Skip to content
    Back to Regulatory Radar
    InformationalGuidanceJanuary 13, 2026

    SEC Regulation S-K Reform Review Puts 2023 Cybersecurity Disclosure Rules Up for Comment

    SEC Chairman Paul Atkins announced a comprehensive review of Regulation S-K on January 13, 2026, requesting public comment (File No. CLL-15) on amending the disclosure regime to focus on material information, with comments due April 13, 2026. Because Item 106 cybersecurity disclosures sit within Regulation S-K, the review opened the 2023 cyber rules to reconsideration, and industry commenters, including Business Roundtable, urged the Commission to eliminate Item 106 and rescind the Item 1.05 Form 8-K incident disclosure requirement. No amendment has been proposed or adopted, and both requirements remain in effect as of August 2026.

    SECSaaSFinTech

    Key Analytics

    January 13, 2026
    Event Date
    Time Remaining
    August 1, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    Public companies must not treat this review as relief; the four-business-day Item 1.05 incident disclosure and Item 106 annual risk management, strategy, and governance disclosures remain binding as of August 2026, and Item 106 is still codified at 17 CFR 229.106. Any rescission or streamlining would require a formal rulemaking with its own proposal and comment period, so the earliest realistic change is well down the road. Organizations that dismantle materiality assessment workflows or 8-K escalation processes based on reform speculation would face enforcement and disclosure liability under rules that are still fully operative. The review does, however, signal that the disclosure burden may lighten, which matters for multi-year compliance investment planning.

    Recommended Actions

    • Continue operating incident materiality assessment and Form 8-K Item 1.05 escalation processes without change; the 2023 rules remain fully enforceable
    • Prepare Item 106 disclosures for the next 10-K cycle as usual, and document the processes behind them so the program can adapt quickly if requirements shift
    • Monitor the CLL-15 comment file and the SEC rulemaking agenda for any formal proposal to amend Item 106 or Form 8-K Item 1.05
    • Brief disclosure committees and boards that reform is possible but not proposed, so governance oversight expectations stay unchanged
    • Engage through counsel or industry associations if the Commission issues a formal cyber disclosure rulemaking proposal

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Low15-35 hours
    Key Workstreams
    • Item 106 drafting and process documentation for the next cycle
    • Disclosure committee briefing that obligations are unchanged
    • CLL-15 monitoring with counsel engagement triggers

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowLow · 15-35 hours
    Start cold under pressureModerate · 35-85 hours

    Roughly 20 to 50 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events