Resources

The regulatory record, and how to prepare.

What the DOL actually said, when it said it, and a study guide for each of the twelve domains it wants a plan fiduciary to check.

Why now

The regulatory window is open, and enforcement is active.

    • The four named national enforcement projects for FY 2026 are cybersecurity of plan systems and data; mental health and substance use disorder parity; surprise billing under the No Surprises Act; and benefit distribution and contribution integrity.
    • Investigators review how plans and service providers protect participant data, governance practices, incident-response protocols, and third-party service-provider oversight.
    • The practical exposure is documentary. A plan that cannot evidence its data-security posture — including the cybersecurity requirements it places on its TPAs and service providers — carries heightened investigation risk. Having done the work is not the same as being able to show it.
    DOL news release, 15 January 2026 ↗