What are the DOL's cybersecurity expectations for plan vendors?
Last updated October 2, 2026
DOL guidance — extended explicitly to health and welfare plans in 2024 — expects fiduciaries to assess vendors' cybersecurity practices, ask for their security programs, audit results, and breach history, and include security and breach-notification obligations in contracts. Ignoring cyber risk is now a fiduciary gap.
The Department of Labor's cybersecurity guidance (first issued 2021, confirmed applicable to all ERISA plans including health plans in 2024) treats vendor cyber risk as squarely a fiduciary concern, because plan data and assets live almost entirely in vendor systems.
For hiring and monitoring service providers, the DOL expects fiduciaries to:
- Ask about the vendor's information security program, standards, and third-party audits
- Review breach history and how incidents were handled
- Negotiate contract terms covering security standards, breach notification, and liability
- Revisit security posture during ongoing monitoring, not just at hire
A one-page cybersecurity questionnaire sent to each vendor annually, filed with the responses, moves you from "never asked" to "documented oversight" — a large legal distance at minimal cost.
Thanks for your feedback!