Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Security standards

SEC · Cyber disclosure (8-K 1.05 / Reg S-K 106)

Material cyber-incident disclosure support.

Applies to: US public companies. Built · in force

What the signed record shows

Tamper-evident detection timing and incident records supporting timely disclosure.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: Rel. 33-11216; 34-97989; 17 CFR 229.106

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

U.S. Securities and Exchange Commission, "Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure", final rule adopted 26 July 2023, Release Nos. 33-11216; 34-97989. Provisions this mapper evidences from the per-event signed record:

Form 8-K Item 1.05
Material Cybersecurity Incidents. A registrant must disclose a material cybersecurity incident within four business days of determining that the incident is material, describing its nature, scope and timing and the material impact (or reasonably likely material impact).
Regulation S-K Item 106(b) (17 CFR 229.106(b))
Risk management and strategy: describe processes for assessing, identifying and managing material risks from cybersecurity threats. Compliance: Item 106 from annual reports for fiscal years ending on or after 15 December 2023; Form 8-K Item 1.05 from 18 December 2023 (smaller reporting companies 15 June 2024).

Taken from the Regulayer entry for this instrument, which is built against the primary text.