SEC Cybersecurity Disclosure Rule
The SEC's 2023 cybersecurity disclosure rules for public companies: a Form 8-K report within four business days of determining that an incident is material, with the Attorney General delay route and later amendments, and annual disclosure of cybersecurity risk management, board oversight and management's role and expertise (Form 10-K Item 1C, Form 20-F Item 16K), with the Form 6-K duty for foreign issuers and Inline XBRL tagging. Built from the rule text in the Federal Register and the SEC staff's published interpretations.
SEC Cybersecurity Disclosure Rule is a compliance framework from United States with 5 domains and 14 controls that map to 1 other frameworks. The largest domains are Form 8-K Item 1.05: Material cybersecurity incidents – SEC Cybersecurity Disclosure Rule (7 controls), Foreign private issuers: Form 20-F Item 16K and Form 6-K – SEC Cybersecurity Disclosure Rule (2 controls), Regulation S-K Item 106(b): Risk management and strategy – SEC Cybersecurity Disclosure Rule (2 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Foreign private issuers: Form 20-F Item 16K and Form 6-K – SEC Cybersecurity Disclosure Rule
| Code | Title |
|---|---|
| sec-cybersecurity-disclosure-rule::16K | Form 20-F Item 16K: annual cybersecurity risk management, strategy and governance disclosure |
| sec-cybersecurity-disclosure-rule::6-K | Form 6-K: furnish material cybersecurity incident information made public abroad |
Form 8-K Item 1.05: Material cybersecurity incidents – SEC Cybersecurity Disclosure Rule
| Code | Title |
|---|---|
| sec-cybersecurity-disclosure-rule::1.05(a) | Form 8-K Item 1.05(a): report a material cybersecurity incident within four business days of the materiality determination |
| sec-cybersecurity-disclosure-rule::1.05(c) | Item 1.05(c): delay only on the Attorney General's written determination |
| sec-cybersecurity-disclosure-rule::1.05(d) | Item 1.05(d): delay for carriers under the FCC customer proprietary network information rule |
| sec-cybersecurity-disclosure-rule::1.05-I1 | Item 1.05 Instruction 1: determine materiality without unreasonable delay after discovery |
| sec-cybersecurity-disclosure-rule::1.05-I2 | Item 1.05 Instruction 2: state what is not yet known and amend within four business days |
| sec-cybersecurity-disclosure-rule::8.01-STAFF | Staff position: voluntary incident disclosures under Item 8.01, not Item 1.05 |
| sec-cybersecurity-disclosure-rule::FD-STAFF | Staff position: sharing incident information privately beyond the Item 1.05 filing, within Regulation FD |
Regulation S-K Item 106(b): Risk management and strategy – SEC Cybersecurity Disclosure Rule
| Code | Title |
|---|---|
| sec-cybersecurity-disclosure-rule::106(b)(1) | Item 106(b)(1): describe processes for assessing, identifying and managing material cybersecurity risks |
| sec-cybersecurity-disclosure-rule::106(b)(2) | Item 106(b)(2): describe whether cybersecurity threats have materially affected or are reasonably likely to materially affect the registrant |
Regulation S-K Item 106(c): Governance – SEC Cybersecurity Disclosure Rule
| Code | Title |
|---|---|
| sec-cybersecurity-disclosure-rule::106(c)(1) | Item 106(c)(1): board oversight of risks from cybersecurity threats |
| sec-cybersecurity-disclosure-rule::106(c)(2) | Item 106(c)(2): management's role and expertise in assessing and managing material cybersecurity risks |
Structured data – SEC Cybersecurity Disclosure Rule
| Code | Title |
|---|---|
| sec-cybersecurity-disclosure-rule::106(d) | Item 106(d), Item 16K(d), Item 1.05(b): Inline XBRL tagging of cybersecurity disclosures |
Maps to 1 other framework
Coverage is not the same as your position
This page shows what SEC Cybersecurity Disclosure Rule overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is SEC Cybersecurity Disclosure Rule and who does it apply to?
SEC Cybersecurity Disclosure Rule is a compliance framework from United States with 5 domains and 14 controls. The SEC's 2023 cybersecurity disclosure rules for public companies: a Form 8-K report within four business days of determining that an incident is material, with the Attorney General delay route and later amendments, and annual disclosure of cybersecurity risk management, board oversight and management's role and expertise (Form 10-K Item 1C, Form 20-F Item 16K), with the Form 6-K duty for foreign issuers and Inline XBRL tagging. Built from the rule text in the Federal Register and the SEC staff's published interpretations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does SEC Cybersecurity Disclosure Rule actually require?
SEC Cybersecurity Disclosure Rule has 14 controls organised across 5 domains. The largest domains are Form 8-K Item 1.05: Material cybersecurity incidents – SEC Cybersecurity Disclosure Rule (7 controls), Foreign private issuers: Form 20-F Item 16K and Form 6-K – SEC Cybersecurity Disclosure Rule (2 controls), Regulation S-K Item 106(b): Risk management and strategy – SEC Cybersecurity Disclosure Rule (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of SEC Cybersecurity Disclosure Rule do I already cover?
SEC Cybersecurity Disclosure Rule maps to 1 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (45% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement SEC Cybersecurity Disclosure Rule?
Start your SEC Cybersecurity Disclosure Rule compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about SEC Cybersecurity Disclosure Rule requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 14 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.
Get Started Free →Free forever — no credit card required