PTIN renewal

PTIN renewal and the security plan you sign for

Every paid preparer who renews a PTIN checks a box on Form W-12 stating they are aware that the law requires a written information security plan. The box takes a second. The plan behind it is the part most firms have never actually built, and this page is about the gap between the two.

Key facts

  • Line 11 of Form W-12 is an acknowledgment you sign, not a document you upload. The IRS does not review your plan at renewal.
  • The requirement itself comes from the FTC Safeguards Rule at 16 CFR 314.3(a), which has no exemption for small firms.
  • Firms holding information on fewer than 5,000 consumers are relieved of four specific written duties under 16 CFR 314.6. The written program is not one of them.

Key takeaways

  • The 2026 renewal fee was $18.75. The IRS has not published the 2027 fee or opening date as of 21 September 2026.
  • Publication 5708 is a sample, and says so. A plan that still reads like the sample is evidence nobody did the tailoring.
  • A plan with an honest gap and a dated remediation step is stronger than one that claims a control the firm does not have.

What Line 11 actually says

Form W-12 carries a section headed Data Security Responsibilities, and it asks you to check Yes or No against one sentence.

The sentence, quoted from Form W-12 (Rev. October 2025), is: "I am aware that paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information."

You must check one box. There is no field to attach anything, no plan reference number, and no step where the IRS looks at what you wrote. That surprises people, and it is worth being clear about, because a lot of marketing in this space implies the opposite.

What you are signing is an acknowledgment of awareness. It is short, it is annual, and more than 800,000 paid preparers sign some version of it every year. That is what makes it the most widely signed statement about information security in American small business, and also the least acted upon.

Where the requirement actually comes from

Not from the PTIN form. The duty sits in the FTC Safeguards Rule, issued under the Gramm-Leach-Bliley Act, and the W-12 simply makes you acknowledge it once a year.

16 CFR 314.3(a) requires a covered financial institution to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The FTC treats paid tax preparation as a covered activity, which is why the IRS puts the acknowledgment on the PTIN form in the first place.

This matters for one practical reason. If you are hoping that skipping the PTIN box or checking No removes the obligation, it does not. The obligation exists in the regulation whether or not you acknowledge it. The form is a reminder, not the source.

It also means the standard you are held to is the regulation's, not the form's. 16 CFR 314.4 lists what the program has to do: name a qualified individual, run a risk assessment, implement specific safeguards including access controls and multi-factor authentication, dispose of information you no longer need, train your people, assess your service providers, and keep the whole thing current.

What being small does and does not change

16 CFR 314.6 lifts four written obligations from firms holding information on fewer than 5,000 consumers. It does not lift the requirement to have a written program.

This is the single most misunderstood provision in the rule, in both directions. Some firms believe being small exempts them entirely, which is wrong and would be an expensive belief to hold during an examination. Others buy penetration tests and formal board reporting they do not owe, because a vendor did not tell them about 314.6.

The four duties that lift are specific and they are listed in the table below. Everything else in 314.4 applies to a one-person practice exactly as it applies to a fifty-person firm, scaled to the size and complexity of what you actually run.

Count consumers honestly when you work out which side of the line you are on. The count includes people whose information you still hold from prior years, not just this season's clients, and it includes information held on your behalf by a service provider.

What happens if you check Yes without a plan

Nothing at renewal. The risk is entirely downstream, and it is real enough to be worth stating plainly rather than dramatising.

There is no audit triggered by checking the box, no cross-reference, and no list of preparers whose plans the IRS intends to inspect. Anyone telling you otherwise is guessing or selling.

What the box does is close a door. Once you have signed an annual federal statement saying you are aware of the requirement, the defence that nobody told you is gone. That matters in three situations that do happen to small firms: an FTC enquiry after a breach, a cyber insurance claim where the application asked whether you had a written plan, and a client whose data was exposed asking what safeguards you had in place.

The proportionate response is not panic. It is to spend an evening producing a plan that is true, and to keep a dated record of the things you have not done yet rather than claiming you have done them.

What a plan has to contain to be worth having

Specificity. A plan that could belong to any firm belongs to no firm, and that is visible immediately to anyone reading it for a reason.

A serious plan names your systems, not categories of system. It says which tax software you use, where client files actually sit, who has access to each, which vendors can reach client data, and what happens when someone leaves. It names a Qualified Individual by name or role under 16 CFR 314.4(a), which for most small firms is the owner.

It also handles the parts you have not finished. If multi-factor authentication is on for email but not for your portal, the plan should say so, name who is fixing it, and give a date. An examiner, an underwriter, and an opposing lawyer all read a dated remediation step as a functioning program. They read an overstated claim as a misrepresentation, and on an insurance application that is a much larger problem than the gap itself.

Publication 5708 is a reasonable place to see the shape of one. It is a sample, the IRS says it is a sample, and the work it leaves you is the work that makes the document real.

Doing this before you renew

Renewal is a useful forcing date even though the two are not formally connected. A short sequence gets you there.

Work out your consumer count first, because it decides which duties you owe. Then write down what is actually true today: your systems, your vendors, who has access, whether MFA is on and where, whether your backups have ever been restored from. Resist the urge to improve the answers while you write them.

Turn each gap into an owner and a date. Then produce the document, keep the evidence with it, and diary a review for next year. The review is not ceremony: 16 CFR 314.4(g) requires you to evaluate and adjust the program in light of changes to your operations.

Renew online through your IRS Tax Professional account if you can. The paper route on Form W-12 takes roughly six weeks to process, which is a bad thing to discover in the last week of December.

What 16 CFR 314.6 lifts for firms under 5,000 consumers, and what it does not
DutyCitationUnder 5,000 consumers
Written information security program314.3(a)Required
Designate a Qualified Individual314.4(a)Required
Written risk assessment with prescribed contents314.4(b)(1)Lifted
Access controls and periodic access review314.4(c)(1)Required
Multi-factor authentication314.4(c)(5)Required
Secure disposal and retention limits314.4(c)(6)Required
Annual penetration test and six-monthly vulnerability assessment314.4(d)(2)Lifted
Security awareness training314.4(e)Required
Service provider assessment314.4(f)Required
Evaluate and adjust the program314.4(g)Required
Written incident response plan314.4(h)Lifted
Annual written report to the board or senior officer314.4(i)Lifted
Notify the FTC of a breach affecting 500 or more consumers314.5Required

FAQ

Do I have to send my security plan to the IRS when I renew?

No. Line 11 is an acknowledgment, not a submission. There is no upload field, no attachment, and no review step. The IRS is asking you to confirm that you know the requirement exists. Any vendor implying the IRS inspects your plan at renewal is selling you fear rather than a document.

What happens if I check Yes and I do not actually have a plan?

Nothing happens at the moment you renew, because nothing is checked. The exposure comes later. You have signed a federal form stating you are aware of the requirement, which means that if the FTC, the IRS, a cyber insurer, or a client's lawyer ever asks, you cannot say you did not know. The honest fix is to build the plan, not to check No.

Should I check No instead?

Checking No does not exempt you from anything. The requirement comes from the Safeguards Rule at 16 CFR 314.3(a), not from the W-12. Checking No records that you are not aware of a legal duty that applies to you anyway, in a signed statement, on a form the IRS keeps. There is no version of this where No is the safer box.

I am a one-person shop. Does this still apply?

Yes. 16 CFR 314.3(a) requires a written program of covered financial institutions with no exemption for size. A firm holding information on fewer than 5,000 consumers is relieved of four specific written obligations under 16 CFR 314.6, but the written program itself is not one of them.

Is IRS Publication 5708 enough on its own?

Publication 5708 is a genuinely useful sample and the IRS says plainly that it is a sample. It leaves the tailoring to you: your systems, your vendors, your staff, your actual safeguards. A plan that still contains the sample's placeholders is evidence that nobody did the work, which is worse than a shorter plan that is true.

When does PTIN renewal open for the 2027 season?

The IRS has not announced the 2027 renewal date as of 21 September 2026. For reference, renewal for the 2026 season opened in late October 2025 and 2025 PTINs expired on 31 December 2025. Renewal has opened in the second half of October in recent years, but treat that as a pattern rather than a published date until the IRS says so.

What did renewal cost last year?

The fee to obtain or renew a PTIN for the 2026 season was $18.75. The IRS has not published the 2027 fee as of 21 September 2026.

How long does renewal take?

Online renewal through the IRS Tax Professional account is usually finished in one sitting. The paper route on Form W-12 takes roughly six weeks to process, which is the reason to not leave it until late December.

Sources

Build the plan you are signing for

Answer plain questions about your firm and get a written information security plan, incident response plan, acceptable use policy, and access control policy, every provision cited to the rule it comes from. $299 once, or $149 a year with the dashboard that tracks the duties above.

Start the questionnaire
Policywright is a documentation product, not a law firm, and nothing here is legal advice. State breach deadlines and legal reliance should be reviewed with qualified counsel before launch or use.