· BreachTrigger
SEC Cyber Disclosure Rules: 4-Business-Day Deadline
TL;DR
Form 8-K Item 1.05, added under Exchange Act Rules 13a-11 and 15d-11 by SEC Release No. 33-11216, requires public companies to disclose material cybersecurity incidents within 4 business days of determining materiality, not from discovery or detection. The clock starts once the company concludes the incident is material enough that a reasonable investor would consider it important. A written determination from the U.S. Attorney General that disclosure would pose a substantial risk to national security or public safety can delay disclosure. Item 8.01 voluntary filings are a separate, non-mandatory disclosure option, not a safe harbor from Item 1.05. For actual SEC enforcement actions and their outcomes, consult the SEC's own enforcement actions and litigation releases rather than a secondhand summary.
Key Dates
- Rule adopted: July 26, 2023 (SEC Release No. 33-11216)
- Effective date: September 5, 2023
- Compliance date, most filers: December 18, 2023
- Compliance date, smaller reporting companies: June 15, 2024
What Are SEC Cybersecurity Disclosure Rules?
The SEC's cyber-breach disclosure rule is Item 1.05 of Form 8-K, "Material Cybersecurity Incidents," added by SEC Release No. 33-11216 and effective September 5, 2023, with compliance required beginning December 18, 2023 for most filers (June 15, 2024 for smaller reporting companies). It requires public companies to report material cybersecurity incidents as a current event on Form 8-K. A separate part of the same rule, Item 106 of Regulation S-K, requires an annual, standing disclosure of a company's cybersecurity risk management, strategy, and governance in its Form 10-K; that is a different obligation from the event-driven Item 1.05 filing this page focuses on.
A "material" incident is one a reasonable investor would consider important in making an investment decision. The SEC has explicitly said it does not apply a bright-line financial or percentage threshold; materiality is a fact-specific judgment combining quantitative factors (direct costs, financial impact) and qualitative factors (reputational harm, competitive position, litigation risk), leaving companies to justify their own calls. Treat any specific percentage or dollar threshold you see cited as a rule of thumb, not an SEC-defined standard, unless it traces to the SEC's own guidance.
When Does the 4-Business-Day Clock Start?
The clock starts when your company first determines (or should have determined) that the incident is material, not when you discovered the breach. This distinction is critical and often misunderstood.
Scenario:
- Monday 9am: Security team detects suspicious lateral movement.
- Thursday 2pm: Incident-response team concludes data was exfiltrated; risk officer determines it affects 8% of customer records (material).
- Deadline: The following Thursday 4pm (4 business days from Thursday).
If you delay your materiality determination, you're not resetting the clock. The SEC's final rule expects the materiality determination to be made "without unreasonable delay" after discovery, and examiners can look at your contemporaneous documentation (IR logs, risk assessments, executive memos) to assess whether the determination itself took longer than it reasonably should have. The SEC has not published a specific number of days that defines "unreasonable delay"; it is assessed on the facts of each case.
What's the Difference Between Disclosure and Discovery?
This is the most frequent source of non-compliance. Discovery is when your security tools first flag suspicious activity (malware alerts, unusual network flows, failed login spikes). Disclosure is the regulatory obligation that begins only after materiality determination.
- Discovery (not a regulatory trigger): breach detected by SIEM alert
- Materiality determination (regulatory clock starts): risk officer signs off that incident meets disclosure thresholds
- Disclosure (obligation): 8-K filed within 4 business days of determination
Many companies mistakenly assume the clock starts at discovery date rather than materiality determination date; getting this distinction right, and documenting it, is a common source of compliance risk.
What About Attorney General National-Security Delays?
Item 1.05(c) includes a national-security and public-safety exception. The decision does not belong to the filing company: only the U.S. Attorney General can trigger it, by determining that disclosure would pose a substantial risk to national security or public safety and notifying the SEC of that determination in writing.
This exception is narrow and works on a fixed schedule:
- The initial delay period is set by the Attorney General, up to 30 days from when disclosure was otherwise due.
- It can be extended for one additional period of up to 30 days if the Attorney General again determines, in writing, that the risk continues.
- In extraordinary circumstances, a final additional delay of up to 60 days is available on the same basis.
- Beyond that combined period, any further delay requires exemptive relief from the SEC itself.
A company cannot self-invoke this delay based on its own view that disclosure is risky, an ongoing internal investigation, or an informal request from law enforcement; it only applies once the Attorney General has made the determination and notified the SEC in writing. The delay provision does not excuse a company from Regulation FD or the antifraud provisions of the securities laws.
What Is Item 8.01 Voluntary Disclosure?
Item 8.01 is an optional disclosure category on Form 8-K for events the company deems important, even if not legally required by other Items. Some companies use Item 8.01 to disclose cybersecurity incidents voluntarily, often to avoid later claims of materiality disputes or to set the narrative early.
Advantages:
- Establishes contemporaneous evidence of materiality determination.
- Avoids later SEC argument that your materiality threshold was too high.
- Provides a narrative opportunity (e.g., "incident disclosed immediately due to risk profile").
Risks:
- Once you disclose via Item 8.01, silence or downplaying the incident later looks evasive.
- Item 8.01 disclosures are more frequently scrutinized by class-action plaintiff attorneys.
There is no published SEC or independent figure for what share of cyber-breach disclosures use Item 8.01 versus Item 1.05; treat any specific percentage you see quoted for this, including in earlier versions of this guide, as unverified. What is documented is that Item 1.05 is mandatory once materiality is determined, while Item 8.01 is voluntary, and the SEC has not signaled a regulatory preference for one over the other for incidents that don't meet the materiality bar.
What Do SEC Enforcement Actions Look For?
The SEC's Division of Enforcement can pursue several categories of cyber-disclosure violation, based on the requirements in the rule itself:
Late disclosure: Filing an Item 1.05 8-K more than four business days after the materiality determination, without a valid Attorney General delay in place.
Materiality disputes: The SEC disagreeing with a company's own conclusion that an incident was not material, particularly where the company's contemporaneous documentation suggests it should have reached a different conclusion.
Insider trading adjacent to breach disclosure: Trading in company securities by officers, directors, or other insiders with knowledge of an undisclosed material incident can separately implicate the antifraud provisions of the securities laws, independent of the Item 1.05 disclosure requirement itself.
Inadequate disclosure: Filings that are vague to the point of not letting an investor actually understand the nature, scope, and impact of the incident, as the rule requires.
This site does not track a verified, sourced count of enforcement actions, specific penalty amounts, or named cases under Item 1.05, and any such figures in an earlier version of this guide were not sourced and should not be relied on. For actual enforcement history, search the SEC's own enforcement actions and litigation releases and administrative proceedings directly.
How Do I Create a Compliance Timeline?
Use this table to track each incident from discovery through disclosure:
| Phase | Actor | Timeline | Trigger | Evidence |
|---|---|---|---|---|
| Detection | SOC/SIEM Team | T+0 to T+1 day | Alert or anomaly | Monitoring logs, alert ticket |
| Initial Assessment | Incident Commander | T+1 to T+2 days | Triage severity (P1-P4) | IR playbook execution, decision log |
| Scope & Impact | Forensics + Data Owner | T+2 to T+4 days | Determine # records, data types | Forensic report, data-loss assessment |
| Materiality Determination | Risk Officer + General Counsel | T+3 to T+5 days | Sign-off: material or not | Risk memo, signed materiality assessment |
| Executive Notification | GC/CFO/CEO | Same day as materiality | Board/Audit Committee briefing | Board minutes or email trail |
| 8-K Preparation | IR + Investor Relations | T+0 to T+3 days (post-determination) | Draft and legal review | Disclosure draft, legal comments |
| 8-K Filing | CFO/Controller | By end of T+4 business days | SEC filing | EDGAR submission timestamp |
| Investor Communication | IR + Legal | T+4 day + follow-up | Press release, call scripts | Communications archive |
Pro tip: Document the materiality determination with a signed, dated memo from your risk officer and GC. This is your best defense if the SEC questions your timeline later. The SEC specifically looks for written evidence that determination occurred when you claim.
How Does Materiality Connect to Disclosure Timing?
Materiality and disclosure timing are inseparable. A common compliance mistake:
- Company detects a breach on Monday.
- Company takes an extended period to complete forensics and determine the incident is not material.
- Company never files an 8-K.
- The SEC later argues the company should have reached its materiality determination sooner than it did, given the facts available, and that disclosure was therefore due earlier.
The SEC's rule expects the materiality determination itself to happen without unreasonable delay after discovery; it does not let a company indefinitely extend its own investigation to avoid the four-day clock ever starting.
To avoid this trap, build a target internal deadline for reaching a materiality determination into your incident-response plan, and document the reasoning either way. If you determine the incident is material but do not yet have all the required information, Item 1.05's Instruction 2 lets you say so in the initial 8-K and file an amendment with the missing details within four business days after they are determined or become available. That mechanism only applies once you've made the materiality determination, it is not a way to file before determining materiality.
Frequently Asked Questions
When did the SEC cybersecurity disclosure rules take effect? The rule (SEC Release No. 33-11216) took effect September 5, 2023. Compliance was required beginning December 18, 2023 for most filers, and June 15, 2024 for smaller reporting companies. See the SEC's own release for the primary text.
What are the SEC's compliance dates for the cybersecurity disclosure rule? December 18, 2023 for most filers; June 15, 2024 for smaller reporting companies. Both dates are separate from the September 5, 2023 effective date of the rule itself.
Does the SEC cybersecurity disclosure rule cover ransomware incidents? Ransomware is not a separate disclosure category under Item 1.05. A ransomware incident is disclosable if and when it meets the same materiality test as any other cybersecurity incident. See Cybersecurity Incident Materiality Determination for how that test works.
Cross-Topic Context: How This Fits Your Broader Compliance
Cybersecurity disclosure isn't isolated. It intersects with:
- SEC Cybersecurity Materiality Determination: The quantitative and qualitative test that decides whether an incident is disclosable.
- What Is SEC 8-K Item 105 Cybersecurity Disclosure: Technical 8-K filing walkthrough.
- SEC 8-K vs. State Data Breach Notification Laws: Why federal rules differ from state breach-notice laws (state laws: 30-60 days; SEC rules: 4 business days).
If your company operates in regulated industries (healthcare, financial services), you may face stricter state disclosure rules and SEC rules simultaneously. State laws can trigger earlier disclosure, which then accelerates SEC determination. See hrcompliancewatch.com for state-by-state requirements.
Protect Your Disclosure Timeline with Automation
Manually tracking materiality determination dates, forensic timelines, and filing deadlines creates risk. BreachTrigger monitors SEC 8-K cyber-breach filings in real-time and alerts you to:
- Late disclosures (filings >4 business days after materiality determination).
- Competitor breach patterns (industry/geography trends).
- Enforcement action signals (SEC language patterns, penalties).
For IR teams and MSSPs, BreachTrigger's Disclosure Timeline Dashboard maps each breach phase, flags compliance risks, and auto-calculates your 4-day deadline. Start monitoring your peers today.
Disclaimer
This post is informational only and does not constitute legal, regulatory, or financial advice. Materiality determinations, disclosure timing, and regulatory compliance decisions should be reviewed with qualified legal counsel and your SEC-reporting accountant. The SEC's final rule, Release No. 33-11216, is available at sec.gov. Verify all dates, thresholds, and procedural requirements against current SEC rules before relying on this information for compliance decisions.
Author: BreachTrigger Editorial Team Last Updated: August 5, 2026. Rule citations verified against SEC Release No. 33-11216. Keywords: SEC cybersecurity disclosure rules, Form 8-K cyber-breach, 4-business-day deadline, materiality determination, SEC enforcement 2026
Frequently asked questions
- When did the SEC cybersecurity disclosure rules take effect?
- The rule (SEC Release No. 33-11216) took effect September 5, 2023. Compliance was required beginning December 18, 2023 for most filers, and June 15, 2024 for smaller reporting companies.
- What are the SEC's compliance dates for the cybersecurity disclosure rule?
- December 18, 2023 for most filers; June 15, 2024 for smaller reporting companies. Both dates are separate from the September 5, 2023 effective date of the rule itself.
- Does the SEC cybersecurity disclosure rule cover ransomware incidents?
- Ransomware is not a separate disclosure category under Item 1.05. A ransomware incident is disclosable if and when it meets the same materiality test as any other cybersecurity incident.