SEC Cybersecurity Disclosure Rule
Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Definitions and Enforcement Posture
Cybersecurity incident is defined as an unauthorized occurrence, or series of related unauthorized occurrences, on or conducted through a registrant's information systems that jeopardizes the confidentiality, integrity, or availability of those systems or any information residing therein. Definitions for threat and information systems are correspondingly broad.
- Internal definitions glossary aligned to Reg S-K 106(a)
- Asset inventory aligned to information systems definition
- Training materials referencing definitions
- Policy update log post-July 2023
- Using NIST-only definitions inconsistent with SEC definitions
- Omitting OT/IoT from information systems scope
- Treating availability impacts as out of scope
- Vendor-hosted SaaS missing from system inventory
SEC enforcement actions (e.g., SolarWinds October 2023 complaint, partial dismissal July 2024) signal scrutiny of cybersecurity disclosures, internal accounting controls (Section 13(b)(2)(B)) as applied to cyber, and statements in risk factors that may mislead investors regarding actual practices.
- Risk factor accuracy review log
- Internal controls testing tied to cyber
- Spokesperson/IR statement vetting record
- Disclosure committee enforcement-trend briefings
- Litigation hold readiness for cyber incidents
- Risk factor language inconsistent with actual security posture
- No periodic vetting of marketing or website security claims
- Internal accounting controls not extended to cyber-relevant assets
Disclosure Controls and Supporting Process
Design and maintain disclosure controls and procedures that ensure information about cybersecurity incidents reaches the disclosure committee, executive officers, and the board on a timely basis to support timely Form 8-K and periodic filing decisions.
- Disclosure committee charter referencing cyber
- Information flow diagram from SOC to disclosure committee
- Sub certification questionnaires
- Tabletop exercises focused on disclosure decisions
- No defined link from SOC to disclosure committee
- Sub certification omits cyber
Maintain an incident response plan that integrates legal, finance, and communications functions, includes specific steps for materiality determination, regulatory notification timing, and external disclosure, and is exercised regularly.
- Incident response plan with disclosure decision tree
- Tabletop exercise after action reports
- Cross functional contact list
- Approved playbooks for ransomware, business email compromise, and supplier compromise
- IR plan owned by IT alone
- Exercises do not test 8-K filing timing
Establish pre arranged engagement protocols with external counsel and forensic providers to support rapid investigation, privilege preservation, and disclosure analysis when a cybersecurity incident occurs.
- Master service agreements with counsel and forensics providers
- Engagement playbook
- Privilege protocol memo
- After action reviews of prior engagements
- No pre arranged retainers
- Privilege rules not understood by IR teams
Coordinate cybersecurity disclosure under SEC rules with other applicable notification regimes including state breach notification laws, sector specific regulators, and federal authorities such as CISA and FBI, while preserving accurate and consistent public messaging.
- Regulatory notification matrix mapping incidents to obligations
- Coordination procedure document
- Approved external communications templates
- Audit trail of notifications made
- Notification matrix not maintained
- Inconsistent messages across regulators and SEC filings
Maintain a repository of past cybersecurity incidents, including non material incidents, to support evaluation of cumulative risk, identification of patterns, and disclosure analysis regarding prior incidents that may now have material implications.
- Centralized incident database
- Quarterly trend analysis report
- Disclosure refresh procedure document
- Audit logs of database access
- No central repository
- Non material incidents not tracked, preventing pattern analysis
Provide periodic training to officers, members of the disclosure committee, IR leaders, and the board on cybersecurity disclosure requirements, materiality factors, and timing obligations.
- Training curriculum document
- Attendance and completion records
- Knowledge checks or post training assessments
- Calendar of training cadence
- Training only at policy rollout, no refreshers
- Board not included in training
Maintain complete records supporting materiality determinations, disclosure timing decisions, and any reliance on delays or omissions, sufficient to evidence compliance under SEC enforcement reviews.
- Recordkeeping policy referencing SEC cyber rules
- Retention schedule with minimum periods
- Audit trail of materiality determinations
- Legal hold procedures invoked on incident detection
- Determination memos not retained beyond audit cycle
- No legal hold automatically triggered on incident detection
Amended Regulation S-P (May 2024) requires covered broker-dealers, investment advisers, funds, and transfer agents to adopt incident response programs and provide customer notification within 30 days of detecting unauthorized access; coordinate with Item 1.05 obligations for registrants.
- Reg S-P incident response policy
- Customer notification templates
- 30-day clock tracker
- Cross-mapped 8-K/Reg S-P decision matrix
- Service provider oversight evidence
- No alignment between Reg S-P clock and 8-K clock
- Customer notification delayed past 30 days
- Service provider notification clauses missing
- Annual policy review skipped
SCI entities (exchanges, clearing agencies, SBSDRs, certain ATSs) remain subject to Reg SCI Rules 1001 through 1007 in addition to the cybersecurity disclosure rule; SCI events may also trigger 8-K Item 1.05 disclosure if the SCI entity is a public registrant.
- SCI event log
- SCI Rule 1002(b) notifications to SEC
- Reconciliation log SCI to Item 1.05
- Joint counsel/CISO playbook
- Treating SCI notification as sufficient for 8-K
- Inconsistent narratives between SCI report and 8-K
- Missing reasonably-designed-policies-and-procedures evidence
Foreign Private Issuers
For foreign private issuers, furnish on Form 6-K information about material cybersecurity incidents that the issuer discloses or otherwise publicizes in a foreign jurisdiction, and disclose comparable information in Form 20-F under Item 16K.
- Filed 6-K furnishings for cyber incidents
- Form 20-F Item 16K section
- Tracking log of foreign disclosures
- Counsel coordination memos
- 6-K not furnished promptly after foreign disclosure
- 20-F Item 16K narrative copies 8-K language without entity tailoring
Governance Disclosure
Per SEC Item 106(c): governance disclosure. Requirements include (a) Board Oversight of Cybersecurity including responsible committee + reporting + frequency + (b) Management's Role and Expertise including specific positions + relevant experience + (c) management reporting to board + escalation + (d) maintain documented governance structure + (e) integrate with broader enterprise governance.
- SEC Cyber evidence for SECCYB-3
- materiality workflow + 4-day disclosure + governance partial
Governance: Regulation S-K Item 106(c)
Describe the board of directors' oversight of risks from cybersecurity threats, identifying any board committee or subcommittee responsible for the oversight and the processes by which the board or committee is informed about such risks.
- Board or committee charter referencing cybersecurity oversight
- Reporting calendar to the board
- Committee meeting minutes evidencing cybersecurity discussions
- Director skills matrix where applicable
- No committee designated
- Briefings infrequent or undocumented
Describe management's role in assessing and managing material risks from cybersecurity threats, including identification of relevant positions or committees, their relevant expertise, and how they monitor prevention, detection, mitigation, and remediation of incidents.
- Org chart showing CISO and accountable executives
- Position descriptions and qualifications
- Internal cyber reporting templates
- Biographies referenced in disclosure
- Expertise of responsible managers not described
- CISO reporting line creates conflict of interest
Incident Disclosure
Per SEC Item 1.05 Form 8-K Cybersecurity Incident Disclosure Rule: disclosure of material cybersecurity incidents. Requirements include (a) Material Cybersecurity Incident 4-Business-Day Disclosure on Form 8-K Item 1.05 within 4 business days of materiality determination + (b) Materiality Determination Without Unreasonable Delay + (c) Materiality Standard (Quantitative + Qualitative) considering nature + scope + timing + impact + (d) National Security/Public Safety Delay per Attorney General determination + (e) Amendment Obligation for Previously Undetermined Information + (f) integrate with broader incident response + materiality processes.
- SEC Cyber evidence for SECCYB-1
- materiality workflow + 4-day disclosure + governance partial
Incident Disclosure: Form 8-K Item 1.05
Establish a documented process to determine without unreasonable delay whether a cybersecurity incident is material, considering qualitative and quantitative factors, including impact on operations, financial condition, reputation, customers, and the entity's broader systems.
- Materiality determination procedure
- Incident materiality scoring rubric
- Records of materiality determinations including timing
- Escalation log to disclosure committee and counsel
- Materiality assessed only by IT without legal or finance involvement
- No documented timing of determination decisions
File a Form 8-K reporting a material cybersecurity incident under Item 1.05 within four business days of determining that the incident is material, describing the material aspects of the nature, scope, timing, and impact on the entity.
- Filed Form 8-K Item 1.05 entries
- Filing workflow runbook
- Disclosure committee approval log
- Counsel sign off
- Filing template not pre approved
- Workflow not tested in tabletop exercises
Coordinate with the United States Attorney General when delay of an Item 1.05 disclosure is sought on grounds of substantial risk to national security or public safety, and document the determination, notification, and any granted delay period.
- Records of Attorney General notifications
- Written determinations of substantial risk
- Delay approval letters from DOJ
- Internal tracking of delay expiry
- No pre established contact protocol with DOJ
- Delay expiry not tracked
If any required information about the nature, scope, timing, or impact of a material cybersecurity incident is not determined or is unavailable at the time of the initial 8-K filing, identify the omitted information and file an amendment to Form 8-K within four business days after the information becomes available.
- Open item log per incident
- Filed 8-K amendments
- Investigation status reports to disclosure committee
- Communication log with external counsel
- Initial filing fails to flag what is undetermined
- No process to track when omitted information becomes available
Treat a series of related occurrences of cybersecurity incidents as a single incident when determining materiality and disclosure obligations under Item 1.05.
- Documented aggregation criteria
- Incident linking analysis
- Decision memos on aggregation
- Threat intelligence ties between events
- Incidents assessed individually without aggregation review
- No criteria for relatedness
Untimely filing of Item 1.05 8-K does not result in loss of Form S-3 short-form registration eligibility, and Section 10(b)/Rule 10b-5 liability attaches only for materially misleading statements, not for omissions during the 4-day window; however, no broader safe harbor exists from Section 11 or other liability for incorrect disclosures.
- S-3 eligibility analysis
- Form 12b-25 (Form NT) considerations
- Counsel legal memo on liability framework
- Disclosure controls test results showing timely filing capability
- Assuming general safe harbor for any cyber disclosure misstatement
- Confusing S-3 protection with substantive liability protection
- Failure to update forward-looking statements legend
Insider Trading Controls
Update insider trading policies and procedures to address timely imposition of trading blackouts and event specific trading restrictions when material non public information regarding a cybersecurity incident exists.
- Updated insider trading policy
- Event specific blackout procedures
- Section 16 officer notification logs
- Trading window suspension records
- Blackouts not triggered on incident detection
- Section 16 officers not notified in time
Process Integration
Per SEC Cybersecurity Disclosure Rules: process integration. Requirements include (a) integrate cyber incident response with disclosure team + legal + investor relations + (b) maintain materiality assessment workflow + (c) coordinate with SEC counsel + (d) document materiality factors + decisions + (e) maintain training for incident response + disclosure teams + (f) integrate with broader compliance.
- SEC Cyber evidence for SECCYB-4
- materiality workflow + 4-day disclosure + governance partial
Risk Management Disclosure
Per SEC Item 106(b) Regulation S-K: annual cybersecurity risk management disclosure. Requirements include (a) Risk Management Processes including assessment + identification + management of material cybersecurity risks + (b) Third-Party Engagement including external service providers + assessors + auditors + (c) Third-Party Risk Oversight + (d) Prior Incident Impact disclosure + (e) integration with overall risk management + ERM + (f) document risk management processes for annual 10-K.
- SEC Cyber evidence for SECCYB-2
- materiality workflow + 4-day disclosure + governance partial
Risk Management and Strategy: Regulation S-K Item 106(b)
Describe in Form 10-K processes for assessing, identifying, and managing material risks from cybersecurity threats, including whether and how such processes are integrated into the overall risk management system, engagement of assessors, consultants, auditors, or other third parties, and processes to oversee third party service provider risks.
- Cyber risk management procedure document
- Engagement letters with external cyber assessors
- Third party risk management policy and reports
- ERM integration mapping
- Cyber risk siloed from ERM
- No documented third party risk oversight tied to disclosure
Describe whether any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect the entity's business strategy, results of operations, or financial condition.
- Material effect analysis memo
- History of prior material incidents and impacts
- Forward looking impact narrative
- Reviewer sign offs
- Generic language used without specific analysis
- Prior incidents not revisited each filing cycle
Establish processes to oversee and identify material cybersecurity risks from the use of third party service providers, including evaluation of supplier security posture, contractual notification obligations, and incident integration into the entity's response and disclosure decisions.
- Third party risk management policy
- Standard contractual cyber clauses
- Supplier inventory with risk tiering
- Records of supplier incident reviews triggering disclosure analysis
- No supplier inventory tied to data sensitivity
- Contracts lack notification timelines aligned to 8-K
Structured Data and Filing Mechanics
Tag the cybersecurity disclosures required by Item 106 of Regulation S-K and Item 1.05 of Form 8-K using inline XBRL in accordance with the EDGAR Filer Manual.
- XBRL taxonomy mapping document
- EDGAR validation logs
- Tagging review checklists
- Vendor or in house tagging engagement records
- Tags applied to wrong concepts
- No documented review of XBRL output
Smaller reporting companies were granted an additional 180 days from the non-SRC Item 1.05 compliance date before being required to begin filing material incident disclosures on Form 8-K Item 1.05.
- SRC determination memo
- Disclosure controls policy with SRC dates
- First SRC Item 1.05 filing readiness checklist
- Counsel calendar of compliance dates
- Misclassification of registrant status
- Missing the June 15 2024 SRC compliance start
- No transition plan when crossing the SRC threshold
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.