When must a US listed company disclose a cybersecurity incident?
Within four business days of determining that the incident is material, on Form 8-K Item 1.05. The four days run from the materiality determination, not from discovery, and the determination itself must be made without unreasonable delay.
The answer differs between the federal level and the states, see the rows below.
The answer by level
Federal level
A registrant reports a cybersecurity incident it has determined to be material on Form 8-K Item 1.05 within four business days of that determination, and describes its risk management, strategy and governance annually under Item 106.
Form 8-K, Item 1.05, Release No. 33-11216Sector rule
Item 106 requires a description of the processes for assessing, identifying and managing material risks from cybersecurity threats, and of the board's oversight of those risks.
17 CFR § 229.106, Regulation S-K Item 106State level
A financial institution covered by New York's cybersecurity regulation notifies the Superintendent within 72 hours of determining that a reportable cybersecurity event occurred.
23 NYCRR Part 500
Source lines
- Form 8-K Item 1.05 requires disclosure of the nature, scope and timing of the incident and its material impact or reasonably likely material impact.
- Regulation S-K Item 106 requires annual description of cybersecurity risk management, strategy and board oversight.
- The Attorney General may authorise a delay when immediate disclosure poses a substantial risk to national security or public safety.
What it means for the company
The clock is governed by an internal decision. Firms that document when the materiality assessment started and ended can defend the timing; firms that cannot show the decision point carry the exposure.
| Level | Requirement | Source |
|---|---|---|
| Federal level | A registrant reports a cybersecurity incident it has determined to be material on Form 8-K Item 1.05 within four business days of that determination, and describes its risk management, strategy and governance annually under Item 106. | Form 8-K, Item 1.05, Release No. 33-11216 |
| Sector rule | Item 106 requires a description of the processes for assessing, identifying and managing material risks from cybersecurity threats, and of the board's oversight of those risks. | 17 CFR § 229.106, Regulation S-K Item 106 |
| State level | A financial institution covered by New York's cybersecurity regulation notifies the Superintendent within 72 hours of determining that a reportable cybersecurity event occurred. | 23 NYCRR Part 500 |
What it means for the individual
Officers and directors face personal exposure where the disclosure describes controls that were not in place. The annual Item 106 text is read together with the incident report.
Source lines
- NYDFS Cybersecurity Regulation23 NYCRR Part 500 · read 2026-08-25 · proof 84b9ef62a7915a15
- U.S. Securities and Exchange CommissionForm 8-K, Item 1.05, Release No. 33-11216 · read 2026-08-25 · proof 84b9ef62a7915a15Official source
- Electronic Code of Federal Regulations17 CFR § 229.106, Regulation S-K Item 106 · read 2026-08-25 · proof 84b9ef62a7915a15Official source
Next step
Map the incident severity scale to the materiality determination, and record the date and time of that determination in the incident log.
This page reports what the sources say, with the identifier and address of the publisher. It is not legal advice and does not decide an individual matter.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.