DOL Cybersecurity Guidance — Implemented, Documented, Defensible

Since 2021, the Department of Labor has treated protecting plan data as fiduciary work — and its 2024 update extended that expectation to every ERISA plan. If you're a TPA, recordkeeper, plan sponsor, or advisor, the EBSA cybersecurity program expectations now land on your desk, personally.

We implement and operate the controls the DOL's twelve best practices describe, and keep the evidence audit-ready — so sponsor questionnaires, plan audits, and EBSA questions get answered with records, not reassurances.

What the DOL actually expects

In April 2021, EBSA published cybersecurity guidance in three pieces: hiring tips for the fiduciaries who select service providers, twelve Cybersecurity Program Best Practices for every provider that touches plan IT systems and data, and online security tips for participants. In September 2024, Compliance Assistance Release No. 2024-01 settled the scope question: the guidance covers all ERISA plans — health and welfare included.

None of it is a formal regulation, and none of it needs to be. ERISA's duty of prudence is statute, and the DOL's position is that prudently selecting and monitoring service providers already includes their cybersecurity. Fiduciary liability is personal — which makes this the rare IT topic that belongs on the owner's desk. We wrote a plain-English breakdown in our guide to the DOL cybersecurity guidance for retirement plans and TPAs.

The twelve best practices, mapped to what we run

EBSA's list isn't exotic — it's a competent security program, in writing. Here is each practice and the control we put behind it:

EBSA best practiceHow CRC Cloud delivers it
1. A formal, well-documented cybersecurity programWe stand up and operate the program: written policies, named owners, and controls that demonstrably run
2. Prudent annual risk assessmentsNIST CSF-based risk assessments on a schedule, with documented findings and a remediation roadmap
3. A reliable annual third-party audit of security controlsWe don't audit you — independence is the point. We prepare you for the auditor: evidence, documentation, and remediation of findings
4. Clearly defined information security roles and responsibilitiesAccountability in writing: our team's responsibilities and your leadership's, with vCIO-level oversight
5. Strong access control proceduresMFA everywhere, least-privilege and role-based access, documented onboarding and offboarding
6. Security reviews of cloud and third-party data storageVendor management support: security review of the platforms holding plan data — and our own hosting sits in an attested facility
7. Periodic cybersecurity awareness training (Secure IT)Recurring security awareness training (Secure IT) with completion records you can produce on request
8. A secure system development life cycle (SDLC) programIf you build systems, this lands on your dev process; we support it with hardened configurations and disciplined patching around everything you run
9. A business resiliency program: continuity, disaster recovery, incident responseImmutable, encrypted backup, replication, disaster recovery tested with defined RTO/RPO, and a written incident response plan
10. Encryption of sensitive data, stored and in transitEncryption both ways as standard, with coverage documented
11. Strong technical controls per best security practicesEDR on endpoints, patching, firewalls, network segmentation, and 24/7 monitoring — kept current, not installed and forgotten
12. Appropriate response to past cybersecurity incidentsManaged detection and response with a 24/7 SOC to contain incidents, plus documented response and disclosure procedures

Practice wording condensed from EBSA's “Cybersecurity Program Best Practices” (April 2021); scope confirmed for all ERISA plans by Compliance Assistance Release No. 2024-01. We implement and operate controls — we don't certify, audit, or guarantee compliance.

Why EBSA moved

Participant data concentrates everything criminals want

Identities, balances, and standing instructions to move money — retirement and benefit plans hold all three. The DOL didn't publish guidance for fun; the numbers explain the urgency, and the liability lands on fiduciaries by name.

$20.9B

U.S. reported cybercrime losses in 2025 — up 26% in a year

FBI IC3 2025

$11.5M

average cost of a U.S. data breach — a record high

IBM Cost of a Data Breach 2026

247

days — average time to identify and contain a breach, across all organizations studied

IBM Cost of a Data Breach 2026

A months-long quiet intrusion into plan data is a fiduciary nightmare with your name on it. See how Secure IT closes that window →

An alarm that only alerts versus a shield actively containing a threat, representing managed detection and response guarding participant data

Participant data needs a guard, not an alarm

Several of the twelve practices — monitoring, technical controls, incident response — assume someone is actually watching. An alert nobody answers at 2 AM is an alarm; a 24/7 Security Operations Center that contains the threat is a guard. That's the difference between our managed detection and response and a stack of security licenses.

  • 24/7 SOC monitoring with SIEM log correlation — evidence for practices 1, 7, and 11
  • Containment and response, not just notification — practice 12, in operation
  • Immutable Microsoft 365 backup on Secure IT, with server and endpoint backup available as priced add-ons — practice 9, restore-tested on a schedule

And when plan data is hosted with us, it lives behind facility credentials we can state plainly. Our infrastructure runs in a Southern California facility engineered to a concurrently maintainable, Tier III-standard design. Its operator holds SOC 1 and SOC 2 Type II attestations, ISO 27001 and PCI-DSS certifications, and NIST 800-53 (PE) High alignment, with N+1 redundant power and cooling and a 99.9% uptime service level. Those are the facility's credentials — not CRC Cloud's — and we keep that distinction explicit.

See backup & disaster recovery →

Built for the people the guidance names

EBSA's expectations reach everyone in the plan-data chain — and we serve each link:

Third-Party Administrators

Sponsor questionnaires are built from the twelve practices, and they're coming at you. We know the vertical well enough to run a dedicated brand for it, TPAIT® (tpait.com). Start with our TPA industry page.

Recordkeepers

You hold the largest concentration of participant data in the chain — the twelve practices were written with you in mind, and diligence requests arrive constantly. We keep the evidence packet ready.

Plan Sponsors

Your fiduciary duty includes vetting every provider's cybersecurity — and running a defensible program yourself. We put the controls and the documentation trail behind both.

Advisors & Fiduciary Firms

Clients ask you whether their plans are protected; your own firm has to clear the same bar. We make both answers yes — with records to show for it.

This page is one lane of a wider practice — explore SOC 2 readiness for the independent-audit side, or everything on our compliance hub →

DOL cybersecurity requirements, asked and answered

What are the DOL cybersecurity requirements for retirement plans?

In April 2021, the Department of Labor's Employee Benefits Security Administration (EBSA) published guidance in three pieces: Tips for Hiring a Service Provider (for fiduciaries), Cybersecurity Program Best Practices (twelve practices expected of recordkeepers and every service provider touching plan data), and Online Security Tips (for participants). Together they say plan data deserves a formal, documented cybersecurity program, and that fiduciaries must vet the cybersecurity of everyone they hire.

Do the DOL cybersecurity requirements apply to health and welfare plans too?

Yes. Compliance Assistance Release No. 2024-01, issued in September 2024, confirmed the 2021 guidance applies to all ERISA-covered plans, health and welfare plans included, not just retirement plans. Some providers had read the original guidance narrowly; EBSA closed that door.

Is the EBSA guidance legally binding?

It is sub-regulatory guidance, not a formal rule, but ERISA's fiduciary duty of prudence is statutory, and the DOL frames prudent selection and monitoring of service providers, including their cybersecurity, as part of that existing duty. EBSA has also asked cybersecurity questions in plan investigations. In practice, the guidance describes the standard of care you will be measured against after something goes wrong.

What are the DOL's twelve cybersecurity best practices?

The twelve are, in condensed form: a formal, well-documented cybersecurity program. Prudent annual risk assessments, and a reliable annual third-party audit of security controls. Clearly defined security roles and responsibilities, plus strong access control procedures. Security reviews of any cloud or third party storing plan data. Periodic cybersecurity awareness training (Secure IT), and a secure system development life cycle program. A business resiliency program covering business continuity, disaster recovery and incident response. Encryption of sensitive data at rest and in transit, with strong technical controls kept current. And appropriate response to past cybersecurity incidents.

Can CRC Cloud certify us as DOL compliant?

No, and nobody can: there is no DOL cybersecurity certification to earn, and we never claim to certify, audit, or guarantee compliance. What we do is implement and operate the controls the twelve practices describe, document them, and keep the evidence audit-ready, so when a plan sponsor, auditor, or EBSA investigator asks, you answer with records instead of promises.

We are a TPA. Does CRC Cloud actually know retirement plans?

Well enough to give the industry its own home. We run a dedicated brand for third-party administrators, TPAIT®, with resources built specifically for retirement-plan providers and fiduciary firms; you can explore it at tpait.com. The underlying delivery is the same CRC Cloud platform, tuned to plan-administration software, recordkeeping data flows, and filing-season uptime.

What will a plan sponsor security questionnaire ask us for?

Assume it is built from the DOL's twelve practices, because increasingly it is: MFA, encryption at rest and in transit, tested backup (published retention rates)s, continuous monitoring, staff training records, a written incident response plan, and independent evidence that it all runs. We keep that evidence packet current so diligence requests take days, not quarters.

Where do we start if we are behind on the DOL guidance?

With an honest map of where you stand. Our free 30-minute assessment is NIST CSF-based and maps your environment against the twelve practices, showing which controls exist, which are partial, and which are missing. How long remediation takes depends on that starting point, so we measure before we prescribe.

Priced openly, like everything else we do. DOL cybersecurity program work carries a published uplift of +10% on the per-user plan and per-server management fee — documentation, evidence and audit support are real recurring hours, so we price them instead of hiding them in a quote. Secure IT is the starting point for compliance work — Core IT is not an option for a regulated environment, because the frameworks lean on the monitored layer it adds. On Secure IT that is $275 per user per month. Backup, private cloud resources and add-ons stay at their flat published rates. See the full compliance uplift table →

Map your firm against the DOL's twelve practices

A free 30-minute, NIST CSF-based assessment with the owner — see which controls exist, which are partial, and which are missing. No pitch deck, no obligation.

Book a Free 30-Minute IT Assessment