2025-05-08

Added · Updated

SEC Disclosure Guidance: Topic No. 2: Cybersecurity

The Division of Corporation Finance provides views on registrants' disclosure obligations regarding cybersecurity risks and cyber incidents under federal securities laws. Registrants must assess materiality to determine disclosure requirements in Risk Factors, Management’s Discussion and Analysis, Description of Business, Legal Proceedings, and Financial Statements, avoiding generic statements or disclosures that compromise security. The guidance specifies that material costs, operational disruptions, litigation, and reputational damage resulting from cyber incidents must be disclosed if they affect financial condition or results of operations. Additionally, registrants must evaluate the effectiveness of disclosure controls and procedures in light of potential cyber incidents affecting information reporting.

Securities and Exchange Commission logo

US Federal

Securities and Exchange Commission

Scan of the document's first page
Share

SEC published 9 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

Securities Act of 19331933Securities Act of 1933 (1933-05-27)Securities Exchange Act of 19341934Securities Exchange Act of 1934 (1934-06-06)SEC Disclosure Guidance: TopicNo. 2: Cybersecurity2025-05-08 · this documentSEC Disclosure Guidance: Topic No. 2: Cybersecurity (2025-05-08)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Securities and Exchange Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from SEC

SEC published 9 documents in the last 30 days. We email you each new one the day it's published.