risk and leadership responsibilities. CIS Controls are used as practical technical reference points where they help evaluate how safeguards are implemented.
The IRS publications, NIST CSF, and CIS Controls support the assessment method, but they do not replace the Safeguards Rule or create a certification of compliance.
REPLACE UNCERTAINTY WITH A CLEAR ANSWER
Know Where Your Firm Stands
Not knowing whether your written security program matches reality creates unnecessary stress for leadership. Start with a short conversation about your firm, what you handle, and what you already have in place. You will leave knowing whether a readiness review makes sense and what the next step should be.