DOL Cybersecurity Audit Firm Selection: Independent RFP
The DOL expects benefit plan fiduciaries to take cybersecurity seriously — including a reliable annual third-party audit of security controls. Culpepper RFP runs the structured, documented process for selecting the firm to perform it, so you can make a technical decision without needing to be technical.
DOL Cybersecurity Guidance Applies to Every ERISA Plan — Not Just Retirement
In 2021, the Department of Labor's Employee Benefits Security Administration issued three-part cybersecurity guidance for benefit plans: hiring tips for plan sponsors selecting service providers, program best practices for the providers themselves, and online security tips for participants. The guidance states plainly that responsible plan fiduciaries have an obligation to ensure proper mitigation of cybersecurity risks.
In September 2024, the DOL issued Compliance Assistance Release 2024-01 to settle a question service providers had been answering incorrectly: the guidance applies to all plans covered by ERISA — health and welfare plans included, not just retirement plans. If your organization has treated cybersecurity diligence as a retirement-plan issue, your health plan's vendors, data flows, and systems are now explicitly in scope.
EBSA has also made clear that it continues to investigate potential ERISA violations related to cybersecurity. The practical question for plan sponsors is the familiar one: could you document the process by which you assessed your providers' cybersecurity — and selected the firm that audited it?
The 12 Areas the DOL Expects to Be Taken Seriously
The DOL's Cybersecurity Program Best Practices outline what sponsors and service providers are expected to have in place:
A formal, well-documented cybersecurity program
Prudent annual risk assessments
A reliable annual third-party audit of security controls
Clearly defined security roles and responsibilities
Strong access control procedures
Appropriate security reviews for cloud or third-party managed data and systems
Periodic cybersecurity awareness training
A secure system development life cycle (SDLC) program
Business resiliency planning — business continuity, disaster recovery, and incident response
Encryption of sensitive data, stored and in transit
Strong technical controls aligned with best practices
Appropriate responses to past cybersecurity incidents
Item 3 is where this page comes in. The third-party audit is the mechanism that verifies the rest — and selecting the right firm to perform it is itself a fiduciary decision that deserves a documented process.
We Don't Perform the Audit. We Run the Selection of the Firm That Does.
Culpepper RFP is not a cybersecurity auditor — by design. Our role is the independent, documented evaluation process for selecting one: identifying qualified firms, organizing criteria that reflect both DOL expectations and your plan's actual vendor landscape, managing the comparison, and producing the decision file that shows how the selection was made.
That separation matters. A firm that performs audits has an interest in how the selection turns out. We don't — which is exactly the quality you want in the entity running the evaluation.
A Technical Decision Most Committees Aren't Built to Make
Cybersecurity audits are technical, and the stakes feel high. It's not always obvious what questions to ask, how to compare proposals, or how to document the rationale in a way that will make sense later to a committee, counsel, or leadership.
The work sits at the intersection of ERISA responsibilities, vendor oversight, and technical cybersecurity requirements — three areas that rarely live in the same person.
Culpepper RFP brings experience across all three: DOL expectations, ERISA context, and practical experience buying, selling, and evaluating cybersecurity consultants. That's what lets your committee compare firms consistently and make a well-supported decision without becoming security experts first.
How the Selection Process Works
Scoping the audit: which providers, systems, and data flows are covered — including health and welfare plan vendors under the 2024 guidance
Identifying qualified cybersecurity audit firms that fit your plan's size and vendor landscape
Writing the RFP and managing the evaluation from start to finish
Organizing criteria that reflect DOL expectations, not generic security checklists
Handling all firm communication during the evaluation period
Summarizing results and presenting findings to your committee
Coordinating finalist presentations and agendas
Managing reference checks
Supporting final fee negotiation
The deliverable is a complete decision file — criteria, comparisons, scoring, and rationale — documenting how the audit firm was selected.
Our References Are Our Clients — All of Them
Our clients engage us for independent evaluations at sensitive moments — often at the direction of counsel — so we don't publish named testimonials or case studies. Discretion is part of the engagement.
What we offer instead is stronger: 100% of Culpepper RFP clients can act as a reference, a standard we've maintained since the firm began. When you're seriously evaluating whether to work with us, we'll connect you directly with organizations similar to yours in size, plan type, and situation — and you can ask them anything.
Looking for a different evaluation? We also run independent evaluations for retirement plan providers, OCIO managers, actuarial, and benefit brokers— each covered on its own page.
Questions Plan Sponsors Ask About DOL Cybersecurity Audits
-
The DOL's guidance is framed as best practices rather than a regulation — but it states that responsible plan fiduciaries have an obligation to ensure proper mitigation of cybersecurity risks, and a reliable annual third-party audit of security controls is item 3 on its best-practices list. In an EBSA investigation or litigation, 'the guidance wasn't technically a rule' is not a position most counsel want to defend. The practical standard is documented diligence, and the audit is how it's demonstrated.
-
All of them. In September 2024, the DOL issued Compliance Assistance Release 2024-01 specifically to correct the misconception that its cybersecurity guidance covered only retirement plans. It applies to every plan covered by ERISA — health and welfare plans included. If your cybersecurity diligence has only ever looked at your recordkeeper, your health plan's vendors and data flows are now explicitly in scope.
-
A provider's certification is evidence about the provider — it is not evidence that you, the fiduciary, performed diligence. The DOL's hiring tips direct sponsors to ask how providers validate their practices, review audit results, examine breach history, and confirm insurance coverage — and to document having done so. An independent audit assesses your plan's actual vendor landscape and gives you a record in your own files, not just a badge in theirs.
-
The same way committees evaluate any specialized provider: with a structured process, consistent criteria, and someone who has seen both sides of the market. We translate the technical differences between proposals into decision terms — scope, methodology, reporting, cost — so your committee compares firms on substance. You don't need to become security experts; you need a documented, defensible selection.
-
No — deliberately. We run the independent selection of the audit firm. A firm that performs audits has a stake in how the selection turns out; we don't. Our deliverable is the documented evaluation and decision file, and the selected firm performs the audit.
-
Most evaluations are completed within our standard 90-day RFP window — cybersecurity audit firm selections are typically narrower in scope than a full provider search. We confirm the timeline during scoping.
-
Yes — every client we've ever worked with. 100% of Culpepper RFP clients can act as a reference. Once you're seriously evaluating an engagement, we'll connect you with organizations similar to yours, and what you ask them is up to you.
Could You Document How Your Plan's Cybersecurity Was Reviewed?
If the DOL asked tomorrow, most plan sponsors couldn't point to a file. Schedule a call with Jay to talk through what your plans — retirement and health — actually need, and what a documented selection process would look like.