Skip to main content
—
Framework library
Framework module · sec-cyber-disclosure

SEC Cybersecurity Disclosure Rules

What a public company must tell investors: a material cybersecurity incident on Form 8-K Item 1.05 within four business days, and its risk-management and board oversight annually under Reg S-K Item 106.

Release Nos. 33-11216; 34-97989 · US Securities and Exchange Commission · published 2023-07-26

Standing today
Directory entry

00Answer

from the registry record
What is SEC Cybersecurity Disclosure Rules?
What a public company must tell investors: a material cybersecurity incident on Form 8-K Item 1.05 within four business days, and its risk-management and board oversight annually under Reg S-K Item 106.
Who does SEC Cybersecurity Disclosure Rules apply to?
SEC Cybersecurity Disclosure Rules applies to public companies, US, per US Securities and Exchange Commission.
What is the current version of SEC Cybersecurity Disclosure Rules?
The current edition is Release Nos. 33-11216; 34-97989, issued by US Securities and Exchange Commission and published 2023-07-26. Source: https://www.sec.gov/newsroom/press-releases/2023-139.
What does an assessment under SEC Cybersecurity Disclosure Rules require?
No control catalog has been ingested for SEC Cybersecurity Disclosure Rules yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

SEC Cybersecurity Disclosure Rules is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Named and tracked only; disclosure obligations not modelled as a control catalog.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Incident materiality determination · Form 8-K Item 1.05 · Regulation S-K Item 106 · Board oversight disclosure · Inline XBRL tagging
Applies to
public companies · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-09-06

03Version ledger

1 edition
Release Nos. 33-11216; 34-97989Current edition2023-07-26

06Related frameworks

scored from registry facts
  1. Sarbanes-Oxley ICFRSOX Sections 302 and 404; PCAOB AS 2201

    Also applies to public companies · The US public-company regime for management assessment and, where applicable, independent audit of internal control over financial reporting. SOX does not prescribe one universal IT-control catalog, and registry tracking is not an audit opinion.

  2. Also applies to public companies · SOX requires management and auditor assessment of internal control over financial reporting but does not prescribe one IT-control catalog. COBIT 2019 is licensed governance guidance often used to design and map IT general controls; neither this record nor COBIT is a SOX certification.

  3. Also applies to public companies · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.

  4. APRA CPS 2302026 determination (effective 2026-07-01)

    Same framework family · Australia's cross-industry prudential standard for operational risk, continuity of critical operations, and material service-provider risk at APRA-regulated entities. It is a binding supervisory standard, not a certification.

SEC Cybersecurity Disclosure Rules | ControlFrame