DOL EBSA Cybersecurity Assessment
Deterministic, not
self‑graded.
Twelve domains, mapped directly to the U.S. Department of Labor’s EBSA cybersecurity best practices. Your service provider answers once, and a published, deterministic rubric scores it — the same answers produce the same score every time, and you can check the arithmetic yourself.
Why now
The regulatory window is open, and enforcement is active.
- The four named national enforcement projects for FY 2026 are cybersecurity of plan systems and data; mental health and substance use disorder parity; surprise billing under the No Surprises Act; and benefit distribution and contribution integrity.
- Investigators review how plans and service providers protect participant data, governance practices, incident-response protocols, and third-party service-provider oversight.
- The practical exposure is documentary. A plan that cannot evidence its data-security posture — including the cybersecurity requirements it places on its TPAs and service providers — carries heightened investigation risk. Having done the work is not the same as being able to show it.
The assessment
Twelve domains. Every one mapped to a specific DOL best practice.
High-weight domains count double toward the final score — the weighting is never hidden behind a black-box number.
- 1Cybersecurity ProgramHigh
- 2Annual Risk AssessmentsHigh
- 3Annual Third-Party Audit of ControlsHigh
- 4Security Roles & ResponsibilitiesMedium
- 5Access ControlsHigh
- 6Cloud & Sub-Processor SecurityHigh
- 7Cybersecurity Awareness TrainingMedium
- 8Secure System Development LifecycleMedium
- 9Business Resiliency (BCP / DR / IR)High
- 10EncryptionHigh
- 11Strong Technical ControlsHigh
- 12Response to Past IncidentsMedium
The scoring engine
Every number is deterministic and auditable.
No LLM touches the score. The formula runs the same way every time and is published here so fiduciaries can verify it themselves.
How the score is calculated
Each domain is scored independently: answered questions earn 1 point for Yes, 0 for No. N/A answers are excluded from the denominator — they don’t penalise providers for genuinely inapplicable controls.
Domain score = Yes answers ÷ Applicable questions × 100
Overall score = Σ (domain score × weight) ÷ 20
8
High-weight domains
Count 2×
4
Medium-weight domains
Count 1×
20
Total weight units
Denominator
High-weight domains cover controls where failures directly expose participant funds or PII — Access Controls, Encryption, and Business Resiliency among them. 7 specific failures (like no MFA, no encryption, or an unassessed sub-processor) are automatic red flags — see the risk bands to the right for what a red flag does to the final score.
Risk rating bands
The overall score maps to one of four risk bands. Band thresholds are fixed and auditable — no LLM adjusts them at runtime.
Strong
90–100%
Adequate
75–89%
Needs Improvement
60–74%
High Risk
0–59%
Any single red flag — an automatic-fail control, such as no MFA or unencrypted data — forces the band straight to High Risk, regardless of the numeric score. Red flags are disclosed explicitly in the report so fiduciaries can act on them.
You can’t N/A your way out of a domain
Because N/A answers leave the denominator, marking an entire domain N/A would quietly remove it from the score. Exactly one domain may be excluded that way — Domain 8, the software-development lifecycle, since most plan and fund offices don’t build software. Every other domain must be genuinely answered: a submission that blanks one out is rejected rather than scored, so a weak area can’t be hidden by omission.
What the AI does — and never does
The score above is computed entirely in deterministic code. The AI layer does one thing: it reads the free-text comment behind each “Yes” and grades how well that comment substantiates the claim — a named tool, document, or date scores high; boilerplate scores low; answering Yes with no evidence at all never earns full credit. That produces a second, clearly-labelled evidence-adjusted score shown beside the official one.
It never sets a Yes or No, never moves the official score, and never cancels a red flag. If the AI is unavailable, the assessment still scores normally.
The difference
Other providers offer self-graded homework. This isn’t.
Other providers
Paladin Assurance





