You Are the Third Party
Third parties now feature in 48% of breaches. Plan sponsors are shifting from annual questionnaires to continuous monitoring — and your firm is the vendor being monitored.
The short answer: every framework a TPA is measured against has quietly moved from point-in-time attestation to continuous evidence. A SOC 2 dated eleven months ago answers a question your client stopped asking. The firms that win renewals in 2027 will be the ones that can show a control was working last Tuesday, not last audit.
48% of breaches now involve a third party, and supply-chain-related breaches rose 60% year over year. Source: Verizon 2026 DBIR (opens in new tab)
The Uncomfortable Reframe
TPAs tend to read breach statistics as a description of threats coming at them. Plan sponsors read the same statistics as a description of risk arriving through their vendors — and in that sentence, you are the vendor. Every improvement in sponsor-side third-party risk management lands on your desk as a request for evidence.
This is not hypothetical positioning. The Department of Labor’s Cybersecurity Program Best Practices are written to be applied by fiduciaries to their service providers. The “Tips for Hiring a Service Provider” guidance is, structurally, a vendor-assessment script. When cybersecurity became a formal EBSA National Enforcement Project in January 2026, it did not create a new obligation for TPAs so much as it gave every plan sponsor a reason to start exercising the one they already had.
What Actually Changed in 2026
Three shifts matter for how your firm will be assessed:
- Initial access moved. Exploitation of unpatched vulnerabilities is now the leading initial access vector at 31% of breaches, while abuse of stolen credentials fell to 13%. Patch cadence is becoming a due-diligence question, not just an internal hygiene metric.
- Remediation is getting slower, not faster. Only 26% of vulnerabilities in the CISA Known Exploited Vulnerabilities catalogue were fully remediated during 2025, down from 38% the prior year, with median time to remediate rising to 43 days.
- Ransomware kept climbing. Ransomware featured in 48% of breaches, up from 44%, though 69% of victims declined to pay.
Read together, these say something specific about how a sponsor will judge you: they are less interested in whether you own a security product and more interested in whether you operate it on a schedule you can prove.
Annual Questionnaire to Continuous Evidence
The annual security questionnaire is a snapshot of what a vendor was willing to assert on one day. That model is eroding across regulated industries — NYDFS requires ongoing due diligence of critical providers, and third-party risk programmes generally are moving toward continuous monitoring rather than periodic review. Retirement plan due diligence follows these currents with a lag, but it follows them.
Practically, expect the questionnaire you receive in 2027 to ask for things a point-in-time answer cannot satisfy:
| The old question | The 2026–27 version | What you need on hand |
|---|---|---|
| Do you have a SOC 2 Type II? | What is the report period, and what has changed since it closed? | Current report plus a bridge letter covering the gap to today |
| Do you patch systems? | What is your median time to remediate a known-exploited vulnerability? | Patch reporting with dates, not a policy document |
| Do you train staff? | What were last quarter’s phishing simulation results by department? | Completion and click-rate reporting over time |
| Do you have MFA? | Is MFA phishing-resistant, and enforced on every administrative path? | Configuration evidence and exception register |
| Do you have an incident response plan? | When did you last test it, and how fast will you notify us? | Tabletop records and a contractual notification window |
The Notification Clause Nobody Negotiates
Most TPA service agreements were drafted before breach-notification timing became a procurement issue. Sponsors are increasingly asking for a defined notification window — often 24 to 72 hours from confirmation of an incident affecting their participants. If your agreement is silent, you will negotiate it under pressure during an actual incident, which is the worst possible moment.
Decide now what you can actually commit to. A window you can meet is worth more than an aggressive one you will miss.
What This Means for Your Firm
None of this requires a transformation programme. It requires that a handful of controls produce dated artefacts as a by-product of running normally:
- Patch and vulnerability reporting you can export on request, with dates
- A bridge letter arrangement with your auditor so your SOC 2 never has an unexplained gap
- Quarterly — not annual — security awareness metrics
- A tested incident response plan with a written notification commitment
- An access review that produces a record, not just a conversation
If your DOL readiness checklist score is solid but every answer depends on someone reconstructing evidence from memory, you have a documentation problem rather than a security problem. That is a considerably cheaper problem to fix — but only before the questionnaire arrives.
Frequently Asked Questions
Does a SOC 2 Type II still matter if sponsors want continuous evidence?
Yes. It remains the report plan sponsors, advisors, and cyber insurers accept, and it is the cleanest way to evidence DOL best practice #3. Continuous monitoring supplements it; it does not replace it. See SOC 2 for TPAs.
What is a bridge letter and why do sponsors ask for one?
A bridge letter (or gap letter) is issued by your auditor to cover the period between the end of your SOC 2 report period and the current date, confirming no material changes to controls. It closes the exact gap a continuous-monitoring mindset makes visible.
We are a small TPA. Is continuous monitoring realistic?
The evidence matters more than the tooling. Dated patch reports, quarterly training metrics, and a documented access review satisfy most of what is being asked without an enterprise platform. The burden is administrative discipline, not licence spend.
Can You Evidence It, Not Just Assert It?
A free assessment maps your current controls against DOL’s 12 practices and shows where evidence is missing.
Book Free IT & Cyber Assessment (opens in new tab)