Law / United States

SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05)

17 CFR 229.106; 17 CFR 249.308 (Form 8-K Item 1.05)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 18 December 2023.

A vulnerability and incident reporting rule binding private bodies.

As of 18 September 2026.

What it requires

  • This instrument reaches your organization only if it is an Securities and Exchange Commission (SEC) reporting company that files on the domestic forms (a United States public company, or an issuer that has registered a class of securities with the Securities and Exchange Commission and files current reports on Form 8-K); a foreign private issuer owes the same two duties on Form 6-K and in item 16K of Form 20-F instead. The activities flagged below are a proxy for the kind of company likely to carry that status and do not by themselves establish it.
  • If your organization is an SEC reporting company, determine, without unreasonable delay after you discover a cybersecurity incident, whether the incident is material, and if it is, file a Form 8-K under Item 1.05 within four business days after you make that determination.
  • Separately, describe in your annual report, under Regulation S-K Item 106, your processes for assessing, identifying and managing material cybersecurity risks and your board's and management's oversight of those risks.
  • An incident disclosure described above may be delayed where the United States Attorney General determines it would pose a substantial risk to national security or public safety and notifies the Commission of that determination in writing; the delay is a capped exception and not a second reporting duty on its own timeline.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

An Securities and Exchange Commission (SEC) reporting company must describe, in its annual report under Regulation S-K Item 106, its processes for assessing and managing cybersecurity risk. It must also describe its board's and management's oversight of that risk. This duty applies beginning with annual reports for fiscal years ending on or after December 15, 2023. Under Item 1.05 of Form 8-K, the same company must determine, without unreasonable delay after discovering a cybersecurity incident, whether the incident is material.

If the incident is material, the company must file a Form 8-K describing it within four business days of that determination. The United States Attorney General may authorize a delay of up to 30 days, and a further 30 days, where disclosure would pose a substantial risk to national security or public safety, and in extraordinary circumstances a final 60 days where the continuing risk is to national security, up to 120 days in total.

Registrants other than smaller reporting companies had to comply with Item 1.05 from December 18, 2023, and smaller reporting companies from June 15, 2024.

When LexLint raises it

  • distributes_software_product
  • ships_mobile_app

Read the law

Electronic Code of Federal Regulations
17 CFR 229.106, with Item 1.05's own text from the SEC's official Form 8-K and the effective and compliance dates from the Commission's 2023 adopting release, 88 FR 51896

Back to the example  ·  Lint your app