DOL Cybersecurity Audit Firm Selection: Independent RFP

The DOL expects benefit plan fiduciaries to take cybersecurity seriously — including a reliable annual third-party audit of security controls. Culpepper RFP runs the structured, documented process for selecting the firm to perform it, so you can make a technical decision without needing to be technical.

Scenic view of a large lake surrounded by green hills in the foreground and mountain range with rugged peaks in the background under an overcast sky.

DOL Cybersecurity Guidance Applies to Every ERISA Plan — Not Just Retirement


In 2021, the Department of Labor's Employee Benefits Security Administration issued three-part cybersecurity guidance for benefit plans: hiring tips for plan sponsors selecting service providers, program best practices for the providers themselves, and online security tips for participants. The guidance states plainly that responsible plan fiduciaries have an obligation to ensure proper mitigation of cybersecurity risks.

In September 2024, the DOL issued Compliance Assistance Release 2024-01 to settle a question service providers had been answering incorrectly: the guidance applies to all plans covered by ERISA — health and welfare plans included, not just retirement plans. If your organization has treated cybersecurity diligence as a retirement-plan issue, your health plan's vendors, data flows, and systems are now explicitly in scope.

EBSA has also made clear that it continues to investigate potential ERISA violations related to cybersecurity. The practical question for plan sponsors is the familiar one: could you document the process by which you assessed your providers' cybersecurity — and selected the firm that audited it?

The 12 Areas the DOL Expects to Be Taken Seriously

The DOL's Cybersecurity Program Best Practices outline what sponsors and service providers are expected to have in place:

  1. A formal, well-documented cybersecurity program

  2. Prudent annual risk assessments

  3. A reliable annual third-party audit of security controls

  4. Clearly defined security roles and responsibilities

  5. Strong access control procedures

  6. Appropriate security reviews for cloud or third-party managed data and systems

  7. Periodic cybersecurity awareness training

  8. A secure system development life cycle (SDLC) program

  9. Business resiliency planning — business continuity, disaster recovery, and incident response

  10. Encryption of sensitive data, stored and in transit

  11. Strong technical controls aligned with best practices

  12. Appropriate responses to past cybersecurity incidents

Item 3 is where this page comes in. The third-party audit is the mechanism that verifies the rest — and selecting the right firm to perform it is itself a fiduciary decision that deserves a documented process.

We Don't Perform the Audit. We Run the Selection of the Firm That Does.

Culpepper RFP is not a cybersecurity auditor — by design. Our role is the independent, documented evaluation process for selecting one: identifying qualified firms, organizing criteria that reflect both DOL expectations and your plan's actual vendor landscape, managing the comparison, and producing the decision file that shows how the selection was made.

That separation matters. A firm that performs audits has an interest in how the selection turns out. We don't — which is exactly the quality you want in the entity running the evaluation.

A Technical Decision Most Committees Aren't Built to Make

Cybersecurity audits are technical, and the stakes feel high. It's not always obvious what questions to ask, how to compare proposals, or how to document the rationale in a way that will make sense later to a committee, counsel, or leadership.

The work sits at the intersection of ERISA responsibilities, vendor oversight, and technical cybersecurity requirements — three areas that rarely live in the same person.

Culpepper RFP brings experience across all three: DOL expectations, ERISA context, and practical experience buying, selling, and evaluating cybersecurity consultants. That's what lets your committee compare firms consistently and make a well-supported decision without becoming security experts first.

How the Selection Process Works

 
  • Scoping the audit: which providers, systems, and data flows are covered — including health and welfare plan vendors under the 2024 guidance

  • Identifying qualified cybersecurity audit firms that fit your plan's size and vendor landscape

  • Writing the RFP and managing the evaluation from start to finish

  • Organizing criteria that reflect DOL expectations, not generic security checklists

  • Handling all firm communication during the evaluation period

  • Summarizing results and presenting findings to your committee

  • Coordinating finalist presentations and agendas

  • Managing reference checks

  • Supporting final fee negotiation

The deliverable is a complete decision file — criteria, comparisons, scoring, and rationale — documenting how the audit firm was selected.

A landscape with a large lake in the foreground, rolling grassy hills, and tall mountains in the background under a cloudy sky.

Our References Are Our Clients — All of Them

Our clients engage us for independent evaluations at sensitive moments — often at the direction of counsel — so we don't publish named testimonials or case studies. Discretion is part of the engagement.

What we offer instead is stronger: 100% of Culpepper RFP clients can act as a reference, a standard we've maintained since the firm began. When you're seriously evaluating whether to work with us, we'll connect you directly with organizations similar to yours in size, plan type, and situation — and you can ask them anything.

Looking for a different evaluation? We also run independent evaluations for retirement plan providers, OCIO managers,  actuarial, and benefit brokers— each covered on its own page.

The DOL's Cybersecurity Guidance

 

Questions Plan Sponsors Ask About DOL Cybersecurity Audits

Could You Document How Your Plan's Cybersecurity Was Reviewed?

If the DOL asked tomorrow, most plan sponsors couldn't point to a file. Schedule a call with Jay to talk through what your plans — retirement and health — actually need, and what a documented selection process would look like.