What EBSA Asks For in a Cybersecurity Investigation: The TPA Document Checklist
When the document request letter arrives, the categories are predictable. Here is what investigators expect—and how to be able to produce it in days, not months.
The short answer: EBSA investigators ask for the evidence behind each of DOL’s 12 cybersecurity best practices—your written security program, risk assessments, third-party audit reports, access-control documentation, vendor reviews, training records, and incident response plan. TPAs that maintain these continuously answer in days. TPAs that assemble them after the letter arrives face extended investigations.
How a Cybersecurity Investigation Starts
Since January 15, 2026 (opens in new tab), cybersecurity has been a formal National Enforcement Project under EBSA—one of the agency’s stated investigation priorities. Examinations typically open with a document request letter; where cooperation stalls, EBSA has subpoena power that courts have enforced against service providers directly (Walsh v. Alight Solutions, 7th Cir. 2022). And since Compliance Assistance Release 2024-01 (opens in new tab), the guidance explicitly reaches every ERISA plan service provider—including TPAs administering 401(k), 403(b), 457(b), defined benefit, and ESOP plans.
ERISA attorneys who defend these investigations describe them as a potential “trap door to endless document requests” (opens in new tab)—because each incomplete answer generates follow-up demands. Preparation is the difference.
The Document Checklist
Mapped to the DOL practice each item evidences:
| Document category | DOL practice | What investigators look for |
|---|---|---|
| Written cybersecurity program / information security policy | #1 | Scope, governance, annual review dates, board or management approval |
| Risk assessments (current and prior years) | #2 | TPA-specific threats, findings, remediation plans with timelines—and whether remediation happened |
| Third-party audit reports | #3 | SOC 2 Type II, SOC 1, penetration tests, or equivalent independent assessments |
| Security roles documentation | #4 | Named individuals with authority for security decisions and incident response |
| Access control policies + evidence | #5 | MFA configuration, least-privilege model, quarterly access reviews, deprovisioning records |
| Vendor due-diligence files | #6 | Security reviews for every vendor touching participant data—recordkeepers, payroll bridges, IT providers |
| Training records | #7 | Completion rates, phishing simulation results, remediation for failures |
| Encryption standards | #10 | At-rest and in-transit standards, backup encryption, key management |
| Business continuity / disaster recovery plans | #9 | Tested plans with RTO/RPO—and test results, not just the binder |
| Incident response plan + incident history | #12 | Documented procedures, tabletop exercises, and records of any actual incidents and participant notifications |
What Trips TPAs Up
Three patterns extend investigations. Scattered evidence: policies live in one system, training logs in another, vendor files in email—and assembling them under deadline produces gaps and inconsistencies. Undocumented practice: many TPAs actually do the work but never generate the artifact; to an investigator, undocumented is indistinguishable from undone. Inconsistent answers: when the risk assessment says one thing and the policy says another, follow-up requests multiply. Firms under investigation should involve ERISA counsel early—scope and privilege questions are legal decisions, not IT decisions.
The 48-Hour Standard
The practical readiness test: could you produce every category above within 48 hours, current as of this quarter? That is the standard we build for TPAIT clients—an evidence folder per DOL practice, refreshed continuously as part of managed service delivery, so a document request letter is an administrative task instead of a crisis. Score yourself honestly with our DOL readiness checklist, and see the compliance guide for implementing whatever is missing.
Common Questions
What triggers an EBSA cybersecurity investigation?
Cybersecurity has been a formal EBSA National Enforcement Project since January 15, 2026, so investigations can arise from routine plan examinations, participant complaints, breach notifications, or referrals. A reported incident involving participant data is the most common trigger, but EBSA also examines cybersecurity as part of broader plan investigations.
Does EBSA investigate TPAs directly, or only plans?
Both. The Walsh v. Alight Solutions ruling (7th Circuit, 2022) confirmed DOL can subpoena non-fiduciary service providers directly, and Compliance Assistance Release 2024-01 states the cybersecurity guidance applies to all ERISA plan service providers, including TPAs.
How fast do you need to respond to an EBSA document request?
Response deadlines are set in the request letter or subpoena and are often negotiable through counsel, but firms that maintain organized, current documentation respond in days rather than weeks. Extended back-and-forth over missing documents is what turns a routine inquiry into a prolonged investigation.
Get Audit-Ready Before the Letter Arrives
A free IT & cybersecurity assessment shows you exactly which documents you could produce today—and which you couldn’t.
Book Free IT & Cyber Assessment (opens in new tab)