The SEC's cybersecurity disclosure regime is three rules, not one. Every M&A deal that touches a public acquirer or a soon-to-be-public target triggers at least one of them. The disclosure question surfaces twice in the life of a deal: first, when a material cyber incident is discovered during diligence, and again after close, when the acquirer files its next 10-K and has to account for what it now owns. Deal teams that route cyber diligence as an operational exercise and hand SEC disclosure to outside counsel as a separate workstream usually find out at the wrong moment that the two were the same workstream.
The Bain Capital / PowerSchool ruling in March 2026 sharpened the stakes. A federal court in the Southern District of California allowed five claims against Bain to proceed on the theory that pre-close operational control over PowerSchool's cybersecurity created a separate liability track for the acquirer, independent of the target's own disclosure duty. Everything downstream of that ruling, from how the diligence memo gets written to what covenants live in the term sheet to what the audit committee actually reviews, has to account for it.
The three rules that create the M&A cyber disclosure duty
All the mechanics that follow reduce to how these three rules interact when a public company is either the acquirer, the target, or the successor entity after close.
The SEC deliberately did not define materiality quantitatively. The determination follows the TSC Industries v. Northway (1976) standard: information is material if there is a substantial likelihood that a reasonable investor would consider it important. The SEC's adopting release specifically rejected commenter requests for a numeric threshold. In practice, the enforcement bar has been set by SolarWinds and Yahoo. A breach affecting hundreds of millions of accounts or the integrity of a core product line is material almost by inspection. The harder cases are targets with mid-sized incidents (5,000 to 50,000 records, or a limited-blast-radius intrusion) where the materiality memo has to do actual work.
When the disclosure clock starts during deal negotiations
The 4-business-day Item 1.05 clock starts on the day the registrant determines the incident is material. The clock does not start on the day of the incident or the day of discovery. This distinction matters enormously in M&A. The SEC has been explicit that a company cannot delay materiality determination to avoid disclosure, but it also cannot rush it before it has the facts.
- Public target discovers an incident mid-deal: The target is a public company. An incident is discovered during exclusivity. The target's board makes the materiality determination, not the acquirer, not the deal team. Once determined material, the target has 4 business days to file. This will almost always require the deal to be publicly acknowledged in the 8-K narrative, ending confidential negotiation. The deal team's leverage on this timing is zero; the target's counsel controls it.
- Public acquirer discovers an undisclosed incident at a private target: The private target has no direct SEC obligation. The acquirer does. If the incident is material to the acquirer's investment thesis or to the combined entity's projected posture, the acquirer's Item 1.05 clock starts when the acquirer's board determines materiality. The 4-day window is on the acquirer, even though the incident occurred pre-signing at an entity the acquirer does not yet own.
- Both entities are public, deal has been announced: Both companies have independent disclosure duties. If the incident affects the target, the target files. If the disclosure materially changes the acquirer's investment case (for example, the CCOD moves by 15% or more of consideration), the acquirer may need to file separately or amend prior deal disclosures. This is where sequencing between the two GCs has to be coordinated hour-by-hour.
- Post-signing, pre-close discovery: The signing has been publicly announced. The deal has not closed. An incident surfaces at the target. The target files if it is public. The acquirer's obligation depends on whether the incident is material to the acquirer's already-disclosed deal terms; MAC clauses, price adjustment triggers, and financing covenants become the operative documents alongside the 8-K analysis.
Post-close: when the acquirer inherits the disclosure obligation
The day after close, the acquirer owns the target's cyber history. Reg S-K Item 106 requires the acquirer's next 10-K to describe the combined entity's risk management, governance, and any material prior incidents. The SEC's 2023 adopting release specifically addresses this: a prior incident at an acquired entity that is material to the combined registrant on a going-forward basis is disclosable, even if it occurred before the acquirer owned the entity.
Some deal teams operate on a working assumption that pre-close incidents at a private target die at signing, that the acquirer inherits only the entity's forward-looking risk and not its historical disclosure exposure. That is wrong. The SEC's Reg S-K Item 106(b)(1)(iv) requires disclosure of prior material incidents at the registrant, and the enforcement pattern (Yahoo 2018, SolarWinds 2023, R.R. Donnelley 2024) has consistently treated the successor entity as inheriting the underlying disclosure obligation. And the private-status shield is narrower than it looks even during independence: the March 2026 Bain Capital / PowerSchool ruling allowed five separate claims against a PE acquirer to proceed on the theory that pre-close operational control over the target's cybersecurity creates its own liability track, independent of any disclosure duty. Two separate doctrines, one shared diligence record.
What the diligence deliverable must contain to support a defensible filing
The gap between "we bought cyber diligence" and "we have a diligence package our GC can rely on for a 4-day Item 1.05 disclosure decision" is where deals get into trouble. A qualitative red/yellow/green heat map does not support a materiality memo. The package the audit committee needs contains six specific artifacts, all sourced during diligence.
- A quantified Cyber Cost of Deal with documented methodology: The Annual Loss Expectancy across the five diligence pillars (attack surface, third-party concentration, data sensitivity, insurability, remediation), computed with sourced probabilities (IBM CODB, Verizon DBIR, Ponemon) and named asset values. This is the number the materiality memo compares against the transaction consideration to argue material-or-not. A worked example shows the shape. Without it, the memo relies on adjectives, which the SEC has explicitly rejected as insufficient.
- A 36-month incident history at the target, with regulatory notification log: Every reportable event in the trailing 36 months: date, nature, scope, customer notification, regulatory notification (HIPAA, GDPR, state AG, any FTC or SEC touchpoint), and resolution cost. Self-reported and third-party-detected incidents both included. Any 'we don't have that' answer from the target is itself a diligence finding; the SEC's Reg S-K disclosure requires the acquirer to know this.
- A named list of critical vendors with change-of-control clauses and incident SLAs: Verizon 2025 DBIR reports third-party involvement in 30% of breaches. If the target's top-10 vendors include SLAs for incident notification that would flow through to the combined entity, those SLAs are part of the disclosure calculus. A vendor-side breach where the target is a downstream customer is inheritable exposure.
- An assessment of the target's Reg S-K Item 106 compliance if the target is public: The target's own risk-management, governance, and board-oversight disclosures under Item 106 are a diligence input. Gaps here (a shallow governance section, missing risk-management process description, unrelated-party board oversight) are red flags that materially higher enforcement risk exists post-close.
- Insurance policy analysis with named exclusions: The active cyber insurance policy, aggregate limit, retention, war/nation-state exclusion language, prior-acts coverage cutoff, and notification requirements. Coverage that lapses on change-of-control (some carriers) or that names the pre-close entity as insured (most) has to be repapered before close, or the combined entity is exposed on Day 1.
- A written materiality memo template pre-approved by acquirer's SEC counsel: The 4-business-day Item 1.05 window does not give the deal team time to draft the memo structure from scratch when an incident surfaces. The template (with the TSC Industries standard applied, the CCOD-vs-consideration ratio, the comparison to enforcement precedent) should exist in the diligence data room before signing so it can be populated in hours, not days, if an incident is discovered.
Four cases every deal team should know cold
The enforcement pattern is short but instructive. All four cases involve M&A or successor-liability dynamics.
The private-target twist
The SEC's rules apply to public registrants. A private target has no direct Item 1.05 or Reg S-K Item 106 obligation. That does not make the disclosure question go away in the deal.
What survives to the public acquirer
The acquirer's Reg S-K Item 106 duty on its next 10-K applies to the combined entity. Prior material incidents at the private target become disclosable if they are material to the combined registrant. The private-status shield covered the target during its independent life; it does not cover the incident forever. The 2023 SEC adopting release makes this explicit: the successor entity's disclosures include the acquired business's history to the extent material.
What surfaces at IPO or exit
Private targets pursuing an IPO or an exit to a public strategic acquirer will surface prior incidents in the S-1 or in the acquirer's diligence. The private-company period is a runway, not a permanent immunity. Companies that treat pre-IPO diligence as the moment to first assemble a comprehensive incident history typically discover during the S-1 process that the timeline is too compressed and the disclosure ends up broader than a properly maintained record would have required.
What good looks like: the disclosure package the audit committee should demand
By the time the deal reaches the acquirer's audit committee, the cyber diligence workstream should have delivered a package that lets the committee answer three specific questions without further discovery:
- Is there a material cyber incident at the target that has not been disclosed?: Answered by the 36-month incident history, the regulatory notification log, and the technical assessment findings. The affirmative or negative answer, with the evidence and the materiality analysis behind it, in one paragraph.
- What is the quantified cyber exposure the combined entity inherits?: Answered by the CCOD number, the confidence interval, the top-three drivers of the number, and the sensitivity of the number to the two or three assumptions most likely to be wrong. Not a heat map. A dollar figure with methodology.
- What is the disclosure posture on Day 1 post-close?: Answered by the pre-approved materiality memo template, the identified prior incidents that will need Reg S-K Item 106 treatment on the next 10-K, and the specific language changes to the acquirer's existing cyber-governance disclosure that the combined entity will require. This is a legal deliverable, not a security deliverable, but the security team has to give the legal team what they need to write it.
If any of these three questions cannot be answered on the day of the IC meeting, the diligence is not complete, regardless of how many artifacts have been produced. The audit committee's job is to certify the disclosure controls; the diligence package's job is to make that certification defensible.
Where the QCD methodology plugs into SEC disclosure
vCISO Lite's Quantitative Cyber Diligence (QCD) methodology was built around the five-pillar framework that maps directly onto what the SEC's disclosure rules require the acquirer to know. Each pillar produces a dollar-denominated finding that supports a materiality memo, and the assembled CCOD number is the exact input the audit committee needs to make a defensible Item 1.05 determination when an incident surfaces. The methodology also produces the artifacts (vendor register with SLAs, 36-month incident history, insurance analysis, governance assessment) that populate Reg S-K Item 106 for the combined entity's first post-close 10-K.
The point is not that QCD is the only way to do this. The point is that any diligence methodology has to produce these artifacts, in this format, on this timeline, or the SEC disclosure obligations cannot be met without a scramble. Deal teams that route cyber diligence to a vendor optimized for a written report (the 40-page PDF with the heat maps) should assume the disclosure question will re-emerge at IC and again post-close, and budget the additional discovery cost.
If you're scoping cyber diligence for an active deal or reviewing the disclosure posture on a recent close, visit vcisolite.com to learn more and get started.