Back to Frameworks

SEC Cybersecurity Disclosure Rule

United States
vRelease Nos. 33-11216; 34-97989 (adopted 26 July 2023, 88 FR 51896); effective 5 September 2023; unamended as of 25 September 2026
5 domains
14 controls

The SEC's 2023 cybersecurity disclosure rules for public companies: a Form 8-K report within four business days of determining that an incident is material, with the Attorney General delay route and later amendments, and annual disclosure of cybersecurity risk management, board oversight and management's role and expertise (Form 10-K Item 1C, Form 20-F Item 16K), with the Form 6-K duty for foreign issuers and Inline XBRL tagging. Built from the rule text in the Federal Register and the SEC staff's published interpretations.

Verified

SEC Cybersecurity Disclosure Rule is a compliance framework from United States with 5 domains and 14 controls that map to 1 other frameworks. The largest domains are Form 8-K Item 1.05: Material cybersecurity incidents – SEC Cybersecurity Disclosure Rule (7 controls), Foreign private issuers: Form 20-F Item 16K and Form 6-K – SEC Cybersecurity Disclosure Rule (2 controls), Regulation S-K Item 106(b): Risk management and strategy – SEC Cybersecurity Disclosure Rule (2 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

Foreign private issuers: Form 20-F Item 16K and Form 6-K – SEC Cybersecurity Disclosure Rule

2 controls
Controls in the Foreign private issuers: Form 20-F Item 16K and Form 6-K – SEC Cybersecurity Disclosure Rule domain of SEC Cybersecurity Disclosure Rule — 2 controls
CodeTitle
sec-cybersecurity-disclosure-rule::16KForm 20-F Item 16K: annual cybersecurity risk management, strategy and governance disclosure
sec-cybersecurity-disclosure-rule::6-KForm 6-K: furnish material cybersecurity incident information made public abroad

Form 8-K Item 1.05: Material cybersecurity incidents – SEC Cybersecurity Disclosure Rule

7 controls
Controls in the Form 8-K Item 1.05: Material cybersecurity incidents – SEC Cybersecurity Disclosure Rule domain of SEC Cybersecurity Disclosure Rule — 7 controls
CodeTitle
sec-cybersecurity-disclosure-rule::1.05(a)Form 8-K Item 1.05(a): report a material cybersecurity incident within four business days of the materiality determination
sec-cybersecurity-disclosure-rule::1.05(c)Item 1.05(c): delay only on the Attorney General's written determination
sec-cybersecurity-disclosure-rule::1.05(d)Item 1.05(d): delay for carriers under the FCC customer proprietary network information rule
sec-cybersecurity-disclosure-rule::1.05-I1Item 1.05 Instruction 1: determine materiality without unreasonable delay after discovery
sec-cybersecurity-disclosure-rule::1.05-I2Item 1.05 Instruction 2: state what is not yet known and amend within four business days
sec-cybersecurity-disclosure-rule::8.01-STAFFStaff position: voluntary incident disclosures under Item 8.01, not Item 1.05
sec-cybersecurity-disclosure-rule::FD-STAFFStaff position: sharing incident information privately beyond the Item 1.05 filing, within Regulation FD

Regulation S-K Item 106(b): Risk management and strategy – SEC Cybersecurity Disclosure Rule

2 controls
Controls in the Regulation S-K Item 106(b): Risk management and strategy – SEC Cybersecurity Disclosure Rule domain of SEC Cybersecurity Disclosure Rule — 2 controls
CodeTitle
sec-cybersecurity-disclosure-rule::106(b)(1)Item 106(b)(1): describe processes for assessing, identifying and managing material cybersecurity risks
sec-cybersecurity-disclosure-rule::106(b)(2)Item 106(b)(2): describe whether cybersecurity threats have materially affected or are reasonably likely to materially affect the registrant

Regulation S-K Item 106(c): Governance – SEC Cybersecurity Disclosure Rule

2 controls
Controls in the Regulation S-K Item 106(c): Governance – SEC Cybersecurity Disclosure Rule domain of SEC Cybersecurity Disclosure Rule — 2 controls
CodeTitle
sec-cybersecurity-disclosure-rule::106(c)(1)Item 106(c)(1): board oversight of risks from cybersecurity threats
sec-cybersecurity-disclosure-rule::106(c)(2)Item 106(c)(2): management's role and expertise in assessing and managing material cybersecurity risks

Structured data – SEC Cybersecurity Disclosure Rule

1 controls
Controls in the Structured data – SEC Cybersecurity Disclosure Rule domain of SEC Cybersecurity Disclosure Rule — 1 controls
CodeTitle
sec-cybersecurity-disclosure-rule::106(d)Item 106(d), Item 16K(d), Item 1.05(b): Inline XBRL tagging of cybersecurity disclosures

Maps to 1 other framework

44 total controls
NIST Cybersecurity Framework 2.0
20 source controls mapped|13 target controls covered
45%

Coverage is not the same as your position

This page shows what SEC Cybersecurity Disclosure Rule overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is SEC Cybersecurity Disclosure Rule and who does it apply to?

SEC Cybersecurity Disclosure Rule is a compliance framework from United States with 5 domains and 14 controls. The SEC's 2023 cybersecurity disclosure rules for public companies: a Form 8-K report within four business days of determining that an incident is material, with the Attorney General delay route and later amendments, and annual disclosure of cybersecurity risk management, board oversight and management's role and expertise (Form 10-K Item 1C, Form 20-F Item 16K), with the Form 6-K duty for foreign issuers and Inline XBRL tagging. Built from the rule text in the Federal Register and the SEC staff's published interpretations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does SEC Cybersecurity Disclosure Rule actually require?

SEC Cybersecurity Disclosure Rule has 14 controls organised across 5 domains. The largest domains are Form 8-K Item 1.05: Material cybersecurity incidents – SEC Cybersecurity Disclosure Rule (7 controls), Foreign private issuers: Form 20-F Item 16K and Form 6-K – SEC Cybersecurity Disclosure Rule (2 controls), Regulation S-K Item 106(b): Risk management and strategy – SEC Cybersecurity Disclosure Rule (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of SEC Cybersecurity Disclosure Rule do I already cover?

SEC Cybersecurity Disclosure Rule maps to 1 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (45% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement SEC Cybersecurity Disclosure Rule?

Start your SEC Cybersecurity Disclosure Rule compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about SEC Cybersecurity Disclosure Rule requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 14 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.

Get Started Free →

Free forever — no credit card required