2025 Form W-12 Changes: Key IRS Data Security Requirements Tax Preparers Must Comply With

By Maribel Hernandez, Director of Business Development, Empowered IT Solutions

As tax preparers navigate the changing landscape of data security regulations, understanding the 2025 Form W-12 changes is essential. Now is the time to understand the key requirements imposed by the IRS, focusing on new data security guidelines that tax preparers must adhere to, specifically regarding the Written Information Security Plan (WISP).

This guide will walk you through the data security requirements, the groundwork for an IRS WISP, and how tax preparers can mitigate cybersecurity risks. Additionally, you’ll discover how Empowered IT Solutions can offer valuable assistance in navigating these changes effectively.

What Are the 2025 IRS Form W-12 Data Security Requirements?

The 2025 IRS Form W-12 introduces critical data security requirements that tax preparers must follow to ensure compliance and protect sensitive client information. These guidelines include security obligations designed to enhance the integrity and safety of taxpayer data. Compliance not only reduces the risk of potential data breaches but also fortifies the preparer’s professional reputation.

Which New Security Obligations Does Form W-12 Impose?

Under the new guidelines, tax preparers are “required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information.” The WISP must outline the administrative, technical, and physical safeguards that keep taxpayer/sensitive information protected. Additionally, tax preparers must have an incident response plan ready to mitigate damage in case of data breaches, which is crucial for maintaining client trust.

Why Is This IRS Update Critical for Tax Preparers?

The IRS update outlined in the 2025 Form W-12 is crucial due to the increasing prevalence of cyber threats targeting sensitive tax data. Failing to comply can lead to criminal penalties and/or the denial or termination of a PTIN. Tax preparers who neglect these updates risk compromising their clients’ personal and financial information, leading to diminished trust and possible long-term damage to their practice.

How to Develop an IRS Written Information Security Plan for Form W-12 Compliance

Creating an IRS Written Information Security Plan (WISP) is vital for tax preparers seeking to renew their PTIN. The process entails detailing security measures, personnel responsibilities, and data protections.

Element

Requirement

Detail

Purpose Statement

Define purpose

What the WISP covers, what taxpayer/sensitive information is being protected, and which systems, employees, locations, and vendors are included.

Risk Assessment

Outline of risks

The risks identified within the firm’s environment, including where sensitive information is stored, processed, transmitted, and potentially exposed.

Safeguards

Protections in place

The firm’s security policies and procedures, and cybersecurity and physical protections to keep taxpayer information safe.

Staff Training

Education program

Implement cybersecurity training to ensure all staff understand their responsibilities under the WISP.

Incident Response Plan

Security incident procedures

What happens if taxpayer information is compromised, including detection, containment, response, recovery, documentation, and applicable notification.

This framework serves as a guide for developing a comprehensive WISP that meets IRS Publication 5708 and 4557 criteria while enhancing overall data security.

What Are the PTIN Data Security Requirements?

Tax preparers holding a Preparer Tax Identification Number (PTIN) must adhere to specific data security compliance obligations under the new IRS regulations.

Which Data Protection Measures Must PTIN Holders Implement?

PTIN holders are required to implement a number of data protection measures, including but not limited to:

  1. Data Encryption: Sensitive information must be encrypted both in transit and at rest to prevent unauthorized access.

  2. Access Controls: By establishing strict access controls, tax preparers can limit data access to authorized personnel only, reducing the risk of breaches.

  3. Monitoring and Logging: Continuous monitoring and logging of access to sensitive data are vital for detecting and responding to potential threats quickly.

Implementing these measures not only meets IRS data protection requirements but also demonstrates a commitment to safeguarding client information.

What Are the Penalties for PTIN Security Noncompliance?

Noncompliance with PTIN security obligations can result in penalties, including substantial fines and potential termination of the PTIN. Tax preparers may find themselves under investigation, with consequences including reputational damage and loss of clients’ trust. Hence, adhering to these requirements is paramount to maintain one’s professional standing and safeguard against financial setbacks.

How Can SMB Tax Preparers Address Cybersecurity Risks and Be Compliant with IRS Standards?

SMB preparers typically lack dedicated IT and security staff as well as enterprise-level budgets, yet they manage sensitive taxpayer data such as Social Security Numbers, Employer Identification Numbers, and bank account details. 

Despite their size, this makes them attractive targets for cybercriminals. Moreover, SMBs are held to the same Written Information Security Plan (WISP) and FTC Safeguards Rule obligations as larger firms, and reliance on seasonal or contract staff during filing season introduces additional access-control risks that are difficult to manage effectively without formal IT policies.

Which Cybersecurity Best Practices Align With IRS Form W-12 Requirements?

To effectively comply with the IRS Form W-12 requirements, tax preparers should adopt the following cybersecurity best practices:

  1. Develop a WISP: Establish a comprehensive WISP that details security measures and incident response protocols.

  2. Conduct Regular Training: Implement ongoing cybersecurity training for all staff, ensuring they are aware of current threats, like phishing.

  3. Implement Security Audits: Perform regular IT security audits to identify gaps and remediate vulnerabilities proactively.

These proactive measures create a safer environment for handling client data and improve authenticity in client relationships.

How Do Managed IT Services Enhance IRS Data Security Requirements?

Utilizing managed IT services can substantially enhance IRS compliance and data protection for tax preparers. These services provide expert evaluation and strengthening of data security measures, significantly reducing risks associated with handling sensitive information.

By leveraging the expertise of a team like Empowered IT Solutions, tax preparers can benefit from advanced 24/7 monitoring systems and proactive threat management that protects the overall data handling environment.

What Local Compliance Considerations Should Tax Preparers in San Diego County Know?

Tax preparers operating in San Diego County must navigate additional local compliance regulations alongside federal requirements. California layers additional data security-related obligations on top of federal rules.

How Do IRS Data Security Requirements Interface with Regional Regulations?

IRS data security requirements intersect with regional regulations, such as local data protection laws that may impose further controls on handling client information. These local laws could include stipulations regarding the sharing of personal information and penalties for data breaches.

Two key examples include the California Consumer Privacy Act (CCPA), which governs how personal information is protected and handled, and California’s data breach notification law (Civil Code Section 1798.82), which requires notifying affected individuals if their data is compromised. Preparers should consider incorporating these into their WISP and consult a compliance professional for specific guidance.

Which Empowered IT Solutions Services Address Unique San Diego Compliance Challenges?

Empowered IT Solutions offers tailored regulatory compliance services that address the unique compliance challenges faced by tax preparers in San Diego County. Our local expertise enables us to assist firms and individual tax preparers in aligning their operational practices with both IRS data security and local regulatory requirements. Tailored assessments help ensure all aspects of compliance are covered, providing peace of mind for tax preparers and their clients.

Where Can Tax Preparers Get Help With IRS WISP Requirements?

With Form W-12 now putting data security responsibilities directly in front of paid tax return preparers, asking them to acknowledge that they are aware they are required by law to create and maintain a Written Information Security Plan (WISP) that provides data and system security protections for taxpayer information.

But simply downloading a WISP template does not secure your practice.

A WISP should reflect the actual cybersecurity protections, policies, procedures, and security practices your firm has in place. Working with an IT and cybersecurity professional can help ensure the security program behind the document is actually implemented, documented, and maintained.

Why Work With a Cybersecurity & Compliance Professional?

Tax preparers are experts at serving their clients, not necessarily cybersecurity or information security compliance.

A cybersecurity and compliance professional can help translate the requirements into practical steps, implement appropriate protections, develop the necessary documentation, identify gaps, and help maintain the program as your technology and business change.

Rather than handing you a generic template and leaving the rest up to you, Empowered IT Solutions helps do the heavy lifting.

Empowered IT Solutions helps tax and accounting practices put the cybersecurity protections, documentation, and employee training behind their WISP in place.

How to Schedule a Free Consultation With Empowered IT Solutions for IRS WISP Data Security Requirements?

Empowered IT Solutions offers a unique combination of expertise and local knowledge, specifically designed to support tax preparers in achieving and maintaining compliance with the latest IRS data security requirements.

To schedule a 15-minute consultation with Empowered IT Solutions to discuss your WISP and data security responsibilities, tax preparers can contact us here.

For those who are attending the 2026 IRS Nationwide Tax Forum held at the Town and Country Resort in San Diego from September 15-17, book a meeting with us and claim a free cybersecurity training session for your whole team!

About the Author

Maribel Hernandez is the Business Development Director at Empowered IT Solutions, where she helps business owners understand and navigate the complex world of IT, cybersecurity, and compliance. With a passion for making technology approachable, she specializes in translating technical concepts into practical business solutions that organizations can confidently implement.

Maribel works closely with business owners, executives, accountants, attorneys, healthcare providers, and nonprofit leaders to identify risks, strengthen cybersecurity programs, and build technology strategies that support long-term growth. Her areas of focus include cybersecurity awareness, compliance readiness, and small business technology planning.