Not exactly. When you renew your PTIN, Form W-12 Line 11 asks you to check Yes or No on whether you’re aware that paid preparers are legally required to maintain a written information security plan. It doesn’t ask whether you actually have one. Renewal season opens mid-October for the following filing year, and your PTIN expires December 31. The awareness box is easy. Actually having a WISP that would hold up if the IRS asked to see it is the part worth taking seriously.
Key takeaways
- PTIN renewal opens mid-October each year, and your PTIN expires December 31.
- Form W-12 Line 11 only asks you to confirm awareness of the WISP requirement, not that you currently have a compliant plan.
- IRS Publication 4557 lays out what your WISP has to include: a named coordinator, an identified set of risks, evaluated safeguards, and a documented, implemented program.
- A false answer anywhere on Form W-12, not just Line 11, can mean PTIN suspension or revocation. Separately, the underlying WISP obligation carries its own exposure under IRC 7216 and the FTC Safeguards Rule.
- Your WISP needs an annual review to stay current, not a one-time draft filed away and forgotten.
Table of Contents
What does Form W-12 Line 11 actually ask?
Line 11 confirms one thing: you know a written information security plan is legally required. It’s an awareness statement, not a compliance certification, and you can check Yes or No.
The form points you to Publication 4557 for what a compliant plan actually requires. If you’d rather start from something you can fill in today, Verito also publishes a free WISP template built to that same baseline. Renewal season opens mid-October for the following filing year, and online renewal usually takes under fifteen minutes. Line 11 is a small, quick part of that process. The obligation it points to isn’t small or quick, and it exists independent of anything you check on this form.
| PTIN renewal, at a glance | Detail |
|---|---|
| Renewal season opens | Mid-October, for the following filing year |
| PTIN expiration | December 31 each year |
| Form | Form W-12, online or paper |
| What Line 11 asks | Whether you’re aware a WISP is legally required |
| What Line 11 certifies | Awareness of the requirement, not current possession of a compliant plan |
| Where to start on the plan itself | Publication 4557, or Verito’s free WISP template |
What does Publication 4557 require in a WISP?
Publication 4557 sets out four core elements your plan needs: designate one or more employees to coordinate your information security program, identify reasonably foreseeable risks to client data, evaluate how well your current safeguards address those risks, and design, implement, and monitor a safeguards program.

None of that is satisfied by a generic IT policy or a template you pull off the internet and never open again. Your plan has to describe your firm as it actually operates: which software holds your client data, who on your team has access to which systems, and what your response looks like if something goes wrong. Verito’s breakdown of Publication 4557 covers the full baseline in more depth, including the IRS Security Six that most safeguards programs build from.
What’s the real exposure if you don’t have one?
That doesn’t mean the form has no teeth. Form W-12’s signature line is direct about the stakes: false or misleading information anywhere on the application can mean losing the PTIN itself, on top of possible criminal penalties. No PTIN means no preparing returns for compensation.
Separate from the form itself, the underlying WISP obligation carries its own exposure. Verito’s guide to Publication 4557 states directly that noncompliance can lead to EFIN revocation, fines, and liability if client data is exposed. That’s not a hypothetical: if a breach or stolen credentials lead to fraudulent returns filed under your number, the IRS can suspend your EFIN while it investigates, and monitoring your EFIN for misuse is its own weekly habit worth building alongside your WISP review. A WISP gap rarely surfaces in a quiet month. It tends to surface after a breach, an audit, or a client’s own security questionnaire, which is the worst possible time to start building a plan from nothing. The FTC Safeguards Rule applies to nearly every tax and accounting firm on top of all this, regardless of what any IRS form asks, and it carries its own separate enforcement path.
Why does a WISP need an annual review?
The IRS expects you to review and update your WISP at least once a year, along with any time you change software, staff, or systems. A plan you drafted a couple of years ago, before new tools or a seasonal hire, describes a practice that no longer exists.

If you put WISP review on the same clock as PTIN renewal, you tend to stay current on both. That same annual habit is also what the FTC Safeguards Rule expects, since it asks for the same kind of documented, living plan the IRS does, just enforced by a different agency.
Where does VeritShield WISP fit in?
VeritShield WISP is a custom written information security plan built for your firm on a 30-minute scoping call with a Verito engineer, delivered within five business days, with unlimited revisions included all year as your firm changes.
| The task | Building it yourself | Covered in VeritShield WISP |
|---|---|---|
| Drafting a plan that matches Publication 4557 | Research the requirements, adapt a template, hope it fits | Delivered in five business days, built around your firm |
| Updating it as your firm changes | Manual rewrite, easy to postpone | Unlimited revisions included, all year, no change fees |
| Keeping it current as staff, software, or offices change | Another from-scratch review each time | Send the change, they update the plan |
VeritShield WISP is sold as an annual plan, per firm, and it’s available whether or not your firm hosts with Verito.
Get your WISP audit-ready before PTIN renewal →