WISP Readiness Checker for Tax Preparers

Free · 20 questions · mapped to 16 CFR 314 and IRS Pub 5708 / 4557 · runs in your browser · not legal or tax advice

When you renew your PTIN, Form W-12 Line 11 asks you to confirm you are aware that paid preparers "are required by law to create and maintain a written information security plan". Answer 20 questions to see where your plan, and the evidence that it runs, has gaps.

Days until PTINs expire (31 December): –. Nothing you enter leaves this page.

Your practice

20 questions

Result

0%

What to work on

Scoring: "Yes, and I can show evidence" = 2, "Partly / no evidence" = 1, "No" or "Not sure" = 0. Items marked not required under 16 CFR 314.6 are left out of the score.

Keep the evidence in one place

The WISP Evidence Workbook (optional, $49 Solo / $99 Firm, Excel / Google Sheets) keeps the records behind each answer: MFA register, quarterly access reviews, training log, vendors, devices, incidents and a signed annual review. Or read the free WISP annual review checklist.

Sources (checked 9 October 2026)

Karuna Labs is not affiliated with the IRS or the FTC. This page is a self-check, not legal, tax, compliance or IT-security advice.

FAQ

Who is this for?
US paid tax return preparers, EAs, CPAs and small tax offices who want a quick self-check of their written information security plan (WISP) before renewing their PTIN.
Why does the PTIN renewal matter?
Form W-12 (Rev. October 2025) Line 11 asks preparers to confirm they are aware that paid tax return preparers are required by law to create and maintain a written information security plan. PTINs expire on 31 December each year, and the IRS says renewal generally opens in mid-October.
Does a high score mean my firm is compliant?
No. This is a self-check of 20 common evidence areas drawn from 16 CFR Part 314 and IRS Publications 5708 and 4557. It is not legal, tax or security advice, and it does not test your systems.
What changes if I have fewer than 5,000 clients?
16 CFR 314.6 says four elements, 314.4(b)(1), (d)(2), (h) and (i), do not apply to institutions that hold customer information on fewer than five thousand consumers. The checker marks the three related questions 'not required?' so you can decide; MFA, encryption, training and vendor oversight still apply.
Are my answers sent anywhere?
No. Everything runs in your browser tab. Nothing is uploaded or stored; closing the tab clears it. The CSV is created on your device.

Privacy: see the privacy page.