SEC Regulation S-K Reform Review Puts 2023 Cybersecurity Disclosure Rules Up for Comment
SEC Chairman Paul Atkins announced a comprehensive review of Regulation S-K on January 13, 2026, requesting public comment (File No. CLL-15) on amending the disclosure regime to focus on material information, with comments due April 13, 2026. Because Item 106 cybersecurity disclosures sit within Regulation S-K, the review opened the 2023 cyber rules to reconsideration, and industry commenters, including Business Roundtable, urged the Commission to eliminate Item 106 and rescind the Item 1.05 Form 8-K incident disclosure requirement. No amendment has been proposed or adopted, and both requirements remain in effect as of August 2026.
Key Analytics
Impact Analysis
Public companies must not treat this review as relief; the four-business-day Item 1.05 incident disclosure and Item 106 annual risk management, strategy, and governance disclosures remain binding as of August 2026, and Item 106 is still codified at 17 CFR 229.106. Any rescission or streamlining would require a formal rulemaking with its own proposal and comment period, so the earliest realistic change is well down the road. Organizations that dismantle materiality assessment workflows or 8-K escalation processes based on reform speculation would face enforcement and disclosure liability under rules that are still fully operative. The review does, however, signal that the disclosure burden may lighten, which matters for multi-year compliance investment planning.
Recommended Actions
- Continue operating incident materiality assessment and Form 8-K Item 1.05 escalation processes without change; the 2023 rules remain fully enforceable
- Prepare Item 106 disclosures for the next 10-K cycle as usual, and document the processes behind them so the program can adapt quickly if requirements shift
- Monitor the CLL-15 comment file and the SEC rulemaking agenda for any formal proposal to amend Item 106 or Form 8-K Item 1.05
- Brief disclosure committees and boards that reform is possible but not proposed, so governance oversight expectations stay unchanged
- Engage through counsel or industry associations if the Commission issues a formal cyber disclosure rulemaking proposal
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Item 106 drafting and process documentation for the next cycle
- ›Disclosure committee briefing that obligations are unchanged
- ›CLL-15 monitoring with counsel engagement triggers
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 20 to 50 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.