Federal law requires all PTIN holders to maintain a Written Information Security Plan. You attest to it on Form W-12, Line 11.
Renewing your PTIN? Federal law requires a WISP.
The Gramm-Leach-Bliley Act and the FTC Safeguards Rule require all paid tax preparers to maintain a Written Information Security Plan. Download the free template 4,000+ tax professionals use and be ready before you renew.
Prepared by IRS-recognized cybersecurity professionals.
Renewing without a WISP means attesting to something you cannot produce.
What you are actually attesting to
Line 11 is a legal statement about your practice. Here is what stands behind it.
Federal law applies to you
The Gramm-Leach-Bliley Act classifies paid tax preparers as financial institutions. The FTC Safeguards Rule then requires a written security plan. It is not optional, and it does not scale down for solo practices.
Penalties reach six figures
Individual preparers face penalties up to $10,000. Businesses can face up to $100,000 per violation. Willful non-compliance can carry criminal exposure on top of the fines.
Enforcement is increasing
The IRS and FTC have both stepped up enforcement as preparer data breaches climb. You can be asked to produce your WISP, and you are expected to have it ready.
What the law actually requires
IRS Publication 4557
The IRS requires administrative, technical and physical safeguards for taxpayer information, documented in a written plan covering data protection, employee training and incident response.
FTC Safeguards Rule
Under Gramm-Leach-Bliley you are a financial institution. You must designate a qualified individual to run the program, carry out a risk assessment, and implement the required safeguards.
Form W-12, Line 11
Since 2019, renewing your PTIN means confirming you maintain a WISP. It is a legal attestation. Checking it without a plan in place is a false statement on a federal form.
Production on request
A plan only counts if it exists in writing and you can hand it over. Both a breach and a routine inquiry can trigger that request.
Your complete WISP compliance package
The template drafts every required section for you, written by cybersecurity professionals, with clear marks where your practice’s real details go. Free, in full, no credit card.
Get my required documentation →- 1Purpose, scope and plan objectives
- 2Responsible individuals and your Data Security Coordinator
- 3Risk assessment
- 4Hardware and software inventory
- 5Data safeguards and access controls
- 6Employee training and management
- 7Incident response and breach notification
- 8Service provider oversight
- 9Annual review and updates
Why tax preparers trust this template
“The FTC sent us a compliance inquiry letter. Thanks to having Bellator’s WISP in place, we provided everything they needed within 24 hours.”
“I had been preparing taxes for 15 years and had no idea I was out of step with federal law by not having a WISP. Customized it in 30 minutes, now I am compliant.”
Three moments that matter
Right now
If you do not have a WISP, you are out of step with the FTC Safeguards Rule today. Not at renewal, not after an incident. Today.
December 31, 2026
The PTIN renewal deadline. Form W-12, Line 11 asks you to attest that your security plan is in place.
Any day after that
The IRS or the FTC can ask you to produce it. There is no grace period for writing one after the request arrives.
Common questions from tax professionals
Is a WISP really required by federal law?
Yes. The Gramm-Leach-Bliley Act and the FTC Safeguards Rule require all paid tax preparers to maintain a Written Information Security Plan, and the IRS reinforces it in Publication 4557. You attest to having one on Form W-12, Line 11, when you renew your PTIN.
What are the penalties for not having one?
Individual preparers face penalties up to $10,000, and businesses up to $100,000 per violation. Willful non-compliance can carry criminal exposure on top of that. Beyond the fines, you are looking at PTIN complications, client exposure, and the fallout of a breach you had no documented plan for.
Will the IRS actually check whether I have one?
Both the IRS and the FTC have increased enforcement as preparer data breaches have risen. You can be asked to produce your WISP, and a breach incident triggers scrutiny on its own. The expectation is that it already exists in writing.
How is this different from a generic template?
It is built directly on IRS Publication 5708 and updated for the 2026-2027 renewal season. It covers the FTC Safeguards Rule elements and the 30-day breach notification procedure, and it is written for tax practices rather than businesses in general.
I am a solo practitioner. Do I still need this?
Yes. The rule applies to every paid preparer regardless of practice size. Solo practitioners often carry more personal exposure rather than less, because there is no corporate structure sitting between them and the liability.
Do not renew while attesting to a plan you do not have.
Sixty seconds to download the template and every supporting document, free. Or let us write the whole plan for you, customized to how your practice actually runs.
This page explains federal compliance requirements for paid tax preparers. Penalty figures reflect current FTC and IRS enforcement guidance and are not legal advice. Bellator Cyber Guard provides templates and guidance; implementation remains the responsibility of each practice.
