CISO Tribune

Guide

SEC Item 1.05 Materiality Decision Guide: Is This Incident Reportable?

A step-by-step decision aid for the SEC's Item 1.05 materiality call: the reasonable-investor test, why discovery does not start the four-business-day clock, and when an incident belongs under Item 8.01 instead. Not legal advice.

By Hadass Liza Bitton · Published October 9, 2026 · Last reviewed October 9, 2026 · 6 min read

TL;DR: Item 1.05 of Form 8-K is not triggered by discovering a cybersecurity incident; it is triggered by the company determining the incident is material, a call the SEC says must be made "without unreasonable delay" but is not on any fixed timer itself. Once that determination is made, the four-business-day filing clock starts. The test is whether a reasonable investor would consider the incident important, weighing both quantitative and qualitative factors, not a dollar threshold. An incident not yet assessed, or assessed and found immaterial, belongs under Item 8.01 instead, per the SEC Division of Corporation Finance's May 2024 statement. This page walks the decision in order; it is not legal advice, and every live call belongs with counsel.

Start here: what question are you actually answering?

Companies that stumble on Item 1.05 usually stumble on sequencing, filing as soon as an incident looks serious rather than once it is determined material. The SEC's own May 2024 statement from Erik Gerding, Director of the Division of Corporation Finance, exists because this was happening in the rule's first months: "Item 1.05 is not a voluntary disclosure, and it is by definition material because it is not triggered until the company determines the materiality of an incident." Filing it early, for an incident whose materiality has not actually been assessed, works against the rule's intent rather than satisfying it.

So the first question is not "did something happen," it is "have we finished deciding whether this is material." Everything below follows from that, per the SEC's own small entity compliance guide and the Gerding statement that corrected early over-filing.

Step 1: Has a materiality determination been made yet?

If the answer is no, Item 1.05 is not due yet, but the clock on making the determination is already running. The compliance guide is specific that the assessment must happen "without unreasonable delay" once the company has gathered enough facts to evaluate it; a company cannot sit on an open question indefinitely and call that compliance. There is no fixed number of days for this step the way there is for the four-business-day filing clock; the standard is reasonableness given what is known and how fast it could reasonably be learned.

While the determination is pending, nothing requires silence. The incident can still be disclosed under a different Form 8-K item if the company chooses to, which leads into Step 3 below.

Step 2: Apply the reasonable-investor test

Once there are enough facts to decide, the question is the same test used for materiality everywhere else in securities law, applied to this incident: would a reasonable investor consider it important, or would it significantly alter the total mix of information already available to the market? The Division of Corporation Finance's statement is explicit that this is not a financial-statement-only question: companies "should consider qualitative factors alongside quantitative factors," and the assessment is not limited to "financial condition and results of operation."

In practice, that means weighing things that do not show up on a balance sheet next to the things that do:

  • Quantitative: remediation cost, revenue at risk, contractual penalties, insurance recovery gaps.
  • Qualitative: reputational harm, likely regulatory or litigation exposure, competitive harm from exposed data, and whether the incident undermines confidence in a control the company has publicly represented as reliable (a point the annual Item 1C governance disclosure, covered in CISO Tribune's guide to the SEC's disclosure rules, puts on the public record every year).

If, weighing both, a reasonable investor would plausibly see this as changing the picture, the incident is material. Go to Step 3's "yes" branch.

Step 3: Route the filing

If material: Item 1.05, four business days from the determination date. The compliance guide's language is direct: the filing must come "within four business days of the registrant determining that a cybersecurity incident is material." That is four business days from the day in Step 2 where the answer became yes, not four business days from discovery, not from when law enforcement was notified, and not from an internal briefing.

If not yet determined, or determined not material: Item 8.01, not Item 1.05. The Gerding statement names this directly: for an incident where the company "has not yet made a materiality determination," or one it "determined was not material," the staff "encourages the company to disclose that cybersecurity incident under a different item of Form 8-K (for example, Item 8.01)." Item 8.01 is the general "Other Events" item; using it here signals an incident worth disclosing without asserting the Item 1.05 materiality finding the market would read into that specific item number.

If a later fact changes the answer: amend, on the same four-day clock. Materiality calls are not necessarily final the day they are made. If new information surfaces that turns a previously immaterial or undetermined incident into a material one, the Gerding statement says the company "should file an Item 1.05 Form 8-K within four business days of such subsequent materiality determination." The clock restarts from the new determination, not from the original incident.

What does not pause or excuse the clock

Two things commonly get treated as off-ramps and are not, under the sources this guide cites:

  • Containing the incident. Nothing in the compliance guide or the Gerding statement ties the materiality determination to whether the incident is still active. An incident that looks resolved can still turn out to be material once its scope and impact are known; "it's over now" is not itself a materiality answer.
  • Wanting more time to investigate. The determination must be made "without unreasonable delay" once there are enough facts to assess it. An open investigation does not, on its own, justify indefinitely deferring the determination; the standard is what a reasonable timeline for assessment looks like given the facts in hand.

The one real delay valve, and it is not the company's call

There is exactly one way to legally delay a material disclosure past the four-business-day clock, and the company cannot invoke it on its own. The compliance guide describes it: the U.S. Attorney General must determine that disclosure "poses a substantial risk to national security or public safety" and notify the SEC of that determination in writing. If that happens, the guide describes an initial delay of up to 30 days, a possible additional 30-day extension, and, in extraordinary circumstances, a final 60-day delay if the Attorney General finds the risk is still substantial. This is a Department of Justice national-security determination, not a business judgment about reputational or competitive harm, however severe.

What this guide does not cover

Item 1.05 itself comes from the SEC's July 26, 2023 rule adoption, Release No. 33-11216, effective September 5, 2023. This page is about the Item 1.05 incident-disclosure decision only. It does not cover the separate, calendar-driven Item 1C annual governance disclosure, which CISO Tribune's SEC disclosure rules guide covers in full, and it is not a substitute for a company's own incident response plan, disclosure controls, or counsel. The sources cited here are the SEC's own compliance guide and a Division of Corporation Finance staff statement; a staff statement, as the Gerding statement itself notes, is not a Commission rule, and neither document is exhaustive legal interpretation for a specific company's facts.

The honest version

The materiality decision is a two-step process the rule splits cleanly: first, decide if it is material, on no fixed clock but "without unreasonable delay"; second, if yes, file within four business days of that decision. Everything that is not yet decided, or decided no, goes to Item 8.01 instead of Item 1.05, and the only way past the four-day clock once a determination is made is a Department of Justice national-security finding, not an internal judgment call. None of this replaces counsel on an actual incident; it is a map of the question the SEC itself has published twice, once as a compliance guide and once as a staff correction to early, over-cautious filings.

Frequently asked questions

What triggers the SEC's four-business-day disclosure clock?
The company's own determination that a cybersecurity incident is material, not the date the incident was discovered. The SEC's compliance guide states the Item 1.05 filing is due "within four business days of the registrant determining that a cybersecurity incident is material," and that determination itself must be made "without unreasonable delay" once the company has enough facts to assess it.
How does a company decide if an incident is material?
By applying the reasonable-investor test the SEC's Division of Corporation Finance described in its May 2024 statement: whether there is a substantial likelihood a reasonable shareholder would consider the incident important, or whether it would have significantly altered the total mix of information available, considering both quantitative and qualitative factors, not financial impact alone.
What happens if an incident has not been assessed yet, or was assessed and found not material?
The SEC's Division of Corporation Finance statement says the staff "encourages the company to disclose that cybersecurity incident under a different item of Form 8-K (for example, Item 8.01)," naming Item 8.01 as the venue for incidents not yet determined material or already determined not material. If a later materiality determination changes that, the statement says the company should then file an Item 1.05 Form 8-K within four business days of that new determination.
Can a company delay disclosure of a material incident?
Only if the U.S. Attorney General determines disclosure would pose a substantial risk to national security or public safety and notifies the SEC in writing. The compliance guide describes an initial delay of up to 30 days, one possible 30-day extension, and, in extraordinary circumstances, a final 60-day delay if the Attorney General finds the risk is still substantial.
Is this decision guide legal advice?
No. It explains, with citations, what the SEC's own compliance guide and staff statement say about the Item 1.05 decision. Every real materiality call should go through counsel and the company's own disclosure controls; this page is a starting map of the question, not a ruling on any specific incident.

Sources

Hadass Liza Bitton

Writer

Hadass Liza Bitton is a writer at CISO Tribune covering security leadership: the people who take the top security seat, the ones who leave it, and what each move signals. Reach her at hadass@cisotribune.com.

The Briefing

Every verified CISO move of the week, in your inbox Friday.

Every verified CISO move and one piece of analysis, weekly.

Unsubscribe any time. See the privacy policy.