The SEC requires public companies to file a Form 8-K within four business days of determining that a cybersecurity incident is material, and to disclose annually how they identify, assess, and manage cyber risk. These two obligations, Item 1.05 and Item 106, now anchor federal cybersecurity disclosure. The immediate task for compliance teams is to document a defensible materiality process and build a cross-functional workflow that gets incidents from detection to filing without missing the clock.
TL;DR:
- Companies must establish a clear process for assessing and documenting materiality within a short, defined timeframe, using decision owners and structured decision trees.
- The four-business-day filing window begins only after a formal materiality determination, not at incident discovery, with delays caused by unprepared internal processes or external vendor responses.
- SEC disclosure requirements include detailed but non-technical descriptions of processes, oversight, and governance, avoiding specific technical tools or vendor names and focusing on outcomes.
- Smaller reporting companies have an extra 180 days before incident reporting becomes mandatory, but XBRL tagging deadlines are one year behind initial disclosures, requiring early testing.
- A delay beyond four days is only possible if the U.S. Attorney General issues a written determination, stating that immediate disclosure would threaten national security or public safety.
Table of Contents
- Sec Cybersecurity Rules: Scope, Filings, and Structured Data
- Incident Reporting Mechanics: Materiality, the Clock, and Amendments
- What Item 106 Requires in Your Annual Report
- Board Oversight and Management Roles: What Governance Disclosure Covers
- Compliance Dates, SRC Timelines, and Inline XBRL Readiness
- The Narrow Attorney General Delay: How It Actually Works
- Building the Gap Assessment: A Compliance Checklist
- Making Cybersecurity Disclosure Part of Your SEC Control Environment
- Closing SEC Cybersecurity Compliance Gaps With Secure Techies
- Sources
- FAQ
Sec Cybersecurity Rules: Scope, Filings, and Structured Data
The SEC's final rules on cybersecurity risk management, strategy, governance, and incident disclosure create two distinct disclosure tracks, and confusing them is one of the most common mistakes counsel makes. Item 1.05 of Form 8-K governs incident disclosure: when a cybersecurity event turns out to be material, the company must say so, fast. Item 106 of Regulation S-K governs the annual narrative: how the company manages cyber risk as an ongoing matter, filed in Form 10-K (or the equivalent disclosure in Form 20-F for foreign private issuers).

The rules reach domestic registrants, foreign private issuers, and business development companies. Smaller reporting companies (SRCs) got a phased runway. They became subject to Item 106 annual reporting requirements at the same general schedule as larger filers, but received an additional 180 days before Item 1.05's incident reporting clock applied to them, giving smaller finance and legal teams extra runway to build the process before the four-day deadline became binding.
Structured data compliance is the part many teams underestimate. The rules require Inline XBRL tagging of the disclosures, both the annual Item 106 narrative and the incident-specific Item 1.05 filings, so the information is machine-readable for investors and data aggregators. Tagging deadlines followed roughly a year behind the initial narrative compliance dates, which sounds generous until you realize XBRL tagging is usually the last thing anyone tests before a live filing.
None of this asks companies to adopt a specific technical framework. The SEC's own small-business compliance guide makes clear that registrants describe their own processes, not a mandated standard like NIST or ISO 27001. That flexibility is useful, but it also means there is no fill-in-the-blank template. Legal and security teams have to build the narrative from what the company actually does.
Incident Reporting Mechanics: Materiality, the Clock, and Amendments
Materiality under Item 1.05 is not a technical severity score. It follows the same reasonable-investor standard that governs materiality everywhere else in securities law: would a reasonable investor consider this incident important to an investment decision, or would it significantly alter the total mix of available information? A ransomware event that encrypts a file server is not automatically material. A breach that exposes customer financial data, disrupts a revenue-generating system for days, or triggers a wave of regulatory inquiries usually is.
The four-business-day clock is where most companies get into trouble, and it does not start at discovery. It starts when the company determines the incident is material, and the SEC's small-business guide is explicit that this determination has to happen "without unreasonable delay." That phrase is doing a lot of legal work. You cannot slow-walk the materiality call to buy time. If your internal process takes three weeks to convene the right people, that delay itself becomes a compliance risk. This is exactly why the SEC's press release on the final rules frames the entire rulemaking around giving investors consistent, timely information, not information delivered at the company's convenience.
Common operational delays that regulators will not view sympathetically:
- Waiting for a full forensic investigation to conclude before assessing materiality.
- Routing the decision through a committee that only meets monthly.
- Treating "we're still assessing scope" as a reason to postpone the materiality call itself, rather than disclosing what is known and amending later.
- Letting outside counsel or a vendor drive the timeline instead of an internal decision owner.
Once the Form 8-K is filed, the obligation is not necessarily finished. If the initial disclosure lacked information, because scope, financial impact, or remediation status was still unclear, the company must file an amendment once that information becomes available. This is where the rule's flexibility actually helps: you are not required to have every fact nailed down on day four, but you are required to update the record as facts emerge.
Materiality factors examiners and investors will look for include the financial impact of remediation and lost business, operational disruption to core systems, exposure to litigation or regulatory penalties, and effects that flow through third-party systems the company relies on for revenue or data processing.
Pro Tip: Build your materiality assessment around a short written checklist with pre-assigned decision owners, not an ad hoc meeting. A documented decision tree with named roles and time-stamped sign-offs is your best evidence that you moved "without unreasonable delay" if regulators ever ask.

What Item 106 Requires in Your Annual Report
Item 106 does not hand you a checklist so much as a set of questions a reasonable investor would want answered. The regulatory text at 17 CFR § 229.106 lists non-exclusive disclosure items registrants should address based on their own facts and circumstances, meaning the SEC expects tailored narrative, not boilerplate.
At minimum, your Item 106 disclosure should describe:
- Your processes for assessing, identifying, and managing material cybersecurity risks, including whether those processes are integrated into your broader enterprise risk management program.
- Whether you engage third parties (assessors, consultants, auditors) as part of those processes.
- How you oversee and identify risks tied to third-party service providers and vendors, an area regulators increasingly treat as a gap in otherwise strong programs.
- Whether risks from previous cybersecurity incidents, including ones that individually were not material, have materially affected or are reasonably likely to materially affect your business strategy, results of operations, or financial condition.
Balancing qualitative and quantitative disclosure is where legal drafting earns its keep. Investors want enough specificity to judge whether your risk management is credible, but Item 106 is not a place to disclose network architecture, patch cadence, or the specific tools protecting your environment. The SEC's adopting release confirms the rule is about giving investors insight into your process and its business impact, not a technical audit.
Practical drafting guidance: describe outcomes and governance, not mechanisms. "We conduct periodic third-party risk assessments and require vendor contractual security commitments" tells an investor what they need to know. Naming your specific endpoint detection platform or firewall vendor tells an attacker what they need to know, and adds nothing to an investor's understanding of your risk posture.
Board Oversight and Management Roles: What Governance Disclosure Covers
Governance disclosure under Item 106 splits into two halves: what the board does, and what management does. On the board side, registrants describe which committee or body oversees cybersecurity risk (often audit committee, sometimes a dedicated risk or technology committee), how often that oversight body receives updates, and how information about cyber risk actually flows up to the board in practice, not just on paper.
On the management side, the disclosure covers who inside the company is responsible for assessing and managing cybersecurity risk, their relevant expertise, and how they're informed about and monitor the prevention, detection, mitigation, and remediation of incidents. This is where a lot of draft disclosures either say too little or say too much. Vague language ("management monitors cyber risk") tells investors nothing. Overly granular language risks handing a roadmap to an adversary.
One notable decision from the adopting release deserves specific mention: the SEC considered, and ultimately did not adopt, a requirement to disclose whether any board member has specific cybersecurity expertise. Registrants are not obligated to make that disclosure, even though many voluntarily do.
Drafting guardrails worth internalizing: describe the reporting cadence and escalation structure, not the specific technical tools or vendor names involved in detection and response. Say "the chief information security officer briefs the audit committee quarterly and immediately following any potentially material incident," not the name of your SIEM platform or the specific playbook your incident response team follows. The goal is investor confidence in the process, not an operations manual for attackers.
Compliance Dates, SRC Timelines, and Inline XBRL Readiness
The rules did not land on every registrant at once. Larger reporting companies faced Item 106 annual disclosure requirements first, with smaller reporting companies given additional time before the same annual reporting obligation applied. Item 1.05 incident reporting followed a similar staggered approach, with smaller reporting companies again receiving extra runway, roughly 180 days, before the four-business-day clock became mandatory for them.
Inline XBRL tagging trailed a year behind the initial narrative and incident disclosure compliance dates, according to the SEC's fact sheet on the final rules. That gap exists for a reason: tagging is a technical, often outsourced process, and the SEC recognized that filers needed time to build it into their disclosure controls before it became mandatory. The problem is that "a year from now" has a way of becoming "next week" faster than compliance calendars expect.
Readiness steps worth locking down now:
- Confirm with your filing agent or XBRL vendor whether they can tag Item 1.05 narrative blocks on short notice, not just scheduled 10-K disclosures.
- Run a test submission through EDGAR with a sample Item 1.05 filing before you ever need to file one for real.
- Add XBRL tagging sign-off to your disclosure controls checklist, alongside legal review and finance sign-off.
- Calendar every SRC-specific extension date separately from the general compliance date; treating them as identical is a common scheduling error.
Pro Tip: Do not wait for a live incident to discover your XBRL vendor cannot turn around a tagged Item 1.05 filing inside four business days. Test the full pipeline, drafting to tagging to EDGAR submission, on a dry run this quarter.
The Narrow Attorney General Delay: How It Actually Works
There is a limited escape valve built into Item 1.05, and it is far narrower than many companies assume. The SEC allows delayed disclosure only if the U.S. Attorney General determines, in writing, that immediate disclosure would pose a substantial risk to national security or public safety, and communicates that determination to the SEC. This detail comes directly from the SEC's press release announcing the final rules.
This is not a general hardship exception, and it is not something a company can invoke on its own judgment. It requires an affirmative written determination from the Attorney General's office, not merely an ongoing law enforcement investigation or a company's preference for discretion. Further delay beyond the initial period may be considered, but only through continued DOJ coordination and SEC involvement, not by a company simply staying quiet.
If your incident response plan anticipates ever seeking this delay, coordination with the FBI needs to start early, not after you have already blown past the four-day clock. The FBI's guidance to victims of cyber incidents walks through how companies should engage law enforcement and document the request. Keep a clear record: who contacted DOJ or the FBI, when, what was requested, and what response was received. That record is what protects you if regulators later ask why disclosure was delayed.
Building the Gap Assessment: A Compliance Checklist
Turning these rules into an operational program comes down to five concrete steps.
- Document a materiality decision process with named owners. Assign specific roles (legal, security, finance, an executive sponsor) to the materiality call, set a decision service-level agreement, such as 24 to 48 hours from significant-incident escalation, and define what counts as sufficient evidence to make the call.
- Map the incident-to-filing workflow end to end. From detection, to internal escalation, to materiality determination, to legal drafting, to XBRL tagging, to EDGAR submission, write down who touches the filing at each stage and how long each stage should take within your four-business-day window.
- Inventory third-party systems and vendor contracts. Item 106 requires disclosure of vendor risk management, and you cannot describe a process you have not actually mapped. Check whether vendor contracts obligate prompt breach notification to you, since a delayed vendor notice can eat into your own materiality clock.
- Validate XBRL tagging capability before you need it. Get a written commitment from your filing vendor on turnaround time for a same-week Item 1.05 tagging job, not just routine annual filings.
- Retain the paper trail. Keep incident response logs, materiality decision memos, board and committee minutes referencing cyber oversight, and legal analysis supporting every disclosure decision. This documentation is your primary defense if the SEC ever questions your timing or your judgment.
Organizations frequently lack a documented, evidence-based decision tree with assigned service-level timelines for exactly this kind of call, and that gap is what turns a defensible four-day filing into a regulatory inquiry about "unreasonable delay." A structured approach to the filing clock closes that gap before it becomes a problem.
Pro Tip: Run a tabletop exercise simulating a material incident discovered on a Friday afternoon. If your process cannot produce a materiality decision and a drafted 8-K by the following Wednesday, you have found your gap before a regulator does.
Making Cybersecurity Disclosure Part of Your SEC Control Environment
Too many companies still treat cyber disclosure as a legal drafting exercise that happens after an incident is already contained. That is backwards. The four-day clock rewards companies that built the decision infrastructure before they needed it, not after.
Integrating cyber reporting into your existing disclosure controls, the same rigor you apply to financial close, matters for auditability and for investor confidence. Continuous monitoring shortens the gap between detection and a defensible materiality call, which is the real bottleneck in this rule. Security, finance, and legal cannot operate as separate silos here. Align them around one testable process, and the four-day clock stops being a threat and starts being a routine control.
— Alex
Closing SEC Cybersecurity Compliance Gaps With Secure Techies
This service offers support to help businesses be ready to comply with the SEC's four-day clock requirements. Where the checklist above calls for documented vendor risk management, tested incident escalation, and evidence you can hand to regulators, Compliance & Security Audits from Securetechie map directly onto those Item 106 and Item 1.05 requirements, giving Southern California businesses a structured way to find the gaps before a filing deadline finds them first.

Beyond the audit itself, Managed Cybersecurity Solutions provide the 24/7 monitoring that shortens the detection-to-decision window this rule is built around, and Backup & Disaster Recovery support the operational resilience regulators expect you to describe in your annual Item 106 narrative. Securetechie's local Southern California team works with flat-rate, transparent pricing and no long-term contracts, so a readiness review does not turn into an open-ended engagement. If your materiality process, vendor inventory, or XBRL testing plan has gaps, consider requesting a gap assessment service and get a clear, prioritized punch list before your next 10-K or a live incident forces the issue.
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.
Sources
- Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure — SEC (Final rule, Release Nos. 33-11216)
- § 229.106 (Item 106) Cybersecurity — e-CFR / LII
- FBI guidance to victims of cyber incidents on SEC reporting requirements — FBI
FAQ
What is the new SEC rule for cybersecurity?
The rule requires public companies to disclose material cybersecurity incidents on Form 8-K, typically within four business days of determining materiality, and to describe their cybersecurity risk management, strategy, and governance annually under Item 106 of Regulation S-K. It applies to domestic registrants, foreign private issuers, and business development companies, with phased timelines for smaller reporting companies.
What are the SEC reporting requirements for cybersecurity incidents?
Once a company determines an incident is material, it must file an Item 1.05 Form 8-K describing the incident's nature, scope, and timing, along with its material impact or reasonably likely material impact, within four business days. If information is incomplete at filing, the company must amend the disclosure once more facts are known.
What are the new cybersecurity laws in the USA affecting public companies?
At the federal securities level, the SEC's disclosure rules are the primary framework, but they interact with other regimes, including state breach notification laws, FINRA cybersecurity guidance for broker-dealers, and, for companies with EU operations or customers, GDPR breach notification obligations. Compliance teams typically need a single incident response plan that can satisfy all of these simultaneously rather than separate parallel processes.
Can a company delay disclosing a material cybersecurity incident?
Only through a narrow exception: the U.S. Attorney General must make a written determination that immediate disclosure poses a substantial risk to national security or public safety, and communicate that to the SEC, as described in the SEC's press release on the final rules. This is not a routine extension a company can request on its own.
Does Securetechie help with SEC cybersecurity compliance?
Securetechie's Compliance & Security Audits service is built to help Southern California businesses identify gaps against frameworks like SEC disclosure rules, HIPAA, and SOC 2. Current pricing for compliance engagements is available directly on the Securetechie site rather than published here.
