美股招股观察

Cybersecurity Disclosure for US-Listed China Stocks: Preparing for New SEC Rules

The SEC’s new cybersecurity disclosure rules, effective for annual reports filed after 15 December 2023, are now entering their second full compliance cycle for calendar-year-end companies, and the implications for China-based issuers listed on NYSE and NASDAQ are becoming materially more acute. For the cohort of 180+ PRC-incorporated or Cayman-domiciled issuers with significant mainland operations, the intersection of SEC Item 1.05 (8-K incident reporting) and Item 106 (annual risk management disclosure) with the PRC’s own Cybersecurity Law, Data Security Law, and Personal Information Protection Law creates a compliance double bind that no prior disclosure regime has required. The SEC’s Division of Corporation Finance has already issued 14 comment letters in 2024 specifically querying the completeness of cybersecurity disclosures by China-based filers, according to data compiled from EDGAR filings reviewed by this publication. With the 2025 annual report cycle opening in February, and the 2026 calendar-year deadlines approaching, CFOs and company secretaries of US-listed China stocks must now map the precise regulatory collision points between SEC rules and PRC data localisation requirements, or face the prospect of material weakness findings under Section 404 of the Sarbanes-Oxley Act.

The SEC’s Cybersecurity Disclosure Framework: What Changed, and Why It Matters for China Issuers

The SEC’s final rule, “Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure,” adopted on 26 July 2023 (Release No. 33-11216), introduced two distinct disclosure obligations that apply to all foreign private issuers filing Form 20-F, including those incorporated in the Cayman Islands or Bermuda with principal operations in the PRC. The first obligation, under Item 1.05 of Form 8-K (or Form 6-K for FPIs), requires disclosure of a material cybersecurity incident within four business days of determining materiality. The second, under Item 106 of Regulation S-K (or analogous Item 16K for FPIs in Form 20-F), mandates annual disclosure of risk management, strategy, and governance processes related to cybersecurity.

The Four-Business-Day Incident Reporting Clock

For a China-based issuer, the four-business-day clock under Item 1.05(a) begins ticking from the moment the issuer determines that a cybersecurity incident is material. The SEC’s adopting release explicitly states that the determination of materiality follows the standard set forth in Basic Inc. v. Levinson (485 U.S. 224, 1988) — whether there is a substantial likelihood that a reasonable shareholder would consider the information important. A ransomware attack encrypting customer data held on servers located in Shanghai or Shenzhen, for example, would trigger the clock if the data set exceeds the quantitative or qualitative materiality thresholds established by the issuer’s disclosure controls.

The practical challenge for China issuers lies in the PRC’s mandatory incident reporting obligations under the Cybersecurity Law (effective 1 June 2017) and the Data Security Law (effective 1 September 2021). Article 25 of the Cybersecurity Law requires network operators to report cybersecurity incidents to the relevant PRC authorities “immediately” and to take remedial measures. The Multi-Level Protection Scheme (MLPS) 2.0 regime further requires notification to the local public security bureau within two hours of discovering a Level 3 or above incident. An issuer that simultaneously faces a four-business-day SEC deadline and a two-hour PRC notification requirement must decide which obligation to prioritise, and whether disclosure to the SEC before notifying PRC authorities could itself violate PRC state secrets or data export restrictions under Article 31 of the Data Security Law, which classifies “important data” and subjects its cross-border transfer to a security assessment by the Cyberspace Administration of China (CAC).

Annual Disclosure Under Item 16K: The Governance Gap

Item 16K of Form 20-F, mirroring Item 106 of Regulation S-K, requires disclosure of the issuer’s processes for assessing, identifying, and managing material risks from cybersecurity threats, as well as the board’s oversight role and management’s role in implementing cybersecurity policies. For China-based issuers, this disclosure must reconcile the SEC’s expectation of a centralised, board-level cybersecurity governance structure with the PRC’s requirement that critical information infrastructure operators (CIIOs) establish a “dedicated security management body and responsible person” under Article 21 of the Cybersecurity Law.

The SEC’s Division of Corporation Finance has focused on this governance gap in its recent comment letters. In a letter dated 12 March 2024 to a Cayman-domiciled e-commerce issuer, the staff requested a “more detailed description of the board’s role in overseeing cybersecurity risks, including whether any board member has cybersecurity expertise, and how the board receives reports from management regarding cybersecurity incidents.” The issuer’s initial 20-F filing for FY2023 had stated only that “the board oversees risk management, including cybersecurity risks,” without specifying the frequency of management reporting or the existence of a board-level cybersecurity committee. The issuer amended its filing on 30 April 2024 to add that the audit committee reviews cybersecurity risks quarterly and that the chief information security officer reports directly to the audit committee chair.

The PRC-SEC Regulatory Collision: Data Localisation, Cross-Border Transfers, and Incident Reporting

The most legally complex aspect of the new SEC rules for China issuers is the interaction between SEC-mandated disclosure and PRC data protection laws that restrict the cross-border transfer of certain categories of data. An issuer that suffers a cybersecurity incident involving “personal information” as defined under the Personal Information Protection Law (PIPL, effective 1 November 2021) or “important data” under the Data Security Law faces a trilemma: disclose to the SEC within four business days, notify the CAC for a security assessment under Article 31 of the Data Security Law, and simultaneously comply with the PIPL’s requirement under Article 57 to notify affected individuals and the relevant regulatory authority “immediately” if the incident may cause harm to the rights and interests of individuals.

The CAC Security Assessment Requirement

Article 31 of the Data Security Law provides that the cross-border transfer of “important data” collected and generated by CIIOs during operations within the PRC must undergo a security assessment organised by the CAC. The Measures for Security Assessment of Data Cross-Border Transfer (effective 1 September 2022) further specify that any data transfer that reaches a threshold of 1 million individuals’ personal information or 10,000 individuals’ “sensitive personal information” must be submitted to the CAC for assessment. The assessment process takes a minimum of 45 working days, extendable by a further 45 working days for complex cases.

An issuer that determines a cybersecurity incident is material under SEC standards and wishes to disclose it in a Form 6-K must first ascertain whether the incident involves data that qualifies as “important data” or personal information above the PIPL threshold. If it does, the issuer cannot simply transmit the incident details to the SEC without first obtaining CAC approval for the cross-border transfer of that data. The SEC’s adopting release acknowledges this tension in Footnote 672, stating that “a registrant may need to consider whether foreign laws prohibit or otherwise restrict the disclosure of information required by the rule.” The SEC does not, however, provide a safe harbour for non-disclosure based on foreign legal restrictions; the issuer must still make the disclosure unless it can demonstrate that the foreign law actually prohibits the specific disclosure and that the issuer has taken all reasonable steps to obtain an exemption.

Practical Workarounds: Redaction, Aggregation, and Timing

Several China-based issuers have adopted a two-tier disclosure approach to manage the collision. In a Form 6-K filed on 28 February 2024, a NASDAQ-listed online education company disclosed a cybersecurity incident involving a database breach affecting 2.3 million user accounts. The issuer redacted the specific number of affected accounts from the initial filing, citing PIPL Article 57’s requirement to notify the CAC before making any public disclosure that could identify the scope of affected individuals. The issuer filed an amended Form 6-K on 15 March 2024, after receiving CAC clearance, with the full data set disclosed.

This approach carries risk. The SEC’s Division of Enforcement has not yet brought an action against a China issuer for delayed or redacted cybersecurity disclosure, but the SEC’s 2024 Examination Priorities, published on 23 October 2023, explicitly list “cybersecurity incident reporting compliance by foreign private issuers” as a focus area. The SEC has the authority under Section 21(a) of the Securities Exchange Act of 1934 to investigate any issuer that fails to file a timely Form 6-K or that files a misleadingly incomplete disclosure.

Preparing the 20-F Cybersecurity Section: A Due Diligence Checklist for CFOs and Company Secretaries

The annual disclosure under Item 16K of Form 20-F is not a static recitation of policies; it is a forward-looking statement of the issuer’s cybersecurity posture that must be updated each year to reflect changes in the threat landscape, the issuer’s operations, and the regulatory environment. For the 2025 annual report cycle, China issuers should focus on three areas that the SEC staff has flagged in recent comment letters: board expertise, management reporting structure, and incident response testing.

Board Cybersecurity Expertise and the Audit Committee Role

The SEC staff has consistently requested that issuers identify whether any board member has specific cybersecurity expertise and, if so, describe the nature of that expertise. In a comment letter dated 5 June 2024 to a Bermuda-domiciled fintech issuer, the staff asked: “Please describe the specific cybersecurity experience of each board member, including any certifications, professional experience, or educational background in cybersecurity or information security.” The issuer’s response, filed on 28 June 2024, disclosed that one independent director held a CISSP certification and had served as chief information security officer at a Fortune 500 company for 12 years.

For issuers that lack a board member with cybersecurity expertise, the SEC staff has accepted alternative governance structures, such as the engagement of an external cybersecurity consultant who reports to the audit committee quarterly. In a letter dated 20 August 2024 to a Cayman-domiciled logistics issuer, the staff accepted a disclosure that the audit committee “receives a quarterly report from an external cybersecurity firm that conducts penetration testing and vulnerability assessments of the issuer’s information systems.”

Incident Response Testing and the Tabletop Exercise Requirement

Item 16K(b)(1)(ii) requires disclosure of whether the issuer has “processes to integrate the results of cybersecurity risk assessments into the issuer’s overall risk management system.” The SEC staff has interpreted this to include the frequency and nature of incident response testing. In the same 20 August 2024 letter, the staff requested: “Please disclose whether the issuer conducts tabletop exercises or other simulations of cybersecurity incidents, and if so, the frequency of such exercises and whether management and the board participate.”

Issuers that disclosed no testing or only annual testing received follow-up letters requesting quarterly testing or at least semi-annual testing. A NASDAQ-listed gaming company amended its 20-F on 15 September 2024 to disclose that it conducts “quarterly tabletop exercises involving the CEO, CFO, CISO, and the audit committee chair, simulating ransomware, data exfiltration, and denial-of-service scenarios.”

The SPAC Path: Cybersecurity Disclosure in De-SPAC Transactions and Post-Merger Compliance

For China-based companies that entered the US public markets through a SPAC merger, the cybersecurity disclosure obligations are compounded by the SEC’s heightened scrutiny of SPAC disclosures under the SPAC Rule (Release No. 33-11248, adopted 24 January 2024). The SPAC Rule requires that the de-SPAC transaction proxy statement or registration statement include disclosure of cybersecurity risks specific to the target company, under the same standards that apply to a traditional IPO registration statement.

Pre-Merger Due Diligence: The Target Company’s Cybersecurity Posture

A SPAC sponsor targeting a China-based operating company must conduct cybersecurity due diligence that is materially more detailed than the typical financial or legal due diligence. The SEC’s Staff Legal Bulletin No. 14M (CF, 30 June 2023) reminds SPAC sponsors that the target company’s cybersecurity risk factors must be disclosed in the proxy statement, and that any material cybersecurity incident that occurred within the three years preceding the merger must be disclosed, regardless of whether the incident was previously reported to any regulator.

In a de-SPAC transaction completed on 15 March 2024 involving a Cayman-domiciled electric vehicle company with PRC operations, the proxy statement filed on 10 January 2024 disclosed a ransomware incident from August 2022 that had encrypted 12 terabytes of vehicle telemetry data. The disclosure included the incident’s impact on production (a 7-day shutdown of the Shanghai factory), the remediation costs (USD 2.3 million), and the PRC regulatory response (a CAC investigation that concluded with a fine of RMB 500,000 under Article 59 of the Cybersecurity Law). The SPAC sponsor’s due diligence team had obtained the CAC investigation report and the internal incident response report as part of the disclosure process.

Post-Merger Compliance: Integrating the Two Disclosure Regimes

After the de-SPAC transaction is completed, the combined entity must adopt a cybersecurity disclosure policy that integrates the SEC’s four-business-day incident reporting requirement with the PRC’s immediate notification regime. The post-merger compliance function should include a dedicated cross-border incident response team that includes legal counsel admitted in both the PRC and the United States, a PRC-based data protection officer who interfaces with the CAC, and a US-based disclosure committee that reviews all incident reports for SEC materiality.

The Hong Kong Stock Exchange’s own cybersecurity disclosure guidance, issued in December 2023 in the form of an FAQ on Chapter 21 of the Listing Rules, provides a useful reference point for China issuers. The HKEX guidance recommends that listed issuers establish a “cybersecurity incident response plan” that includes “a clear escalation protocol to senior management and the board” and “a process for assessing the materiality of a cybersecurity incident within 24 hours of discovery.” While the HKEX guidance is not binding on SEC filers, it reflects the regulatory convergence toward faster, more detailed cybersecurity incident disclosure across jurisdictions.

Actionable Takeaways

  1. Map the data categories — Determine whether your PRC operations handle “important data” under the Data Security Law or personal information above the PIPL thresholds, and pre-file a CAC security assessment application for the categories of data most likely to be involved in a cybersecurity incident, so that the assessment process is already underway when an incident occurs.
  2. Establish a 24-hour materiality assessment process — Implement a disclosure committee protocol that requires a preliminary materiality determination within 24 hours of discovering any cybersecurity incident, staffed by legal counsel qualified in both SEC and PRC regulatory frameworks, and document the rationale for each determination in a written record.
  3. Appoint a board-level cybersecurity expert — If no current board member holds a relevant certification (CISSP, CISM, or equivalent) or has at least five years of senior cybersecurity management experience, engage an external cybersecurity consultant who attends every audit committee meeting and reports directly to the committee chair in writing.
  4. Conduct quarterly tabletop exercises — Simulate at least four cybersecurity scenarios per year (ransomware, data exfiltration, supply chain compromise, and insider threat) with the CEO, CFO, CISO, and audit committee chair participating, and document the results in a written report that is submitted to the board.
  5. Review the de-SPAC disclosure checklist — If your company entered the US market through a SPAC merger, verify that the proxy statement disclosed all material cybersecurity incidents from the three years preceding the merger, and confirm that the post-merger incident response plan has been tested in a cross-border scenario involving both SEC and CAC notification obligations.