Skip to content
Bellator Cyber Guard
IRS Compliance

PTIN Requirements for Tax Preparers

Everything paid tax preparers need to know about getting and renewing a PTIN — including the 2026 fee, annual deadline, Form W-12 Line 11, and written data-security responsibilities.

15 min
Online Renewal

Typical IRS estimate for online completion

$18.75
2026 PTIN Fee

Current IRS application and renewal fee

Oct–Dec
Renewal Window

Annual renewal period each year

W-12
Data Security

Line 11 acknowledges WISP responsibility

What is a PTIN and why does it matter?

A Preparer Tax Identification Number (PTIN) is the IRS-issued identification number required for anyone who prepares or substantially assists with federal tax returns for compensation. A PTIN is not a professional license, but a valid PTIN is required on the returns you prepare.

PTINs expire on December 31 and must be renewed annually. Current Form W-12 Line 11 asks whether you are aware that paid tax return preparers are required by law to create and maintain a Written Information Security Plan (WISP).

Bottom line: Renew before December 31, use the current IRS fee and form, and treat Line 11 as a direct reminder to keep a written, practice-specific security plan.

PTIN renewal security checklist

1

Verify your IRS account security

Enable multi-factor authentication on your IRS online account. Use a unique, strong password that isn’t shared with any other service. The IRS recommends changing it annually.

2

Confirm your WISP is current

Review your Written Information Security Plan before renewal. Line 11 asks you to acknowledge awareness of the legal duty to create and maintain one; use IRS Publications 5708, 5709, and 4557 as practical guides.

3

Verify endpoint protection

Every device used for tax preparation — desktops, laptops, tablets — must have active antivirus or EDR protection. Document which software you use and when it was last updated.

4

Complete security awareness training

All employees with access to taxpayer data must complete annual security training. Keep signed acknowledgment forms with dates, topics covered, and attendance records.

5

Run a dark web credential scan

Check whether your PTIN, EFIN, email, or passwords have been exposed in any data breaches. If compromised credentials are found, change them immediately and document the remediation.

6

Review and update access controls

Verify that only authorized staff can access taxpayer data and tax preparation software. Remove access for former employees. Document who has access to what.

7

Submit your renewal

Log in to the IRS PTIN system, complete the renewal questions, and pay the $18.75 fee for 2026. Save the confirmation; the IRS estimates online renewal takes about 15 minutes.

Form W-12 Line 11: what it actually asks

Current Form W-12 Line 11 asks whether you are aware that paid tax return preparers are required by law to create and maintain a Written Information Security Plan. It does not say the IRS inspected, certified, or approved your WISP.

What Line 11 does

Makes the WISP responsibility explicit
Asks you to acknowledge awareness
Applies to paid preparers of every size

What it does not do

It is not an IRS WISP audit
It does not approve your safeguards
It does not replace a tailored security plan

Use the renewal prompt as a checkpoint: confirm that your WISP reflects your current staff, systems, vendors, safeguards, backup process, and incident-response contacts.

PTIN misuse: warning signs and next steps

A stolen or misused PTIN can show up as returns you did not prepare or a mismatch in your IRS return count. The IRS advises tax professionals to review the weekly return information available in their PTIN accounts and report suspected misuse.

Warning signs your PTIN may be compromised

Unexpected IRS correspondence about returns you did not prepare
Clients reporting duplicate-return rejections
Your weekly return count is higher than expected
Unfamiliar changes or activity in your PTIN account

If you suspect PTIN misuse: Use IRS Form 14157 to report it and include the information you have about the person or entity using your number. If the incident also involves a data breach, follow the IRS tax-professional data-breach reporting process and your WISP incident-response plan.

Need a WISP before your PTIN renewal?

Line 11 directly reminds paid preparers of the legal duty to create and maintain a WISP. Get a free template to build your own, or let our team write a custom WISP tailored to your practice.

PTIN requirements — frequently asked questions

Form W-12 Line 11 asks applicants to acknowledge awareness that paid preparers are legally required to create and maintain a WISP. The form does not say the IRS inspected or approved the plan. A practical WISP should document safeguards appropriate to the practice, including access controls, multi-factor authentication, endpoint protection, staff training, vendor oversight, backups, and incident response.

For 2026, the IRS PTIN fee is $18.75. Renewal season begins in mid-October and PTINs expire on December 31. The IRS estimates about 15 minutes for online renewal; paper Form W-12 processing takes about six weeks.

Yes. A PTIN can be misused on returns prepared by someone else. Review the weekly return information in your PTIN account and investigate mismatches promptly. Good account security, multi-factor authentication, unique passwords, and monitoring help reduce risk, but suspected PTIN misuse should be reported to the IRS on Form 14157.

Paid tax return preparers are required to create and maintain a WISP. Form W-12 Line 11 asks you to acknowledge awareness of that responsibility; it is not worded as a certification that the IRS reviewed or approved your WISP. Keep the plan current and tailored to the people, systems, vendors, and risks in your practice.

Use IRS Form 14157 to report suspected PTIN misuse and include the information you have about the person or entity using your number. Secure the associated accounts, review your weekly return information, document the incident, and follow the IRS tax-professional data-breach reporting process if taxpayer data may also have been exposed.

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

  • Know what applies
  • Document the evidence
  • Make the safeguard operational

A defensible path

  1. 01

    Confirm the requirement

    Separate what is required from recommendations and vendor language.

  2. 02

    Map it to your environment

    Connect the rule to people, devices, data, vendors, and current procedures.

  3. 03

    Close and document the gaps

    Prioritize changes and keep evidence that the process is being followed.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.