Framework library
Framework module · sec-cyber-disclosure

SEC Cybersecurity Disclosure Rules

What a public company must tell investors: a material cybersecurity incident on Form 8-K Item 1.05 within four business days, and its risk-management and board oversight annually under Reg S-K Item 106.

Release Nos. 33-11216; 34-97989 · US Securities and Exchange Commission · published 2023-07-26

Standing today
Catalog only

01Standing

Catalog only

A directory entry — authority, version ledger, verification — not a workspace you can open.

SEC Cybersecurity Disclosure Rules is tracked in the registry — authority, version ledger, verification — and nothing is modelled for it yet. Import its catalog to begin.

Named and tracked only; disclosure obligations not modelled as a control catalog.

02Registry record

checked 2026-08-06
Registry status
Planned · namedWe name the regime and track its authority. Nothing is modelled yet.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Incident materiality determination · Form 8-K Item 1.05 · Regulation S-K Item 106 · Board oversight disclosure · Inline XBRL tagging
Applies to
public companies · US
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06

03Version ledger

1 edition
Release Nos. 33-11216; 34-97989Current edition2023-07-26
SEC Cybersecurity Disclosure Rules — framework module | ControlFrame