SEC Cybersecurity Disclosure Rule
SEC Cybersecurity Risk Management Strategy Governance and Incident Disclosure (Final Rule Jul 2023, Form 8-K Item 1.05 + Reg S-K Item 106).
SEC Cybersecurity Disclosure Rule is a compliance framework from United States with 12 domains and 30 controls. The largest domains are Disclosure Controls and Supporting Process (9 controls), Incident Disclosure: Form 8-K Item 1.05 (6 controls), Risk Management and Strategy: Regulation S-K Item 106(b) (3 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (12)
Definitions and Enforcement Posture
Definitions and Enforcement Posture
| Code | Title |
|---|---|
| SEC-DEFINITIONS | Definitions: Cybersecurity Incident, Threat, Information Systems |
| SEC-ENFORCEMENT | Enforcement Posture (SolarWinds Precedent and Beyond) |
Disclosure Controls and Supporting Process
Disclosure Controls and Supporting Process
| Code | Title |
|---|---|
| SEC-CYB-12 | Disclosure Controls Tailored to Cybersecurity |
| SEC-CYB-13 | Incident Response Plan Alignment with Disclosure Obligations |
| SEC-CYB-16 | External Counsel and Forensic Engagement Protocols |
| SEC-CYB-17 | Coordination with Other Regulatory Notifications |
| SEC-CYB-18 | Historical Incident Tracking and Repeat Disclosure Analysis |
| SEC-CYB-19 | Training for Material Cybersecurity Disclosure Decision Makers |
| SEC-CYB-20 | Recordkeeping for Cybersecurity Materiality Determinations |
| SEC-REG-S-P | Regulation S-P Customer Notification Coordination |
| SEC-REG-SCI | Reg SCI Coordination for Covered Entities |
Foreign Private Issuers
Foreign Private Issuers
| Code | Title |
|---|---|
| SEC-CYB-11 | Foreign Private Issuer Disclosures on Form 6-K and 20-F |
Governance Disclosure
| Code | Title |
|---|---|
| SECCYB-3 | Governance (Item 106(c)) - Board and Management Oversight |
Governance: Regulation S-K Item 106(c)
Governance: Regulation S-K Item 106(c)
| Code | Title |
|---|---|
| SEC-CYB-08 | Board Oversight of Cybersecurity Risks |
| SEC-CYB-09 | Management Role and Expertise in Cybersecurity |
Incident Disclosure
| Code | Title |
|---|---|
| SECCYB-1 | Material Cybersecurity Incident 4-Business-Day Disclosure (Item 1.05) |
Incident Disclosure: Form 8-K Item 1.05
Incident Disclosure: Form 8-K Item 1.05
| Code | Title |
|---|---|
| SEC-CYB-01 | Material Cybersecurity Incident Determination |
| SEC-CYB-02 | Form 8-K Item 1.05 Filing within Four Business Days |
| SEC-CYB-03 | National Security or Public Safety Delay Coordination |
| SEC-CYB-04 | Updating Disclosures for Material Information Not Yet Determined |
| SEC-CYB-05 | Related Occurrences and Aggregation |
| SEC-SAFE-HARBOR | Limited Safe Harbor for Item 1.05 Late Filings |
Insider Trading Controls
Insider Trading Controls
| Code | Title |
|---|---|
| SEC-CYB-14 | Insider Trading Window Considerations for Cyber Incidents |
Process Integration
| Code | Title |
|---|---|
| SECCYB-4 | Disclosure Process Integration and Materiality Workflow |
Risk Management Disclosure
| Code | Title |
|---|---|
| SECCYB-2 | Risk Management Processes (Item 106(b)) |
Risk Management and Strategy: Regulation S-K Item 106(b)
Risk Management and Strategy: Regulation S-K Item 106(b)
| Code | Title |
|---|---|
| SEC-CYB-06 | Risk Management and Strategy Disclosure |
| SEC-CYB-07 | Material Effects of Cybersecurity Threats Disclosure |
| SEC-CYB-15 | Third Party Service Provider Cybersecurity Risk Oversight |
Structured Data and Filing Mechanics
Structured Data and Filing Mechanics
| Code | Title |
|---|---|
| SEC-CYB-10 | Periodic Filing Inline XBRL Tagging |
| SEC-SCA-SUB-FILER | Smaller Reporting Company Extended Compliance Date |
What is SEC Cybersecurity Disclosure Rule and who does it apply to?
SEC Cybersecurity Disclosure Rule is a compliance framework from United States with 12 domains and 30 controls. SEC Cybersecurity Risk Management Strategy Governance and Incident Disclosure (Final Rule Jul 2023, Form 8-K Item 1.05 + Reg S-K Item 106). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does SEC Cybersecurity Disclosure Rule actually require?
SEC Cybersecurity Disclosure Rule has 30 controls organised across 12 domains. The largest domains are Disclosure Controls and Supporting Process (9 controls), Incident Disclosure: Form 8-K Item 1.05 (6 controls), Risk Management and Strategy: Regulation S-K Item 106(b) (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of SEC Cybersecurity Disclosure Rule do I already cover?
SEC Cybersecurity Disclosure Rule does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement SEC Cybersecurity Disclosure Rule?
Start your SEC Cybersecurity Disclosure Rule compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about SEC Cybersecurity Disclosure Rule requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 30 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required