Compyl

SEC Cybersecurity Disclosure Rules: A Compliance Guide for Public Companies

August 11, 2026
Regulation · SEC

SEC Cybersecurity Disclosure Rules: A Compliance Guide for Public Companies

By Compyl ResearchLast updated: August 11, 202612 min read

The SEC’s cybersecurity disclosure rules, adopted July 26, 2023, require public companies to report material cybersecurity incidents on Form 8-K Item 1.05 within four business days of determining materiality, and to describe their cyber risk management, strategy, and governance every year under Regulation S-K Item 106. Both requirements remain fully in effect in August 2026, despite a pending industry petition to rescind Item 1.05.

Key takeaways
  • The four-business-day clock runs from the materiality determination, not from discovery — but the rule requires that determination to be made without unreasonable delay after discovery. You cannot buy time by not deciding.
  • As of August 2026 the rules are unchanged and enforceable. A May 22, 2025 joint petition (File No. 4-856) from five banking and securities trade groups asks the SEC to rescind Item 1.05, but the Commission has not proposed a rule, and cybersecurity disclosure does not appear on its 2026 rulemaking agenda.
  • Most companies now disclose non-material incidents under Item 8.01 instead. Debevoise’s tracker counted roughly 29 Item 1.05 filings versus 50 Item 8.01 filings in the first two years of the rule.
  • Enforcement has narrowed. The SEC collected about $7 million from four issuers in October 2024 for misleading incident and risk-factor disclosure, then dismissed the SolarWinds case with prejudice on November 20, 2025 — leaving affirmative misstatements, not control deficiencies, as the live risk.
  • Item 106 comment letters cluster on three things: Item 1C omitted entirely, thin description of management’s cybersecurity expertise, and vague threat identification and oversight processes.

What Do the SEC Cybersecurity Disclosure Rules Require?

The SEC adopted its cybersecurity disclosure rules on July 26, 2023. They do two separate things, and conflating them is the most common source of confusion inside compliance teams.

The first is event-driven. Form 8-K Item 1.05 requires a domestic registrant to disclose a cybersecurity incident it has determined to be material, describing the material aspects of the incident’s nature, scope, and timing, and the material impact or reasonably likely material impact on the company’s financial condition and results of operations. Foreign private issuers report comparable information on Form 6-K.

The second is periodic. Regulation S-K Item 106 — which appears as Item 1C in the Form 10-K — requires an annual description of the processes for assessing, identifying, and managing material risks from cybersecurity threats, plus board oversight and management’s role. Foreign private issuers use Item 16K of Form 20-F.

What the rules do not do is mandate any security control. There is no required framework, no minimum control set, no certification. This is a disclosure regime layered on top of whatever program you already run.

Compliance dates (all now in effect)
  • Item 106 / Item 1C annual disclosure: fiscal years ending on or after December 15, 2023.
  • Item 1.05 8-K and Form 6-K: December 18, 2023 for most registrants; June 15, 2024 for smaller reporting companies.
  • Inline XBRL tagging: annual reports for fiscal years ending on or after December 15, 2024; incident reports from December 18, 2024.

Those dates come from the SEC’s own small entity compliance guide. Every phase-in has passed, including the 180-day extension smaller reporting companies received for incident reporting.

Are the SEC Cybersecurity Rules Still in Effect in August 2026?

Yes. Both Item 1.05 and Item 106 are in force and unamended. The answer needs context, because a serious repeal effort has been running since 2025 and has generated a lot of premature commentary.

On May 22, 2025, five trade associations — the American Bankers Association, Bank Policy Institute, Securities Industry and Financial Markets Association, Independent Community Bankers of America, and Institute of International Bankers — filed a joint petition for rulemaking (File No. 4-856) asking the SEC to rescind Item 1.05 and the parallel Form 6-K requirement. Their four arguments: public disclosure collides with confidential reporting channels under CIRCIA and to law enforcement; disclosure is compelled before investigation and remediation are complete; ransomware crews weaponize the rule as extortion leverage, as AlphV did when it reported MeridianLink to the SEC; and persistent Item 1.05-versus-8.01 confusion produces disclosure that is not decision-useful.

The petition is docketed and open for comment. It is not a rule. Rescission requires notice-and-comment rulemaking under the Administrative Procedure Act, and the Commission has not proposed one. Harvard’s corporate governance forum noted in January 2026 that the SEC “did not indicate an intent to revisit the cybersecurity disclosure rules” in its regulatory agenda. Chairman Paul Atkins’ July 7, 2026 statement on the 2026 regulatory agenda centers on crypto asset rules, revitalizing public markets, and retail access to private markets. Cybersecurity disclosure is not among the priorities described.

One point of frequent confusion: in June 2025 the SEC formally withdrew fourteen pending proposed rules, including the proposed cybersecurity risk management rules for investment advisers, registered investment companies, and BDCs. Those never became final. The 2023 public company rules were untouched.

The practical read in August 2026: plan as though Item 1.05 is permanent. Even in the most favorable scenario a proposal, comment period, and final rule take many quarters, and the underlying obligation not to make materially misleading statements about cyber risk survives any rescission.

Which Filings Are Required, and What Are the Deadlines?

The table below is the whole disclosure surface in one view. Only one row carries a hard four-business-day clock, and it is triggered by a judgment call, not an event.

Form Item Trigger Deadline
Form 8-K Item 1.05 Company determines a cybersecurity incident is material 4 business days after the materiality determination
Form 8-K/A Item 1.05 amendment Required information was undetermined or unavailable at the original filing 4 business days after determining or obtaining that information
Form 8-K Item 8.01 (voluntary) Incident is immaterial, or materiality is not yet determined, but disclosure is warranted None — voluntary, no prescribed deadline
Form 10-K Item 1C (Reg S-K Item 106) Every annual report Filed with the 10-K; required for fiscal years ending on or after Dec 15, 2023
Form 20-F Item 16K Foreign private issuer annual report Filed with the 20-F
Form 6-K Material cybersecurity incident FPI discloses or is required to disclose the incident in its home jurisdiction or to security holders Promptly, under the general Form 6-K furnishing standard
Form 8-K Item 1.05(c) — AG delay US Attorney General certifies disclosure poses a substantial risk to national security or public safety Up to 30 days, extendable by 30 and then 60 days (120 days total)
Form 8-K Item 1.05(d) — FCC delay Registrant is subject to the FCC breach notification rule at 47 CFR 64.2011 Applicable FCC period, and in no event more than 7 business days
All of the above Inline XBRL (Rule 405, Reg S-T) Item 1.05 and Item 106 disclosure must be tagged 10-K: fiscal years ending on or after Dec 15, 2024; 8-K: from Dec 18, 2024

The Form 8-K/A row is a standing duty, not a courtesy: if you filed with “the investigation is ongoing” language, you have re-armed the four-business-day clock for whenever the missing facts land.

How Do You Determine Whether a Cybersecurity Incident Is Material?

The SEC declined to invent a cybersecurity-specific materiality test. As then-Corporation Finance Director Erik Gerding explained in a December 14, 2023 statement, the standard is the familiar one from TSC Industries and Basic: information is material if there is a substantial likelihood a reasonable shareholder would consider it important, or if it would significantly alter the total mix of information available.

The instruction that actually creates pressure is timing. Item 1.05 requires the materiality determination to be made without unreasonable delay after discovery of the incident. The four-business-day filing window starts at determination, but the determination itself is on a clock. A deliberately slow-walked analysis is a rule violation, not a safe harbor.

Quantitative factors are necessary but rarely sufficient

Remediation cost, lost revenue from downtime, ransom demands, forensics and legal fees, notification costs, and expected penalties all belong in the model, as does reasonably likely future impact. This is where cyber risk quantification earns its place — a defensible loss range beats a debate about gut feel when the audit committee asks how you reached “not material.”

Qualitative factors decide most close calls

The adopting release and staff guidance point to reputational harm, effects on customer and vendor relationships, litigation and regulatory risk, competitive harm from stolen intellectual property, and impact on the ability to execute strategy. An incident with modest direct cost can still be material because of what it reveals.

Ransomware: five staff interpretations you should have on file

On June 24, 2024 the staff published five Form 8-K C&DIs (104B.05 through 104B.09) that close off the most tempting shortcuts. Paying a ransom and getting your data back does not end the materiality analysis. A ransom payment after a materiality determination does not extinguish the filing obligation. Insurance coverage does not make an incident immaterial, and you should consider the effect on the future availability and cost of that coverage. The size of the demand or payment is one factor among many. And a series of related ransom attacks that each look immaterial must be assessed in the aggregate.

That tracks the rule’s own definition: Item 106(a) defines a cybersecurity incident as “an unauthorized occurrence, or a series of related unauthorized occurrences.” Serial low-grade intrusions by the same actor are one incident for disclosure purposes.

What Belongs in an Item 1.05 8-K, and What Doesn’t?

Item 1.05 asks for two things: the material aspects of the incident’s nature, scope, and timing, and the material impact or reasonably likely material impact on financial condition and results of operations. That is the entire required scope.

The rule expressly does not require technical detail about your systems, the specific vulnerability exploited, your remediation status, or your incident response plans. Write to the investor question — what happened, how big, what does it cost — not to the forensic narrative.

If required information is not determined or available when the filing is due, say so, then file a Form 8-K/A within four business days of getting it. Half of early filers did exactly that.

Item 1.05 is not a place to be cautious

The single most useful piece of staff guidance is Gerding’s May 21, 2024 statement: “Item 1.05 is not a voluntary disclosure, and it is by definition material.” Filing under Item 1.05 out of an abundance of caution tells the market you concluded the incident was material. If you have not made that determination, or you concluded the incident is immaterial, use Item 8.01. If you later determine the incident is material, file the Item 1.05 8-K within four business days of that determination.

What two years of filings actually look like

The behavioral shift after that guidance is visible in the data. A NYU Program on Corporate Compliance and Enforcement study of the rule’s first year (December 18, 2023 through December 31, 2024) found 26 companies filed under Item 1.05 and 34 under Item 8.01, with the Item 8.01 count jumping from 6 before the May 2024 statement to 28 after. Median time from detection to filing was 4.5 business days and the mean was 7.88. Thirteen of the 26 Item 1.05 filers amended. Seventeen of 26 stated no material financial impact in the initial filing. None disclosed a ransom payment.

By the two-year mark, Debevoise’s Form 8-K tracker (updated May 21, 2026) counted roughly 79 cybersecurity 8-Ks across about 74 issuers, split around 29 Item 1.05 filings to 50 Item 8.01 filings, with only a small number of voluntary filings later escalating to a materiality determination. The mandatory channel is narrow; the voluntary channel is where most disclosure now happens.

When Can You Delay Disclosure for National Security?

Item 1.05(c) allows a delay only if the US Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety and notifies the SEC in writing. The delay is up to 30 days, extendable by another 30, and in extraordinary circumstances by a further 60 — 120 days maximum, after which additional delay would require a Commission exemptive order.

DOJ published its Material Cybersecurity Incident Delay Determinations guidelines on December 12, 2023. Three operational points matter more than the legal standard:

  • You contact the FBI, not the SEC. Requests go to the FBI directly, or through CISA, the Secret Service, or a sector risk management agency, and the FBI routes them to DOJ.
  • Contact must be immediate — ideally before you finish the materiality analysis. The Attorney General has to act inside the same four-business-day window that runs from your determination. If you call on day three, there is effectively no time to process a request.
  • The test is about the disclosure, not the incident. Qualifying scenarios are narrow: an unpatched vulnerability whose publication would spawn copycat attacks, incidents touching systems that hold sensitive government information, or disclosure that would undermine remediation of critical infrastructure.

There is a second, much narrower delay in Item 1.05(d) for registrants subject to the FCC’s breach notification rule at 47 CFR 64.2011, capped at seven business days.

Neither provision is a general-purpose extension. The way to make the delay path usable is to put named FBI field office and CISA contacts in the incident response plan before you need them, and to rehearse the “do we call the Bureau” decision in a tabletop exercise rather than at 2 a.m. during a live intrusion.

What Does Item 106 Require in Your 10-K?

Regulation S-K Item 106 has two substantive paragraphs, and the SEC staff reads both closely.

Item 106(b): risk management and strategy

Describe your processes for assessing, identifying, and managing material risks from cybersecurity threats in sufficient detail for a reasonable investor to understand them. Three sub-items are explicitly enumerated: whether and how those processes are integrated into your overall risk management system; whether you engage assessors, consultants, auditors, or other third parties; and whether you have processes to oversee and identify risks from your use of third-party service providers. You must also state whether cybersecurity threats, including past incidents, have materially affected or are reasonably likely to materially affect your business strategy, results of operations, or financial condition.

Item 106(c): governance

Describe the board’s oversight of cybersecurity risk, identifying any responsible committee and the process by which it is informed. Then describe management’s role: which positions or committees are responsible, their relevant expertise, how they monitor prevention, detection, mitigation, and remediation, and whether they report to the board. Expertise may include prior relevant roles, certifications, degrees, or other knowledge and skills.

Where comment letters land

Staff comment volume on Item 1C is modest but consistent. Gibson Dunn’s review of 2025 Form 10-K practice identifies three recurring themes: requests for more information on the cybersecurity expertise of the individuals responsible for the program, requests to provide Item 1C disclosure where it was omitted from the 10-K entirely, and requests for more detail on the processes used to oversee and identify threats. Harvard’s January 2026 season guidance flags a specific pattern — companies that describe the CISO’s qualifications but say nothing about other information security personnel have been asked to revise future filings.

The fixes are unglamorous. Name the committee and the reporting cadence. Describe expertise with substance rather than a title. Say something real about third-party oversight. Because Item 106 asks how cyber risk is integrated into enterprise risk management, the disclosure is only as good as the underlying reporting — a defined set of risk management metrics and a standing board package should exist before drafting season. Directors assessing their own readiness will find a useful frame in this board member’s blueprint for risk and compliance.

What Has SEC Enforcement Actually Punished?

The enforcement record is short and points one way: the SEC has punished misleading statements, not imperfect security.

On October 22, 2024, the SEC charged four companies with misleading cyber disclosures tied to the SolarWinds Orion compromise: $4 million (Unisys), $1 million (Avaya), $995,000 (Check Point), and $990,000 (Mimecast), roughly $7 million in total. The alleged conduct was framing known intrusions as hypothetical risk and using generic language while knowing specifics — one issuer described limited email access when the intruder had reached at least 145 files in cloud storage. Unisys was also charged with disclosure controls violations. As the SEC put it, “the federal securities laws prohibit half-truths, and there is no exception for statements in risk-factor disclosures.”

Then the pendulum swung. The Commission’s landmark case against SolarWinds and its CISO, filed in October 2023, survived a July 2024 motion to dismiss only as to representations in the company’s public Security Statement — and on November 20, 2025 it was dismissed with prejudice. Commentators read the dismissal as the SEC retreating from expansive theories that treated internal accounting controls provisions as a hook for technical security failings, and returning to fraudulent-disclosure fundamentals.

Two conclusions follow. First, the highest-probability failure mode is not a late 8-K; it is a risk factor that describes as possible something that has already happened, or an incident 8-K that understates known scope. Second, a narrower SEC enforcement appetite does not reduce total exposure — securities class actions and sector regulators still price cyber disclosure, and the Division of Examinations kept cybersecurity governance, vendor oversight, access controls, and incident response on its 2026 priorities.

How Do You Build a Disclosure Program That Holds Up?

All of this reduces to one operational problem: on the day an incident lands, can you produce a documented, timely, defensible materiality decision and a filing that matches the facts? Here is the sequence that gets you there.

  1. Write the escalation path from the SOC to the disclosure committee. Define the severity thresholds that automatically trigger a disclosure assessment — not a filing, an assessment. Ambiguity here is what produces “unreasonable delay.”
  2. Pre-agree the materiality criteria. Set quantitative bands tied to your existing financial materiality thresholds plus an explicit list of qualitative triggers: regulated data, safety systems, outage duration, IP theft, executive or board data. Have finance sign off in advance.
  3. Stand up a named disclosure committee with a service level. Legal, finance, security, IR, and a designated decision owner, committed to convene within a fixed number of hours. Record who attended, what was considered, and what was decided.
  4. Time-stamp everything. Discovery, escalation, committee convening, determination, filing. If the SEC or a plaintiff ever reconstructs your timeline, it should be your timeline, not theirs.
  5. Draft the filings in advance. Keep Item 1.05 and Item 8.01 templates, a holding statement, and a Form 8-K/A skeleton on the shelf. Drafting under a four-business-day clock is how understatements happen.
  6. Extend the obligation to third parties. Item 106(b) requires you to describe third-party risk oversight, and a vendor breach can be material to you. Contract for notification windows short enough to leave you time to analyze.
  7. Exercise it. Run the disclosure decision inside your incident response tabletops, with counsel and IR in the room, and confirm your business continuity plan accounts for the reporting workload during a live outage. The petitioners’ complaint that disclosure competes for frontline responders is a real operational constraint even if it never becomes a legal one.
  8. Report to the board on a fixed cadence. Item 106(c) asks you to describe the process by which the board is informed. If that process is “the CISO presents annually,” the disclosure will read that way.
  9. Reconcile Item 1C to reality each year. Before filing, walk the prior year’s incidents against the risk factors and the program description. Anything described as hypothetical that actually occurred is the fact pattern the October 2024 settlements punished.

IBM’s 2026 Cost of a Data Breach study, published July 29, 2026, put the global average breach cost at $4.99 million and found one in four malicious breaches was AI-enabled, a 56% year-over-year increase, with those breaches averaging about $6 million. Incidents in that range are exactly where the materiality call is contested and the documentation has to hold.

Frequently asked questions

When does the four-business-day SEC cybersecurity disclosure clock start?
It starts when the company determines the incident is material, not when the incident is discovered or contained. Item 1.05 separately requires that materiality determination to be made without unreasonable delay after discovery, so delaying the decision to delay the filing is itself a violation.
Are the SEC cybersecurity disclosure rules still in effect in 2026?
Yes. Item 1.05 and Regulation S-K Item 106 remain in force and unamended as of August 2026. A May 2025 joint petition from banking and securities trade groups (File No. 4-856) asks the SEC to rescind Item 1.05, but no rulemaking has been proposed and the topic is not on the 2026 agenda.
What is the difference between Form 8-K Item 1.05 and Item 8.01 for a cyber incident?
Item 1.05 is mandatory and, per SEC staff, is by definition a statement that the incident is material. Item 8.01 is a voluntary channel for incidents that are immaterial or whose materiality is undetermined. If an Item 8.01 incident is later deemed material, file an Item 1.05 8-K within four business days.
Can a company delay an Item 1.05 8-K filing?
Only if the US Attorney General determines that disclosure poses a substantial risk to national security or public safety and notifies the SEC. Delays run up to 30 days, extendable by 30 and then 60, for 120 days total. Requests go to the FBI immediately, ideally before the materiality determination is finished.
Does paying a ransom make a cybersecurity incident immaterial?
No. SEC staff C&DIs issued June 24, 2024 state that recovering data after paying does not end the materiality analysis, that a payment after a materiality determination does not remove the filing obligation, and that insurance coverage does not by itself render an incident immaterial.
What do SEC comment letters criticize most in Item 1C cybersecurity disclosure?
Three things recur: Item 1C omitted from the Form 10-K entirely, thin descriptions of the relevant cybersecurity expertise of the people running the program beyond the CISO, and vague accounts of the processes used to identify and oversee cybersecurity threats, including third-party provider risk.
Sources
  1. SEC Press Release 2023-139: SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
  2. SEC Small Entity Compliance Guide: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
  3. 17 CFR 229.106 (Regulation S-K Item 106) – Cybersecurity, eCFR
  4. SEC Form 8-K (Item 1.05 Material Cybersecurity Incidents)
  5. SEC Staff Statement: Disclosure of Cybersecurity Incidents Determined To Be Material and Other Cybersecurity Incidents (May 21, 2024)
  6. SEC Staff Statement: Cybersecurity Disclosure (December 14, 2023)
  7. SEC Compliance and Disclosure Interpretations: Exchange Act Form 8-K, Section 104B
  8. Joint Petition for Rulemaking to Rescind Form 8-K Item 1.05 (File No. 4-856, May 22, 2025)
  9. SEC Withdrawal of Proposed Cybersecurity Risk Management Rules for Investment Advisers and Funds (June 2025)
  10. SEC Chairman Paul Atkins, Statement on the 2026 Regulatory Agenda (July 7, 2026)
  11. SEC Press Release 2024-174: SEC Charges Four Companies With Misleading Cyber Disclosures (October 22, 2024)
  12. DOJ Material Cybersecurity Incident Delay Determinations Guidelines (December 12, 2023)
  13. NYU Program on Corporate Compliance and Enforcement: Lessons Learned – One Year of Form 8-K Material Cybersecurity Incident Reporting (March 2025)
  14. Debevoise Data Blog: Cybersecurity Incident Disclosure Form 8-K Tracker, Two-Year Update (May 21, 2026)
  15. Harvard Law School Forum on Corporate Governance: SolarWinds Dismissed – What the SEC’s U-turn Signals for Cyber Enforcement (December 2025)
  16. Harvard Law School Forum on Corporate Governance: Key Considerations for the 2025 Annual Reporting Season (January 2026)
  17. Gibson Dunn: Observations and Considerations on 2025 Form 10-Ks
  18. IBM Cost of a Data Breach Report 2026 (July 29, 2026)

Make SEC Cyber Disclosure Repeatable With Compyl

Compyl connects your incident data, control evidence, and risk register so a materiality assessment produces a documented, time-stamped decision trail instead of a scramble. Board reporting, third-party oversight, and Item 106 evidence stay current year-round, so drafting Item 1C is a review rather than a reconstruction.

Request a demo →

About this guide. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.


Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies