home  /  insights  /  sec-cyber-disclosure-what-it-requires
Standard of Care

What do the SEC cybersecurity disclosure rules require after an incident?

A Form 8-K within four business days of the materiality determination — not within four days of discovery — plus an annual account of the program itself. The gap between those two clocks is where most of the argument lives.

September 15, 2026 · 12 min read

The short answer

Two separate things. Item 1.05 of Form 8-K requires a registrant that has determined a cybersecurity incident is material to describe, within four business days of that determination, the material aspects of the nature, scope and timing of the incident and its material or reasonably likely material impact — and Instruction 1 requires the materiality determination itself to be made “without unreasonable delay after discovery of the incident.” Item 106 of Regulation S-K separately requires an annual account, in the Form 10-K, of how the registrant assesses and manages cybersecurity risk, including whether it oversees risk from third-party service providers, and of how the board and management oversee it. Both were adopted by the Securities and Exchange Commission on July 26, 2023 in Release Nos. 33-11216 and 34-97989. As of September 15, 2026 the Form 8-K published by the Commission carries Item 1.05 in the language adopted in 2023, and the codified text of Item 106 at 17 CFR 229.106 carries a single source credit to 88 FR 51942 (Aug. 4, 2023).

What this article establishes

  • The rules were adopted July 26, 2023 in SEC Release Nos. 33-11216; 34-97989 (File No. S7-09-22), published at 88 Fed. Reg. 51896 and effective September 5, 2023; the SEC’s press release 2023-139 set Form 8-K compliance at the later of 90 days after Federal Register publication or December 18, 2023, with smaller reporting companies given an additional 180 days, which the adopting release states put their Item 1.05 compliance date at June 15, 2024.
  • General Instruction B.1 to Form 8-K states that “A report pursuant to Item 1.05 is to be filed within four business days after the registrant determines that it has experienced a material cybersecurity incident” — the trigger is the determination, and Instruction 1 to Item 1.05 requires that determination “without unreasonable delay after discovery of the incident.”
  • The adopting release recounts that the Commission affirmed in the proposing release that the materiality standard is the ordinary securities-law standard, citing TSC Industries, Inc. v. Northway, Inc., 426 U.S. 438, 449 (1976), Basic Inc. v. Levinson, 485 U.S. 224, 232 (1988), and Matrixx Initiatives, Inc. v. Siracusano, 563 U.S. 27 (2011).
  • Item 1.05(c) permits delay only on a written determination by the United States Attorney General of substantial risk to national security or public safety: up to 30 days, a further 30, and in extraordinary circumstances a final 60, after which the Commission “will consider additional requests for delay and may grant such relief through Commission exemptive order.” The Department of Justice published its process in “Department of Justice Material Cybersecurity Incident Delay Determinations,” dated December 12, 2023.
  • What the Commission’s own pages show as of September 15, 2026: the Form 8-K it publishes carries Item 1.05 as adopted; 17 CFR 229.106 carries the single source credit 88 FR 51942 (Aug. 4, 2023); the Division of Corporation Finance’s Form 8-K Compliance and Disclosure Interpretations page carries nine questions numbered 104B.01 through 104B.09 and a last-updated date of June 24, 2024; the Commission’s rulemaking index lists no final rule amending the public-company cybersecurity disclosure rules after July 26, 2023; and the petition filed May 22, 2025 by the American Bankers Association, Bank Policy Institute, SIFMA, Independent Community Bankers of America and Institute of International Bankers to rescind Item 1.05 stands on the petitions page under File No. 4-856.

What does Item 1.05 of Form 8-K actually require a company to say?

Item 1.05(a) of Form 8-K requires that, if the registrant experiences a cybersecurity incident it determines to be material, it “describe the material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely material impact on the registrant, including its financial condition and results of operations.” That is the whole of the affirmative requirement. It is a disclosure about consequence, not a technical account of the intrusion.

Two instructions narrow it further. Instruction 4 provides that a registrant “need not disclose specific or technical information about its planned response to the incident or its cybersecurity systems, related networks and devices, or potential system vulnerabilities in such detail as would impede the registrant’s response or remediation of the incident.” Instruction 2 handles the case in which the facts are not yet known: the registrant says so in the filing, then must amend within four business days after it determines the missing information, without unreasonable delay, or after that information becomes available.

Item 1.05(b) requires the disclosure to be tagged in an Interactive Data File under Rule 405 of Regulation S-T, which is why these filings are machine-readable and easy for anyone — including opposing counsel — to collect and compare across registrants. An Item 1.05 filing is a securities disclosure about impact, drafted under a four-day clock, and not a forensic finding.

Does the four-business-day clock run from discovery of the incident or from the materiality determination?

From the materiality determination. General Instruction B.1 to Form 8-K provides that “A report pursuant to Item 1.05 is to be filed within four business days after the registrant determines that it has experienced a material cybersecurity incident.” Discovery does not start the clock, and the widely repeated shorthand that companies have four days to disclose a breach is wrong as a statement of the rule.

The Securities and Exchange Commission anticipated the obvious consequence of that design and constrained it. Instruction 1 to Item 1.05 provides that “A registrant’s materiality determination regarding a cybersecurity incident must be made without unreasonable delay after discovery of the incident.” The adopting release explains the purpose plainly. It recounts that “[t]o protect against any inclination on the part of a registrant to delay making a materiality determination with a view toward prolonging the filing deadline, the Commission proposed adding Instruction 1 to Item 1.05 requiring that ‘a registrant shall make a materiality determination regarding a cybersecurity incident as soon as reasonably practicable after discovery of the incident.’” The instruction was adopted in the “without unreasonable delay” form that now appears on the form.

So there are two clocks, and the second is the unfamiliar one. The first is mechanical and four business days long. The second has no fixed length and is judged after the fact against the pace of the investigation, which is why the internal record of when the company learned what — the scoping timeline, the escalation emails, the dated forensic updates — becomes the evidence on the question. That record is also among the first things to expire, which is the subject of what disappears first after a breach.

What counts as material for purposes of the SEC cybersecurity rules?

The ordinary securities-law materiality standard, not a cybersecurity-specific test. The adopting release recounts that “[t]he Commission affirmed in the Proposing Release that the materiality standard registrants should apply in evaluating whether a Form 8-K would be triggered under proposed Item 1.05 would be consistent with that set out in the numerous cases addressing materiality in the securities laws,” citing TSC Industries, Inc. v. Northway, Inc., 426 U.S. 438, 449 (1976), Basic Inc. v. Levinson, 485 U.S. 224, 232 (1988), and Matrixx Initiatives, Inc. v. Siracusano, 563 U.S. 27 (2011), and likewise with Securities Act Rule 405 and Exchange Act Rule 12b-2.

The Division of Corporation Finance has since worked several recurring fact patterns through that standard in its Form 8-K Compliance and Disclosure Interpretations 104B.05 through 104B.09, all dated June 24, 2024. Their consistent direction is that operational recovery does not resolve the securities question: a registrant that makes a ransom payment and has its operations restored or its data returned still has to make a materiality determination; reimbursement of a ransom payment under an insurance policy does not necessarily render an incident immaterial; and the size of a ransom payment is one factor rather than a determinative one.

Note what this standard is not. It is not the standard for whether individuals were injured, and it is not the standard for whether a state notification duty was triggered — three questions that run on three clocks and can produce three answers about the same incident. The gap between data being exposed and anyone being harmed by it is treated separately in exposure is not misuse.

Can a company delay an Item 1.05 disclosure for national security reasons?

Only if the United States Attorney General determines that the disclosure poses a substantial risk to national security or public safety and notifies the Commission in writing. Item 1.05(c) then permits delay “for a time period specified by the Attorney General, up to 30 days,” an additional period of up to 30 days on a further written determination, and “in extraordinary circumstances” a final additional period of up to 60 days. Beyond that, “the Commission will consider additional requests for delay and may grant such relief through Commission exemptive order.”

The Department of Justice published the process in a document titled “Department of Justice Material Cybersecurity Incident Delay Determinations,” dated December 12, 2023. It routes requests through the Federal Bureau of Investigation, describes a limited set of categories in which public disclosure — rather than the incident itself — would create the risk, and makes one timing point that matters operationally: “The Attorney General must invoke the provision permitting a delay in disclosing an incident under the Commission rule within four business days of a determination by the registrant that the registrant has experienced a material cybersecurity incident.” The guidelines accordingly tell registrants to contact the FBI early, “even beginning well before the registrant has completed its materiality analysis.”

The mechanism has been used and the filings show it. AT&T Inc. filed a Form 8-K on July 12, 2024 under Item 1.05, bearing a date of report of May 6, 2024, stating that “On May 9, 2024, and again on June 5, 2024, the U.S. Department of Justice determined that, under Item 1.05(c) of Form 8-K, a delay in providing public disclosure was warranted.” A narrower delay exists in Item 1.05(d) for registrants subject to the Federal Communications Commission’s breach rule at 47 CFR 64.2011, capped at seven business days after the notification required under that rule.

What do the SEC rules require in the annual report, and what do they say about vendors?

Item 1C of Form 10-K requires the information called for by Item 106 of Regulation S-K, 17 CFR 229.106, which is an annual description of the program rather than of any incident. Item 106(b)(1) requires the registrant to “Describe the registrant’s processes, if any, for assessing, identifying, and managing material risks from cybersecurity threats in sufficient detail for a reasonable investor to understand those processes,” addressing as applicable whether those processes are integrated into overall risk management, whether the registrant engages assessors, consultants or auditors, and — at Item 106(b)(1)(iii) — “Whether the registrant has processes to oversee and identify such risks from cybersecurity threats associated with its use of any third-party service provider.”

Item 106(b)(2) requires the registrant to describe whether risks from cybersecurity threats, “including as a result of any previous cybersecurity incidents,” have materially affected or are reasonably likely to materially affect it. Item 106(c) covers governance: paragraph (c)(1) requires a description of the board’s oversight and any responsible committee, and paragraph (c)(2) requires a description of management’s role, including which positions or committees are responsible, their relevant expertise, how they monitor prevention, detection, mitigation and remediation, and whether they report to the board.

For litigators the significance of Item 106 is that it is an annual, dated description of the very program a standard-of-care analysis will later examine, written before anyone knew which control would matter. It is discoverable, comparable year over year, and can be measured against the company rather than against a general standard — the same dynamic that makes framework adoption cut both ways, discussed in whether following the NIST Cybersecurity Framework is enough and in frameworks and benchmarking.

What does the record show about changes to the SEC cybersecurity rules as of September 2026?

As of September 15, 2026 the rule text the Securities and Exchange Commission publishes is the text it adopted. Item 1.05 appears on the Form 8-K the Securities and Exchange Commission posts at sec.gov in the language adopted on July 26, 2023 in Release Nos. 33-11216; 34-97989, published at 88 Fed. Reg. 51896 and effective September 5, 2023; the codified Item 106 at 17 CFR 229.106 carries a single source credit, 88 FR 51942 (Aug. 4, 2023), with no later amendment credit; and the Securities and Exchange Commission’s rulemaking index lists no final rule amending the public-company cybersecurity disclosure rules after that adoption. Form 20-F Item 16K and the corresponding Form 6-K requirements for foreign private issuers were adopted in the same release. What has accumulated around the rules is staff guidance and an unresolved argument about repeal.

The guidance came in two pieces. On May 21, 2024, Erik Gerding, then Director of the Division of Corporation Finance, issued a statement titled “Disclosure of Cybersecurity Incidents Determined To Be Material and Other Cybersecurity Incidents,” which reserved Item 1.05 for incidents actually determined to be material: “If a company chooses to disclose a cybersecurity incident for which it has not yet made a materiality determination, or a cybersecurity incident that the company determined was not material, the Division of Corporation Finance encourages the company to disclose that cybersecurity incident under a different item of Form 8-K (for example, Item 8.01).” The staff also published nine Compliance and Disclosure Interpretations numbered 104B.01 through 104B.09 — the first three dated December 12, 2023 and the fourth December 14, 2023, all addressed to the delay mechanism, and the last five dated June 24, 2024. That page carries a last-updated date of June 24, 2024.

The argument about repeal is live and unresolved on the public record. On May 22, 2025 the American Bankers Association, Bank Policy Institute, Securities Industry and Financial Markets Association, Independent Community Bankers of America and Institute of International Bankers petitioned the Securities and Exchange Commission to rescind Item 1.05 and the corresponding Form 6-K requirement, arguing among other things that the rule forces premature disclosure, conflicts with confidential incident reporting regimes, and has been used as extortion leverage; the petition sits on the Securities and Exchange Commission’s rulemaking petitions page under File No. 4-856. On January 13, 2026, Chairman Paul S. Atkins issued a “Statement on Reforming Regulation S-K” inviting public comment by April 13, 2026 under file number CLL-15; that statement does not mention Item 1.05 or cybersecurity.

The enforcement record over the same period has two parts. On October 22, 2024 the Securities and Exchange Commission announced settled charges against Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies Ltd. and Mimecast Limited over disclosures concerning the SolarWinds Orion compromise, with penalties of $4 million, $1 million, $995,000 and $990,000 respectively. The Securities and Exchange Commission’s own litigated action against SolarWinds Corp. and its chief information security officer, Timothy G. Brown, was filed October 30, 2023 in the Southern District of New York as No. 1:23-cv-09518-PAE, amended February 16, 2024, and largely cut back on July 18, 2024, when Judge Paul A. Engelmayer granted the defendants’ motion to dismiss in part and denied it in part, SEC v. SolarWinds Corp., 741 F. Supp. 3d 37 (S.D.N.Y. 2024). On November 20, 2025 the parties filed a joint stipulation under Federal Rule of Civil Procedure 41(a)(1)(A)(ii) dismissing the remaining litigation with prejudice “as to the conduct alleged in the Amended Complaint through the date of the filing of this Stipulation, and without costs or fees to either party.” The stipulation recites that the Commission sought dismissal “in the exercise of its discretion” and that the decision “does not necessarily reflect the Commission’s position on any other case.” SEC Litigation Release No. 26423 reports the same disposition.

Filing behavior has settled accordingly. Debevoise & Plimpton LLP, which has tracked these filings since the rules took effect, reported on May 21, 2026 that from December 18, 2023 to that date, 29 issuers had made Item 1.05 filings and 50 issuers had made Item 8.01 cybersecurity filings, with five filing under both. What an incident cost belongs to the Economic Damages Institute at economicdamagesinstitute.com rather than here.

For informational purposes only. Not legal advice, not a security assessment, and not an opinion on whether any organization’s security was reasonable.

Related

The practice area

incident conciergeorientation · not a security opinion
Happy to. Tell me roughly what happened and when it was discovered — and whether anything has been rebooted, reimaged or restored since. That last answer decides what evidence is still recoverable, so it is worth establishing before anything else.