Back to Frameworks

SEC Cybersecurity Disclosure Rule

United States
4 domains
26 controls

SEC Cybersecurity Risk Management Strategy Governance and Incident Disclosure (Final Rule Jul 2023, Form 8-K Item 1.05 + Reg S-K Item 106).

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

Governance

5 controls
Controls in the Governance domain of SEC Cybersecurity Disclosure Rule5 controls
CodeTitle
SEC-ENFORCEMENTEnforcement Posture (SolarWinds Precedent and Beyond)
SEC-FPI-20FForeign Private Issuer Annual Disclosure on Form 20-F
SEC-INSIDER-TRADINGInsider Trading Controls During Cyber Incidents
SEC-SK-106-EBoard Oversight of Cybersecurity Risk (Item 106(c)(1))
SEC-SK-106-FManagement's Role and Expertise (Item 106(c)(2))

Material Incident Disclosure

12 controls
Controls in the Material Incident Disclosure domain of SEC Cybersecurity Disclosure Rule12 controls
CodeTitle
SEC-8K-1.05-AMaterial Cybersecurity Incident 4-Business-Day Disclosure
SEC-8K-1.05-BMateriality Determination Without Unreasonable Delay
SEC-8K-1.05-CMateriality Standard (Quantitative + Qualitative)
SEC-8K-1.05-DNational Security/Public Safety Delay (Attorney General Notification)
SEC-8K-1.05-EAmendment Obligation for Previously Undetermined Information
SEC-8K-1.05-FAggregation of Related Cybersecurity Incidents
SEC-8K-1.05-GThird-Party System Incident Disclosure
SEC-8K-1.05-HRansom Payment and Negotiation Disclosure Considerations
SEC-8K-1.05-IItem 1.05 vs Item 8.01 Voluntary Disclosure
SEC-FPI-6KForeign Private Issuer Reporting on Form 6-K
SEC-SAFE-HARBORLimited Safe Harbor for Item 1.05 Late Filings
SEC-SCA-SUB-FILERSmaller Reporting Company Extended Compliance Date

Risk Management

8 controls
Controls in the Risk Management domain of SEC Cybersecurity Disclosure Rule8 controls
CodeTitle
SEC-DEFINITIONSDefinitions: Cybersecurity Incident, Threat, Information Systems
SEC-DISC-CTRLSDisclosure Controls and Procedures Update for Cyber
SEC-REG-S-PRegulation S-P Customer Notification Coordination
SEC-REG-SCIReg SCI Coordination for Covered Entities
SEC-SK-106-ARisk Management Process Description (Item 106(b)(1))
SEC-SK-106-BEngagement of Assessors, Consultants, Auditors, Third Parties
SEC-SK-106-COversight of Third-Party Cybersecurity Risk
SEC-SK-106-GInline XBRL Tagging Requirement

Strategy

1 controls
Controls in the Strategy domain of SEC Cybersecurity Disclosure Rule1 controls
CodeTitle
SEC-SK-106-DMaterial Effects of Prior Incidents (Item 106(b)(2))

Frequently Asked Questions

What is SEC Cybersecurity Disclosure Rule?

SEC Cybersecurity Disclosure Rule is a compliance framework from United States with 4 domains and 26 controls. SEC Cybersecurity Risk Management Strategy Governance and Incident Disclosure (Final Rule Jul 2023, Form 8-K Item 1.05 + Reg S-K Item 106). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does SEC Cybersecurity Disclosure Rule have?

SEC Cybersecurity Disclosure Rule has 26 controls organised across 4 domains. The largest domains are Material Incident Disclosure (12 controls), Risk Management (8 controls), Governance (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does SEC Cybersecurity Disclosure Rule map to?

SEC Cybersecurity Disclosure Rule does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with SEC Cybersecurity Disclosure Rule compliance?

Start your SEC Cybersecurity Disclosure Rule compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about SEC Cybersecurity Disclosure Rule requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 26 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required