What the SEC Cybersecurity Disclosure Rules Mean for Your Vendor Risk Program

If your company is publicly traded, or if you work with companies that are, the SEC’s cybersecurity disclosure rules have raised the stakes for vendor risk management in a concrete way.

Since the rules took effect in late 2023, public companies have been required to disclose material cybersecurity incidents on Form 8-K and describe their cybersecurity risk management practices — including how they handle third-party risk — in their annual Form 10-K filings.

That last part matters for vendor risk teams. The rules do not just apply to incidents that originate inside your organization. If a vendor breach causes a material impact to your business, that disclosure obligation likely applies. And your 10-K now needs to describe the process you use to manage vendor-related cyber risk.

This post breaks down what the rules actually require, how they apply to third-party and vendor risk specifically, and what your program needs to have documented to be in a defensible position.

What the SEC Rules Require

The SEC adopted its final cybersecurity disclosure rules in July 2023. They apply to domestic public companies registered with the SEC. Here is what those rules require at a high level.

Form 8-K Item 1.05: Incident Disclosure

When a public company determines that a cybersecurity incident is material, it must file a Form 8-K under Item 1.05 within four business days of that determination.

The disclosure must include:

  • The nature, scope, and timing of the incident
  • The material impact, or reasonably likely material impact, on the company

The rules do not set a fixed threshold for what counts as material. Materiality follows the standard SEC definition: information that a reasonable investor would consider important when making an investment decision. Whether an incident clears that bar is a judgment call that requires legal, finance, and risk teams to work together.

Important: the four-day clock starts when materiality is determined, not when the incident is discovered. That distinction gives companies some runway, but it also requires a documented process for making and recording that determination.

Form 10-K: Annual Cybersecurity Disclosures

In their annual reports, public companies must now include disclosures covering:

Risk management and strategy: A description of the processes the company uses to assess, identify, and manage material cybersecurity risks — including risks that arise from third-party service providers.

Governance: A description of board oversight of cybersecurity risk and management’s role in assessing and managing that risk. This includes identifying whether and how the board or a board committee receives information about cybersecurity risks.

These are not checkbox disclosures. The SEC expects them to be substantive and company-specific, not boilerplate language copied from a template.

Where Third-Party and Vendor Risk Fit In

The rules specifically call out third-party service providers as a category of risk that must be addressed in 10-K disclosures. This is not incidental — regulators have watched high-profile supply chain and vendor-related incidents cause material harm to public companies for years, and they want to know that companies have a process for managing that exposure.

Here is what that means in practice for vendor risk programs.

Third-Party Incidents Can Trigger 8-K Disclosure

If a vendor you rely on experiences a cybersecurity incident and that incident causes a material impact to your business — disrupted operations, compromised data, significant financial exposure — you may be required to file an 8-K even though the breach did not happen in your own environment.

This means vendor risk teams need to be plugged into incident response workflows. When a vendor reports a breach or an incident comes to light through external channels, someone needs to assess whether the impact to your company meets the materiality threshold and escalate accordingly.

Your 10-K Must Describe Your Third-Party Risk Process

The annual disclosure requirement asks companies to describe how they manage cybersecurity risks from third-party service providers. That requires having an actual, documented process to describe.

Vague language about “monitoring vendor relationships” or “requiring vendors to maintain security standards” is unlikely to satisfy an investor relations review, an auditor, or the SEC. The disclosure should reflect a real program: how you identify which vendors pose material risk, what due diligence you conduct, how you handle findings, and how you monitor over time.

If your vendor risk program is informal, undocumented, or limited to an annual questionnaire, the 10-K disclosure requirement is a strong reason to formalize it.

Board Reporting Now Has a Compliance Dimension

The governance section of the 10-K requires companies to describe how the board is informed about cybersecurity risk. If your vendor risk program surfaces significant findings, those findings may need a path to board-level reporting.

For many risk teams, this is new territory. It means thinking not just about how you assess vendors, but about how you communicate material vendor risk to senior leadership in a way that is documented and consistent.

Based on the disclosure requirements, here is a practical checklist of what a vendor risk program at a public company — or a company whose clients include public companies — should be able to demonstrate.

What Your Program Needs to Have Ready

A documented vendor risk management process. This means written policies and procedures that describe how you identify in-scope vendors, what due diligence you conduct, and how you handle risk findings. The process does not need to be elaborate, but it does need to exist in writing.

A vendor inventory with risk tiering. The 10-K disclosure is more credible and defensible when a company can point to a structured approach to identifying which vendors present material cyber risk. Tiering vendors by access level, data sensitivity, and operational dependency is a foundation for this.

A materiality assessment process for vendor incidents. When a vendor breach occurs, you need a defined process for assessing whether the impact to your company is material and for escalating that determination to legal and finance teams within a timeline that supports the four-day 8-K window.

Documentation of due diligence activities. Questionnaire responses, assessment findings, remediation tracking, and evidence review should be documented and retained. In the event of an SEC inquiry or litigation, documentation of your process is what demonstrates you took a reasonable approach.

Board or executive reporting cadence. If your vendor risk program identifies significant or material risks, there should be a documented path for escalating those findings to senior leadership or the board.

Key Takeaways

  • The SEC’s cybersecurity disclosure rules require public companies to disclose material incidents within four business days of determining materiality — and third-party incidents can qualify.
  • Annual 10-K filings must describe the company’s process for managing cybersecurity risk from third-party service providers. That requires having a real, documented process.
  • Vendor risk teams need to be connected to incident response workflows so that vendor breaches can be assessed for materiality quickly.
  • Board-level reporting of cybersecurity risk is now a disclosure requirement, which gives vendor risk programs a reason to develop consistent executive communication practices.
  • If your vendor risk program is undocumented or limited in scope, the 10-K requirement is a practical forcing function to formalize it.

FAQ

Q: Do the SEC cybersecurity disclosure rules apply to private companies? The rules apply to companies registered with the SEC — primarily public companies. However, private companies that are vendors to public companies may face increased scrutiny because their clients are now required to describe how they manage third-party cyber risk. If you are a vendor to public companies, expect more rigorous due diligence requests.

Q: What counts as a “material” cybersecurity incident under the SEC rules? The SEC applies its standard materiality definition: information that a reasonable investor would consider important. There is no fixed dollar threshold or specific criteria. Factors typically considered include financial impact, operational disruption, reputational harm, and the sensitivity of any data compromised. Each incident requires a documented judgment call involving legal, finance, and risk teams.

Q: Does the four-day disclosure clock start when the incident is discovered or when it is determined to be material? The clock starts when the company determines that the incident is material, not when it is first discovered. This makes the materiality determination process itself a critical step — it needs to happen promptly and be documented, because the timing of that determination affects the disclosure deadline.

Q: What should a 10-K disclosure about third-party risk management actually say? The SEC expects company-specific, substantive disclosures rather than generic language. A strong disclosure would describe how the company identifies which third parties present material risk, what due diligence processes it uses, how it monitors vendors over time, and how significant findings are escalated. Boilerplate language is unlikely to satisfy investors, auditors, or regulators. (Verify specific disclosure language with your legal and investor relations teams.)

Q: If a vendor we use gets breached but we are not sure yet whether it affected us, do we need to file an 8-K? The obligation to file is triggered when materiality is determined, not when an incident at a vendor is first reported. If you learn of a vendor breach, you should assess the potential impact to your business and document that assessment. If you conclude the impact is not material, document that conclusion and the reasoning. If the situation is unclear, involve legal counsel promptly.

Q: How often do we need to update our 10-K disclosures about vendor risk? The 10-K is filed annually, so the cybersecurity risk management disclosures are updated each year. If your vendor risk program changes materially during the year, those changes should be reflected in the next annual filing. Some changes may also warrant disclosure in interim filings depending on their nature. (Verify with your legal and investor relations teams.)

Contact Us

Let’s explore how Sling can work for you.