← Back to all briefings
Compliance 5 min read Published Updated Credibility 40/100

Compliance Briefing — SEC Adopts Final Cybersecurity Disclosure Rules

On 26 July 2023 the U.S. SEC adopted rules requiring public companies to disclose material cybersecurity incidents within four business days and to detail cyber risk governance in annual reports.

Single-point timeline showing the publication date sized by credibility score.
Publication date and credibility emphasis for this briefing. Source data (JSON)

The U.S. Securities and Exchange Commission finalized cybersecurity disclosure rules on 26 July 2023. Registrants must file an Item 1.05 Form 8-K within four business days of determining that a cyber incident is material, describing the nature, scope, timing, and likely impact. Annual reports on Form 10-K now require information on cybersecurity risk management, strategy, and board oversight.

Compliance dates begin in December 2023 for large companies, with smaller reporting companies following in 2024. CISOs and legal teams should formalize materiality assessment processes, board reporting, and escalation playbooks to meet the accelerated filing timeline.

Single-point timeline showing the publication date sized by credibility score.
Publication date and credibility emphasis for this briefing. Source data (JSON)

Continue in the Compliance pillar

Return to the hub for curated research and deep-dive guides.

Visit pillar hub

Latest guides

  • Cyber Disclosure
  • Materiality
  • Public Companies
  • United States
Back to curated briefings