Section node
Annual risk management and governance
17 CFR 229.106
- What this page is
- Section node, 17 CFR 229.106
- Checked against the official source
- 2026-08-15Changed
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does 17 CFR 229.106 require, and where does it carry an outcome in the rule tree?
17 CFR 229.106 is the paragraph the SEC cyber disclosure decision agent rests on for this question. Processes for cybersecurity risk, board oversight and management role, in the annual report. The block was read against the publisher on 2026-08-15 and carries 1 outcomes in the agent's rule tree. The reference can be cited as it stands, with a link to the official text and a content hash.
17 CFR 229.106Checked against the publisher 2026-08-15Official text
A source reference, not legal advice.
- Jurisdiction
- Release No. 33-11216, Form 8-K Item 1.05, 17 CFR 229.106
- Section node
- item-106
- Read
- 2026-08-15
- Hash
- sha256:95250560c83d9c4c
Outcomes resting on this section
The rules below point to this section in their outcome. The verdict is a machine classification, not a judgment on an individual matter.
sec-assess
Materiality must be determined without unreasonable delay
Instruction 1 to Form 8-K Item 1.05 requires materiality to be determined without unreasonable delay after discovery. The annual disclosure under 17 CFR 229.106 applies regardless.
risk, Requirement applies conditionally
Section nodes
- Material incident reportForm 8-K Item 1.05
- Materiality determinationForm 8-K Item 1.05, Instruction 1
- National security delayForm 8-K Item 1.05(c)
The verdict is a machine classification of the outcome, not legal advice and not a compliance decision.
Verifiable trust signals
- Six fixed blocks, one source per line
- No sentence written by a language model
- Engine version and read date on every answer
- No customer data, no documents, no advice
- Model card and audit published under the EU AI Act