For CPA & tax firms of 5–40 staff

The WISP is mandatory. The downtime is optional.

Every paid tax preparer — at any size — is required to maintain a Written Information Security Plan under the FTC Safeguards Rule. ATCOS builds the real thing, implements the controls behind it, and keeps your firm running when April depends on it.

Does a small tax practice really need a WISP?

Yes — it's not optional at any size. The FTC Safeguards Rule and the IRS require every paid preparer to maintain a WISP, and PTIN renewal asks you to attest to your data-security responsibilities. A real WISP is a living program — named responsibilities, access controls, MFA, encryption, incident response — not a downloaded template in a drawer. 88% of CPA firms now carry cyber insurance; the underwriters read these documents.

The ATCOS package for accounting firms

Why now (May–June)

The weeks after filing season are when firms fix what they swore they'd fix in March. Remediation, migrations, and WISP builds done now are invisible by January. Firms that wait until Q4 do this work during extension season instead.

We only need help January–April. Can we pay for just that?

Seasonal-only support means your January emergency is handled by whoever's available, with no knowledge of your environment. The annual agreement prices the off-season light and the season heavy — same budget, but the firm is actually known and ready.

Our IT person handles the computers. Who handles the WISP?

That's the usual gap: the tech keeps machines running but nobody owns the written program, the risk assessment, or the attestation. Co-managed mode adds exactly that layer without replacing anyone.

Get the WISP done before extension season

Fixed fee, fixed scope, written for your firm — not a template.

Book a Strategy Call