← Back to blog

2026-09-23

The Item 1.05 cyber 8-K: four business days, starting on a date you pick

If your company experiences a cybersecurity incident and determines it is material, Form 8-K Item 1.05 is due within four business days of that determination — not four business days after the incident happened, and not four business days after you found out about it. That one distinction is the whole rule, and most summaries of it get the starting point wrong.

The clock, exactly as the form states it

General Instruction B.1 to Form 8-K is specific about where the four days start: "A report pursuant to Item 1.05 is to be filed within four business days after the registrant determines that it has experienced a material cybersecurity incident." Determination, not discovery. That sounds like it gives a company room to work. It is closer to the opposite: the deadline is set by a decision the company itself makes, and a company that makes that decision late has an exposure with no fixed number attached to it. Instruction 1 says the determination itself "must be made without unreasonable delay after discovery of the incident" — a real requirement, but one with no day count in it.

Two worked examples

A clean four days. Incident discovered Monday, 2 March 2026. Company determines it is material on Thursday, 5 March 2026. Counting business days from the determination — Friday 6th, Monday 9th, Tuesday 10th, Wednesday 11th — the filing is due Wednesday, 11 March 2026. Discovery to determination was three days; the filing clock itself never touched discovery at all.

A holiday inside the window. Determination made Tuesday, 30 June 2026. Wednesday 1 July and Thursday 2 July count. Friday 3 July does not — Independence Day, 4 July, falls on a Saturday in 2026, so the federal holiday is observed on the preceding Friday, and observed holidays are non-business days for this purpose. Monday 6 July and Tuesday 7 July are the remaining two counted days, which puts the filing due Tuesday, 7 July 2026 — one calendar day later than a holiday-free week would produce, because the holiday removed a working day rather than adding one to the count.

The exposure with no number in it

A long gap between discovery and determination does not move the four-day deadline — the deadline still runs from whenever the determination actually happens, even 60 or 90 days later. What changes is the second question: was that gap itself unreasonable? Nothing in the rule scores that, but nothing about it is invisible either. The 8-K states the determination date, EDGAR stamps the filing date, and the incident-response timeline, the insurer notification and the first internal email using the word "material" all exist somewhere. A company that waits a long time to determine materiality is not avoiding the four-day clock — it is trading a bright-line deadline for a standard that gets argued afterward, by someone who already knows how the incident turned out.

One incident can be several intrusions

Item 106(a) of Regulation S-K (17 CFR 229.106(a)) defines a cybersecurity incident as "an unauthorized occurrence, or a series of related unauthorized occurrences." Several small intrusions by the same actor, each individually assessed and found immaterial on its own, can together be one incident that is material — and if they are related, the materiality assessment has to be made on the series, not on each piece separately. A file of careful individual decisions, none of them wrong on its own terms, is not the same as having asked the question the rule actually asks.

Neither delay is something a company grants itself

Two provisions can push the due date back, and both require someone outside the company to act first. Item 1.05(c): the Attorney General determines that disclosure poses a substantial risk to national security or public safety and notifies the Commission in writing — an open investigation or a law-enforcement request on its own is not this. Item 1.05(d): a narrower delay tied to 47 CFR 64.2011, capped at seven business days after the required notification, and it only holds if correspondence reaches EDGAR by the original due date. A company that believes it is inside a delay it never actually obtained is worse off than one that simply filed late, because the record will show it knew the date.

What this does not tell you

Whether an incident is material at all is a judgment about the total mix of information available to a reasonable investor, and no calculator can make that call for you. What a deadline tool can do is get the arithmetic right once the determination is made, hold the real federal holiday calendar rather than a generic weekday count, and put the discovery-to-determination gap in front of you instead of letting it go unmeasured. We built one that does exactly that — it runs the same business-day count shown above against the real calendar, and it separates the deadline it can compute from the "unreasonable delay" question it deliberately will not score. It lives at unfoldcfo.com/tools/cyber-materiality.

Sources. Form 8-K, General Instruction B.1 and Item 1.05 with its Instructions 1–4, as published at sec.gov. 17 CFR 229.106(a), eCFR. General information, not legal advice — securities counsel owns the materiality judgment and any decision about a specific incident.

The Item 1.05 cyber 8-K: four business days, starting on a date you pick | UnfoldCFO