A state capitol building beside a procurement contract stamped with security requirements

The short answer: if a client plan is a governmental 457(b) or 403(b), the Department of Labor’s cybersecurity guidance is not the rule you are being measured against. State procurement security addenda, state cloud authorization programs such as GovRAMP and TX-RAMP, and fifty separate breach-notification statutes are. Most TPAs serving public-sector plans discover this during a contract renewal, which is late.

ERISA Title I “shall not apply to any employee benefit plan if… such plan is a governmental plan.” ERISA §4(b)(1) — 29 U.S.C. §1003(b)(1) (opens in new tab)

The Exclusion Is Real, and the Wording Matters

Governmental plans are carved out of ERISA Title I by §4(b)(1), with “governmental plan” defined at §3(32) (29 U.S.C. §1002(32)) to cover plans established or maintained for their employees by the federal government, by a state or political subdivision, or by their agencies and instrumentalities. A county’s 457(b), a school district’s 403(b), a state university system’s plan — all outside.

That carve-out has a direct consequence for cybersecurity obligations, and the DOL has been precise about it. When EBSA issued Compliance Assistance Release No. 2024-01 (opens in new tab) on September 6, 2024, to settle an argument about scope, it clarified that the 2021 guidance applies to “all types of ERISA plans, including health and welfare plans and all employee pension benefit plans.” The Tips for Hiring a Service Provider (opens in new tab) are addressed to “plan sponsors of all types and sizes of ERISA plans.”

Read that qualifier carefully. The clarification widened the guidance across plan types; it did not reach across the statutory boundary. Our DOL compliance guide and readiness checklist remain the right framework for ERISA work. For public-sector plans, they are an excellent template and a poor citation.

What Sits in Its Place

Nothing about the ERISA exclusion lowers the bar. It replaces one federal framework with a layered, state-by-state set of requirements that are frequently more prescriptive and carry harder consequences — a failed certification can disqualify a bid outright.

Requirements that reach public-sector plan service providers
SourceWhat it isWhy it reaches a TPA
State procurement security addendaContract riders imposing named controls, audit rights, and breach-notice windowsAttached to the administration agreement itself; non-negotiable in many jurisdictions
GovRAMP (formerly StateRAMP)Non-profit authorization program built on NIST SP 800-53 controls; operating as GovRAMP since February 2025; public-sector organizations in more than half of US states engage with itNorth Carolina: new executive-branch contracts for vendor-hosted services from April 2026, full compliance from April 1, 2027, existing contracts at renewal or amendment; FedRAMP Rev. 5 may be accepted in lieu. Nevada: new contracts with a cloud component from July 1, 2026, with GovRAMP Core status due within 12 months of contract execution where applicable — and Nevada states it will not accept SOC 2, ISO 27001, HITRUST, or TX-RAMP in its place
TX-RAMPTexas DIR program, Levels 1 and 2, certification valid three yearsLevel 2 mandatory since January 1, 2022, and Level 1 since January 1, 2024, for cloud services contracted by state agencies, higher education, and public community colleges; a certified provider must report a breach of system security to DIR within 48 hours of becoming aware
State breach-notification statutesFifty separate regimes with differing triggers, timelines, and regulator-notice dutiesDetermined by participant residence, not by where your firm sits
FTC Safeguards Rule (GLBA)Information-security program requirements for “financial institutions” under FTC jurisdiction; since May 13, 2024, notice to the FTC within 30 days of a breach affecting 500 or more consumersDepends on the vendor’s own activities, not the plan type — the FTC’s list includes account servicers and financial advisers not registered with the SEC. FTC (opens in new tab)
SEC Regulation S-P (amended)Applies to broker-dealers, investment companies, SEC-registered advisers and transfer agents; fully in effect since June 3, 2026A TPA holding customer information for one of those firms is its service provider and will be asked to report breaches within 72 hours. See the 72-hour clause
IRS Publication 1075Safeguards for federal tax information held by agencies and their contractorsApplies only where FTI is genuinely in scope — confirm before assuming it is
NIST Cybersecurity Framework 2.0Voluntary framework, the common vocabulary across most state programsThe cheapest way to answer public-sector questionnaires consistently

One qualification matters. The state programs above govern contracts with state executive-branch agencies for services that store, process, or transmit state data. A county’s 457(b) or a school district’s 403(b) is usually contracted locally and is not automatically covered — though local entities increasingly borrow the same requirements in their own procurement terms. Establish which entity you are actually contracting with before deciding which program applies.

Two regimes in the table attach to the vendor rather than the plan: the FTC Safeguards Rule and amended SEC Regulation S-P. They apply the same way whether the plan is governmental or ERISA-covered, which makes them easy to overlook in a public-sector bid.

Four Ways This Is Harder Than ERISA Work

The buyer is procurement, not a fiduciary committee. An ERISA sponsor is discharging a duty of prudence and has latitude in how. A public procurement officer is applying a rule and often has none. “We follow DOL best practices” is a persuasive answer to the first and a non-responsive answer to the second.

Certification is not attestation. GovRAMP and TX-RAMP are authorizations against a prescribed baseline. You hold one or you do not. A SOC 2 Type II is still worth having — it is what everyone else accepts — but it will not substitute where certification is a statutory condition of contracting.

There is no single deadline. Requirements land per state, per program, per contract cycle. A firm administering plans in eight states is tracking eight timetables.

Your answers may become public. Security questionnaire responses submitted to a public entity can fall within that state’s public records law. Write them as though they will be read by someone who is not your client.

This Is Not Theoretical

In 2024, Carruth Compliance Consulting — an administrator focused on 403(b) and 457 plans for public-sector employers — disclosed a network intrusion affecting roughly 48,400 participants, with the consequences landing on the school districts it served. Details are in our TPA breach reports.

The pattern there is the one worth internalizing: when a public-sector plan administrator is compromised, the affected parties are government employers with statutory notification duties of their own, public boards, and local press. The escalation path is shorter and more visible than in the private sector.

What to Have Ready

  • A jurisdiction map. Which public-sector plans you administer, in which states, under which contracting entity. Most firms cannot produce this in an afternoon, and it is the prerequisite for everything else.
  • A control set mapped to NIST CSF 2.0. One mapping answers most state questionnaires without rewriting your posture for each.
  • A clear scope statement describing exactly which of your services are cloud-hosted, participant-facing, and in-scope for a state authorization program — and which are not.
  • Breach-notification timing you can actually meet, written into the agreement rather than negotiated during an incident.
  • A subcontractor register. Public-sector addenda routinely require disclosure and flow-down. See continuous monitoring and third-party risk.
  • Evidence with dates on it. Access reviews, patch reports, tested recovery. The same discipline covered in our TPA IT readiness assessment.

None of this is exotic. It is the ERISA discipline plus a map and a scope statement. The firms that struggle are the ones that assumed the exclusion meant the question would not be asked.

To see which of these programs are likely to reach your firm, try the free TPA Cyber Rules Navigator.

Frequently Asked Questions

Does DOL cybersecurity guidance apply to governmental 457(b) and 403(b) plans?

Not as a binding requirement. ERISA §4(b)(1) excludes governmental plans from Title I, and CAR 2024-01 confirms the cybersecurity guidance applies to all types of ERISA plans. Treat the DOL’s twelve best practices as a strong industry template rather than the governing instrument — most public-sector sponsors still expect something equivalent, because their own procurement rules demand it.

Do we need GovRAMP or TX-RAMP certification?

It depends on the state and on whether you are supplying a cloud service to the government entity. A TPA that only administers a plan under contract with a district may not trigger these programs; a TPA hosting a participant-facing portal often does. Confirm with the contracting entity rather than assuming in either direction.

Is a SOC 2 Type II enough for a public-sector plan sponsor?

Necessary, frequently not sufficient. Bring the SOC 2, then separately establish whether a state authorization program applies to the specific service you provide.

Administering Public-Sector Plans?

A free assessment maps your current controls to NIST CSF 2.0 and flags where state programs are likely to reach your services.

Book Free IT & Cyber Assessment (opens in new tab)