What are the DOL's cybersecurity expectations for plan vendors?

Last updated October 2, 2026

DOL guidance — extended explicitly to health and welfare plans in 2024 — expects fiduciaries to assess vendors' cybersecurity practices, ask for their security programs, audit results, and breach history, and include security and breach-notification obligations in contracts. Ignoring cyber risk is now a fiduciary gap.

The Department of Labor's cybersecurity guidance (first issued 2021, confirmed applicable to all ERISA plans including health plans in 2024) treats vendor cyber risk as squarely a fiduciary concern, because plan data and assets live almost entirely in vendor systems.

For hiring and monitoring service providers, the DOL expects fiduciaries to:

  • Ask about the vendor's information security program, standards, and third-party audits
  • Review breach history and how incidents were handled
  • Negotiate contract terms covering security standards, breach notification, and liability
  • Revisit security posture during ongoing monitoring, not just at hire

A one-page cybersecurity questionnaire sent to each vendor annually, filed with the responses, moves you from "never asked" to "documented oversight" — a large legal distance at minimal cost.

Thanks for your feedback!

Put these answers to work

Fiduciary In A Box walks your team through every one of these requirements step by step — documenting decisions, organizing files, and keeping your plan compliant year-round.

See how FIAB works