Accounting and CPA IT

It is March. Nothing can go down.

A tax firm has about ten weeks where an outage costs the year, and a written security obligation that most firms satisfy with a template somebody downloaded in 2023. TechGig builds and maintains the stack CPA firms actually run, and produces the Written Information Security Plan the IRS expects to see, tailored to your firm rather than filled in around your name.

What tax firms live with

The problems that surface at the worst possible time.

These are the failure modes the accounting Foundation was scoped around. None of them are hypothetical, and all of them get worse in filing season.

  • The WISP is a template with your name typed into it

    The IRS requires a written information security plan to obtain or renew a PTIN, and the FTC Safeguards Rule requires one that matches how your firm actually operates. A generic template satisfies neither on examination.

  • Clients email W-2s and Social Security numbers

    They will keep doing it until there is an easier channel that is also secure. The fix is a portal your clients will actually use, not a policy telling them to stop.

  • Client data lives on staff laptops as working copies

    Returns get worked on locally, saved to a desktop, and never cleaned up. Nobody has an inventory of which machines hold what, which is the first question asked after a laptop goes missing.

  • Phishing that knows your calendar

    Filing season brings targeted campaigns impersonating clients, the IRS, and your own partners. They land in February because that is when nobody has time to look twice.

  • Hosted tax software that stalls under load

    UltraTax or Lacerte in a hosted environment behaves differently in week two of April than it did in November. Usually bandwidth, sometimes a session-host sizing problem, rarely the vendor.

  • Seasonal staff onboarded fast and offboarded never

    You add preparers in January and they keep their access through the summer. Access review is the cheapest control in the plan and the one most often skipped.

Foundation bundle

The compliance floor a CPA firm should be standing on.

A scoped, fixed-price engagement that produces the written plan and closes the gaps it exposes, done for you in one pass. Comparable engagements from compliance consultants run several thousand dollars. Prefer to start smaller? A baseline assessment and a remediation roadmap get you there in steps. After this, ongoing work runs on a regular plan or per-ticket.

Foundation bundle
$899to$1,149

17 credits, one-time engagement

What is included

  • Written Information Security Plan tailored to IRS Pub 4557 and the FTC Safeguards Rule: data inventory, designated security coordinator, written safeguards, incident response plan, and an annual review schedule
  • Client data handling audit from intake through working copies, archival storage, retention and destruction, with Gramm-Leach-Bliley and Pub 4557 gaps flagged against named owners and due dates
  • Firewall hardening: rules, port exposure, and access control policies reviewed and rebuilt
  • Business email security: phishing response, spam filter tuning, and quarantine management

The lower price is Standard-tier delivery; the higher is Specialist-tier. We confirm the right fit and the exact number on the scoping call.

After the bundle

Ongoing work, billed the way you want.

Most firms roll into a plan once the foundation is in place, because the WISP carries an annual review obligation and filing season carries a support load. A few stay on pure pay-per-ticket.

  1. 01

    The annual WISP review

    The plan is not a one-time document. It has to be revisited as your firm, your staff, and your vendors change, and the revision history is part of what makes it credible.

  2. 02

    Filing season support

    Hosted tax software behaving under real load, printer and scanner throughput at the front desk, and a second set of hands during the weeks when a lost afternoon is a lost week.

  3. 03

    Access reviews and staff lifecycle

    Seasonal preparers onboarded in one ticket and genuinely offboarded in another, with the access review documented where the plan says it lives.

Why TechGig

The plan and the remediation come from the same bench.

Compliance consultants write the document and hand you a list. IT shops fix what you point at. A written plan is only worth anything if the safeguards it describes are the ones actually running, which means the people writing it and the people configuring it have to be the same team.

See plans and per-ticket pricing
  • Vertical-tagged dispatch

    An UltraTax or CCH Axcess ticket goes to a tech who has worked that stack, not the next name in a generic queue.

  • The plan describes your firm

    The WISP is built from the data inventory and handling audit we run in your environment, so what it claims and what your network does are the same thing.

  • No per-seat billing

    Most firms swell with seasonal preparers in January. Per-seat pricing charges you for that before a single ticket is worked. Plan or per-ticket, headcount is irrelevant.

Compliance FAQ

What CPA firms ask before they switch.

Plain answers. Where the real answer is "it depends", we tell you what it depends on.

Scoped to your firm

Start with the plan you are required to have.

A scoping call tells you what your firm needs and what it does not. If your current plan and setup are already in shape, we say so rather than selling you a bundle.

Start with free AI chat, no credit card. Plans have no contracts and cancel anytime. Bundles are one-time and fixed-price.