SEC Filing Requirements

Explore top LinkedIn content from expert professionals.

Summary

SEC filing requirements outline the mandatory disclosures companies must make to the U.S. Securities and Exchange Commission, ensuring transparency for investors, especially regarding cybersecurity incidents and digital assets. These rules help safeguard markets by requiring timely, detailed information about risks, business operations, and the management of emerging technologies like crypto assets.

  • Prepare clear disclosures: Make sure your company reports significant events and material risks in straightforward language that investors can easily understand.
  • File promptly: Submit required SEC forms, such as those for cybersecurity breaches or crypto asset offerings, within the specified deadlines to stay compliant.
  • Explain governance roles: Describe how your board and management assess and manage risks related to cybersecurity and digital assets in your annual reports.
Summarized by AI based on LinkedIn member posts
  • 🇺🇸#SEC provides much needed clarity on the application of the federal securities laws to #cryptoassets 🔴(10 April) U.S. Securities and Exchange Commission Offerings and Registrations of Securities in the #Crypto Asset Markets 🔵 Purpose and Scope ⚪️ Clarifies disclosure rules for crypto-related securities ⚪️ Applies to equity/debt tied to networks, apps, crypto assets ⚪️ Covers “subject crypto asset” in investment contracts ⚪️ Issued during Crypto Task Force’s ongoing work 🔵 Disclosure Requirements (Securities Act & Exchange Act) ⚪️ Aims to protect investors and ensure efficient markets ⚪️ Applies to Forms S-1, 10, 20-F, and 1-A ⚪️ Disclosures must reflect issuer-specific facts ⚪️ Scaled disclosure allowed if applicable 🔵 Description of Business ⚪️ Must describe material aspects of the issuer’s business ⚪️ Use clear, simple language—not technical jargon ⚪️ Should relate to the issuer, not general blockchain tech ⚪️ Observed examples: 🔻 Business stage and development plans 🔻 Consistency with public materials (e.g., white papers) 🔻 Specific activities and continuity post-launch 🔻 Revenue generation plans 🔻 Crypto asset’s function in business ⚪️ If developing/acquiring a network or app: 🔻 Team’s goals and development status 🔻 Milestones, timeline, funding 🔻 Architecture, objectives, validation process 🔻 IP rights, open-source vs proprietary tech 🔻 Services, roles (e.g., validators, users, governance) 🔻 Upgrade/security measures, governance structure 🔵 Risk Factors ⚪️ Must disclose material investment risks ⚪️ Tailored to business and security nature ⚪️ Examples include: 🔻 Technology/cybersecurity risks 🔻 Business implementation challenges 🔻 Volatility, liquidity, holder rights 🔻 Regulatory compliance risks 🔵 Description of Securities ⚪️ Must include terms, rights, characteristics ⚪️ Rights & Preferences: 🔻 Transferability, holder rights, modifications 🔻 Voting, dividends, enforcement 🔻 Proxy compliance ⚪️ Technical Specs: 🔻 Network/code change process 🔻 Wallets, fees, ownership records 🔻 Divisibility, audit results ⚪️ Supply: 🔻 Total supply, mint/burn, vesting 🔻 Control mechanisms 🔻 Market maker agreements 🔵 Directors, Officers & Key Personnel ⚪️ Disclose those with managerial influence ⚪️ Includes third-party executives (e.g., sponsors) ⚪️ Must disclose fees paid to such parties 🔵 Financial Statements ⚪️ Must follow SEC rules ⚪️ Complex issues may be directed to Chief Accountant 🔵 Exhibits ⚪️ File all instruments defining holder rights ⚪️ Include smart contract code if relevant ⚪️ Update with code changes 🔵 Contacting the Division ⚪️ SEC encourages questions and requests ⚪️ Contact info available on the SEC site https://lnkd.in/ghcfWFp6

  • View profile for Jonathan T. Marks, CPA, CFE, MBA, NACD Board Fellow

    Forensic Strategist. Framework Builder. Educator. | Translating Complexity into Clarity for Boards & Executives | Author, Advisor & Lifelong Optimist

    26,667 followers

    The U.S. Securities and Exchange Commission (SEC) voted on July 26, 2023, mandating public companies to promptly inform investors about significant cybersecurity breaches. They will have to report within four days of acknowledging a material cybersecurity event via Form 8-K disclosures. The regulation aims to mitigate situations where investors learn about significant cyberattacks through the media before the companies disclose them. The SEC has adjusted the requirements in response to comments on the proposal. For instance, if the U.S. Attorney General identifies that an immediate disclosure would present a considerable risk to national security or public safety, companies will be allowed a reasonable delay in filing material cybersecurity breach on Form 8-K. Despite modifications, SEC Commissioners Hester Peirce and Mark Uyeda, who voted against the rules, argue that the changes still do not sufficiently address several concerns. They pointed to potential disclosures that could serve as a roadmap for malicious actors planning future attacks. The new rule also compels companies to disclose significant information about their cybersecurity risk management, strategy, and governance. Despite criticism, the majority of the commission contends that the benefits of the rules surpass the costs. The rules mandate companies to describe the material aspects of the breach's nature, scope, and timing, and its material impact on the company when filing Form 8-K on a significant cybersecurity incident. Companies must also explain their processes for identifying and managing material risks from cybersecurity threats and disclose the material effects or anticipated material effects of risks from cybersecurity threats and previous cybersecurity incidents. The Bank Policy Institute (BPI) criticizes the rule, stating that it could harm investors and amplify security risks. They noted that companies are required to notify investors even when a cybersecurity breach is ongoing, potentially exposing vulnerabilities at other companies or sectors. Nevertheless, experts emphasize that companies need to prepare for the implementation of these rules. The new regulations pose challenges, particularly in determining what constitutes "without unreasonable delay" during a materiality analysis of an ongoing cyber incident. The new regulations are scheduled to take effect 30 days after publication in the Federal Register, and comparable disclosures will be required by foreign private issuers. Compliance dates are set for mid-December. Smaller reporting companies have an extra 180 days to start complying for Form 8-K disclosure. All companies must tag disclosures required in the final rules using Inline eXtensible Business Reporting Language (XBRL) starting one year after initial compliance.

  • View profile for Ian Yip

    Founder & CEO at Avertro | Entrepreneur | Cybersecurity | AI | Startups | Leadership

    12,125 followers

    Well, it's now official. The U.S. Securities and Exchange Commission (SEC) just put out this press release. SEC registrants (any company that files documents with the SEC) must: 1) Disclose any #cybersecurity incident they determine to be material and to describe the material aspects of the incident's nature, scope, and timing, as well as its material impact or reasonably likely material impact on the registrant. This is due four business days after it is determined that a cybersecurity incident is material. 2) Describe their processes, if any, for assessing, identifying, and managing material #risks from cybersecurity threats, as well as reasonably likely material effects of risks from cybersecurity #threats and previous cybersecurity incidents. 3) Describe the #board of directors’ oversight of risks from cybersecurity threats and management’s role and expertise in assessing and managing material risks from cybersecurity threats. The 2nd and 3rd disclosures will be required in a registrant's annual report, due beginning with fiscal years ending on or after December 15, 2023.

  • View profile for Johnny Reinsch

    Saving digital assets from death and taxes

    34,196 followers

    🚨 BREAKING: SEC changes course! And redefined securities disclosure for crypto. After years of regulatory fog and enforcement actions, the Division of Corporation Finance has finally released guidance that translates traditional securities disclosure for the digital asset economy. The implications are profound: 1️⃣ Code is now legal documentation - Smart contracts that define investor rights must be filed as exhibits and updated when modified, just like traditional legal agreements 2️⃣ Admin keys = material information - Who controls protocol upgrades, token minting, or emergency pauses? These questions are now central to regulatory compliance 3️⃣ RWA tokenization faces heightened scrutiny - No more vague claims that tokens "represent" real assets; issuers must detail the precise legal mechanisms connecting on-chain and off-chain rights This isn't just another regulatory burden—it's the beginning of a new disclosure language that acknowledges blockchain's unique architecture while upholding investor protection principles. Chris Brummer and I published our analysis of what this means for token issuers, RWA projects, and the path forward for compliant innovation in digital assets. cc Bluprynt and Tokenized Asset Coalition Link to our post in first comment below👇

  • View profile for David Cass

    Managing Director CISO | President CISOs Connect and Security Current | Senior Partner at Law & Forensics | Cybersecurity | Cryptocurrency | Digital Banking | Compliance | Data Protection | Faculty Harvard (HES) |

    22,423 followers

    The Securities and Exchange Commission (SEC) has activated its new disclosure and management regulations for public enterprises concerning cybersecurity. These rules come as a response to the increasing reliance on electronic systems, disruptions to which can lead to far-reaching consequences. With this implementation, the SEC aims to standardize how and where companies communicate their security disclosures. Companies are now required to disclose significant security incidents and provide details about the incident's nature, timing, and potential impact. Additionally, companies need to explain how they manage cyber threats, their strategies, and the role of governance in handling these risks. The term 'material', in this context, pertains to any incident or risk that would be deemed significant by a reasonable investor. The updated guidelines also highlight that the materiality of an incident remains unchanged, even if the system involved belonged to a third party. Make sure your organization has defined what it considers material before having to evaluate an actual event. This initiative underscores the SEC's commitment to enhancing transparency and ensuring stakeholders are consistently informed about cybersecurity developments. #SEC #Cybersecurity #Transparency #EnterpriseSecurity

  • View profile for Kristen Sullivan

    Partner at Deloitte | CPA | Audit & Assurance | Sustainability

    12,131 followers

    #𝗘𝗦𝗚𝗶𝗻𝗧𝗵𝗿𝗲𝗲: 𝗜𝘁’𝘀 𝗴𝗼 𝘁𝗶𝗺𝗲!  𝙃𝙤𝙩 𝙤𝙛𝙛 𝙩𝙝𝙚 𝙥𝙧𝙚𝙨𝙨! Deloitte’s comprehensive Heads Up https://lnkd.in/ewk2x8_d provides a deep dive analysis of the final SEC Climate Disclosure Rule. Check out this practical tool that helps unpack the requirements and nuances of the final rule, including practical examples. A few areas of further emphasis to highlight connectedness considerations across multiple areas of the final rule: 𝟭. 𝗦𝘁𝗿𝗮𝘁𝗲𝗴𝘆: More than 90% of the S&P 500 disclosed matters related to climate change or GHG emissions in the risk factors section of their most recent annual report. However, much more specific disclosure will be required under the final rule, including specific disclosures by type of climate risk (physical and transition). For material climate-related risks, required disclosures about the impact (actual or potential) of the risk to “strategy, business model, and outlook” include specific information on how they affect strategy, targets/goals, resources, etc. For LAFs, #DCPs related to these disclosures will need to be in place and tested by 1/1/25.  𝟮. 𝗖𝗹𝗶𝗺𝗮𝘁𝗲 𝗥𝗶𝘀𝗸 𝗠𝗮𝗻𝗮𝗴𝗲𝗺𝗲𝗻𝘁: A registrant is required to disclose its 𝗽𝗿𝗼𝗰𝗲𝘀𝘀𝗲𝘀 for “identifying, assessing and managing” material climate-related risks, including evaluating whether the risk has been incurred/likely to be incurred, response to the risk including whether it will address the material risk and whether the process is integrated into #ERM. Orgs should consider existing processes in place for purposes of #TCFD or #CDP disclosures, which are both designed to meet info needs of investors. Again, for LAFs, #DCPs related to these disclosures (including the process by which the materiality determination was made) will need to be in place and tested by 1/1/25. 𝟯. 𝗧𝗮𝗿𝗴𝗲𝘁𝘀 𝗮𝗻𝗱 𝗚𝗼𝗮𝗹𝘀: A registrant must disclose info on their publicly announced or 𝙞𝙣𝙩𝙚𝙧𝙣𝙖𝙡 climate-related targets or goals, if material. Required disclosures then include; scope of activities (e.g., Scopes 1,2,3 GHG emissions), how measured, time horizon, baseline, update on progress, etc. This is where disclosure of GHG emissions could be required well ahead of phase-in implementation dates for Scopes 1 & 2 GHG emissions, for example. Again, for LAFs, this means #DCPs related to these disclosures (potentially including Scopes 1,2,3 GHG emissions) will need to be in place and tested by 1/1/25. Additionally, the final rule requires disclosures about any voluntary assurance obtained (before required) if the GHG emissions disclosures are included in the SEC filing. The time to accelerate preparedness is now, #assurancereadiness can be an important tool. Please note the implementation considerations included in the Heads Up! #deloitteesgnow

  • View profile for Indy Dhami

    Executive Advisor | Ex Big 4 Partner | Industry Fellow | Cyber & Resilience

    7,360 followers

    A concise summary of the U.S. Securities and Exchange Commission rules on #cybersecurity disclosures. The key areas CFO's and business leaders need to be cognisant of are: ✅ Validate materiality determinations, catalogue prior security incidents, and update processes accordingly to meet the new rules. ⏩ Improve incident reporting mechanisms to inform regulatory bodies within 4 business days if the incident is deemed to be material. 📄 Disclose the processes in place to identify, assess and manage material risks from cybersecurity threats in annual reports. 💲 Update incident response/management and risk management processes to ensure that those responsible for disclosures use quantitative and qualitative factors in decision making. 🔀 Evaluate past incident data and tracking of cyber attacks/threats to inform judgements on materiality impact using benchmarking and 3rd party independent assessments. 🗻 Enhance the "tone from the top" ensuring governance and oversight is in place that includes the board and audit committee. 🔎 Improve 3rd party oversight of critical suppliers to identify any material risks, increased rigour and controls may be required to ensure sufficient cyber risk management.  

  • View profile for Myrto Lalacos
    Myrto Lalacos Myrto Lalacos is an Influencer

    Helping VC firms launch and grow | Founder, The Emerging VC | Ex-VC turned VC Builder | LinkedIn Top Voice

    21,903 followers

    You launched your VC fund. Now meet your regulatory to-do list... Venture capital is a regulated industry, which means paperwork, filings, and deadlines every single year. And it's the same in every country. In Delaware, where 60% of the world's VC funds are domiciled, a standard fund structure there requires annual filings across 4 different government systems: - SEC - State securities - Delaware - IRS. Each with its own portal, login, and deadlines. Miss one and you're facing penalties, loss of Good Standing, and very awkward conversations with LPs. Every year you need to file the following: 📋 REGULATORY FILINGS → Form ADV Annual Amendment → Form D amendments if fundraising continues beyond 12 months → IARD System Fees → State Blue Sky filings for each state where you have LPs → Delaware Registered Agent renewal 📋 TAX FILINGS → Delaware Franchise Tax for all 3 of your firm entities → Form 1065 and K-1s for Fund LP and GP (March 15 or extended to Sept 15) And here's what most new managers don't realize: No single lawyer can handle all of this. No single accountant can either. Your bank definitely can't. A corporate attorney might draft your docs but won't know the difference between 506(b) and 506(c). A local accountant might use QuickBooks instead of fund administration software and botch your capital calls. Your registered agent won't remind you about Form ADV deadlines. This is why no serious emerging manager tries to do this alone, or their 'friend who is a lawyer'. That's why VCs turn to fund administrator who handle: ✅ All filings across all systems ✅ Deadline tracking and reminders ✅ Coordination with counsel ✅ K-1 preparation and LP reporting It saves time, it's done properly and nothing is missed. Your reputation as a new fund manager is everything. One missed filing, one late K-1, one loss of Good Standing, and sadly sophisticated LPs will notice. The managers who win set up the right infrastructure from day one. If you found a setup that works or does NOT work share it below, new managers need to hear what's actually working 🙏 --- ✍️ Myrto Lalacos Follow for more on launching, running, and investing in VC firms.

  • View profile for Adeo Ressi

    Backing Emerging VC Managers Worldwide | CEO, Decile Group | Chairman, Founder Institute | Inventor of the SAFE Note

    83,294 followers

    You closed your fund. Congratulations. Now comes the part nobody warned you about. Compliance. Every year, your Delaware fund structure requires filings across: → SEC (EDGAR system) → State Securities (varies by state) → Delaware Division of Corporations → IRS Each system has different logins. Different interfaces. Different payment methods. Different quirks that can derail a filing at 4:55 PM on deadline day. Miss a deadline? Penalties. Loss of Good Standing. Frozen banking relationships. Awkward conversations with LPs who expected better. Here's what compliance actually costs: - Form ADV Amendment: $1,150 - $1,550 - Delaware Franchise Tax (3 entities): $900 - IARD System Fees: $150 - $550 - Registered Agent: ~$300 Total: $2,550 - $3,350 annually. That's the price of running a fund. Not optional. Most first-time managers learn this the hard way. Scrambling at 4 PM on March 1st. Realizing they missed a state filing nobody told them about. We just published the complete guide: Every filing. Every deadline. Every cost. No surprises. The unsexy work of venture capital. But the managers who get this right? They build LP trust that compounds for decades. Link in comments.

Explore categories