Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

When must you file Form 8-K Item 1.05 for a cyber incident?

Updated

Form 8-K Item 1.05: if a registrant determines a cybersecurity incident is material, file within four business days of that determination — not discovery, not GDPR awareness, not four calendar days. Item 1.05 is not Item 8.01 and not Item 106. Not legal advice; does not start a clock.

SEC cybersecurity-disclosure jurisdiction guide, last verified 8 September 2026 against Form 8-K Item 1.05 (SEC 873 (02-25)), 17 CFR 229.106 (Item 106; eCFR Title 17 displayed as of 3 September 2026, last amended 17 August 2026), Release Nos. 33-11216 and 34-97989 (26 July 2023; 88 FR 51896), Exchange Act Form 8-K C&DIs Section 104B (staff last update 24 June 2024), the Division of Corporation Finance small-entity compliance guide (last reviewed 10 September 2024), and the 21 May 2024 staff statement on Item 1.05 versus other Form 8-K items. C&DIs and staff statements are staff interpretations, not the Form and not a Commission rule. Last verified, no 2024, 2025, or 2026 Commission amendment had rewritten Item 1.05(a)'s four-business-day words. It is not legal advice, not a filing, not a materiality determination, and not a substitute for counsel.

This is Form 8-K Item 1.05 and Item 106, not YOUR determination

Audience: a CISO, a general counsel, a disclosure committee, or counsel at a public company or an IPO-track issuer triaging a cybersecurity incident that may sit under the Exchange Act reporting rules. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that you are a registrant, that the incident is material, that four business days have started, or that you must file.

Item 1.05 and Item 106 are legal requirements only if those provisions apply to YOUR facts. They apply to Exchange Act reporting companies as the adopting release and the small-entity compliance guide describe — domestic registrants on Form 8-K / Form 10-K; foreign private issuers on Form 6-K / Form 20-F Item 16K. The rules do not apply to eligible registrants that file on Form 40-F under the Multijurisdictional Disclosure System, nor to asset-backed issuers as defined in Item 1101 of Regulation AB. This page does not decide that YOU are a registrant. Last verified 8 September 2026. Not legal advice.

  • Statute versus guidance: Form 8-K Item 1.05 and 17 CFR 229.106 (Regulation S-K Item 106) are legal requirements only if they apply. Release 33-11216 / 34-97989 is the adopting release. Exchange Act Form 8-K C&DIs Section 104B and Division of Corporation Finance staff statements are staff interpretations; they are not the Form and not a Commission rule. This page quotes which kind of text it is relying on.
  • This page does not start four business days, does not convert four business days into four calendar days or 96 hours, and does not paste GDPR 72 hours or CRA 24-hour / 72-hour marks onto Item 1.05.
  • The reporting-deadlines page on this site is the statute table of clocks. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The failure-to-report-consequences page on this site is the maxima table. The US-state-laws guide on this site is the representative high-variance comparison. The HIPAA breach-notification guide on this site.
  • The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker is not an Item 1.05 clock, and it does not file with EDGAR. The CRA Article 14 reporting guide on this site is that ladder's statute.

Four business days from the materiality determination, not discovery

General Instruction B.1 to Form 8-K: a report pursuant to Item 1.05 is to be filed within four business days after the registrant determines that it has experienced a material cybersecurity incident. The small-entity compliance guide restates the same point: the deadline is tied not to discovery but to the registrant's determination that the incident is material. This page does not find that determination on YOUR facts, and it does not start the four business days. Last verified 8 September 2026. Not legal advice.

Item 1.05 clock (legal requirement only if Item 1.05 applies — not YOUR start time; not legal advice; does not start a clock)
ElementWhat the text saysKind of textLast verified
DutyIf the registrant experiences a cybersecurity incident that is determined by the registrant to be material, describe the material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely material impact on the registrant, including its financial condition and results of operations.Legal requirement — Form 8-K Item 1.05(a). Only if Item 1.05 applies. The filing is a current report on Form 8-K, not a Form 10-K Item 106 narrative and not an Item 8.01 other-events report.8 September 2026
Clock-startFour business days after the registrant determines that it has experienced a material cybersecurity incident. Not discovery. Not becoming aware as GDPR Article 33(1) uses those words. Not the CRA manufacturer-awareness mark. Four business days are not four calendar days and are not 96 hours.Legal requirement — Form 8-K General Instruction B.1 (Item 1.05 sentence) and Item 1.05(a). Not a finding that YOU have determined materiality.8 September 2026
Determination timing (Instruction 1)A registrant's materiality determination regarding a cybersecurity incident must be made without unreasonable delay after discovery of the incident. Discovery is the event after which Instruction 1 requires the determination. Discovery is not the four-business-day start. This page does not convert 'without unreasonable delay' into a number of hours.Legal requirement — Instruction 1 to Item 1.05. Not a finding that YOUR determination was unreasonably delayed.8 September 2026
Content still unknown (Instruction 2)To the extent that the information called for in Item 1.05(a) is not determined or is unavailable at the time of the required filing, the registrant shall include a statement to this effect in the filing and then must file an amendment to its Form 8-K filing under this Item 1.05 containing such information within four business days after the registrant, without unreasonable delay, determines such information or within four business days after such information becomes available.Legal requirement — Instruction 2 to Item 1.05. An amendment is not a licence to skip the initial Item 1.05 filing once materiality has been determined.8 September 2026
Definition usedThe definition of the term 'cybersecurity incident' in 17 CFR 229.106(a) applies to Item 1.05: an unauthorized occurrence, or a series of related unauthorized occurrences, on or conducted through a registrant's information systems that jeopardizes the confidentiality, integrity, or availability of a registrant's information systems or any information residing therein.Legal requirement — Instruction 3 to Item 1.05, pointing at Item 106(a). A series of related unauthorized occurrences is in that definition.8 September 2026

Materiality-determination decision aid — not a determination

Materiality is a legal and facts-and-circumstances test. This page does not find that YOUR incident is material. A decision aid is not a determination. Counsel and the disclosure committee apply the test to YOUR facts. Last verified 8 September 2026. Not legal advice.

Materiality decision aid (not a determination; not legal advice; C&DIs labelled as staff interpretations)
QuestionWhat the cited text saysWhat this page does not doKind of text
Are you a registrant to whom Item 1.05 applies?Domestic registrants file Item 1.05 on Form 8-K. Foreign private issuers furnish comparable incident disclosure on Form 6-K if the incident is disclosed or otherwise publicized (or is required to be disclosed or publicized) in a foreign jurisdiction, to any stock exchange, or to security holders. Form 40-F MJDS filers and asset-backed issuers as defined in Item 1101 of Regulation AB are outside the rules as the small-entity compliance guide states them.Does not decide that YOU are a registrant, an FPI, an SRC, a BDC, or an asset-backed issuer. Does not start a clock.Legal requirement (the forms) plus small-entity compliance guide (staff summary, not the Form).
Has a cybersecurity incident occurred as Item 106(a) defines it?An unauthorized occurrence, or a series of related unauthorized occurrences, on or conducted through a registrant's information systems that jeopardizes confidentiality, integrity, or availability. C&DI 104B.09 (staff interpretation, 24 June 2024) restates that related incidents, collectively, may be material even if each, individually, is not.Does not decide that YOUR event is a cybersecurity incident. Does not aggregate YOUR events into a series.Legal requirement — Item 106(a) / Instruction 3. C&DI 104B.09 is a staff interpretation.
Has the registrant determined the incident is material?The ordinary securities-law test, as the adopting release and C&DI 104B.05 restate it: whether there is a substantial likelihood that a reasonable shareholder would consider it important in making an investment decision, or whether it would have significantly altered the total mix of information made available. Quantitative and qualitative factors. 'Reasonably likely' material impact is the impact language in Item 1.05(a), not a knowledge test and not GDPR awareness.Does not find materiality on YOUR facts. Does not start four business days from discovery. A decision aid is not a determination.Legal requirement (Item 1.05(a) trigger). Adopting release and C&DI 104B.05 restate the Supreme Court cases; those restatements are not a substitute for the Form.
Was the determination made without unreasonable delay after discovery?Instruction 1 requires that. The adopting release says a materiality determination necessitates an informed and deliberative process, and that adhering to normal internal practices and disclosure controls and procedures will suffice to demonstrate good faith compliance. Those words do not convert 'without unreasonable delay' into a number of hours.Does not find that YOUR process was unreasonably delayed. Does not start four business days from discovery.Legal requirement — Instruction 1. Adopting-release discussion is not the Form.
If materiality is determined — four business daysFile Item 1.05 within four business days of that determination. Four business days, not four calendar days, not 96 hours, not GDPR 72 hours, not CRA 24 hours.Does not start the four business days. Does not file. Does not convert business days into calendar days.Legal requirement — General Instruction B.1 and Item 1.05(a).

Item 1.05 is not Item 8.01 and is not Item 106

Three different Form / Regulation S-K items. Do not collapse them. Last verified 8 September 2026. Not legal advice.

Item 1.05 versus Item 8.01 versus Item 106 (not a filing instruction; not legal advice)
ItemWhat it isClock / cadenceWhat it is not
Form 8-K Item 1.05 — Material Cybersecurity IncidentsCurrent report of a cybersecurity incident the registrant has determined to be material. Content: material aspects of nature, scope, and timing, and the material impact or reasonably likely material impact, including financial condition and results of operations.Four business days after the materiality determination. Instruction 1 still requires that determination without unreasonable delay after discovery.Not Item 8.01. Not annual Item 106. Not a GDPR Article 33 notice. Not a state AG or individual notice.
Form 8-K Item 8.01 — Other EventsThe 21 May 2024 Division of Corporation Finance staff statement: if a company chooses to disclose a cybersecurity incident for which it has not yet made a materiality determination, or one it determined was not material, the Division encourages disclosure under a different item of Form 8-K (for example, Item 8.01). That statement is staff guidance, not the Form. If the company later determines the incident is material, it should file an Item 1.05 Form 8-K within four business days of that subsequent determination.Item 8.01 is not the Item 1.05 four-business-day clock. A later Item 1.05 clock, if it starts, starts at the later materiality determination.Not a finding that YOUR Item 8.01 was required, permitted, or sufficient. Not Item 1.05. Staff statement, not a Commission rule.
Regulation S-K Item 106 — Cybersecurity (annual)Periodic disclosure in the annual report on Form 10-K (Item 16K on Form 20-F for FPIs): processes for assessing, identifying, and managing material risks from cybersecurity threats; whether risks from cybersecurity threats, including as a result of previous incidents, have materially affected or are reasonably likely to materially affect the registrant; board oversight; management's role.Annual report cadence — not four business days. Structured data (Inline XBRL) is a separate tagging requirement in Item 106(d) and Item 1.05(b).Not a current report of a material incident. Filing Item 106 in a 10-K does not discharge Item 1.05, and an Item 1.05 filing does not discharge Item 106.

Delay provision — Attorney General, not a self-help FBI path

Item 1.05(c) is the national-security and public-safety delay. The actor who can trigger it is the United States Attorney General, by a written determination to the Commission — not the registrant, not the FBI acting alone, and not CISA. A second, narrower delay sits in Item 1.05(d) for registrants subject to the FCC CPNI breach rule. Last verified 8 September 2026. Not legal advice.

Item 1.05(c) and 1.05(d) delay paths (legal requirement only if Item 1.05 applies; C&DIs labelled as staff interpretations; not legal advice)
PathWhat the text saysKind of textWhat this page does not do
Item 1.05(c) — initial AG delayNotwithstanding General Instruction B.1, if the United States Attorney General determines that disclosure required by paragraph (a) poses a substantial risk to national security or public safety, and notifies the Commission of such determination in writing, the registrant may delay providing the disclosure for a time period specified by the Attorney General, up to 30 days following the date when the disclosure required by this Item 1.05 was otherwise required to be provided.Legal requirement — Item 1.05(c).Does not find a substantial risk. Does not notify the Commission. Does not start or stop four business days. The registrant cannot self-invoke this delay.
Item 1.05(c) — additional 30 daysDisclosure may be delayed for an additional period of up to 30 days if the Attorney General determines that disclosure continues to pose a substantial risk to national security or public safety and notifies the Commission of such determination in writing.Legal requirement — Item 1.05(c).Does not grant an extension. Requesting a further delay is not the grant.
Item 1.05(c) — extraordinary final 60 daysIn extraordinary circumstances, disclosure may be delayed for a final additional period of up to 60 days if the Attorney General determines that disclosure continues to pose a substantial risk to national security and notifies the Commission of such determination in writing. That extraordinary limb names national security, not public safety. Beyond the final 60-day delay, if the Attorney General indicates that further delay is necessary, the Commission will consider additional requests for delay and may grant such relief through Commission exemptive order.Legal requirement — Item 1.05(c).Does not find extraordinary circumstances. Does not issue an exemptive order.
C&DI 104B.01–.03 — if the AG declines or the delay endsRequesting a delay does not change the filing obligation. If the Attorney General declines or does not respond before the Form 8-K otherwise would be due, file within four business days of the materiality determination. If a granted delay expires without a further determination, file within four business days of that expiration. If the Attorney General later notifies that disclosure no longer poses the risk, file within four business days of that notification.Staff interpretation — C&DIs 104B.01, 104B.02, 104B.03 (12 December 2023). Not the Form.Does not treat an FBI field-office conversation as an AG determination. C&DIs point at the Department of Justice Material Cybersecurity Incident Delay Determinations memorandum for DOJ procedure; that memorandum is not Item 1.05(c).
C&DI 104B.04 — consulting DOJ / FBI / CISAThe sole fact that a registrant consults with the Department of Justice regarding the availability of a delay under Item 1.05(c) does not necessarily result in a determination that the incident is material. Item 1.05 does not preclude consulting with DOJ, including the FBI, CISA, or any other law enforcement or national security agency at any point, including before a materiality assessment is completed.Staff interpretation — C&DI 104B.04 (14 December 2023). Not the Form. Consultation is not the delay grant.Does not invent an FBI or CISA delay authority. The delay grantor in Item 1.05(c) is the Attorney General, by written notice to the Commission.
Item 1.05(d) — FCC CPNI overlapIf a registrant that is subject to 47 CFR 64.2011 is required to delay disclosing a data breach pursuant to such rule, it may delay providing Item 1.05 for such period that is applicable under 47 CFR 64.2011(b)(1) and in no event for more than seven business days after notification required under such provision has been made, so long as the registrant notifies the Commission in correspondence submitted to the EDGAR system no later than the date when the disclosure required by this Item 1.05 was otherwise required to be provided. Last verified 8 September 2026, 47 CFR 64.2011(b)(1) still directed covered carriers not to notify customers or disclose the breach publicly until seven full business days have passed after notification to the United States Secret Service and the FBI, with listed exceptions. A 12 February 2024 FCC rewrite of § 64.2011 was published as delayed indefinitely; this page does not treat that delayed text as in force.Legal requirement — Item 1.05(d), only if 47 CFR 64.2011 applies to YOU. Narrower than Item 1.05(c).Does not decide that YOU are a telecommunications carrier subject to 47 CFR 64.2011. Does not paste the seven-business-day CPNI hold onto registrants who are not subject to that rule.

Ransomware CDIs — staff interpretations, 24 June 2024

C&DIs 104B.05–104B.09 address ransomware. They are staff interpretations of Item 1.05, last staff update 24 June 2024. They are not the Form, not a Commission amendment, and not a finding about YOUR incident. Last verified 8 September 2026. Not legal advice.

  • 104B.05: a ransomware attack that disrupts operations or exfiltrates data, followed by a ransom payment and apparent cessation before the materiality determination, does not relieve the registrant of the requirement to make a materiality determination. Cessation, including as a result of payment, does not by itself mean the incident is not material. The ordinary securities-law materiality test still applies.
  • 104B.06: if the registrant has determined the incident to be material, a later ransom payment and cessation before the Item 1.05 deadline do not relieve the requirement to report under Item 1.05 within four business days of that materiality determination.
  • 104B.07: insurance reimbursement of all or a substantial portion of a ransom payment does not necessarily make the incident not material. The adopting release's qualitative and quantitative facts-and-circumstances analysis still applies, and may include subsequent availability or cost of insurance.
  • 104B.08: the size of the ransom payment, by itself, is not determinative of materiality. A small payment does not necessarily make the incident immaterial. The Commission declined a quantifiable trigger.
  • 104B.09: a series of ransomware incidents that are each, individually, immaterial may still require Item 1.05 disclosure if they were related and, collectively, material. Item 106(a) includes a series of related unauthorized occurrences.
  • These CDIs do not invent a ransomware-specific amendment to Item 1.05. Last verified 8 September 2026, Item 1.05(a)'s four-business-day words were still the 26 July 2023 text.

What Item 1.05(a) requires — and what Instruction 4 does not require

Item 1.05(a) is the content list for the current report. Instruction 4 is the limit on technical detail. Item 1.05(b) is Inline XBRL, not a second clock. Last verified 8 September 2026. Not legal advice.

  • Item 1.05(a): the material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely material impact on the registrant, including its financial condition and results of operations.
  • Instruction 4: a registrant need not disclose specific or technical information about its planned response to the incident or its cybersecurity systems, related networks and devices, or potential system vulnerabilities in such detail as would impede the registrant's response or remediation of the incident.
  • Item 1.05(b): provide the information required by this Item in an Interactive Data File in accordance with Rule 405 of Regulation S-T and the EDGAR Filer Manual. Tagging is not the four-business-day determination.
  • The 20 June 2024 staff statement on selective disclosure: nothing in Item 1.05 prohibits privately discussing a material incident with other parties, including commercial counterparties, beyond what was included in the Item 1.05 Form 8-K. That statement is staff guidance, not the Form. Regulation FD is a different rule.

Item 106 annual risk-management, strategy, and governance

Item 106 is the annual 10-K (and Form 20-F Item 16K) disclosure. It is not the Item 1.05 current report. Last verified 8 September 2026 against 17 CFR 229.106. Not legal advice.

Regulation S-K Item 106 (legal requirement only if Item 106 applies — not YOUR 10-K text; not legal advice)
ParagraphWhat the text requiresKind of text
Item 106(a) definitionsCybersecurity incident, cybersecurity threat, and information systems — the same incident definition Instruction 3 imports into Item 1.05.Legal requirement — 17 CFR 229.106(a).
Item 106(b)(1) risk management and strategyDescribe the registrant's processes, if any, for assessing, identifying, and managing material risks from cybersecurity threats in sufficient detail for a reasonable investor to understand those processes. Non-exclusive list: integration into overall risk management; use of assessors, consultants, auditors, or other third parties; processes to oversee and identify such risks associated with use of any third-party service provider.Legal requirement — 17 CFR 229.106(b)(1).
Item 106(b)(2) material effectDescribe whether any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect the registrant, including its business strategy, results of operations, or financial condition and if so, how.Legal requirement — 17 CFR 229.106(b)(2). Not an Item 1.05 current report.
Item 106(c)(1) board oversightDescribe the board of directors' oversight of risks from cybersecurity threats. If applicable, identify any board committee or subcommittee responsible and describe the processes by which the board or such committee is informed about such risks.Legal requirement — 17 CFR 229.106(c)(1).
Item 106(c)(2) management's roleDescribe management's role in assessing and managing material risks from cybersecurity threats. Non-exclusive list: which management positions or committees are responsible and the relevant expertise of such persons; processes by which they are informed about and monitor prevention, detection, mitigation, and remediation of cybersecurity incidents; whether they report such risks to the board or a committee.Legal requirement — 17 CFR 229.106(c)(2).

Legal requirement versus SEC guidance

This page labels each cited text. Last verified 8 September 2026. Not legal advice.

Kind of text (not a hierarchy of authority for YOUR facts; not legal advice)
TextKindWhat it is not
Form 8-K Item 1.05, including Instructions 1–4 and paragraphs (a)–(d)Legal requirement, only if Item 1.05 applies.Not a staff CDI. Not a determination that YOUR incident is material.
17 CFR 229.106 (Regulation S-K Item 106)Legal requirement, only if Item 106 applies. Annual 10-K / 20-F disclosure.Not Item 1.05. Not a current report.
Release Nos. 33-11216 and 34-97989 (26 July 2023)Adopting release for the 2023 rules. Explains the Commission's reasons. Quotes the materiality cases the Commission applied.Not a 2024, 2025, or 2026 amendment. Last verified 8 September 2026, Item 1.05(a) still carried the 26 July 2023 words.
Exchange Act Form 8-K C&DIs Section 104B (last staff update 24 June 2024)Staff interpretations. C&DIs 104B.01–.04 (December 2023) on the AG delay; 104B.05–.09 (24 June 2024) on ransomware.Not the Form. Not a Commission rule. Not a finding about YOUR incident.
Small-entity compliance guide; 21 May 2024 and 20 June 2024 staff statementsStaff summaries and statements by the Director of the Division of Corporation Finance. The compliance guide says it is not a substitute for the rule.Not the Form. The 21 May 2024 Item 8.01 encouragement is staff guidance on voluntary disclosure, not a second Item 1.05 duty.

State-law notice does not discharge Item 1.05

Item 1.05 is securities-law disclosure to investors on Form 8-K. A state attorney-general or individual notice under a state breach-notification statute is a different recipient class. Filing one never discharges the other. Last verified 8 September 2026. Not legal advice.

  • Item 1.05 does not discharge Cal. Civ. Code §1798.82, N.Y. Gen. Bus. Law §899-aa, or any other state individual / AG / credit-bureau notice. Those statutes, when they apply, run on their own clocks — often from discovery or determination of a security breach, not from a securities-law materiality determination.
  • A state notice does not discharge Item 1.05. Four business days from a materiality determination is not a state's 'without unreasonable delay' and is not a 30-calendar-day individual-notice mark.
  • The US-state-laws guide on this site is the representative high-variance comparison. The who-to-notify page on this site is the recipient-class map. The reporting-deadlines page on this site is the statute table. The HIPAA breach-notification guide on this site.
  • HIPAA 45 CFR §§164.400–414, when it applies, is a different regime. The HIPAA breach-notification guide on this site.

Where this shows up in ShipReady Metrics

The signed-in app does not decide that you are a registrant, does not make a materiality determination, does not start a four-business-day clock, does not draft Item 1.05 or Item 106 text, does not file with EDGAR, and does not submit a Form 8-K, Form 10-K, Form 6-K, or Form 20-F. None of the surfaces below is an Item 1.05 analysis, an 8-K exhibit, an Item 106 narrative, or an instruction to submit a filing.

If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organization has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. It is not an Item 1.05 four-business-day clock, not a materiality determination, and not an EDGAR filing. It tracks a clock the organization already recorded. It is not a determination that CRA applies. The CRA Article 14 reporting guide on this site is that ladder's statute. A named human still submits.

The obligation map lists frameworks the organization has marked in-scope. That in-scope mark is not a determination that the issuer is a reporting company, not a determination that Item 1.05 or Item 106 applies, and not a legal opinion that an incident is material. SOX is a bundled framework in the catalog (`sox`, labelled Sarbanes–Oxley Act §302/§404 — IT General Controls readiness). SOX defines no control catalog; the internal ITGC control ids (ITGC-AC-01 and siblings) are ShipReadyMetrics-authored conventions. Marking `sox` in-scope is a SOX ITGC readiness subset, not Section 404 evidence, not an Item 106 process description, and not an Item 1.05 analysis. The SOX starter control set is crosswalked to canonical controls; evidence collection and the evidence-review overlay record control-mapped artifacts for that subset. Those rows are not an 8-K exhibit and not Item 106 disclosure. The cyber risk register lives under Security. It is a cyber risk register. It is not an Item 1.05 materiality analysis, not a disclosure-committee minute, and not a four-business-day clock. There is no SEC reporting ladder and no EDGAR filing surface. A named human / counsel still files.

Key terms used on this page

Short labels. They are not a glossary of every securities-law term. Last verified 8 September 2026. Not legal advice.

Key terms (not legal advice; not YOUR facts)
TermHow this page uses it
Item 1.05Form 8-K Item 1.05, Material Cybersecurity Incidents. Current report. Four business days from the materiality determination. Not Item 8.01. Not Item 106.
Item 8.01Form 8-K Item 8.01, Other Events. The 21 May 2024 staff statement encourages this item (or another non-1.05 item) for incidents not determined material, or not yet determined. Staff guidance, not the Form.
Item 10617 CFR 229.106, Regulation S-K Item 106 Cybersecurity. Annual risk-management, strategy, governance, and material-effect disclosure on Form 10-K (Item 16K on Form 20-F).
Materiality determinationThe registrant's determination that a cybersecurity incident is material. That determination starts the four business days. Instruction 1 requires it without unreasonable delay after discovery. Discovery is not the four-business-day start.
Four business daysThe Item 1.05 filing mark. Not four calendar days. Not 96 hours. Not GDPR 72 hours. Not CRA 24 hours.
Attorney General delayItem 1.05(c): United States Attorney General determines that disclosure poses a substantial risk to national security or public safety and notifies the Commission in writing. Not a self-help FBI or CISA delay.
Cybersecurity incident (Item 106(a))An unauthorized occurrence, or a series of related unauthorized occurrences, on or conducted through a registrant's information systems that jeopardizes confidentiality, integrity, or availability.

Primary sources (last verified 8 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Form 8-K Item 1.05 (SEC 873 (02-25), fetched from sec.gov/files/form8-k.pdf) is a legal requirement only when Item 1.05 applies. Item 1.05(a) is the material-incident current report. Item 1.05(b) is Inline XBRL. Item 1.05(c) is the Attorney General national-security / public-safety delay. Item 1.05(d) is the narrower 47 CFR 64.2011 CPNI overlap. Instructions 1–4 cover determination timing, amendments, the Item 106(a) definition, and the technical-detail limit. General Instruction B.1 states the four-business-day mark from determination. 17 CFR 229.106 (Item 106; eCFR Title 17 displayed as of 3 September 2026, last amended 17 August 2026) is the annual risk-management, strategy, and governance disclosure; its source note remains 88 FR 51942, 4 August 2023. Release Nos. 33-11216 and 34-97989 (26 July 2023) adopted those provisions. Exchange Act Form 8-K C&DIs Section 104B (staff last update 24 June 2024) and the 21 May 2024 and 20 June 2024 staff statements are staff interpretations, not the Form. The small-entity compliance guide (last reviewed 10 September 2024) is a staff summary and says it is not a substitute for the rule. 47 CFR 64.2011 is cited only for the Item 1.05(d) overlap as in force last verified above. Last verified 8 September 2026, no 2024, 2025, or 2026 Commission amendment had rewritten Item 1.05(a)'s four-business-day words. These are the SEC provisions this page treats, not a complete world list of breach laws. Not legal advice.

The reporting-deadlines page on this site is the statute table of clocks. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The failure-to-report-consequences page on this site is the maxima table. The do-I-have-to-report page on this site is the class map. The reporting-decision-tree page on this site is the branching tree. The who-to-notify page on this site is the recipient-class map. The regulator-customer-individual page on this site is the three-stream comparison. The which-jurisdictions-apply page on this site is the applicability map. The prepare-regulatory-report page on this site is the field checklist. The document-your-decision page on this site is the decision record. The supporting-evidence page on this site is the evidentiary record. The GDPR breach-notification guide on this site is Articles 33–34 of EU GDPR. The NIS2 incident-reporting guide on this site. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. The CRA Article 14 reporting guide on this site. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner. The US-state-laws guide on this site is the representative high-variance comparison. The HIPAA breach-notification guide on this site. The Canada PIPEDA jurisdiction guide on this site is PIPEDA ss. 10.1–10.3 and SOR/2018-64. A dedicated Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link.

Frequently asked questions

When must you file Form 8-K Item 1.05 for a cyber incident?

Item 1.05(a) and General Instruction B.1: if the registrant determines a cybersecurity incident is material, file within four business days of that determination. Instruction 1 still requires the determination without unreasonable delay after discovery. Discovery is not the four-business-day start. Four business days are not four calendar days. Last verified 8 September 2026. Not legal advice.

Is this legal advice?

No. It is an SEC cybersecurity-disclosure jurisdiction guide distilled from Form 8-K Item 1.05, 17 CFR 229.106, Release 33-11216, and staff C&DIs Section 104B (staff interpretations, not the Form). Whether you are a registrant, whether an incident is material, and whether four business days have started are legal questions for counsel on your facts. This page does not start a reporting clock.

Does ShipReady file Form 8-K with the SEC?

No. The signed-in app does not file Item 1.05, does not file Item 106, does not submit through EDGAR, and does not start those clocks. Compliance → CRA reporting tracks the Article 14 ladder from recorded awareness for findings the org classified as CRA-in-scope — one product tracker, not Item 1.05. The obligation map is frameworks marked in-scope, not a determination that you are a registrant. There is no SEC reporting ladder.

Does the four-business-day clock start at discovery?

No. The clock starts at the materiality determination, not discovery, not GDPR-style awareness, and not CRA manufacturer-awareness. Instruction 1 separately requires that determination without unreasonable delay after discovery. This page does not convert that phrase into hours. Not legal advice.

Is Item 1.05 the same as Item 8.01 or Item 106?

No. Item 1.05 is the material-incident current report. Item 8.01 is other events; the 21 May 2024 staff statement encourages it for incidents not determined material. Item 106 is annual 10-K risk-management, strategy, and governance disclosure. Filing one never discharges the others. Not legal advice.

Does paying a ransom mean the incident is not material?

Not by itself. C&DIs 104B.05–104B.08 (staff interpretations, 24 June 2024): cessation after payment does not relieve the materiality determination or, once materiality is determined, the Item 1.05 filing; insurance reimbursement and payment size are not by themselves determinative. Those CDIs are not the Form. Counsel applies YOUR facts. Not legal advice.

Does a state breach notice discharge Item 1.05?

No. State individual, attorney-general, and credit-bureau notices are different recipient classes on different clocks. Item 1.05 does not discharge them, and they do not discharge Item 1.05. The US-state-laws guide on this site is the representative high-variance comparison. Not legal advice.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.