HireACISO

SEC cyber disclosure for Canadian firms

If your company files with the SEC, cybersecurity is a disclosure obligation with a four business day clock on material incidents and an annual description of how the board oversees cyber risk. If you are a Canadian private company selling into the United States, none of it binds you and all of it reaches you anyway, through your customers' diligence.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

The SEC's cybersecurity rules do two things. Item 1.05 of Form 8-K requires a domestic registrant to disclose a cybersecurity incident it has determined to be material within four business days of that materiality determination, describing the nature, scope and timing and the material impact or reasonably likely material impact. Regulation S-K Item 106 requires an annual description of the processes for assessing and managing material cyber risk, board oversight of that risk including which committee holds it, and the role and relevant expertise of the management people responsible.

Canadian companies fall into three groups with very different obligations.

How SEC cyber disclosure reaches Canadian companies
You areWhat appliesThe practical burden
A Canadian company filing as a US domestic registrant Item 1.05 of Form 8-K and Regulation S-K Item 106 in full Four business day incident clock and annual governance disclosure. The heaviest case
A foreign private issuer, including most MJDS filers Form 6-K for material incidents you disclose or make public elsewhere, and Form 20-F Item 16K for annual governance. MJDS filers report on Form 40-F, driven by Canadian continuous disclosure No fixed four day federal clock, but Canadian materiality and prompt disclosure duties apply, and once you disclose in Canada you furnish it in the United States
A Canadian private company selling to US public companies Nothing directly Everything indirectly. Your customers need to know within their own clock, so their contracts push short notification windows and governance questions onto you

The third row is why most readers are here

A US-listed customer that cannot assess materiality quickly cannot meet its own four day obligation, so it pushes the problem up the supply chain. That is the mechanism behind the 24 to 72 hour incident notification clauses now standard in enterprise agreements, and behind questions about who your accountable security person is and what your board sees. You are not being regulated. You are being made auditable by someone who is.

The four day clock does not start where people think

It starts on the determination of materiality, not on discovery, and the rule says that determination must be made without unreasonable delay. That distinction is the whole compliance problem. Deciding slowly to buy time is the failure mode the rule was written to catch, and a timeline showing three weeks between "we knew" and "we determined" draws attention.

Materiality is the ordinary securities standard: would a reasonable investor consider it important. It is not a record count and there is no volume threshold, which frustrates security teams who want one. An incident touching a small number of records in a critical system can be material and a large volume of low-sensitivity data may not be. What a company needs, and what most do not have, is a written process saying who convenes, on what evidence, within what window, and how the decision is recorded. Building that process is normal vCISO work and it belongs next to the incident response plan rather than in a separate legal binder nobody opens during an incident.

What Item 106 forces a board to be able to say

The annual disclosure is short, which makes it revealing. It has to describe processes, board oversight and management expertise, and none of those can be invented in the week the filing is drafted. The disclosure has to be accurate and the audit committee signs off on it.

Processes for assessing and managing material cyber risk
A described risk process, not a list of tools. It has to connect to the company's overall risk management. This is what a risk register is for.
Whether risks have materially affected or are reasonably likely to materially affect the business
An honest statement about strategy, operations and financial condition. Boilerplate here is what draws comment letters.
Board oversight, and which committee
Naming the committee is the easy part. Being able to show it received something four times a year, with minutes, is the part companies fail. See CISO board reporting.
Management's role and relevant expertise
Who is responsible, what their background is, and how they inform the board. A company with no named security leader has to write that sentence, and it reads exactly as badly as it sounds.

The last item is the one that turns a disclosure rule into a hiring decision. It does not require a full-time employee, a CISO title or any certification. A named accountable executive supported by a fractional security leader is disclosable and defensible, provided the accountability sits inside the company and the expertise is real. Describing an outside retainer as your management expertise, with nobody internal accountable, is not.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

What Canadian securities law asks in parallel

Canada has no equivalent prescriptive cyber disclosure rule. What it has is the general continuous disclosure obligation: a material change is disclosed promptly by news release and material change report, and CSA staff have published guidance expecting cybersecurity risk disclosure to be specific to the issuer rather than generic risk factor boilerplate. In practice a cross-listed Canadian issuer ends up running to the stricter of the two, because disclosing in Canada triggers furnishing in the United States, and because investors compare the two documents.

For a federally regulated financial institution there is a third clock entirely, since OSFI expects prompt notification of reportable technology and cyber incidents to your lead supervisor. Those criteria are different again, and running three notification tests during an incident is why they get written down in advance. See vCISO work for OSFI regulated institutions.

What to actually build

  1. Write the materiality determination process before you need it: who convenes, how fast, what evidence they see, and how the decision and its timing are recorded. One page.
  2. Put the securities clock inside the incident plan, beside the PIPEDA and Law 25 assessments and the contractual notification windows. Four separate documents guarantee one gets missed.
  3. Fix the board cadence now. Four sessions a year with minutes that show what was presented is the evidence Item 106 rests on, and it cannot be created retroactively.
  4. Name the accountable executive and be able to describe their expertise in two sentences that survive reading by an investor.
  5. Read your customer contracts for the notification windows you have already agreed to. Most companies have signed shorter clocks than any regulator imposes and have never counted them.
  6. Rehearse it. A tabletop that includes the disclosure decision, not just the technical response, is the only way to find out that your general counsel and your security lead disagree about what material means.

What this adds to a security budget

Incremental annual cost of SEC-driven cyber governance, Canadian company, CAD
ItemTypical costWho does it
Materiality process and disclosure controls design$8,000 to $25,000 one timevCISO with securities counsel
Quarterly board and audit committee reporting$18,000 to $50,000 per yearSecurity leadership, 3 to 6 hours a month
Annual disclosure drafting support$5,000 to $15,000Security leadership plus counsel
Tabletop including the disclosure decision$8,000 to $20,000 per yearExternal facilitation is worth it here
Added per year, after the first$31,000 to $85,000Mostly leadership time

Find security leadership that has filed before

Tell us your filing status and your timeline. We will put it in front of Canadian providers who have taken a public company through this.

Get matched

Common questions

Do SEC cybersecurity rules apply to Canadian companies?

They apply if you file with the SEC. A Canadian company filing as a US domestic registrant is subject to the Form 8-K Item 1.05 four business day incident disclosure and the Regulation S-K Item 106 annual governance disclosure. A foreign private issuer, including most MJDS filers, uses Form 6-K and Form 20-F Item 16K or reports on Form 40-F driven by Canadian continuous disclosure. A Canadian private company is not covered at all, though its US-listed customers will push the obligation into the contract.

When does the four business day clock start?

On the determination that an incident is material, not on discovery, and the determination itself must be made without unreasonable delay. Deferring the determination to buy time is the specific behaviour the rule targets. Keep a timestamped record of when you learned what and when you decided, because the gap between those two dates is what gets examined.

Does Item 106 require us to have a CISO?

No. It requires you to describe management's role in assessing and managing cyber risk and the relevant expertise of the people responsible. It does not name a title, mandate a full-time employee or require a certification. A named internal executive who is accountable, supported by a fractional security leader with real depth, is disclosable. Having nobody to name is the problem, because the sentence you are left writing tells investors exactly that.

We are a Canadian supplier to a US-listed company. What will they ask us for?

Incident notification inside 24 to 72 hours of discovery rather than of materiality, a named security contact, evidence of board or executive oversight, and often audit rights. The reason is that they cannot assess materiality on their own four day clock without knowing quickly. Treat the notification window as a real operational commitment, since it is usually the shortest clock you are subject to.

What about the UK and EU equivalents?

Different mechanism, similar direction. NIS2 places duties on management bodies of in-scope entities to approve cyber risk management measures and to follow training, with personal liability attached, and DORA imposes detailed ICT risk and incident reporting requirements on EU financial entities and their critical technology suppliers. A Canadian company selling into both markets typically ends up with one governance model built to the strictest requirement rather than three parallel programs.