Skip to content
Saturday, August 22, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Business News

How the SEC's four-business-day cyber incident rule actually works

The clock starts when a public company decides an incident is material, not when it finds one. Here is what Item 1.05 requires, who got more time, and what private operators should copy.

AV
Asha Venkataswamy, · August 20, 2026 · 7 min read
How the SEC's four-business-day cyber incident rule actually works

A U.S. public company must file an Item 1.05 Form 8-K within four business days of determining that a cybersecurity incident is material — not within four business days of discovering it. The requirement took effect in December 2023, covers nearly every registrant, and asks for business impact rather than technical detail.

The gap between discovery and determination is where the confusion lives. The Securities and Exchange Commission adopted the rules on July 26, 2023; they were published at 88 FR 51896 on August 4, 2023 and became effective September 5, 2023, per the final rule text (Release Nos. 33-11216; 34-97989).

What does Item 1.05 actually require?

The final rule requires a registrant to "describe the material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely material impact on the registrant, including its financial condition and results of operations." That is the whole obligation.

What it does not require matters as much. The SEC's small-entity guidance states the rule does not call for specific technical details that would impede a company's response or remediation. If facts were undetermined or unavailable at filing time, the rule directs registrants to amend the prior Item 1.05 Form 8-K later. Incomplete information is not a reason to miss the deadline.

When does the four-day clock start?

The clock starts on the materiality determination. The SEC's fact sheet for the final rules states that registrants "must determine the materiality of an incident without unreasonable delay following discovery" and then "file an Item 1.05 Form 8-K generally within four business days of such determination."

So there are two obligations, not one. The four-day window is explicit. The determination step is governed by a standard rather than a fixed number of hours, which is why disclosure committees and boards are the pressure point, not the security team. Materiality uses the ordinary securities-law test: information is material if there is a substantial likelihood a reasonable shareholder would consider it important in making an investment decision.

Who is covered, and who got more time?

All registrants are covered, with a staggered start. Per the SEC's small-entity compliance guide, incident reporting under Item 1.05 began December 18, 2023 for companies other than smaller reporting companies, and June 15, 2024 for smaller reporting companies after a 180-day grace period.

TechCrunch, reporting on December 18, 2023, described smaller reporting companies as those with public float under $250 million or annual revenues under $100 million. Both dates are long past; the phase-in is history.

Annual disclosure arrived first. The fact sheet states all registrants had to provide annual cybersecurity disclosures beginning with annual reports for fiscal years ending on or after December 15, 2023. Inline XBRL tagging followed on December 15, 2024 for annual reports and December 18, 2024 for incident reports, per the compliance guide. Foreign private issuers are in scope too: the fact sheet says Form 6-K was amended to require them to furnish information on material incidents, and Form 20-F to require disclosure comparable to Item 106.

What about incidents that are not material?

They do not belong under Item 1.05. In a May 21, 2024 statement, Erik Gerding, then director of the SEC's Division of Corporation Finance, said Item 1.05 should be used only for incidents a company has determined to be material, and that voluntary disclosure of an immaterial incident — or one not yet assessed — belongs under Item 8.01.

His stated reason was signal quality: "if all cybersecurity incidents are disclosed under Item 1.05, then there is a risk that investors will misperceive immaterial cybersecurity incidents as material, and vice versa." He was explicit that he was not discouraging voluntary disclosure, only mislabeled disclosure. The follow-on rule matters operationally: a company that files under Item 8.01 and later concludes the incident is material must file a separate Item 1.05 Form 8-K within four business days of that determination.

Can disclosure be delayed?

Yes, through one narrow channel. Disclosure may be delayed if the U.S. Attorney General determines immediate disclosure would pose a substantial risk to national security or public safety. The compliance guide describes an initial delay of up to 30 days, extendable by 30 more, with a further 60 days in extraordinary circumstances.

No delay exists for commercial inconvenience, an unfinished investigation, or a pending negotiation with an attacker.

Where each disclosure belongs

VehicleWhat it carriesTiming
Form 8-K, Item 1.05An incident determined to be material: nature, scope, timing, and material or reasonably likely material impactGenerally within four business days of the materiality determination
Form 8-K, Item 8.01Voluntary disclosure of an incident that is immaterial or not yet assessed for materialityAt the company's discretion; a later materiality finding triggers a separate Item 1.05 filing
Form 10-K, Item 1C (Regulation S-K Item 106)Processes for assessing and managing material cyber risks; board oversight; management's roleAnnually, from fiscal years ending on or after December 15, 2023
Forms 6-K and 20-FComparable disclosure for foreign private issuersPer the same rulemaking

What private companies should take from this

Nothing here binds a private company. The structure is still worth copying, because the hard part is not the filing — it is answering a materiality question quickly and defensibly while an incident is still moving.

  1. Write down who makes the call. Name the roles that decide materiality, and a backup for each. A determination nobody owns drifts.
  2. Define the trigger that convenes them, so the security team is not also judging escalation at 2 a.m.
  3. Keep a timeline log from the first alert: discovery, escalation, and decision times, recorded as they happen.
  4. Pre-draft the disclosure skeleton — nature, scope, timing, impact — as four headings with blanks.
  5. Separate impact assessment from forensics. Waiting for a complete forensic picture before starting the materiality analysis is the most common way the clock gets lost.

One caution: this securities obligation sits alongside, not instead of, state breach-notification laws, contractual notice terms, and sector regulators. Those run on their own clocks.

Frequently asked questions

Does the four-day clock start when we discover the breach? No. It starts when the company determines the incident is material. The separate obligation is that the materiality determination itself must be made without unreasonable delay following discovery, per the SEC's fact sheet for the final rules.

Do we have to say whether data was stolen? Item 1.05 asks for the material aspects of nature, scope, and timing plus material impact. The SEC's guidance states the rule does not require technical details that would impede response or remediation. Many filings disclose data impact anyway, once known.

What if we file and then learn more? Amend. The final rule directs registrants to amend a prior Item 1.05 Form 8-K to disclose information called for by Item 1.05(a) that was undetermined or unavailable when the original filing went in.

Is there any way to keep an incident quiet? Only the national-security channel. Disclosure may be delayed where the U.S. Attorney General determines immediate disclosure would pose a substantial risk to national security or public safety, in the increments the compliance guide describes. Nothing else in the rule permits a delay.

For a related business news perspective, read Curiteva Surpasses 1,000 Procedures With Inspire® Cervical Trabecular PEEK™ With HAFUSE® Technology.

Sources

  1. SEC small-entity compliance guide: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
  2. Federal Register: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (88 FR 51896)
  3. Erik Gerding, SEC Division of Corporation Finance: Disclosure of Cybersecurity Incidents Determined To Be Material and Other Cybersecurity Incidents
  4. SEC Fact Sheet: Public Company Cybersecurity Disclosures; Final Rules (33-11216)
  5. TechCrunch, Carly Page: As the SEC's new data breach disclosure rules take effect, here's what you need to know