The short answer: EBSA investigators ask for the evidence behind each of DOL’s 12 cybersecurity best practices—your written security program, risk assessments, third-party audit reports, access-control documentation, vendor reviews, training records, and incident response plan. TPAs that maintain these continuously answer in days. TPAs that assemble them after the letter arrives face extended investigations.

How a Cybersecurity Investigation Starts

Since January 15, 2026 (opens in new tab), cybersecurity has been a formal National Enforcement Project under EBSA—one of the agency’s stated investigation priorities. Examinations typically open with a document request letter; where cooperation stalls, EBSA has subpoena power that courts have enforced against service providers directly (Walsh v. Alight Solutions, 7th Cir. 2022). And since Compliance Assistance Release 2024-01 (opens in new tab), the guidance explicitly reaches every ERISA plan service provider—including TPAs administering 401(k), 403(b), 457(b), defined benefit, and ESOP plans.

ERISA attorneys who defend these investigations describe them as a potential “trap door to endless document requests” (opens in new tab)—because each incomplete answer generates follow-up demands. Preparation is the difference.

The Document Checklist

Mapped to the DOL practice each item evidences:

Documents EBSA typically requests from TPAs, by DOL best practice
Document categoryDOL practiceWhat investigators look for
Written cybersecurity program / information security policy#1Scope, governance, annual review dates, board or management approval
Risk assessments (current and prior years)#2TPA-specific threats, findings, remediation plans with timelines—and whether remediation happened
Third-party audit reports#3SOC 2 Type II, SOC 1, penetration tests, or equivalent independent assessments
Security roles documentation#4Named individuals with authority for security decisions and incident response
Access control policies + evidence#5MFA configuration, least-privilege model, quarterly access reviews, deprovisioning records
Vendor due-diligence files#6Security reviews for every vendor touching participant data—recordkeepers, payroll bridges, IT providers
Training records#7Completion rates, phishing simulation results, remediation for failures
Encryption standards#10At-rest and in-transit standards, backup encryption, key management
Business continuity / disaster recovery plans#9Tested plans with RTO/RPO—and test results, not just the binder
Incident response plan + incident history#12Documented procedures, tabletop exercises, and records of any actual incidents and participant notifications

What Trips TPAs Up

Three patterns extend investigations. Scattered evidence: policies live in one system, training logs in another, vendor files in email—and assembling them under deadline produces gaps and inconsistencies. Undocumented practice: many TPAs actually do the work but never generate the artifact; to an investigator, undocumented is indistinguishable from undone. Inconsistent answers: when the risk assessment says one thing and the policy says another, follow-up requests multiply. Firms under investigation should involve ERISA counsel early—scope and privilege questions are legal decisions, not IT decisions.

The 48-Hour Standard

The practical readiness test: could you produce every category above within 48 hours, current as of this quarter? That is the standard we build for TPAIT clients—an evidence folder per DOL practice, refreshed continuously as part of managed service delivery, so a document request letter is an administrative task instead of a crisis. Score yourself honestly with our DOL readiness checklist, and see the compliance guide for implementing whatever is missing.

Common Questions

What triggers an EBSA cybersecurity investigation?

Cybersecurity has been a formal EBSA National Enforcement Project since January 15, 2026, so investigations can arise from routine plan examinations, participant complaints, breach notifications, or referrals. A reported incident involving participant data is the most common trigger, but EBSA also examines cybersecurity as part of broader plan investigations.

Does EBSA investigate TPAs directly, or only plans?

Both. The Walsh v. Alight Solutions ruling (7th Circuit, 2022) confirmed DOL can subpoena non-fiduciary service providers directly, and Compliance Assistance Release 2024-01 states the cybersecurity guidance applies to all ERISA plan service providers, including TPAs.

How fast do you need to respond to an EBSA document request?

Response deadlines are set in the request letter or subpoena and are often negotiable through counsel, but firms that maintain organized, current documentation respond in days rather than weeks. Extended back-and-forth over missing documents is what turns a routine inquiry into a prolonged investigation.

Get Audit-Ready Before the Letter Arrives

A free IT & cybersecurity assessment shows you exactly which documents you could produce today—and which you couldn’t.

Book Free IT & Cyber Assessment (opens in new tab)