The SEC cybersecurity disclosure rules are requirements from the US Securities and Exchange Commission that make public companies tell investors about material cybersecurity incidents and explain, each year, how they manage cybersecurity risk and who oversees it. Adopted in 2023, they added an incident item to Form 8-K and a cybersecurity section to annual reports, with parallel forms for foreign private issuers. This entry is a buyer-side overview, not legal advice; the rules may be revised, so confirm current requirements with securities counsel.
At a glance
- Material cybersecurity incidents are generally reported on Form 8-K within four business days of the company determining they are material.
- Annual reports describe processes for assessing and managing cyber risk, the board’s oversight and management’s role and expertise.
- Materiality is a judgment the company makes, considering both financial and non-financial impact.
- Incidents at providers that run the company’s systems can trigger the rules, so vendor notice terms matter.
- Industry groups have asked the SEC to rescind the incident reporting item; confirm current status before relying on any summary.
What problem it solves
Before these rules, cyber incident disclosure by public companies was inconsistent: some incidents surfaced months later, and descriptions of security programs varied widely. Investors argued they couldn’t compare how companies handled a risk that can affect revenue, operations and reputation.
The rules set a common clock for material incidents and a common structure for describing cyber risk management and governance. For companies, they turned cybersecurity into a disclosure-controls question: can the right people learn about an incident, assess it and decide quickly enough to file?
How it works
Incident disclosure. When a company determines that a cybersecurity incident is material, it files a Form 8-K describing the nature, scope and timing of the incident and its material or reasonably likely material impact. The four-business-day clock starts at the materiality determination, which must be made without unreasonable delay after discovery. Companies don’t have to disclose technical details that would hinder their response. SEC staff have said that incidents not yet judged material, or judged immaterial, can be disclosed voluntarily under a different item.
Annual disclosure. In the annual report, companies describe their processes for identifying, assessing and managing material cyber risks, whether risks from threats or past incidents have materially affected them, how the board oversees cyber risk and which managers are responsible and what expertise they have.
Internal machinery. In practice, companies connect their incident response (IR) plan to disclosure controls: escalation criteria, a materiality committee, documented decisions and tabletop exercises that include legal and finance. A risk register and a documented program help support the annual description.
Disclosure requirements
The rules have no compliance levels. Their structure is a set of disclosure items, which differ by filer type.
| Item | Who it applies to | What triggers it | What is filed |
|---|---|---|---|
| Form 8-K, Item 1.05 | US domestic SEC registrants | Determining that a cybersecurity incident is material | Description of the incident and its material impact, amended as information becomes available |
| Regulation S-K Item 106 (Form 10-K) | US domestic SEC registrants | Each annual report | Cyber risk management processes, board oversight, management’s role and expertise |
| Form 6-K | Foreign private issuers | Material incidents they disclose or are required to disclose elsewhere | Incident information furnished to the SEC |
| Form 20-F | Foreign private issuers | Each annual report | Cyber risk management and governance disclosures comparable to Item 106 |
| National security or public safety delay | Domestic registrants filing Form 8-K Item 1.05 | The Attorney General determines that disclosure would pose a substantial risk to national security or public safety and notifies the SEC | The Item 1.05 Form 8-K disclosure is delayed for a limited period, subject to the rule’s terms and Department of Justice procedures; Form 6-K timing instead follows the foreign, exchange or security-holder disclosure that triggers it |
Smaller reporting companies had a later start date for incident reporting, and specific timing rules may change; check with counsel.
When it matters for buyers
- When you are public or preparing to go public. Your incident response and vendor contracts need to support a four-business-day decision process.
- When choosing providers that run critical systems or hold sensitive data. A data breach at your MSP, cloud platform or SaaS vendor may become your disclosure question.
- When the board asks about cyber oversight. The annual disclosure describes who is responsible, so roles need to be real.
- When you sell to public companies. Expect contract terms requiring fast incident notice and cooperation.
Our governance, risk and compliance and incident response overviews cover help with programs, playbooks and retainers.
Questions to ask vendors
- How quickly will you notify us of an incident affecting our data or systems, and what information will the first notice include?
- Will you share forensic findings and impact details fast enough for us to assess materiality?
- Who is our escalation contact during an incident, and is that contact available around the clock?
- Which subcontractors could be involved in an incident affecting our service?
- What independent reports or certifications cover your security program for this service?
- Will you support our tabletop exercises and incident response testing?
How it differs from 23 NYCRR 500
The New York DFS cybersecurity regulation (23 NYCRR 500) applies to financial services companies licensed by the New York Department of Financial Services, whether public or private. It requires a full cybersecurity program and confidential notice to the regulator, generally within 72 hours of determining that a reportable incident occurred. The SEC rules apply to SEC registrants, require public disclosure to investors and turn on materiality. A New York-licensed public insurer or bank may need to meet both on different clocks, so map them in one plan. Vendor oversight under third-party risk management (TPRM) supports both.
