Back to Frameworks

SEC Cybersecurity Disclosure Rule

United States
12 domains
30 controls

SEC Cybersecurity Risk Management Strategy Governance and Incident Disclosure (Final Rule Jul 2023, Form 8-K Item 1.05 + Reg S-K Item 106).

Verified

SEC Cybersecurity Disclosure Rule is a compliance framework from United States with 12 domains and 30 controls. The largest domains are Disclosure Controls and Supporting Process (9 controls), Incident Disclosure: Form 8-K Item 1.05 (6 controls), Risk Management and Strategy: Regulation S-K Item 106(b) (3 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (12)

Definitions and Enforcement Posture

2 controls

Definitions and Enforcement Posture

Controls in the Definitions and Enforcement Posture domain of SEC Cybersecurity Disclosure Rule2 controls
CodeTitle
SEC-DEFINITIONSDefinitions: Cybersecurity Incident, Threat, Information Systems
SEC-ENFORCEMENTEnforcement Posture (SolarWinds Precedent and Beyond)

Disclosure Controls and Supporting Process

9 controls

Disclosure Controls and Supporting Process

Controls in the Disclosure Controls and Supporting Process domain of SEC Cybersecurity Disclosure Rule9 controls
CodeTitle
SEC-CYB-12Disclosure Controls Tailored to Cybersecurity
SEC-CYB-13Incident Response Plan Alignment with Disclosure Obligations
SEC-CYB-16External Counsel and Forensic Engagement Protocols
SEC-CYB-17Coordination with Other Regulatory Notifications
SEC-CYB-18Historical Incident Tracking and Repeat Disclosure Analysis
SEC-CYB-19Training for Material Cybersecurity Disclosure Decision Makers
SEC-CYB-20Recordkeeping for Cybersecurity Materiality Determinations
SEC-REG-S-PRegulation S-P Customer Notification Coordination
SEC-REG-SCIReg SCI Coordination for Covered Entities

Foreign Private Issuers

1 controls

Foreign Private Issuers

Controls in the Foreign Private Issuers domain of SEC Cybersecurity Disclosure Rule1 controls
CodeTitle
SEC-CYB-11Foreign Private Issuer Disclosures on Form 6-K and 20-F

Governance Disclosure

1 controls
Controls in the Governance Disclosure domain of SEC Cybersecurity Disclosure Rule1 controls
CodeTitle
SECCYB-3Governance (Item 106(c)) - Board and Management Oversight

Governance: Regulation S-K Item 106(c)

2 controls

Governance: Regulation S-K Item 106(c)

Controls in the Governance: Regulation S-K Item 106(c) domain of SEC Cybersecurity Disclosure Rule2 controls
CodeTitle
SEC-CYB-08Board Oversight of Cybersecurity Risks
SEC-CYB-09Management Role and Expertise in Cybersecurity

Incident Disclosure

1 controls
Controls in the Incident Disclosure domain of SEC Cybersecurity Disclosure Rule1 controls
CodeTitle
SECCYB-1Material Cybersecurity Incident 4-Business-Day Disclosure (Item 1.05)

Incident Disclosure: Form 8-K Item 1.05

6 controls

Incident Disclosure: Form 8-K Item 1.05

Controls in the Incident Disclosure: Form 8-K Item 1.05 domain of SEC Cybersecurity Disclosure Rule6 controls
CodeTitle
SEC-CYB-01Material Cybersecurity Incident Determination
SEC-CYB-02Form 8-K Item 1.05 Filing within Four Business Days
SEC-CYB-03National Security or Public Safety Delay Coordination
SEC-CYB-04Updating Disclosures for Material Information Not Yet Determined
SEC-CYB-05Related Occurrences and Aggregation
SEC-SAFE-HARBORLimited Safe Harbor for Item 1.05 Late Filings

Insider Trading Controls

1 controls

Insider Trading Controls

Controls in the Insider Trading Controls domain of SEC Cybersecurity Disclosure Rule1 controls
CodeTitle
SEC-CYB-14Insider Trading Window Considerations for Cyber Incidents

Process Integration

1 controls
Controls in the Process Integration domain of SEC Cybersecurity Disclosure Rule1 controls
CodeTitle
SECCYB-4Disclosure Process Integration and Materiality Workflow

Risk Management Disclosure

1 controls
Controls in the Risk Management Disclosure domain of SEC Cybersecurity Disclosure Rule1 controls
CodeTitle
SECCYB-2Risk Management Processes (Item 106(b))

Risk Management and Strategy: Regulation S-K Item 106(b)

3 controls

Risk Management and Strategy: Regulation S-K Item 106(b)

Controls in the Risk Management and Strategy: Regulation S-K Item 106(b) domain of SEC Cybersecurity Disclosure Rule3 controls
CodeTitle
SEC-CYB-06Risk Management and Strategy Disclosure
SEC-CYB-07Material Effects of Cybersecurity Threats Disclosure
SEC-CYB-15Third Party Service Provider Cybersecurity Risk Oversight

Structured Data and Filing Mechanics

2 controls

Structured Data and Filing Mechanics

Controls in the Structured Data and Filing Mechanics domain of SEC Cybersecurity Disclosure Rule2 controls
CodeTitle
SEC-CYB-10Periodic Filing Inline XBRL Tagging
SEC-SCA-SUB-FILERSmaller Reporting Company Extended Compliance Date

What is SEC Cybersecurity Disclosure Rule and who does it apply to?

SEC Cybersecurity Disclosure Rule is a compliance framework from United States with 12 domains and 30 controls. SEC Cybersecurity Risk Management Strategy Governance and Incident Disclosure (Final Rule Jul 2023, Form 8-K Item 1.05 + Reg S-K Item 106). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does SEC Cybersecurity Disclosure Rule actually require?

SEC Cybersecurity Disclosure Rule has 30 controls organised across 12 domains. The largest domains are Disclosure Controls and Supporting Process (9 controls), Incident Disclosure: Form 8-K Item 1.05 (6 controls), Risk Management and Strategy: Regulation S-K Item 106(b) (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of SEC Cybersecurity Disclosure Rule do I already cover?

SEC Cybersecurity Disclosure Rule does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement SEC Cybersecurity Disclosure Rule?

Start your SEC Cybersecurity Disclosure Rule compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about SEC Cybersecurity Disclosure Rule requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 30 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required