FTC Safeguards Rule · IRS Publication 5708 · 2027 filing season prep is open Questions: hello@shieldsheet.com
ShieldSheet

ShieldSheet for tax & accounting firms

Your written security plan, done before tax season.

Every tax and bookkeeping firm needs a Written Information Security Plan under the FTC Safeguards Rule. Pay, answer a 15-minute intake, and get a plan mapped to IRS Publication 5708, ready to sign within 48 hours.

Plan templates written and reviewed by a cybersecurity professional (M.S., Cybersecurity) · Word + PDF · No taxpayer data collected

Written Information Security PlanRev. 2026-1

Sample Tax & Accounting LLC

Prepared under 16 CFR Part 314, structured after IRS Pub 5708

  1. § 1Purpose & scopedone
  2. § 2Qualified Individualdone
  3. § 3Risk assessmentdone
  4. § 4Safeguards & MFAdone
  5. § 5Service providersdone
  6. § 6Incident responsedone
Ready to sign
Qualified IndividualDate
Form W-12

Every PTIN application and renewal asks preparers to acknowledge the written security plan requirement.

IRS · line 11
30 days

Deadline to notify the FTC after a breach exposing unencrypted data of 500 or more consumers.

16 CFR 314.4(j) · since May 2024
48 hours

Finish the intake and your plan is delivered within 48 hours, in Word and PDF, with a short list of gaps to close.

Word + PDF · gap list included

Built on the published guidance

FTC Safeguards RuleIRS Pub 5708IRS Pub 4557Gramm-Leach-Bliley ActNIST CSF 2.0CIS Controls v8

The ShieldSheet approach

Six things the Safeguards Rule asks of your firm, handled in one plan

Each section of your plan answers a specific element of 16 CFR 314.4. Pick one to see what we write and what you get.

One person, the Qualified Individual, oversees the program. In a small firm that's usually the owner.
A written look at where client data lives in your office and what could realistically go wrong.
Access control, encryption, multi-factor authentication, secure disposal, and change management.
Security awareness for everyone with access, and a record of how you check your software and IT providers.
What happens in the first hour, the first day, and the first 30 days after an incident.
A yearly review and a short written report to the owner. We schedule the refresh for you.

Solutions

One engine, three ways to use it

ShieldSheet drafts security documents from what's true about an organization, cites every answer, and flags what it can't confirm.

Inside the plan

Written for your office, section by section

These excerpts come from a sample plan. Yours names your software, your staff count, and your vendors. Anything we can't confirm is flagged for you.

Industries

The Safeguards Rule covers more businesses than most people think

Any non-bank business that handles consumers' financial information falls under it. We start with tax and accounting, and build plans for the rest on request.

Available now

Tax preparers

Seasonal and year-round offices, PTIN holders, EFINs.

Available now

CPA & bookkeeping

Payroll, bookkeeping, and advisory firms with client ledgers.

On request

Mortgage brokers

Loan files, credit reports, and borrower documents.

On request

Auto dealers

Dealers that arrange financing or leasing.

On request

Non-bank lenders

Consumer and small-dollar lenders, check cashers.

On request

Collection agencies

Debtor records and payment information.

On request

Investment advisors

Advisors not registered with the SEC.

On request

Real estate appraisers

Appraisal files tied to consumer loans.

The cost of getting it done

Compare writing it yourself, hiring it out, and ShieldSheet

Move the sliders to match your firm. The defaults are examples, not quotes.

What an hour of your time is worth in season.
Reading Pub 5708, drafting, and checking your setup.
Enter a real quote if you have one.

First-year cost, including your time

Write it yourself
Hire a consultant
ShieldSheet

saved in the first year compared with the next-cheapest option. ShieldSheet includes $149 plus about 30 minutes of your time for the intake and review.

Consultant figure assumes about one hour of your time to brief them.

Pricing

Clear prices. Cancel any time.

Most firms

WISP for your practice

$149per year
  • Full written plan, § 1–8, plus appendices
  • Tailored to your software, staff, and vendors
  • Word and PDF, ready to sign
  • Gap list with practical next steps
  • Yearly refresh before tax season
Get your WISP

After checkout you go straight to your dashboard to start the intake.

Ongoing

Safeguards care plan

$49per month
  • Everything in the WISP
  • Yearly risk assessment refresh
  • Annual written report to the owner
  • Training and incident logs kept current
  • Help when an insurer or client sends a security questionnaire
Start the care plan
For IT providers

White-label partner

$99per plan
  • Your logo and contact details on every plan
  • You set the client price
  • Plans delivered with your branding
  • Security questionnaires from $150
  • No minimums, no monthly fee
Become a partner

ShieldSheet partner program

Your accounting clients need this every year. Deliver it under your name.

When a client asks their IT provider for a security plan, you shouldn't lose two days to it. Send us the intake, and we return a finished plan with your branding. You keep the relationship and the margin.

Talk to us about partnering
01Client completes a 15-minute intake15 min
02ShieldSheet prepares the planwithin 48 h
03You deliver it with your logo$99 to you
04Yearly refresh, same termsrecurring

Frequently asked questions

What firms usually ask

Do tax preparers really need a written security plan?

Yes. Tax and accounting firms are financial institutions under the FTC Safeguards Rule, which requires a written information security program. IRS Publication 5708 explains this and gives a sample structure, which our plans follow.

Is this a template?

No. Your answers shape every section: the software you use, who has access, where files are stored, and which vendors you rely on. Anything we can't confirm is flagged for you to check instead of filled in with a guess.

Do you need access to my client files?

No. The intake asks how your office works, never for taxpayer data. Please don't send us any.

Who stands behind the plan?

Every section template was written and reviewed by a cybersecurity professional with a master's degree in cybersecurity. Your plan is assembled from those reviewed templates and your answers. Any control you didn't confirm is flagged as a gap, never claimed.

What do I get at the end?

Your plan in Word and PDF, appendices for assets, vendors, training, and incidents, and a short list of gaps to close first.

I already have a WISP. Can you update it?

Yes. Send your current plan with the intake and we'll bring it in line with how your office works today, at the same price.

What if we have a breach?

Your plan includes the response steps and the FTC notice rule for incidents involving 500 or more people. Care plan clients also get help working through it.

Can my IT provider deliver this for me?

Yes. Many firms get their plan through their IT provider, who resells ShieldSheet under their own name.

Is this legal advice?

No. We prepare the plan from security best practice and the published guidance. For questions about your legal obligations, talk to your attorney.

Get your plan on file before the first return of the season.

Questions first? Write to hello@shieldsheet.com and a person will answer within one business day.

Get your WISP · $149