The short answer: a SOC 2 Type II is the report plan sponsors, their advisors, and cyber insurers accept as proof of your security controls—and it is the cleanest way to evidence DOL best practice #3 (annual third-party audit). SOC 1 answers a different question: it supports your clients’ plan audits. A growing TPA eventually needs both stories straight.

The Alphabet, Sorted

SOC reports come from the AICPA’s System and Organization Controls framework. The confusion is that each report answers a different audience:

SOC reports from a TPA’s perspective
ReportWhat it coversWho asks for itWhen it matters
SOC 1Controls relevant to clients’ financial reporting (ICFR)Plan auditors, clients’ CPAsAnnual plan audit season—auditors relying on your processing
SOC 2 Type ISecurity control design at a point in timeSponsors early in due diligence; insurersYour first examination—proves the controls exist
SOC 2 Type IISecurity control design and operating effectiveness over 6–12 monthsSponsor due-diligence questionnaires, advisors, cyber insurers, DOL examinersThe de facto standard—proves the controls actually run
SOC 3Public summary of a SOC 2Marketing audiencesWebsite trust page; never a substitute in diligence

What DOL Actually Expects

Best practice #3 in DOL’s Cybersecurity Program Best Practices (opens in new tab) calls for an annual third-party audit of security controls, and DOL’s companion hiring tips tell plan fiduciaries to ask service providers for exactly that evidence. Since Compliance Assistance Release 2024-01 (opens in new tab), that expectation reaches every service provider on 401(k), 403(b), 457(b), defined benefit, and welfare plans alike. In an EBSA document request, third-party audit reports are a standing line item.

The Distinction That Catches TPAs: Facility vs. Firm

Hosting your systems in an audited datacenter (ISO 27001, SOC 1/2, NIST 800-53) answers questions about the facility. Sponsor due diligence increasingly asks about your firm’s controls—your access management, your training, your incident response. Both layers matter: inherit the facility’s attestations for infrastructure, and document your own controls at the entity level. Conflating the two is the most common gap we see in due-diligence responses—and the first thing a sophisticated advisor probes.

A Realistic Path for a Small or Mid-Sized TPA

Year one: independent NIST CSF or SOC 2 readiness assessment, remediate the gaps, adopt the policies. Then a SOC 2 Type I to certify design, followed by the Type II examination over the next observation period. Every step is a defensible due-diligence answer—and each maps directly to DOL practices #1–#5. TPAIT builds and maintains the underlying controls and evidence for clients as part of managed service delivery, so the examination is an audit of work already documented, not a scramble.

Common Questions

Do TPAs need a SOC 1 or a SOC 2 report?

Usually both stories matter. SOC 1 covers controls relevant to your clients' financial reporting — plan auditors ask for it. SOC 2 covers security, availability, and confidentiality controls — plan sponsor due-diligence questionnaires and DOL best practice #3 point there. A SOC 2 Type II is the report that satisfies security due diligence.

Is a SOC 2 report legally required by the DOL?

No statute names SOC 2. But DOL best practice #3 expects an annual third-party audit of security controls, and a SOC 2 Type II examination is the most widely accepted way to evidence it. In practice, sponsors and their advisors increasingly treat it as table stakes when selecting a TPA.

What if a full SOC 2 Type II is cost-prohibitive for a small TPA?

Start with a SOC 2 Type I (a point-in-time examination) or an independent NIST CSF assessment, and put the Type II on a 12-month roadmap. Documented progression toward a Type II is a credible answer in due diligence; having nothing is not.

Build the Controls Before the Questionnaire Arrives

A free assessment maps your current posture against DOL’s 12 practices and a SOC 2 readiness baseline.

Book Free IT & Cyber Assessment (opens in new tab)