Skip to content
    Back to Regulatory Radar
    InformationalGuidanceJune 12, 2025

    SEC Withdraws 2022 Cybersecurity Rule Proposals for Investment Advisers and Funds

    The SEC formally withdrew 14 pending rule proposals via a notice dated June 12, 2025 and published in the Federal Register on June 17, 2025 (Release No. 33-11377). The withdrawn items include the March 2022 cybersecurity risk management proposal for registered investment advisers, registered investment companies, and business development companies, along with the April 2023 companion proposal covering broker-dealers, clearing agencies, transfer agents, and other market entities. The Commission stated it does not intend to issue final rules on these proposals and will publish a new proposed rule if it pursues future action in any of these areas.

    SECFinTech

    Key Analytics

    June 12, 2025
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    Registered advisers and funds no longer face the proposal's prospective mandates for written cybersecurity programs, confidential incident reporting to the Commission, and public risk disclosure. Withdrawal is not deregulation of cybersecurity; the amended Regulation S-P incident response and customer notification requirements adopted in 2024 remain in force, the 2023 public company cybersecurity disclosure rules are unaffected, and SEC examinations continue to scrutinize cybersecurity under the Advisers Act compliance rule and antifraud provisions. Any future SEC rulemaking in this area must start over with a new proposal, which gives firms advance visibility and a comment opportunity before new obligations attach.

    Recommended Actions

    • Remove the withdrawn 2022 adviser and fund cybersecurity proposal from regulatory readiness roadmaps and reallocate that planning effort to obligations still in force
    • Confirm compliance with the amended Regulation S-P incident response program and customer notification requirements, which were adopted separately in 2024 and are unaffected by the withdrawal
    • Maintain written cybersecurity policies and incident response procedures regardless; SEC examinations and enforcement continue to reach cybersecurity through the Advisers Act compliance rule and antifraud provisions
    • Monitor the SEC rulemaking agenda for any re-proposal, since the Commission stated that future action in these areas would begin with a new proposed rule

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Low15-40 hours
    Key Workstreams
    • Regulation S-P compliance confirmation against current procedures
    • Roadmap removal of the withdrawn 2022 adviser proposal
    • Rulemaking agenda monitoring for a re-proposal

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowLow · 15-40 hours
    Start cold under pressureModerate · 40-90 hours

    Roughly 25 to 50 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events