ERISA-covered plans often hold millions of dollars or more in assets and maintain personal data on participants, which can make them tempting targets for cyber-criminals. Responsible plan fiduciaries have an obligation to ensure proper mitigation of cybersecurity risks. The Employee Benefits Security Administration has prepared the following best practices for use by recordkeepers and other service providers responsible for plan-related IT systems and data, and for plan fiduciaries making prudent decisions on the service providers they should hire.

Department of Labor Cybersecurity Best Practices for ERISA-Covered Plans
Formats for Download
Related Resources
Description:
In 2021, the Department of Defense announced a new strategic effort to provide enhanced cyber security efforts for their building projects going forward. The Cybersecurity Maturity Model Certification (CMMC) will ensure accountability for companies to implement cybersecurity standards in order to protect sensitive data during the design, build and operations of DoD facilities. Recently, the DoD has simplified and revised the CMMC to make it more streamlined and faster in what they are calling, “CMMC 2.0”. This short video is part of a best practices series regarding the CMMC.
Description:
In 2021, the Department of Defense announced a new strategic effort to provide enhanced cyber security efforts for their building projects going forward. The Cybersecurity Maturity Model Certification (CMMC) will ensure accountability for companies to implement cybersecurity standards in order to protect sensitive data during the design, build and operations of DoD facilities. Recently, the DoD has simplified and revised the CMMC to make it more streamlined and faster in what they are calling, “CMMC 2.0”. This short video is part of a best practices series regarding the CMMC.
Description:
In 2021, the Department of Defense announced a new strategic effort to provide enhanced cyber security efforts for their building projects going forward. The Cybersecurity Maturity Model Certification (CMMC) will ensure accountability for companies to implement cybersecurity standards in order to protect sensitive data during the design, build and operations of DoD facilities. Recently, the DoD has simplified and revised the CMMC to make it more streamlined and faster in what they are calling, “CMMC 2.0”. This short video is part of a best practices series regarding the CMMC.
Description:
In 2021, the Department of Defense announced a new strategic effort to provide enhanced cyber security efforts for their building projects going forward. The Cybersecurity Maturity Model Certification (CMMC) will ensure accountability for companies to implement cybersecurity standards in order to protect sensitive data during the design, build and operations of DoD facilities. Recently, the DoD has simplified and revised the CMMC to make it more streamlined and faster in what they are calling, “CMMC 2.0”. This short video is part of a best practices series regarding the CMMC.
Description:
In 2021, the Department of Defense announced a new strategic effort to provide enhanced cyber security efforts for their building projects going forward. The Cybersecurity Maturity Model Certification (CMMC) will ensure accountability for companies to implement cybersecurity standards in order to protect sensitive data during the design, build and operations of DoD facilities. Recently, the DoD has simplified and revised the CMMC to make it more streamlined and faster in what they are calling, “CMMC 2.0”. This short video is part of a best practices series regarding the CMMC.
Description:
In 2021, the Department of Defense announced a new strategic effort to provide enhanced cyber security efforts for their building projects going forward. The Cybersecurity Maturity Model Certification (CMMC) will ensure accountability for companies to implement cybersecurity standards in order to protect sensitive data during the design, build and operations of DoD facilities. Recently, the DoD has simplified and revised the CMMC to make it more streamlined and faster in what they are calling, “CMMC 2.0”. This short video is part of a best practices series regarding the CMMC.
Description:
In 2021, the Department of Defense announced a new strategic effort to provide enhanced cyber security efforts for their building projects going forward. The Cybersecurity Maturity Model Certification (CMMC) will ensure accountability for companies to implement cybersecurity standards in order to protect sensitive data during the design, build and operations of DoD facilities. Recently, the DoD has simplified and revised the CMMC to make it more streamlined and faster in what they are calling, “CMMC 2.0”. This short video is part of a best practices series regarding the CMMC.
Description:
In 2021, the Department of Defense announced a new strategic effort to provide enhanced cyber security efforts for their building projects going forward. The Cybersecurity Maturity Model Certification (CMMC) will ensure accountability for companies to implement cybersecurity standards in order to protect sensitive data during the design, build and operations of DoD facilities. Recently, the DoD has simplified and revised the CMMC to make it more streamlined and faster in what they are calling, “CMMC 2.0”. This short video is part of a best practices series regarding the CMMC.
Description:
In 2021, the Department of Defense announced a new strategic effort to provide enhanced cyber security efforts for their building projects going forward. The Cybersecurity Maturity Model Certification (CMMC) will ensure accountability for companies to implement cybersecurity standards in order to protect sensitive data during the design, build and operations of DoD facilities. Recently, the DoD has simplified and revised the CMMC to make it more streamlined and faster in what they are calling, “CMMC 2.0”. This short video is part of a best practices series regarding the CMMC.
Description:
In 2021, the Department of Defense announced a new strategic effort to provide enhanced cyber security efforts for their building projects going forward. The Cybersecurity Maturity Model Certification (CMMC) will ensure accountability for companies to implement cybersecurity standards in order to protect sensitive data during the design, build and operations of DoD facilities. Recently, the DoD has simplified and revised the CMMC to make it more streamlined and faster in what they are calling, “CMMC 2.0”. This short video is part of a best practices series regarding the CMMC.