Free compliance template

Massachusetts WISP template for 201 CMR 17.00.

An editable Word template for the written information security program Massachusetts requires of businesses that hold residents' personal information. Fill in the blanks, assign a coordinator, and use the built-in logs to show the program is maintained.

  • 12 sections mapped to the regulation's program and computer-system requirements
  • Appendices for data inventory, vendors, incidents, training, and annual review
  • Plain-language prompts written for small and midsize businesses

Get the free template

We'll only use your details to follow up about the template. No spam.

What is a WISP?

A written plan for protecting resident personal information.

Massachusetts regulation 201 CMR 17.00 requires every person or business that owns or licenses personal information about a Massachusetts resident to develop, implement, and maintain a comprehensive written information security program. The program must contain administrative, technical, and physical safeguards appropriate to the size of the business, its resources, the amount of data stored, and the need for security.

The rule reaches beyond Massachusetts: a business in Rhode Island or anywhere else that keeps payroll, customer, or patient records for Massachusetts residents is in scope. For a fuller overview, read our guide to Massachusetts 201 CMR 17.00 data security requirements.

What the template includes

Purpose, scope, and definitions

Who the program covers and what counts as personal information under the regulation.

Program coordinator

The employee responsible for maintaining, enforcing, and reviewing the WISP.

Records inventory

Where paper and electronic records with resident personal information live.

Risk assessment

Reasonably foreseeable internal and external risks and how current safeguards address them.

Employee policies and training

Access rules, remote-work expectations, discipline, and departing-employee procedures.

Service provider oversight

Selecting vendors that can protect personal information and requiring it by contract.

Physical safeguards

Locked storage, visitor rules, and secure disposal of records and devices.

Computer system requirements

Authentication, access control, encryption, monitoring, patching, malware protection, and training.

Incident response

Documenting incidents, post-incident review, and Massachusetts breach-notification steps.

Annual review and approval

Reviewing scope at least annually and after material business changes.

A WISP only counts if the safeguards are real.

Regulators and insurers look for evidence that the controls in your WISP are actually running: MFA, encrypted laptops, patching, endpoint protection, tested backups, and training records. Meta IT Pro implements and documents those safeguards through our compliance IT services and cybersecurity services.

Request a WISP readiness review

Frequently asked questions

Who needs a WISP in Massachusetts?

201 CMR 17.00 applies to persons who own or license personal information about Massachusetts residents, including many businesses located outside the state. Personal information generally means a resident's name combined with a Social Security number, driver's license or state ID number, or a financial account or card number with any required access code.

Is this template enough to be compliant?

No template is compliant on its own. The regulation expects a program appropriate to your size, resources, the amount of data you hold, and the need for security. You need to tailor the template, implement the safeguards it describes, train employees, and review it at least annually. It is not legal advice.

What technical controls does 201 CMR 17.04 expect?

To the extent technically feasible: secure user authentication, access limited to those who need it, encryption of personal information sent across public networks or wirelessly and stored on laptops or portable devices, monitoring for unauthorized use, up-to-date firewall protection and security patches, current malware protection, and employee security training.

Can Meta IT Pro help implement the WISP?

Yes. We help Massachusetts and Rhode Island businesses put the technical safeguards in place, such as MFA, device encryption, patching, endpoint protection, backups, and logging, and keep the evidence that shows the program is working.

This template is provided for general information and is not legal advice. Consult qualified counsel about your specific obligations under 201 CMR 17.00 and M.G.L. c. 93H.

Free IT & cybersecurity assessment

Understand your priorities before IT and security problems become expensive.

Start with a no-obligation conversation about your technology, Microsoft 365 environment, backup readiness, and material cybersecurity concerns.

  • Preliminary security and IT review
  • Microsoft 365 configuration discussion
  • Backup and recovery-readiness review
  • Prioritized next-step recommendations

By submitting, you ask Meta IT Pro to contact you about this request and acknowledge our Privacy Policy. Do not include passwords, authentication codes, financial details, medical records, or other sensitive information.