Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

When must a US listed company disclose a cybersecurity incident?

Within four business days of determining that the incident is material, on Form 8-K Item 1.05. The four days run from the materiality determination, not from discovery, and the determination itself must be made without unreasonable delay.

The answer differs between the federal level and the states, see the rows below.

The answer by level

  • Federal level

    A registrant reports a cybersecurity incident it has determined to be material on Form 8-K Item 1.05 within four business days of that determination, and describes its risk management, strategy and governance annually under Item 106.

    Form 8-K, Item 1.05, Release No. 33-11216
  • Sector rule

    Item 106 requires a description of the processes for assessing, identifying and managing material risks from cybersecurity threats, and of the board's oversight of those risks.

    17 CFR § 229.106, Regulation S-K Item 106
  • State level

    A financial institution covered by New York's cybersecurity regulation notifies the Superintendent within 72 hours of determining that a reportable cybersecurity event occurred.

    23 NYCRR Part 500

Source lines

  • Form 8-K Item 1.05 requires disclosure of the nature, scope and timing of the incident and its material impact or reasonably likely material impact.
  • Regulation S-K Item 106 requires annual description of cybersecurity risk management, strategy and board oversight.
  • The Attorney General may authorise a delay when immediate disclosure poses a substantial risk to national security or public safety.

What it means for the company

The clock is governed by an internal decision. Firms that document when the materiality assessment started and ended can defend the timing; firms that cannot show the decision point carry the exposure.

Comparison across levels and states
LevelRequirementSource
Federal levelA registrant reports a cybersecurity incident it has determined to be material on Form 8-K Item 1.05 within four business days of that determination, and describes its risk management, strategy and governance annually under Item 106.Form 8-K, Item 1.05, Release No. 33-11216
Sector ruleItem 106 requires a description of the processes for assessing, identifying and managing material risks from cybersecurity threats, and of the board's oversight of those risks.17 CFR § 229.106, Regulation S-K Item 106
State levelA financial institution covered by New York's cybersecurity regulation notifies the Superintendent within 72 hours of determining that a reportable cybersecurity event occurred.23 NYCRR Part 500

What it means for the individual

Officers and directors face personal exposure where the disclosure describes controls that were not in place. The annual Item 106 text is read together with the incident report.

Source lines

  • NYDFS Cybersecurity Regulation
    23 NYCRR Part 500 · read 2026-08-25 · proof 84b9ef62a7915a15
  • U.S. Securities and Exchange Commission
    Form 8-K, Item 1.05, Release No. 33-11216 · read 2026-08-25 · proof 84b9ef62a7915a15
    Official source
  • Electronic Code of Federal Regulations
    17 CFR § 229.106, Regulation S-K Item 106 · read 2026-08-25 · proof 84b9ef62a7915a15
    Official source

Next step

Map the incident severity scale to the materiality determination, and record the date and time of that determination in the incident log.

All US questions

This page reports what the sources say, with the identifier and address of the publisher. It is not legal advice and does not decide an individual matter.

Next step

Three ways to put the register to work in your own practice.

Start with your task