Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

SEC Cybersecurity Rule Compliance

The Security and Exchanges Commission (SEC) recently published its Final Rule: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure that will force publicly traded companies to adjust practices for ongoing cybersecurity governance and incident response. The SEC, Generally Accepted Accounting Principles (GAAP) and International Financial Reporting Standards (IFRS) lack specificity in defining the criteria for materiality. Therefore, organizations generally have leeway to define it on their own. The lack of authoritative definition for materiality is not unique, since the concept of risk appetite, risk tolerance and risk threshold also suffer from nebulous definitions by statutory and regulatory authorities.

SEC Cybersecurity Rule  documentation template
Key Takeaways - SEC Cybersecurity Rule Compliance
  • The SEC Cybersecurity Disclosure Rule (effective December 2023) requires publicly traded companies to disclose material cybersecurity incidents on Form 8-K within four business days.
  • Annual reporting on Form 10-K must describe the company's cybersecurity risk management processes, strategy and governance, including board oversight.
  • Materiality is determined using existing standards. The SEC did not create a new threshold. Companies must apply traditional materiality analysis to cyber incidents.
  • The rule applies to SEC registrants, including foreign private issuers. Smaller reporting companies got a delayed implementation timeline.
  • Compliance requires cross-functional coordination between cybersecurity, legal, finance and the board to ensure timely and accurate disclosures.
Overview

How Do You Determine SEC Cybersecurity Rule Materiality?

For an item to be considered material, the control deficiency, risk, threat or incident (singular or a combination) generally must meet one, or more, of the following criteria where the potential financial impact is:

  • ≥ 5% of pre-tax income;
  • ≥ 0.5% of total assets;
  • ≥ 1% of total equity (shareholder value); and/or
  • ≥ 0.5% of total revenue.

This materiality determination can be visualized with this infographic with the callout for publicly traded companies having a requirement to publicly disclose material cybersecurity incidents:

Cybersecurity Materiality
SEC Cybersecurity Rule Definitions

Material Risk vs Material Threat vs Material Incident

With evolving regulatory requirements for public disclosures, it is increasingly important to understand the nuances between material weakness vs material risk vs material threat vs material incident, since they have specific meanings:

SEC Cybersecurity Rule - Material Weakness

A material weakness is a deficiency, or a combination of deficiencies, in an organization's cybersecurity and/or data privacy controls (across its supply chain) where it is probable that reasonable threats will not be prevented or detected in a timely manner that directly, or indirectly, affects assurance that the organization can adhere to its stated risk tolerance.

  • When there is an existing deficiency (e.g., control deficiency) that poses a material impact, that is a material weakness (e.g., inability to maintain access control, lack of situational awareness to enable the timely identification and response to incidents, lacking pre-production control validation testing, etc.).
  • A material weakness will be identified as part of a gap assessment, audit or assessment as a finding due to one or more control deficiencies.
  • A material weakness should be documented in an organization's Plan of Action & Milestones (POA&M), risk register, or similar tracking mechanism used for remediation purposes.
Material Control

SEC Cybersecurity Rule - Material Risk

A risk is a situation where (1) someone or something valued is exposed to danger, harm or loss (noun); or (2) to expose someone or something valued to danger, harm or loss (verb).

  • When there is an identified risk that poses a material impact, that is a material risk.
  • A material risk is a quantitative or qualitative scenario where the exposure to danger, harm or loss has a material impact (e.g., potential class action lawsuit, death related to product usage, etc.)
  • A material risk should be identified and documented in an organization's "risk catalog" that chronicles the organization's relevant and plausible risks.
Material Risk

SEC Cybersecurity Rule - Material Threat

A threat is (1) a person or thing likely to cause damage or danger (noun); or (2) to indicate impending damage or danger (verb).

  • When there is an identified threat that poses a material impact, that is a material threat.
  • A material threat is a vector that causes damage or danger that has a material impact (e.g., poorly governed Artificial Intelligence (AI) initiatives, nation state hacking operations, dysfunctional internal management practices, etc.).
  • A material threat should be identified and documented in an organization's "threat catalog" that chronicles the organization's relevant and plausible threats.
Material Threat

SEC Cybersecurity Rule - Material Incident

An incident is an occurrence that actually or potentially (1) jeopardizes the Confidentiality, Integrity, Availability or Safety (CIAS) of a system, application, service or the data that it processes, stores and/or transmits; or (2) constitutes a violation or imminent threat of violation of an organization's policies, procedures or acceptable use practices.

  • When there is an incident that poses a material impact, that is a material incident.
  • A material incident is an occurrence that does or has the potential to (1) affect the CIAS of systems, applications, services or data; or (2) a violation of organizational practices that has a material impact (e.g., malware on sensitive/regulated systems, emergent AI actions, illegal conduct, business interruption, etc.).
  • A material incident should be identified and documented in an organization's Incident Response Plan (IRP) that chronicles the organization's relevant and plausible incidents, so there are appropriate steps in place to identify, respond to and recover from such incidents.
Material Incident
Cybersecurity Risk Management

SEC Final Rule Cybersecurity Risk Management

In collaboration with the Secure Controls Framework (SCF), ComplianceForge authored a white paper on this subject of aligning risk appetite, risk tolerance and risk thresholds with your organization's strategic, operational and tactical business planning activities. You'll find the SEC Final Rule discussed in the document, as well as how to address cybersecurity governance from a strategic, operational and tactical perspective.

Practitioner's Guide to Risk Management example
Common Questions

Frequently-Asked Questions

Here are answers to common questions about the SEC cybersecurity disclosure rule:

What is the SEC cybersecurity disclosure rule?
The SEC cybersecurity disclosure rule, adopted July 26, 2023, requires public companies to disclose material cybersecurity incidents under Item 1.05 of Form 8-K and to describe their cybersecurity risk management, strategy and governance annually under Item 106 of Regulation S-K in Form 10-K. Foreign private issuers make comparable disclosures on Forms 6-K and 20-F. Annual disclosures began with fiscal years ending on or after December 15, 2023.
When must a material cybersecurity incident be reported on Form 8-K?
A company must file under Item 1.05 of Form 8-K generally within four business days after it determines that a cybersecurity incident is material, and it must make that materiality determination without unreasonable delay after discovery. The filing clock starts at the materiality decision, not at discovery. Disclosure can be delayed if the U.S. Attorney General determines it would pose a substantial risk to national security or public safety, initially for up to 30 days with limited extensions.
What does Item 106 of Regulation S-K require?
Item 106 requires a company's Form 10-K to describe its processes, if any, for assessing, identifying and managing material risks from cybersecurity threats, and whether those risks have materially affected or are reasonably likely to materially affect the business. It also requires a description of the board of directors' oversight of cybersecurity risk and management's role and expertise in assessing and managing material cybersecurity risks. These are disclosures about governance and process, not a list of required controls.
Is the SEC cybersecurity disclosure rule still in effect in 2026?
Yes, form 8-K Item 1.05 and Regulation S-K Item 106 remain in effect in 2026. In May 2025, banking and securities industry groups, including SIFMA and the Bank Policy Institute, petitioned the SEC to rescind the Form 8-K incident disclosure requirement, and some of the same groups urged changes again after SEC Chairman Atkins sought public comment on reforming Regulation S-K in January 2026. Neither step changes the rule, so public companies should keep their materiality and disclosure processes in place.
What documentation supports SEC cybersecurity rule compliance?
Because Item 106 asks companies to describe their cybersecurity risk management processes and governance, the most useful documentation is a written risk management program, an incident response plan that defines how incidents are escalated for a materiality decision, and records of board and management oversight. ComplianceForge's Risk Management Program (RMP) and Integrated Incident Response Program (IIRP) give you editable templates for those processes, and your legal and finance teams can align them with your disclosure controls.