SOC 2 for TPAs: What Plan Sponsors Actually Accept
DOL expects an annual third-party audit of your security controls. Here is how SOC 1, SOC 2, and the alternatives actually play in plan-sponsor due diligence.
The short answer: a SOC 2 Type II is the report plan sponsors, their advisors, and cyber insurers accept as proof of your security controls—and it is the cleanest way to evidence DOL best practice #3 (annual third-party audit). SOC 1 answers a different question: it supports your clients’ plan audits. A growing TPA eventually needs both stories straight.
The Alphabet, Sorted
SOC reports come from the AICPA’s System and Organization Controls framework. The confusion is that each report answers a different audience:
| Report | What it covers | Who asks for it | When it matters |
|---|---|---|---|
| SOC 1 | Controls relevant to clients’ financial reporting (ICFR) | Plan auditors, clients’ CPAs | Annual plan audit season—auditors relying on your processing |
| SOC 2 Type I | Security control design at a point in time | Sponsors early in due diligence; insurers | Your first examination—proves the controls exist |
| SOC 2 Type II | Security control design and operating effectiveness over 6–12 months | Sponsor due-diligence questionnaires, advisors, cyber insurers, DOL examiners | The de facto standard—proves the controls actually run |
| SOC 3 | Public summary of a SOC 2 | Marketing audiences | Website trust page; never a substitute in diligence |
What DOL Actually Expects
Best practice #3 in DOL’s Cybersecurity Program Best Practices (opens in new tab) calls for an annual third-party audit of security controls, and DOL’s companion hiring tips tell plan fiduciaries to ask service providers for exactly that evidence. Since Compliance Assistance Release 2024-01 (opens in new tab), that expectation reaches every service provider on 401(k), 403(b), 457(b), defined benefit, and welfare plans alike. In an EBSA document request, third-party audit reports are a standing line item.
The Distinction That Catches TPAs: Facility vs. Firm
Hosting your systems in an audited datacenter (ISO 27001, SOC 1/2, NIST 800-53) answers questions about the facility. Sponsor due diligence increasingly asks about your firm’s controls—your access management, your training, your incident response. Both layers matter: inherit the facility’s attestations for infrastructure, and document your own controls at the entity level. Conflating the two is the most common gap we see in due-diligence responses—and the first thing a sophisticated advisor probes.
A Realistic Path for a Small or Mid-Sized TPA
Year one: independent NIST CSF or SOC 2 readiness assessment, remediate the gaps, adopt the policies. Then a SOC 2 Type I to certify design, followed by the Type II examination over the next observation period. Every step is a defensible due-diligence answer—and each maps directly to DOL practices #1–#5. TPAIT builds and maintains the underlying controls and evidence for clients as part of managed service delivery, so the examination is an audit of work already documented, not a scramble.
Common Questions
Do TPAs need a SOC 1 or a SOC 2 report?
Usually both stories matter. SOC 1 covers controls relevant to your clients' financial reporting — plan auditors ask for it. SOC 2 covers security, availability, and confidentiality controls — plan sponsor due-diligence questionnaires and DOL best practice #3 point there. A SOC 2 Type II is the report that satisfies security due diligence.
Is a SOC 2 report legally required by the DOL?
No statute names SOC 2. But DOL best practice #3 expects an annual third-party audit of security controls, and a SOC 2 Type II examination is the most widely accepted way to evidence it. In practice, sponsors and their advisors increasingly treat it as table stakes when selecting a TPA.
What if a full SOC 2 Type II is cost-prohibitive for a small TPA?
Start with a SOC 2 Type I (a point-in-time examination) or an independent NIST CSF assessment, and put the Type II on a 12-month roadmap. Documented progression toward a Type II is a credible answer in due diligence; having nothing is not.
Build the Controls Before the Questionnaire Arrives
A free assessment maps your current posture against DOL’s 12 practices and a SOC 2 readiness baseline.
Book Free IT & Cyber Assessment (opens in new tab)