Blog · Compliance · July 12, 2026 · By Mike Parker

The DOL's Cybersecurity Expectations for Retirement Plans

Since 2021, the Department of Labor has treated protecting plan data as fiduciary work — and its 2024 update extended that expectation to every ERISA plan. Here's what sponsors and TPAs are actually supposed to do.

For years, cybersecurity for a 401(k) worked on an unspoken assumption: the recordkeeper has it handled. Then participant accounts started getting drained by criminals with stolen credentials, lawsuits followed, and in April 2021 the Department of Labor's Employee Benefits Security Administration (EBSA) put the assumption in writing — and reversed it. Protecting plan data and assets, the DOL said, is part of the fiduciary job. Not the vendor's job. Yours.

If you sponsor a retirement plan, or you're the third-party administrator sitting between sponsors and recordkeepers, this guidance is the quiet standard you're being measured against.

What the DOL actually issued

The April 2021 guidance came in three pieces, each aimed at a different audience:

  • Tips for Hiring a Service Provider with Strong Cybersecurity Practices — for sponsors and fiduciaries: what to ask recordkeepers, TPAs, and custodians before and after hiring them.
  • Cybersecurity Program Best Practices — twelve practices the DOL expects of recordkeepers and every other service provider that touches plan IT systems and data.
  • Online Security Tips — for participants themselves: account hygiene, MFA, monitoring for fraud.

Then came the update. In September 2024, EBSA issued Compliance Assistance Release No. 2024-01, and its message was scope: the guidance applies to all ERISA-covered plans — health and welfare plans included — not just retirement plans. Some service providers had argued the 2021 documents were retirement-only; the DOL, prompted by a 2022 recommendation from its ERISA Advisory Council, shut that reading down. As of mid-2026 that framework still stands, and cybersecurity questions now show up inside EBSA plan investigations alongside the traditional fee and document requests.

Why "guidance" still reaches you

None of this is a formal regulation. It doesn't need to be. ERISA's duty of prudence is statute, and the DOL's position is that prudently selecting and monitoring service providers already includes their cybersecurity. The guidance simply spells out what prudent looks like. That has two practical consequences: EBSA investigators use it as their checklist, and plaintiffs' attorneys use it as their yardstick when a participant's account gets emptied. Fiduciary liability is personal — which makes this the rare IT topic that belongs on the owner's desk, not just the administrator's.

The framework, in three numbers

A standard of care with a page count

The DOL didn't publish vague encouragement. It published documents specific enough to audit against — which is exactly how they're being used.

3

guidance documents — for fiduciaries, service providers, and participants

DOL EBSA, April 2021

12

best practices expected of every provider touching plan data

EBSA Cybersecurity Program Best Practices

247

days — average time to identify and contain a breach; longer than a full plan-year audit cycle

IBM Cost of a Data Breach 2026

The twelve best practices, translated

The DOL’s list for service providers, in plain English:

  • Formal, documented security program
  • Annual risk assessment
  • Annual independent audit of security controls
  • Clearly assigned security roles
  • Strong access controls
  • Security review of any cloud or third party storing plan data
  • Awareness training for staff
  • Secure development process for the systems they build
  • Business resiliency program — business continuity, disaster recovery, incident response
  • Encryption of sensitive data at rest and in transit
  • Strong technical controls kept current
  • Defined response to — and disclosure of — incidents

Read it twice and you'll notice something: it's simply a competent security program. Nothing exotic. The regulatory move was making it expected, in writing, for anyone who touches plan data.

The vendor-diligence checklist fiduciaries are supposed to run

Drawing from the DOL's hiring tips, here's what selecting and monitoring a recordkeeper, custodian, or subservice provider should look like on paper:

  1. Ask for the audit, not the brochure. Independent security audit results (SOC 2-type reports), what the findings were, and what got remediated.
  2. Put security in the contract. Explicit information-security obligations, breach-notification timelines, cooperation duties, and limits on data use, retention, and destruction. Watch for clauses that quietly disclaim liability for breaches.
  3. Verify insurance. Does the provider carry coverage that would actually respond to a cyber incident affecting your participants?
  4. Check the record. Public breach history, litigation, regulatory actions — and how the provider handled them.
  5. Confirm participant-facing controls. MFA on portals, fraud monitoring, and an account-restoration guarantee in writing if funds are stolen.
  6. Re-review annually and write it down. Diligence isn't a hiring event; it's a monitoring cycle. The fiduciary file — questionnaires, responses, minutes — is what proves prudence later.

If you're the TPA, you're also the vendor

Here's the part that lands on third-party administrators specifically: those checklists are coming at you. Sponsors' counsel and advisors increasingly send diligence questionnaires built straight from the DOL's twelve practices, and "we're a small shop" is not one of the twelve. A TPA that can hand back an evidence packet — independent audit attestations, MFA and encryption policies, tested backup and disaster recovery, an incident response plan, training records — doesn't just stay compliant. It wins business from the TPAs who answer with a shrug.

That evidence packet is largely an IT deliverable, and it's the kind we build through our managed cybersecurity service for firms that handle other people's money and data for a living.

The DOL didn't just publish advice. It described the standard of care — and documented diligence is how fiduciaries meet it.

Quick answers

DOL cybersecurity guidance, answered plainly

Does the DOL cybersecurity guidance apply to health and welfare plans too?

Yes. That was the point of Compliance Assistance Release No. 2024-01, issued in September 2024: the Department of Labor confirmed its 2021 cybersecurity guidance applies to all ERISA-covered plans — health and welfare plans included — not just retirement plans. Some service providers had read the original guidance narrowly; the DOL closed that door.

Is the guidance legally binding?

It is sub-regulatory guidance, not a formal rule — but the fiduciary duty of prudence under ERISA is statutory, and the DOL frames prudent selection and monitoring of service providers, including their cybersecurity, as part of that existing duty. EBSA has also asked cybersecurity questions in plan investigations. In practice, the guidance describes the standard of care a fiduciary will be measured against after something goes wrong.

What cybersecurity documentation should a plan fiduciary keep?

A file that shows diligence actually happened: the security questionnaires you sent providers and their answers, the independent audit reports you reviewed and what you did about findings, contract provisions on security and breach notification, insurance confirmations, annual re-review notes, and minutes recording the decisions. If it is not written down, from the DOL's perspective it did not happen.

We are a small TPA. Where do we start?

Start by assuming every sponsor questionnaire you will receive is built from the DOL's twelve best practices, and map your own environment against them: MFA everywhere, monitored endpoints, encrypted and tested backups, a written incident response plan, annual risk assessment, and staff training. Then assemble an evidence packet — audit reports, policies, insurance — so you can answer diligence requests in days instead of scrambling each time.

Who actually enforces this?

The DOL's Employee Benefits Security Administration, through plan audits and investigations where cybersecurity questions now appear alongside the traditional ones. The second enforcement channel is civil litigation: participants whose accounts are drained sue plan sponsors and providers, and the DOL guidance gives plaintiffs a ready-made yardstick for what prudent parties should have done.

Could you answer a sponsor's security questionnaire today?

A free 30-minute assessment with the owner — we'll map your environment against the DOL's twelve practices and show you what the evidence packet is missing. No pitch deck, no obligation.

Book a Free 30-Minute IT Assessment