How the rules apply to smaller reporting companies
Smaller Reporting Companies (SRCs) are subject to the same core cybersecurity disclosure requirements as larger public companies. This includes reporting material cybersecurity incidents on Form 8-K and providing annual disclosures in Form 10-K regarding risk management, strategy, and governance.
What it means
The SEC has not provided a general exemption for SRCs from these rules because cybersecurity risks can be material regardless of a company's size. In practice, this means an SRC must have the same capability to identify "material" incidents and disclose them within the required timeframe as any other public entity.
While the complexity of an SRC’s cybersecurity program may be smaller than that of a large corporation, the disclosure obligation is binary: if an incident is material, it must be reported. Similarly, the annual disclosures regarding governance must reflect the actual structure of the company; for example, if the board handles oversight directly rather than through a dedicated committee, that specific arrangement must be documented and disclosed.
How to meet it
- Establish a formal process for determining "materiality" that involves both technical staff and legal/financial stakeholders.
- Update the Incident Response Plan (IRP) to include a specific trigger and workflow for notifying the legal team to evaluate SEC reporting obligations.
- Document the company's cybersecurity risk management strategy, including how it identifies risks and manages third-party provider vulnerabilities.
- Define and record the governance structure: identify which individual or committee is responsible for overseeing cyber risks and how they are informed of those risks.
- Create a recurring calendar invite or checklist for annual 10-K filings to ensure cybersecurity disclosures are updated based on changes in strategy or governance throughout the year.
Evidence an auditor asks for
- Materiality assessment memos that document the reasoning used to decide whether a specific incident was material or non-material.
- A written Incident Response Plan that explicitly references SEC disclosure timelines and requirements.
- Board of Directors or Audit Committee meeting minutes showing evidence of cybersecurity oversight and risk reviews.
- Documentation of the framework (e.g., NIST, ISO) or internal standards used to manage cyber risks as described in the 10-K.
Common pitfalls
- Assuming that "Smaller Reporting Company" status provides an exemption from these specific rules; it does not.
- Relying solely on technical severity scores (e.g., CVSS) to determine materiality instead of considering financial, operational, and reputational impacts.
- Failing to document the *process* of determining non-materiality, leaving the company unable to prove why a reported incident was omitted from an 8-K filing.