Skip to main content
Pilot program now open · Built around IRS Pub 5708, 4557 & the FTC Safeguards Rule

WISP Compliance Software for Tax Preparers and Small Businesses

Generate, manage, and maintain your Written Information Security Program while tracking compliance requirements under IRS Publication 5708 and the FTC Safeguards Rule.

Built by cybersecurity professionals with real-world compliance and incident response experience.

No credit card requiredPilot program accessCompliance readiness, not legal advice
wispwolf.app/dashboard
Compliance Score
82B
▲ +6 this month
MFA Coverage
100%
Documented
Open Gaps
7
3 critical
Renewal
64d
On track
Compliance HealthPilot
MFA enforced on all adminsPASS
Conditional access policy documentedPASS
Backup retention ≥ 30 daysREVIEW
Annual WISP review signedPASS
IRS Publication 5708 Aligned
FTC Safeguards Rule 16 CFR Part 314
AES-256 Encrypted at Rest
Built by Cybersecurity Professionals
The Problem

A WISP is not supposed to be a one-time PDF

The FTC Safeguards Rule and IRS Publication 5708 describe an ongoing, living program—not a document you sign once and forget. Most firms get this wrong.

Outdated the day you save it

Your PDF can't reflect new hires, removed accounts, or last week's failed backup.

Annual review? What review?

FTC requires periodic risk assessments. A static document doesn't remind you—or prove you did it.

No evidence under audit

When the IRS or your cyber insurer asks for proof, screenshots aren't a defense.

Templates miss your stack

Generic templates ignore your Microsoft 365 tenant, your MFA posture, and your actual risk.

Why This Matters

Built directly on federal compliance requirements

WISPWolf maps every control to specific statutory and regulatory obligations—so you can show your work, not just check a box.

16 CFR Part 314

FTC Safeguards Rule

Requires covered financial institutions—including most tax & accounting firms—to develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards.

Source: Federal Trade Commission
IRS Pub 5708

Creating a Written Information Security Plan

The IRS requires all paid tax return preparers to create, maintain, and annually review a WISP to protect taxpayer data, with documented incident response and ongoing risk assessment.

Source: Internal Revenue Service
How It Works

From zero to audit-ready in under an hour

A guided path from intake to a continuously-monitored compliance program.

STEP 01

Tell us about your firm

5-minute intake: services, staff size, data systems, jurisdictions. No templates—your plan is generated for you.

01
STEP 02

AI drafts your WISP

Mapped to FTC Safeguards Rule + IRS Pub 5708. Administrative, technical, and physical safeguards in plain English.

02
STEP 03

Connect Microsoft 365

Read-only connection pulls live MFA, conditional access, and tenant posture as evidence behind every control.

03
STEP 04

See your live score

A continuously updated letter grade and gap list. Know exactly what's strong and what needs attention.

04
STEP 05

Stay renewed, automatically

Annual review reminders, change tracking, signed attestations, and audit-ready exports.

05
The Dashboard

Compliance you can actually see.

A live view of your WISP — score, gaps, evidence, and what's due next. Updated continuously, not once a year.

app.wispwolf.com/dashboard
Acme Tax & Co.
Compliance Score
82B
+6 this month
Risk
Low–Mid
Last review
Jun 2026
Renewal
64 days
WISPWolf Verified
Evidence-backed readiness · Reviewed Jun 2026
Compliance Health

Controls organized in one place

Pilot · Automated evidence coming soon
  • MFA enforced on all admins
    Attested · current period
    Pass
  • Conditional access policy documented
    Attested · current period
    Pass
  • Encryption enabled (AES-256)
    Attested · Jun 18
    Pass
  • Backups confirmed (30d retention)
    Attested · Jun 12
    Pass
  • Vendor inventory not yet uploaded
    Action required
    Review
  • Security awareness training — last logged 14 mo ago
    Action required
    Review
Open Gaps · 7

What to fix next

  • critical
    No vendor inventory on file
    Maps to FTC §314.4(d)
  • critical
    Annual security training overdue
    Maps to IRS Pub 4557
  • moderate
    Incident response plan not signed
    Maps to IRS Pub 5708
Compliance Timeline

Annual renewal in 64 days

Jun 2026TodaySep 2026 · Renewal
  • WISP generated
    May 19, 2026
  • M365 evidence connected
    May 22, 2026
  • Coordinator signed off
    Jun 02, 2026
  • Annual review attestation
    Due Sep 17, 2026
Score under 70 · MSP Referral

Need help fixing these gaps?

Get matched with up to 3 local compliance-focused MSPs. Optional and transparent — shared only with your consent.

Score 85+ · Insurance Readiness

Export your Compliance Evidence Package

A strong compliance score may help support cyber insurance underwriting. Export a broker-ready PDF when you need it.

See a live dashboard WISPWolf assists with compliance readiness and documentation. It does not provide legal advice or guarantee compliance.
Features

Everything a modern compliance program needs

Compliance is not a one-time document. It is a program of evidence, review, and response.

AI-Assisted WISP Generator

Tailored plans drafted from your firm's intake, not a generic template library.

Compliance Readiness Score

A clear readiness grade that updates as your security posture changes.

Automated Evidence Validation

Soon

Coming Soon: validate compliance answers against connected business systems instead of memory or screenshots.

Annual Renewal Workflow

Guided review cycles with signed attestations and reminders before your renewal is due.

Audit-Ready Exports

PDF and structured exports built for insurers, regulators, and clients.

Policy Acknowledgement Tracking

Owner, security lead, and staff each get the right view and the right sign-off.

Incident Response Playbooks

Pre-built breach response steps mapped to small-business reality.

Gap Remediation Plan

Prioritized action list with ownership, timeline, and clear next steps.

The Difference

Why WISPWolf Is Different

WISPWolf is designed to move businesses beyond static WISP documents and toward an ongoing compliance program.

Traditional WISP ProcessWISPWolf
Static WISP documentGuided compliance management
Manual updates throughout the yearOngoing policy and control tracking
Annual review done from scratchStructured annual review workflow
No compliance scoringCompliance readiness scoring
Gaps surface only during an auditGap identification with prioritized findings
Scattered screenshots and email attachmentsOrganized evidence collection
No remediation trackingRemediation tracking with assigned owners
No employee acknowledgement trackingPolicy acknowledgement tracking
No centralized dashboardCentralized compliance management dashboard

WISPWolf is a pilot-stage compliance platform. Some workflows are actively being rolled out to early customers.

Built by people who have done this work

Built from Real Compliance and Cybersecurity Experience

WISPWolf is a pilot-stage platform created by cybersecurity professionals with hands-on experience in compliance programs, incident response, and small-business risk.

Tax professionalsAccounting firmsInsurance agenciesFinancial service providersSmall businesses handling sensitive client data

Practical WISP guidance for small businesses

WISPWolf turns dense federal guidance into a step-by-step compliance program any firm can actually run — without paying for a five-figure consulting engagement.

Compliance documentation built around real-world security controls

Every control in the platform is mapped to the FTC Safeguards Rule, IRS Publication 5708, and IRS Publication 4557 — and described in language a non-technical owner can follow.

Designed by professionals who understand the real risk

Built by people who have worked breaches, audits, insurance questionnaires, and client data exposure. WISPWolf reflects what actually matters when something goes wrong.

Pilot program now open. WISPWolf does not publish customer counts, audit pass rates, or named testimonials we cannot independently verify.

Pilot Roadmap

Coming Soon: Evidence-Based Compliance

WISPWolf is being designed to help businesses validate compliance answers using connected security and productivity systems. Instead of relying only on memory or manual screenshots, future versions will help verify whether key safeguards are actually in place.

Pilot Roadmap · Coming Soon

Automated Evidence Validation

Soon

Verify whether key safeguards are actually in place — not just claimed on a form.

Connected Business Systems

Soon

Pull readiness signals from the productivity and security platforms your firm already uses.

Compliance Health Dashboard

Soon

A single live view of where your program stands and what needs attention.

Security Control Verification

Soon

Confirm controls like access management, logging, and backups against real configuration.

Audit Evidence Exports

Soon

Generate audit-ready packets that explain not only what you claim, but how it was verified.

Ongoing Risk Alerts

Soon

Get notified when something drifts — before it becomes a finding, claim, or breach.

Pilot customers help shape which integrations and validations ship first.

Pricing

Simple, transparent pricing

Pick the tier that matches your firm. Pilot pricing — cancel anytime.

Starter

$39/month

For solo preparers and small practices getting compliant.

  • Guided WISP assessment
  • AI-assisted WISP draft
  • FTC and IRS control mapping
  • PDF export
  • Annual review reminders
Start with Starter
Best Value

Professional

$99/month

For growing firms that want an ongoing compliance program.

  • Everything in Starter
  • Compliance readiness score
  • Gap remediation workflow
  • Evidence organization
  • Policy acknowledgement tracking
  • Priority support
Choose Professional

Agency

$199/month

For multi-location firms and partners managing several programs.

  • Everything in Professional
  • Multi-client or multi-location support
  • Team workflow
  • Advanced reporting
  • Partner-ready dashboard
  • Dedicated onboarding support
Choose Agency

Pilot program now open. 14-day free trial. No credit card required to start. Some advanced features are labeled “Coming Soon” and are actively in development.

Why firms trust WISPWolf

Compliance grounded in federal guidance, not marketing claims

IRS Pub 5708 + 4557
Built directly around federal WISP guidance
FTC Safeguards Rule
Mapped to 16 CFR Part 314 control categories
Pilot Program
Now open to early firms and small businesses
Built by Pros
Real-world compliance and incident response experience
IRS + FTC Mapped
AES-256 Encryption
US-hosted
Pilot-Stage Platform

WISPWolf assists with compliance readiness and documentation. It does not provide legal advice or guarantee regulatory compliance.

FAQ

Questions, answered

Still have questions?

Talk to a compliance specialist—no sales pitch.

Book a 15-min walkthrough