SEC Cybersecurity Disclosure Rules

Regulation United States (federal) · 2023

SEC rules require public companies to disclose a material cybersecurity incident on Form 8-K Item 1.05 within four business days of determining materiality, and to describe their risk management processes and board oversight annually in Form 10-K Item 1C. It is the regime that made a security incident a securities-disclosure event, and its reach extends well past registrants to every vendor whose outage could be material to one.

Horizontal regime. It binds companies by what they do with data, software or customers, not by the sector they sit in. The industries below are where it creates specific, additional duties — not the limit of who has to comply.

Countries

Where this binds. Each links to the providers apis.io has catalogued there.

Regions

Industries

Each links to that industry as a scored cohort — so the question "how ready is this sector for the regime that governs it?" becomes one you can actually look at.