Resources
The regulatory record, and how to prepare.
What the DOL actually said, when it said it, and a study guide for each of the twelve domains it wants a plan fiduciary to check.
Why now
The regulatory window is open, and enforcement is active.
- The four named national enforcement projects for FY 2026 are cybersecurity of plan systems and data; mental health and substance use disorder parity; surprise billing under the No Surprises Act; and benefit distribution and contribution integrity.
- Investigators review how plans and service providers protect participant data, governance practices, incident-response protocols, and third-party service-provider oversight.
- The practical exposure is documentary. A plan that cannot evidence its data-security posture — including the cybersecurity requirements it places on its TPAs and service providers — carries heightened investigation risk. Having done the work is not the same as being able to show it.
Study guides
Twelve domains. Twelve intensive guides.
Each guide breaks down one domain: why it matters, what a strong program looks like, the gaps we see most often, and how to close them before your assessment. Free to read once you sign in.

Domain 1High
Cybersecurity Program

Domain 2High
Annual Risk Assessments

Domain 3High
Annual Third-Party Audit of Controls

Domain 4Medium
Security Roles & Responsibilities

Domain 5High
Access Controls

Domain 6High
Cloud & Sub-Processor Security

Domain 7Medium
Cybersecurity Awareness Training

Domain 8Medium
Secure System Development Lifecycle

Domain 9High
Business Resiliency (BCP / DR / IR)

Domain 10High
Encryption

Domain 11High
Strong Technical Controls

Domain 12Medium