Skip to content

Evidence request lists

SEC Cybersecurity Disclosure Rule

Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Definitions and Enforcement Posture

SEC-DEFINITIONS
Definitions: Cybersecurity Incident, Threat, Information Systems

Cybersecurity incident is defined as an unauthorized occurrence, or series of related unauthorized occurrences, on or conducted through a registrant's information systems that jeopardizes the confidentiality, integrity, or availability of those systems or any information residing therein. Definitions for threat and information systems are correspondingly broad.

Artefacts an auditor will ask for
  • Internal definitions glossary aligned to Reg S-K 106(a)
  • Asset inventory aligned to information systems definition
  • Training materials referencing definitions
  • Policy update log post-July 2023
Where this commonly fails
  • Using NIST-only definitions inconsistent with SEC definitions
  • Omitting OT/IoT from information systems scope
  • Treating availability impacts as out of scope
  • Vendor-hosted SaaS missing from system inventory
SEC-ENFORCEMENT
Enforcement Posture (SolarWinds Precedent and Beyond)

SEC enforcement actions (e.g., SolarWinds October 2023 complaint, partial dismissal July 2024) signal scrutiny of cybersecurity disclosures, internal accounting controls (Section 13(b)(2)(B)) as applied to cyber, and statements in risk factors that may mislead investors regarding actual practices.

Artefacts an auditor will ask for
  • Risk factor accuracy review log
  • Internal controls testing tied to cyber
  • Spokesperson/IR statement vetting record
  • Disclosure committee enforcement-trend briefings
  • Litigation hold readiness for cyber incidents
Where this commonly fails
  • Risk factor language inconsistent with actual security posture
  • No periodic vetting of marketing or website security claims
  • Internal accounting controls not extended to cyber-relevant assets

Disclosure Controls and Supporting Process

SEC-CYB-12
Disclosure Controls Tailored to Cybersecurity

Design and maintain disclosure controls and procedures that ensure information about cybersecurity incidents reaches the disclosure committee, executive officers, and the board on a timely basis to support timely Form 8-K and periodic filing decisions.

Artefacts an auditor will ask for
  • Disclosure committee charter referencing cyber
  • Information flow diagram from SOC to disclosure committee
  • Sub certification questionnaires
  • Tabletop exercises focused on disclosure decisions
Where this commonly fails
  • No defined link from SOC to disclosure committee
  • Sub certification omits cyber
SEC-CYB-13
Incident Response Plan Alignment with Disclosure Obligations

Maintain an incident response plan that integrates legal, finance, and communications functions, includes specific steps for materiality determination, regulatory notification timing, and external disclosure, and is exercised regularly.

Artefacts an auditor will ask for
  • Incident response plan with disclosure decision tree
  • Tabletop exercise after action reports
  • Cross functional contact list
  • Approved playbooks for ransomware, business email compromise, and supplier compromise
Where this commonly fails
  • IR plan owned by IT alone
  • Exercises do not test 8-K filing timing
SEC-CYB-16
External Counsel and Forensic Engagement Protocols

Establish pre arranged engagement protocols with external counsel and forensic providers to support rapid investigation, privilege preservation, and disclosure analysis when a cybersecurity incident occurs.

Artefacts an auditor will ask for
  • Master service agreements with counsel and forensics providers
  • Engagement playbook
  • Privilege protocol memo
  • After action reviews of prior engagements
Where this commonly fails
  • No pre arranged retainers
  • Privilege rules not understood by IR teams
SEC-CYB-17
Coordination with Other Regulatory Notifications

Coordinate cybersecurity disclosure under SEC rules with other applicable notification regimes including state breach notification laws, sector specific regulators, and federal authorities such as CISA and FBI, while preserving accurate and consistent public messaging.

Artefacts an auditor will ask for
  • Regulatory notification matrix mapping incidents to obligations
  • Coordination procedure document
  • Approved external communications templates
  • Audit trail of notifications made
Where this commonly fails
  • Notification matrix not maintained
  • Inconsistent messages across regulators and SEC filings
SEC-CYB-18
Historical Incident Tracking and Repeat Disclosure Analysis

Maintain a repository of past cybersecurity incidents, including non material incidents, to support evaluation of cumulative risk, identification of patterns, and disclosure analysis regarding prior incidents that may now have material implications.

Artefacts an auditor will ask for
  • Centralized incident database
  • Quarterly trend analysis report
  • Disclosure refresh procedure document
  • Audit logs of database access
Where this commonly fails
  • No central repository
  • Non material incidents not tracked, preventing pattern analysis
SEC-CYB-19
Training for Material Cybersecurity Disclosure Decision Makers

Provide periodic training to officers, members of the disclosure committee, IR leaders, and the board on cybersecurity disclosure requirements, materiality factors, and timing obligations.

Artefacts an auditor will ask for
  • Training curriculum document
  • Attendance and completion records
  • Knowledge checks or post training assessments
  • Calendar of training cadence
Where this commonly fails
  • Training only at policy rollout, no refreshers
  • Board not included in training
SEC-CYB-20
Recordkeeping for Cybersecurity Materiality Determinations

Maintain complete records supporting materiality determinations, disclosure timing decisions, and any reliance on delays or omissions, sufficient to evidence compliance under SEC enforcement reviews.

Artefacts an auditor will ask for
  • Recordkeeping policy referencing SEC cyber rules
  • Retention schedule with minimum periods
  • Audit trail of materiality determinations
  • Legal hold procedures invoked on incident detection
Where this commonly fails
  • Determination memos not retained beyond audit cycle
  • No legal hold automatically triggered on incident detection
SEC-REG-S-P
Regulation S-P Customer Notification Coordination

Amended Regulation S-P (May 2024) requires covered broker-dealers, investment advisers, funds, and transfer agents to adopt incident response programs and provide customer notification within 30 days of detecting unauthorized access; coordinate with Item 1.05 obligations for registrants.

Artefacts an auditor will ask for
  • Reg S-P incident response policy
  • Customer notification templates
  • 30-day clock tracker
  • Cross-mapped 8-K/Reg S-P decision matrix
  • Service provider oversight evidence
Where this commonly fails
  • No alignment between Reg S-P clock and 8-K clock
  • Customer notification delayed past 30 days
  • Service provider notification clauses missing
  • Annual policy review skipped
SEC-REG-SCI
Reg SCI Coordination for Covered Entities

SCI entities (exchanges, clearing agencies, SBSDRs, certain ATSs) remain subject to Reg SCI Rules 1001 through 1007 in addition to the cybersecurity disclosure rule; SCI events may also trigger 8-K Item 1.05 disclosure if the SCI entity is a public registrant.

Artefacts an auditor will ask for
  • SCI event log
  • SCI Rule 1002(b) notifications to SEC
  • Reconciliation log SCI to Item 1.05
  • Joint counsel/CISO playbook
Where this commonly fails
  • Treating SCI notification as sufficient for 8-K
  • Inconsistent narratives between SCI report and 8-K
  • Missing reasonably-designed-policies-and-procedures evidence

Foreign Private Issuers

SEC-CYB-11
Foreign Private Issuer Disclosures on Form 6-K and 20-F

For foreign private issuers, furnish on Form 6-K information about material cybersecurity incidents that the issuer discloses or otherwise publicizes in a foreign jurisdiction, and disclose comparable information in Form 20-F under Item 16K.

Artefacts an auditor will ask for
  • Filed 6-K furnishings for cyber incidents
  • Form 20-F Item 16K section
  • Tracking log of foreign disclosures
  • Counsel coordination memos
Where this commonly fails
  • 6-K not furnished promptly after foreign disclosure
  • 20-F Item 16K narrative copies 8-K language without entity tailoring

Governance Disclosure

SECCYB-3
Governance (Item 106(c)) - Board and Management Oversight

Per SEC Item 106(c): governance disclosure. Requirements include (a) Board Oversight of Cybersecurity including responsible committee + reporting + frequency + (b) Management's Role and Expertise including specific positions + relevant experience + (c) management reporting to board + escalation + (d) maintain documented governance structure + (e) integrate with broader enterprise governance.

Artefacts an auditor will ask for
  • SEC Cyber evidence for SECCYB-3
Where this commonly fails
  • materiality workflow + 4-day disclosure + governance partial

Governance: Regulation S-K Item 106(c)

SEC-CYB-08
Board Oversight of Cybersecurity Risks

Describe the board of directors' oversight of risks from cybersecurity threats, identifying any board committee or subcommittee responsible for the oversight and the processes by which the board or committee is informed about such risks.

Artefacts an auditor will ask for
  • Board or committee charter referencing cybersecurity oversight
  • Reporting calendar to the board
  • Committee meeting minutes evidencing cybersecurity discussions
  • Director skills matrix where applicable
Where this commonly fails
  • No committee designated
  • Briefings infrequent or undocumented
SEC-CYB-09
Management Role and Expertise in Cybersecurity

Describe management's role in assessing and managing material risks from cybersecurity threats, including identification of relevant positions or committees, their relevant expertise, and how they monitor prevention, detection, mitigation, and remediation of incidents.

Artefacts an auditor will ask for
  • Org chart showing CISO and accountable executives
  • Position descriptions and qualifications
  • Internal cyber reporting templates
  • Biographies referenced in disclosure
Where this commonly fails
  • Expertise of responsible managers not described
  • CISO reporting line creates conflict of interest

Incident Disclosure

SECCYB-1
Material Cybersecurity Incident 4-Business-Day Disclosure (Item 1.05)

Per SEC Item 1.05 Form 8-K Cybersecurity Incident Disclosure Rule: disclosure of material cybersecurity incidents. Requirements include (a) Material Cybersecurity Incident 4-Business-Day Disclosure on Form 8-K Item 1.05 within 4 business days of materiality determination + (b) Materiality Determination Without Unreasonable Delay + (c) Materiality Standard (Quantitative + Qualitative) considering nature + scope + timing + impact + (d) National Security/Public Safety Delay per Attorney General determination + (e) Amendment Obligation for Previously Undetermined Information + (f) integrate with broader incident response + materiality processes.

Artefacts an auditor will ask for
  • SEC Cyber evidence for SECCYB-1
Where this commonly fails
  • materiality workflow + 4-day disclosure + governance partial

Incident Disclosure: Form 8-K Item 1.05

SEC-CYB-01
Material Cybersecurity Incident Determination

Establish a documented process to determine without unreasonable delay whether a cybersecurity incident is material, considering qualitative and quantitative factors, including impact on operations, financial condition, reputation, customers, and the entity's broader systems.

Artefacts an auditor will ask for
  • Materiality determination procedure
  • Incident materiality scoring rubric
  • Records of materiality determinations including timing
  • Escalation log to disclosure committee and counsel
Where this commonly fails
  • Materiality assessed only by IT without legal or finance involvement
  • No documented timing of determination decisions
SEC-CYB-02
Form 8-K Item 1.05 Filing within Four Business Days

File a Form 8-K reporting a material cybersecurity incident under Item 1.05 within four business days of determining that the incident is material, describing the material aspects of the nature, scope, timing, and impact on the entity.

Artefacts an auditor will ask for
  • Filed Form 8-K Item 1.05 entries
  • Filing workflow runbook
  • Disclosure committee approval log
  • Counsel sign off
Where this commonly fails
  • Filing template not pre approved
  • Workflow not tested in tabletop exercises
SEC-CYB-03
National Security or Public Safety Delay Coordination

Coordinate with the United States Attorney General when delay of an Item 1.05 disclosure is sought on grounds of substantial risk to national security or public safety, and document the determination, notification, and any granted delay period.

Artefacts an auditor will ask for
  • Records of Attorney General notifications
  • Written determinations of substantial risk
  • Delay approval letters from DOJ
  • Internal tracking of delay expiry
Where this commonly fails
  • No pre established contact protocol with DOJ
  • Delay expiry not tracked
SEC-CYB-04
Updating Disclosures for Material Information Not Yet Determined

If any required information about the nature, scope, timing, or impact of a material cybersecurity incident is not determined or is unavailable at the time of the initial 8-K filing, identify the omitted information and file an amendment to Form 8-K within four business days after the information becomes available.

Artefacts an auditor will ask for
  • Open item log per incident
  • Filed 8-K amendments
  • Investigation status reports to disclosure committee
  • Communication log with external counsel
Where this commonly fails
  • Initial filing fails to flag what is undetermined
  • No process to track when omitted information becomes available
SEC-CYB-05
Related Occurrences and Aggregation

Treat a series of related occurrences of cybersecurity incidents as a single incident when determining materiality and disclosure obligations under Item 1.05.

Artefacts an auditor will ask for
  • Documented aggregation criteria
  • Incident linking analysis
  • Decision memos on aggregation
  • Threat intelligence ties between events
Where this commonly fails
  • Incidents assessed individually without aggregation review
  • No criteria for relatedness
SEC-SAFE-HARBOR
Limited Safe Harbor for Item 1.05 Late Filings

Untimely filing of Item 1.05 8-K does not result in loss of Form S-3 short-form registration eligibility, and Section 10(b)/Rule 10b-5 liability attaches only for materially misleading statements, not for omissions during the 4-day window; however, no broader safe harbor exists from Section 11 or other liability for incorrect disclosures.

Artefacts an auditor will ask for
  • S-3 eligibility analysis
  • Form 12b-25 (Form NT) considerations
  • Counsel legal memo on liability framework
  • Disclosure controls test results showing timely filing capability
Where this commonly fails
  • Assuming general safe harbor for any cyber disclosure misstatement
  • Confusing S-3 protection with substantive liability protection
  • Failure to update forward-looking statements legend

Insider Trading Controls

SEC-CYB-14
Insider Trading Window Considerations for Cyber Incidents

Update insider trading policies and procedures to address timely imposition of trading blackouts and event specific trading restrictions when material non public information regarding a cybersecurity incident exists.

Artefacts an auditor will ask for
  • Updated insider trading policy
  • Event specific blackout procedures
  • Section 16 officer notification logs
  • Trading window suspension records
Where this commonly fails
  • Blackouts not triggered on incident detection
  • Section 16 officers not notified in time

Process Integration

SECCYB-4
Disclosure Process Integration and Materiality Workflow

Per SEC Cybersecurity Disclosure Rules: process integration. Requirements include (a) integrate cyber incident response with disclosure team + legal + investor relations + (b) maintain materiality assessment workflow + (c) coordinate with SEC counsel + (d) document materiality factors + decisions + (e) maintain training for incident response + disclosure teams + (f) integrate with broader compliance.

Artefacts an auditor will ask for
  • SEC Cyber evidence for SECCYB-4
Where this commonly fails
  • materiality workflow + 4-day disclosure + governance partial

Risk Management Disclosure

SECCYB-2
Risk Management Processes (Item 106(b))

Per SEC Item 106(b) Regulation S-K: annual cybersecurity risk management disclosure. Requirements include (a) Risk Management Processes including assessment + identification + management of material cybersecurity risks + (b) Third-Party Engagement including external service providers + assessors + auditors + (c) Third-Party Risk Oversight + (d) Prior Incident Impact disclosure + (e) integration with overall risk management + ERM + (f) document risk management processes for annual 10-K.

Artefacts an auditor will ask for
  • SEC Cyber evidence for SECCYB-2
Where this commonly fails
  • materiality workflow + 4-day disclosure + governance partial

Risk Management and Strategy: Regulation S-K Item 106(b)

SEC-CYB-06
Risk Management and Strategy Disclosure

Describe in Form 10-K processes for assessing, identifying, and managing material risks from cybersecurity threats, including whether and how such processes are integrated into the overall risk management system, engagement of assessors, consultants, auditors, or other third parties, and processes to oversee third party service provider risks.

Artefacts an auditor will ask for
  • Cyber risk management procedure document
  • Engagement letters with external cyber assessors
  • Third party risk management policy and reports
  • ERM integration mapping
Where this commonly fails
  • Cyber risk siloed from ERM
  • No documented third party risk oversight tied to disclosure
SEC-CYB-07
Material Effects of Cybersecurity Threats Disclosure

Describe whether any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect the entity's business strategy, results of operations, or financial condition.

Artefacts an auditor will ask for
  • Material effect analysis memo
  • History of prior material incidents and impacts
  • Forward looking impact narrative
  • Reviewer sign offs
Where this commonly fails
  • Generic language used without specific analysis
  • Prior incidents not revisited each filing cycle
SEC-CYB-15
Third Party Service Provider Cybersecurity Risk Oversight

Establish processes to oversee and identify material cybersecurity risks from the use of third party service providers, including evaluation of supplier security posture, contractual notification obligations, and incident integration into the entity's response and disclosure decisions.

Artefacts an auditor will ask for
  • Third party risk management policy
  • Standard contractual cyber clauses
  • Supplier inventory with risk tiering
  • Records of supplier incident reviews triggering disclosure analysis
Where this commonly fails
  • No supplier inventory tied to data sensitivity
  • Contracts lack notification timelines aligned to 8-K

Structured Data and Filing Mechanics

SEC-CYB-10
Periodic Filing Inline XBRL Tagging

Tag the cybersecurity disclosures required by Item 106 of Regulation S-K and Item 1.05 of Form 8-K using inline XBRL in accordance with the EDGAR Filer Manual.

Artefacts an auditor will ask for
  • XBRL taxonomy mapping document
  • EDGAR validation logs
  • Tagging review checklists
  • Vendor or in house tagging engagement records
Where this commonly fails
  • Tags applied to wrong concepts
  • No documented review of XBRL output
SEC-SCA-SUB-FILER
Smaller Reporting Company Extended Compliance Date

Smaller reporting companies were granted an additional 180 days from the non-SRC Item 1.05 compliance date before being required to begin filing material incident disclosures on Form 8-K Item 1.05.

Artefacts an auditor will ask for
  • SRC determination memo
  • Disclosure controls policy with SRC dates
  • First SRC Item 1.05 filing readiness checklist
  • Counsel calendar of compliance dates
Where this commonly fails
  • Misclassification of registrant status
  • Missing the June 15 2024 SRC compliance start
  • No transition plan when crossing the SRC threshold
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.