Regulations › US federal

SEC cyber disclosure

SEC cybersecurity disclosure rules

In force security disclosure
WhenIn effect since 5 September 2023
Who enforces itUS Securities and Exchange Commission
Who it applies toPublic companies registered with the SEC.

Disclosure of material cybersecurity incidents within four business days of determining materiality, and annual disclosure of risk management and governance.

The law in brief

The SEC's cybersecurity disclosure rules, adopted in July 2023, require public companies to disclose material cybersecurity incidents quickly and to describe, every year, how they manage cybersecurity risk and how the board and management oversee it.

The incident rule is the one practitioners feel most: once a company determines an incident is material, it has four business days to file a Form 8-K. The hard work is the materiality determination, which must be made without unreasonable delay after discovery.

Who it applies to

  • Public companies that file reports with the SEC under the Securities Exchange Act of 1934, including smaller reporting companies.
  • Foreign private issuers make comparable disclosures on Form 6-K and Form 20-F.
  • A cybersecurity incident is an unauthorized occurrence, or a series of related ones, on or through the company's information systems that jeopardizes their confidentiality, integrity or availability or the information in them. Incidents at vendors that affect the company's systems or data can qualify.

What it requires

Form 8-K within four business days

Disclose a material cybersecurity incident on Form 8-K Item 1.05 within four business days after determining it is material, describing its nature, scope and timing and its material or reasonably likely material impact.

Decide materiality without unreasonable delay

Make the materiality determination without unreasonable delay after discovering an incident.

Delay only for national security or public safety

Filing may be delayed only if the US Attorney General determines that disclosure poses a substantial risk to national security or public safety and notifies the SEC.

Annual risk management disclosure

Describe in the annual report your processes for assessing, identifying and managing material cybersecurity risks, whether they are integrated into overall risk management, and whether they use third parties.

Annual governance disclosure

Describe the board's oversight of cybersecurity risk and management's role in assessing and managing it, including relevant expertise.

Enforcement and penalties

The SEC enforces through its usual powers, including charges over misleading disclosures, inadequate disclosure controls and late filings. Disclosure failures can also support investor lawsuits under the securities laws.

What's changing

Petition to rescind Item 1.05. In 2025, banking and securities industry groups petitioned the SEC to rescind the Form 8-K incident requirement. The rule applies unless and until the SEC changes it; Regulatory Watch reports any rulemaking.

What to do first

  1. Write a materiality process: who decides, on what facts, how fast, and how it is documented.
  2. Connect incident response to disclosure counsel, so escalation to the materiality decision is quick.
  3. Include third-party incidents in the escalation path.
  4. Draft the Form 8-K template focused on the material impact, not technical detail that would help attackers.
  5. Prepare the annual Item 106 disclosure from real processes, board minutes and management roles.
  6. Test disclosure controls against a tabletop incident.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources