DOL Cybersecurity Guidance — Implemented, Documented, Defensible
Since 2021, the Department of Labor has treated protecting plan data as fiduciary work — and its 2024 update extended that expectation to every ERISA plan. If you're a TPA, recordkeeper, plan sponsor, or advisor, the EBSA cybersecurity program expectations now land on your desk, personally.
We implement and operate the controls the DOL's twelve best practices describe, and keep the evidence audit-ready — so sponsor questionnaires, plan audits, and EBSA questions get answered with records, not reassurances.
What the DOL actually expects
In April 2021, EBSA published cybersecurity guidance in three pieces: hiring tips for the fiduciaries who select service providers, twelve Cybersecurity Program Best Practices for every provider that touches plan IT systems and data, and online security tips for participants. In September 2024, Compliance Assistance Release No. 2024-01 settled the scope question: the guidance covers all ERISA plans — health and welfare included.
None of it is a formal regulation, and none of it needs to be. ERISA's duty of prudence is statute, and the DOL's position is that prudently selecting and monitoring service providers already includes their cybersecurity. Fiduciary liability is personal — which makes this the rare IT topic that belongs on the owner's desk. We wrote a plain-English breakdown in our guide to the DOL cybersecurity guidance for retirement plans and TPAs.
The twelve best practices, mapped to what we run
EBSA's list isn't exotic — it's a competent security program, in writing. Here is each practice and the control we put behind it:
| EBSA best practice | How CRC Cloud delivers it |
|---|---|
| 1. A formal, well-documented cybersecurity program | We stand up and operate the program: written policies, named owners, and controls that demonstrably run |
| 2. Prudent annual risk assessments | NIST CSF-based risk assessments on a schedule, with documented findings and a remediation roadmap |
| 3. A reliable annual third-party audit of security controls | We don't audit you — independence is the point. We prepare you for the auditor: evidence, documentation, and remediation of findings |
| 4. Clearly defined information security roles and responsibilities | Accountability in writing: our team's responsibilities and your leadership's, with vCIO-level oversight |
| 5. Strong access control procedures | MFA everywhere, least-privilege and role-based access, documented onboarding and offboarding |
| 6. Security reviews of cloud and third-party data storage | Vendor management support: security review of the platforms holding plan data — and our own hosting sits in an attested facility |
| 7. Periodic cybersecurity awareness training (Secure IT) | Recurring security awareness training (Secure IT) with completion records you can produce on request |
| 8. A secure system development life cycle (SDLC) program | If you build systems, this lands on your dev process; we support it with hardened configurations and disciplined patching around everything you run |
| 9. A business resiliency program: continuity, disaster recovery, incident response | Immutable, encrypted backup, replication, disaster recovery tested with defined RTO/RPO, and a written incident response plan |
| 10. Encryption of sensitive data, stored and in transit | Encryption both ways as standard, with coverage documented |
| 11. Strong technical controls per best security practices | EDR on endpoints, patching, firewalls, network segmentation, and 24/7 monitoring — kept current, not installed and forgotten |
| 12. Appropriate response to past cybersecurity incidents | Managed detection and response with a 24/7 SOC to contain incidents, plus documented response and disclosure procedures |
Practice wording condensed from EBSA's “Cybersecurity Program Best Practices” (April 2021); scope confirmed for all ERISA plans by Compliance Assistance Release No. 2024-01. We implement and operate controls — we don't certify, audit, or guarantee compliance.
Participant data concentrates everything criminals want
Identities, balances, and standing instructions to move money — retirement and benefit plans hold all three. The DOL didn't publish guidance for fun; the numbers explain the urgency, and the liability lands on fiduciaries by name.
$20.9B
U.S. reported cybercrime losses in 2025 — up 26% in a year
FBI IC3 2025$11.5M
average cost of a U.S. data breach — a record high
IBM Cost of a Data Breach 2026247
days — average time to identify and contain a breach, across all organizations studied
IBM Cost of a Data Breach 2026A months-long quiet intrusion into plan data is a fiduciary nightmare with your name on it. See how Secure IT closes that window →
Participant data needs a guard, not an alarm
Several of the twelve practices — monitoring, technical controls, incident response — assume someone is actually watching. An alert nobody answers at 2 AM is an alarm; a 24/7 Security Operations Center that contains the threat is a guard. That's the difference between our managed detection and response and a stack of security licenses.
- 24/7 SOC monitoring with SIEM log correlation — evidence for practices 1, 7, and 11
- Containment and response, not just notification — practice 12, in operation
- Immutable Microsoft 365 backup on Secure IT, with server and endpoint backup available as priced add-ons — practice 9, restore-tested on a schedule
And when plan data is hosted with us, it lives behind facility credentials we can state plainly. Our infrastructure runs in a Southern California facility engineered to a concurrently maintainable, Tier III-standard design. Its operator holds SOC 1 and SOC 2 Type II attestations, ISO 27001 and PCI-DSS certifications, and NIST 800-53 (PE) High alignment, with N+1 redundant power and cooling and a 99.9% uptime service level. Those are the facility's credentials — not CRC Cloud's — and we keep that distinction explicit.
See backup & disaster recovery →Built for the people the guidance names
EBSA's expectations reach everyone in the plan-data chain — and we serve each link:
Third-Party Administrators
Sponsor questionnaires are built from the twelve practices, and they're coming at you. We know the vertical well enough to run a dedicated brand for it, TPAIT® (tpait.com). Start with our TPA industry page.
Recordkeepers
You hold the largest concentration of participant data in the chain — the twelve practices were written with you in mind, and diligence requests arrive constantly. We keep the evidence packet ready.
Plan Sponsors
Your fiduciary duty includes vetting every provider's cybersecurity — and running a defensible program yourself. We put the controls and the documentation trail behind both.
Advisors & Fiduciary Firms
Clients ask you whether their plans are protected; your own firm has to clear the same bar. We make both answers yes — with records to show for it.
This page is one lane of a wider practice — explore SOC 2 readiness for the independent-audit side, or everything on our compliance hub →
DOL cybersecurity requirements, asked and answered
What are the DOL cybersecurity requirements for retirement plans?
In April 2021, the Department of Labor's Employee Benefits Security Administration (EBSA) published guidance in three pieces: Tips for Hiring a Service Provider (for fiduciaries), Cybersecurity Program Best Practices (twelve practices expected of recordkeepers and every service provider touching plan data), and Online Security Tips (for participants). Together they say plan data deserves a formal, documented cybersecurity program, and that fiduciaries must vet the cybersecurity of everyone they hire.
Do the DOL cybersecurity requirements apply to health and welfare plans too?
Yes. Compliance Assistance Release No. 2024-01, issued in September 2024, confirmed the 2021 guidance applies to all ERISA-covered plans, health and welfare plans included, not just retirement plans. Some providers had read the original guidance narrowly; EBSA closed that door.
Is the EBSA guidance legally binding?
It is sub-regulatory guidance, not a formal rule, but ERISA's fiduciary duty of prudence is statutory, and the DOL frames prudent selection and monitoring of service providers, including their cybersecurity, as part of that existing duty. EBSA has also asked cybersecurity questions in plan investigations. In practice, the guidance describes the standard of care you will be measured against after something goes wrong.
What are the DOL's twelve cybersecurity best practices?
The twelve are, in condensed form: a formal, well-documented cybersecurity program. Prudent annual risk assessments, and a reliable annual third-party audit of security controls. Clearly defined security roles and responsibilities, plus strong access control procedures. Security reviews of any cloud or third party storing plan data. Periodic cybersecurity awareness training (Secure IT), and a secure system development life cycle program. A business resiliency program covering business continuity, disaster recovery and incident response. Encryption of sensitive data at rest and in transit, with strong technical controls kept current. And appropriate response to past cybersecurity incidents.
Can CRC Cloud certify us as DOL compliant?
No, and nobody can: there is no DOL cybersecurity certification to earn, and we never claim to certify, audit, or guarantee compliance. What we do is implement and operate the controls the twelve practices describe, document them, and keep the evidence audit-ready, so when a plan sponsor, auditor, or EBSA investigator asks, you answer with records instead of promises.
We are a TPA. Does CRC Cloud actually know retirement plans?
Well enough to give the industry its own home. We run a dedicated brand for third-party administrators, TPAIT®, with resources built specifically for retirement-plan providers and fiduciary firms; you can explore it at tpait.com. The underlying delivery is the same CRC Cloud platform, tuned to plan-administration software, recordkeeping data flows, and filing-season uptime.
What will a plan sponsor security questionnaire ask us for?
Assume it is built from the DOL's twelve practices, because increasingly it is: MFA, encryption at rest and in transit, tested backup (published retention rates)s, continuous monitoring, staff training records, a written incident response plan, and independent evidence that it all runs. We keep that evidence packet current so diligence requests take days, not quarters.
Where do we start if we are behind on the DOL guidance?
With an honest map of where you stand. Our free 30-minute assessment is NIST CSF-based and maps your environment against the twelve practices, showing which controls exist, which are partial, and which are missing. How long remediation takes depends on that starting point, so we measure before we prescribe.
Priced openly, like everything else we do. DOL cybersecurity program work carries a published uplift of +10% on the per-user plan and per-server management fee — documentation, evidence and audit support are real recurring hours, so we price them instead of hiding them in a quote. Secure IT is the starting point for compliance work — Core IT is not an option for a regulated environment, because the frameworks lean on the monitored layer it adds. On Secure IT that is $275 per user per month. Backup, private cloud resources and add-ons stay at their flat published rates. See the full compliance uplift table →