Skip to content
Bellator Cyber Guard
NOTICE

Federal law requires all PTIN holders to maintain a Written Information Security Plan. You attest to it on Form W-12, Line 11.

BELLATOR CYBER GUARD
Questions? (800) 492-6076
IRS PTIN RENEWAL · 2026–2027 SEASON

Renewing your PTIN? Federal law requires a WISP.

The Gramm-Leach-Bliley Act and the FTC Safeguards Rule require all paid tax preparers to maintain a Written Information Security Plan. Download the free template 4,000+ tax professionals use and be ready before you renew.

Get your required PTIN documentation
Free. No credit card. Instant download.
Your details stay with Bellator. Never sold, never shared.
28-page WISP template built on IRS Publication 5708
Employee security training guide, ready to use
Data breach response plan for the FTC 30-day window
Annual compliance checklist and FTC Safeguards map

Prepared by IRS-recognized cybersecurity professionals.

PTIN RENEWAL DEADLINE

Renewing without a WISP means attesting to something you cannot produce.

What you are actually attesting to

Line 11 is a legal statement about your practice. Here is what stands behind it.

I

Federal law applies to you

The Gramm-Leach-Bliley Act classifies paid tax preparers as financial institutions. The FTC Safeguards Rule then requires a written security plan. It is not optional, and it does not scale down for solo practices.

II

Penalties reach six figures

Individual preparers face penalties up to $10,000. Businesses can face up to $100,000 per violation. Willful non-compliance can carry criminal exposure on top of the fines.

III

Enforcement is increasing

The IRS and FTC have both stepped up enforcement as preparer data breaches climb. You can be asked to produce your WISP, and you are expected to have it ready.

What the law actually requires

IRS Publication 4557

The IRS requires administrative, technical and physical safeguards for taxpayer information, documented in a written plan covering data protection, employee training and incident response.

FTC Safeguards Rule

Under Gramm-Leach-Bliley you are a financial institution. You must designate a qualified individual to run the program, carry out a risk assessment, and implement the required safeguards.

Form W-12, Line 11

Since 2019, renewing your PTIN means confirming you maintain a WISP. It is a legal attestation. Checking it without a plan in place is a false statement on a federal form.

Production on request

A plan only counts if it exists in writing and you can hand it over. Both a breach and a routine inquiry can trigger that request.

Your complete WISP compliance package

The template drafts every required section for you, written by cybersecurity professionals, with clear marks where your practice’s real details go. Free, in full, no credit card.

Get my required documentation →
CONTENTS · 9 REQUIRED SECTIONS
  1. 1Purpose, scope and plan objectives
  2. 2Responsible individuals and your Data Security Coordinator
  3. 3Risk assessment
  4. 4Hardware and software inventory
  5. 5Data safeguards and access controls
  6. 6Employee training and management
  7. 7Incident response and breach notification
  8. 8Service provider oversight
  9. 9Annual review and updates

Why tax preparers trust this template

The FTC sent us a compliance inquiry letter. Thanks to having Bellator’s WISP in place, we provided everything they needed within 24 hours.
David Martinez, CPAMartinez & Associates, Phoenix AZ
I had been preparing taxes for 15 years and had no idea I was out of step with federal law by not having a WISP. Customized it in 30 minutes, now I am compliant.
Jennifer Park, EAPark Tax Services, Seattle WA

Three moments that matter

Right now

If you do not have a WISP, you are out of step with the FTC Safeguards Rule today. Not at renewal, not after an incident. Today.

December 31, 2026

The PTIN renewal deadline. Form W-12, Line 11 asks you to attest that your security plan is in place.

Any day after that

The IRS or the FTC can ask you to produce it. There is no grace period for writing one after the request arrives.

Common questions from tax professionals

Is a WISP really required by federal law?

Yes. The Gramm-Leach-Bliley Act and the FTC Safeguards Rule require all paid tax preparers to maintain a Written Information Security Plan, and the IRS reinforces it in Publication 4557. You attest to having one on Form W-12, Line 11, when you renew your PTIN.

What are the penalties for not having one?

Individual preparers face penalties up to $10,000, and businesses up to $100,000 per violation. Willful non-compliance can carry criminal exposure on top of that. Beyond the fines, you are looking at PTIN complications, client exposure, and the fallout of a breach you had no documented plan for.

Will the IRS actually check whether I have one?

Both the IRS and the FTC have increased enforcement as preparer data breaches have risen. You can be asked to produce your WISP, and a breach incident triggers scrutiny on its own. The expectation is that it already exists in writing.

How is this different from a generic template?

It is built directly on IRS Publication 5708 and updated for the 2026-2027 renewal season. It covers the FTC Safeguards Rule elements and the 30-day breach notification procedure, and it is written for tax practices rather than businesses in general.

I am a solo practitioner. Do I still need this?

Yes. The rule applies to every paid preparer regardless of practice size. Solo practitioners often carry more personal exposure rather than less, because there is no corporate structure sitting between them and the liability.

Do not renew while attesting to a plan you do not have.

Sixty seconds to download the template and every supporting document, free. Or let us write the whole plan for you, customized to how your practice actually runs.

Bellator Cyber Guard · (800) 492-6076 · security@bellatorcyber.com

This page explains federal compliance requirements for paid tax preparers. Penalty figures reflect current FTC and IRS enforcement guidance and are not legal advice. Bellator Cyber Guard provides templates and guidance; implementation remains the responsibility of each practice.