S. 536Senate115th Congress (2017-2019)In Committee

Cybersecurity Disclosure Act of 2017

Sponsored by Jack ReedSen. Jack Reed (D-RI)
Introduced March 7, 2017

AI-Generated Summary

Updated April 15, 2026 at 1:39 PM UTC

The Cybersecurity Disclosure Act of 2017 would make publicly traded companies tell investors about their cybersecurity oversight. It requires the Securities and Exchange Commission (SEC) to create rules that force companies to disclose whether any board member or governing‑body official has cybersecurity expertise, or to explain what other cybersecurity considerations were used when selecting board members. The goal is to give shareholders clearer information about how companies manage cyber risks.

Key Provisions

  • The SEC must issue final rules within 360 days of the law’s enactment to require the new disclosures.
  • Reporting companies must state in their annual reports or proxy statements whether any board or governing‑body member has cybersecurity expertise, describing the nature of that expertise.
  • If no board member has such expertise, companies must explain what other cybersecurity factors were considered when evaluating or nominating board members.
  • The SEC, working with the National Institute of Standards and Technology (NIST), will define what counts as cybersecurity expertise, using standards such as NIST’s NICE Cybersecurity Workforce Framework.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

4 earlier actions
SenateCommittee Latest Action

Committee on Banking, Housing, and Urban Affairs. Hearings held. Hearings printed: S.Hrg. 115-406.

June 28, 2018

View full timeline
SenateIntro Referral

Introduced in Senate

March 7, 2017

SenateIntro Referral

Read twice and referred to the Committee on Banking, Housing, and Urban Affairs. (Sponsor introductory remarks on measure: CR S1641-1642)

March 7, 2017

SenateCommittee

Committee on Banking, Housing, and Urban Affairs. Hearings held. Hearings printed: S.Hrg. 115-95.

September 12, 2017

SenateCommittee

Committee on Banking, Housing, and Urban Affairs. Hearings held. Hearings printed: S.Hrg. 115-307.

May 24, 2018

SenateCommittee

Committee on Banking, Housing, and Urban Affairs. Hearings held. Hearings printed: S.Hrg. 115-406.

June 28, 2018

Floor Debate

3 members

What members said about S. 536 on the floor

3 Democrats
Dianne Feinstein
Sen. Dianne FeinsteinD-CA · Mar 7, 2017

Mr. President, today I am reintroducing a bill for the private relief of Shirley Constantino Tan. Ms. Tan is a Filipina national living in Pacifica, CA. She is the proud mother of 20-year-old U.S.…

Jack Reed
Sen. Jack ReedD-RI · Mar 7, 2017

Mr. President, today I am reintroducing the Cybersecurity Disclosure Act of 2017 along with two members of the Select Committee on Intelligence, Senator Collins, and the ranking member, Senator…

Jack Reed
Sen. Jack ReedD-RI · Mar 7, 2017

Mr. President, today I am reintroducing the Cybersecurity Disclosure Act of 2017 along with two members of the Select Committee on Intelligence, Senator Collins, and the ranking member, Senator…

Patrick J. Leahy
Sen. Patrick J. LeahyD-VT · Mar 7, 2017

Mr. President, today, I have reintroduced legislation to protect Americans from being stripped of their legal rights by little known clauses that are now hidden in an alarming number of contracts.…

Bill Text

Latest available legislative text

Reading Mode
Latest
Introduced in SenateIssued March 7, 2017

II

115th CONGRESS

1st Session

S. 536

IN THE SENATE OF THE UNITED STATES

March 7, 2017

Mr. Reed (for himself, Ms. Collins, and Mr. Warner) introduced the following bill; which was read twice and referred to the Committee on Banking, Housing, and Urban Affairs

A BILL

To promote transparency in the oversight of cybersecurity risks at publicly traded companies.

1.

Short title

This Act may be cited as the Cybersecurity Disclosure Act of 2017.

2.

Cybersecurity transparency

(a)

Definitions

In this section—

(1)

the term Commission means the Securities and Exchange Commission;

(2)

the term cybersecurity threat—

(A)

means an action, not protected by the First Amendment to the Constitution of the United States, on or through an information system that may result in an unauthorized effort to adversely impact the security, availability, confidentiality, or integrity of an information system or information that is stored on, processed by, or transiting an information system; and

(B)

does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement;

(3)

the term information system—

(A)

has the meaning given the term in section 3502 of title 44, United States Code; and

(B)

includes industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers;

(4)

the term issuer has the meaning given the term in section 3 of the Securities Exchange Act of 1934 (15 U.S.C. 78c);

(5)

the term NIST means the National Institute of Standards and Technology; and

(6)

the term reporting company means any company that is an issuer—

(A)

the securities of which are registered under section 12 of the Securities Exchange Act of 1934 (15 U.S.C. 78l); or

(B)

that is required to file reports under section 15(d) of such Act (15 U.S.C. 78o(d)).

(b)

Requirement To issue rules

Not later than 360 days after the date of enactment of this Act, the Commission shall issue final rules to require each reporting company, in the annual report submitted under section 13 or section 15(d) of the Securities Exchange Act of 1934 (15 U.S.C. 78m and 78o(d)) or the annual proxy statement submitted under section 14(a) of such Act (15 U.S.C. 78n(a))—

(1)

to disclose whether any member of the governing body, such as the board of directors or general partner, of the reporting company has expertise or experience in cybersecurity and in such detail as necessary to fully describe the nature of the expertise or experience; and

(2)

if no member of the governing body of the reporting company has expertise or experience in cybersecurity, to describe what other cybersecurity steps taken by the reporting company were taken into account by such persons responsible for identifying and evaluating nominees for any member of the governing body, such as a nominating committee.

(c)

Cybersecurity expertise or experience

For purposes of subsection (b), the Commission, in consultation with NIST, shall define what constitutes expertise or experience in cybersecurity, such as professional qualifications to administer information security program functions or experience detecting, preventing, mitigating, or addressing cybersecurity threats, using commonly defined roles, specialities, knowledge, skills, and abilities, such as those provided in NIST Special Publication 800–181 entitled NICE Cybersecurity Workforce Framework, or any successor thereto.