S. 592Senate116th Congress (2019-2021)In Committee

Cybersecurity Disclosure Act of 2019

Sponsored by Jack ReedSen. Jack Reed (D-RI)
Introduced February 28, 2019

AI-Generated Summary

Updated April 14, 2026 at 2:29 AM UTC

The Cybersecurity Disclosure Act of 2019 would amend the Securities Exchange Act of 1934 to require publicly traded companies to be more transparent about their cybersecurity oversight. Within a year of the law’s passage, the SEC must issue rules—working with the National Institute of Standards and Technology (NIST)—that tell companies how to report whether any board member has cybersecurity expertise, or what other input is used when no such expertise exists. The bill applies to any company that files periodic reports with the SEC.

Key Provisions

  • Adds new definitions for terms such as “cybersecurity,” “cybersecurity threat,” “information system,” and “reporting company.”
  • Mandates that the SEC issue final rules within 360 days requiring each reporting company to disclose in its annual report or proxy statement whether any board member has cybersecurity expertise, describing the nature of that expertise.
  • If no board member has such expertise, companies must explain what other considerations (e.g., input from nominating committees) were used to assess cybersecurity oversight.
  • Requires the SEC, in consultation with NIST, to define what counts as cybersecurity expertise using standards like NIST’s NICE Cybersecurity Workforce Framework.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

3 earlier actions
SenateCommittee Latest Action

Committee on Banking, Housing, and Urban Affairs. Hearings held. Hearings printed: S.Hrg. 116-118.

June 11, 2019

View full timeline
SenateIntro Referral

Introduced in Senate

February 28, 2019

SenateIntro Referral

Read twice and referred to the Committee on Banking, Housing, and Urban Affairs. (Sponsor introductory remarks on measure: CR S1595-1596)

February 28, 2019

SenateCommittee

Committee on Banking, Housing, and Urban Affairs. Hearings held.

February 28, 2019

SenateCommittee

Committee on Banking, Housing, and Urban Affairs. Hearings held. Hearings printed: S.Hrg. 116-118.

June 11, 2019

Floor Debate

8 members

What members said about S. 592 on the floor

3 Republicans5 Democrats
Tom Udall
Sen. Tom UdallD-NM · Feb 28, 2019

Thank you for the recognition, Madam President. Today I rise to call on this body to defend the Constitution, to protect the separation of powers, and to safeguard Congress's role as a coequal branch…

Chuck Grassley
Sen. Chuck GrassleyR-IA · Feb 28, 2019

Mr. President, before the Presidents Day recess, I announced that I would introduce legislation if the tax extenders weren't included in the legislation that we passed at that time that would keep…

Susan M. Collins
Sen. Susan M. CollinsR-ME · Feb 28, 2019

Mr. President, I rise today to speak on the resolution that I am joining Senator Udall in introducing. It would reverse the President's ill-advised decision to declare a national emergency and…

Jack Reed
Sen. Jack ReedD-RI · Feb 28, 2019

Mr. President, today I am reintroducing the Cybersecurity Disclosure Act along with two members of the Select Committee on Intelligence, Senator Collins, and the ranking member, Senator Warner, in…

Jack Reed
Sen. Jack ReedD-RI · Feb 28, 2019

Mr. President, today I am reintroducing the Cybersecurity Disclosure Act along with two members of the Select Committee on Intelligence, Senator Collins, and the ranking member, Senator Warner, in…

Show 4 more
Thomas R. Carper
Sen. Thomas R. CarperD-DE · Feb 28, 2019

Mr. President, during the debate on the nomination of Andrew Wheeler to be Administrator of the Environmental Protection Agency I came to the floor to express concerns on a number of issues,…

Charles E. Schumer
Sen. Charles E. SchumerD-NY · Feb 28, 2019

Mr. President, I am joined this morning by a group of my Democratic colleagues to talk about the greatest threat facing our country and our planet--climate change. Despite the gravity and scale of…

John Thune
Sen. John ThuneR-SD · Feb 28, 2019

Mr. President, I ask unanimous consent that the text of the bill be printed in the Record.

Richard J. Durbin
Sen. Richard J. DurbinD-IL · Feb 28, 2019

Mr. President, I ask unanimous consent that the text of the bill be printed in the Record.

Bill Text

Latest available legislative text

Reading Mode
Latest
Introduced in SenateIssued February 28, 2019

II

116th CONGRESS

1st Session

S. 592

IN THE SENATE OF THE UNITED STATES

February 28, 2019

Mr. Reed (for himself, Ms. Collins, Mr. Warner, Mr. Kennedy, and Mr. Jones) introduced the following bill; which was read twice and referred to the Committee on Banking, Housing, and Urban Affairs

A BILL

To amend the Securities Exchange Act of 1934 to promote transparency in the oversight of cybersecurity risks at publicly traded companies.

1.

Short title

This Act may be cited as the Cybersecurity Disclosure Act of 2019.

2.

Cybersecurity transparency

The Securities Exchange Act of 1934 (15 U.S.C. 78a et seq.) is amended by inserting after section 14B (15 U.S.C. 78n–2) the following:

14C.

Cybersecurity transparency

(a)

Definitions

In this section—

(1)

the term cybersecurity means any action, step, or measure to detect, prevent, deter, mitigate, or address any cybersecurity threat or any potential cybersecurity threat;

(2)

the term cybersecurity threat

(A)

means an action, not protected by the First Amendment to the Constitution of the United States, on or through an information system that may result in an unauthorized effort to adversely impact the security, availability, confidentiality, or integrity of an information system or information that is stored on, processed by, or transiting an information system; and

(B)

does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement;

(3)

the term information system

(A)

has the meaning given the term in section 3502 of title 44, United States Code; and

(B)

includes industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers;

(4)

the term NIST means the National Institute of Standards and Technology; and

(5)

the term reporting company means any company that is an issuer—

(A)

the securities of which are registered under section 12; or

(B)

that is required to file reports under section 15(d).

(b)

Requirement To issue rules

Not later than 360 days after the date of enactment of this section, the Commission shall issue final rules to require each reporting company, in the annual report of the reporting company submitted under section 13 or section 15(d) or in the annual proxy statement of the reporting company submitted under section 14(a)—

(1)

to disclose whether any member of the governing body, such as the board of directors or general partner, of the reporting company has expertise or experience in cybersecurity and in such detail as necessary to fully describe the nature of the expertise or experience; and

(2)

if no member of the governing body of the reporting company has expertise or experience in cybersecurity, to describe what other aspects of the reporting company’s cybersecurity were taken into account by any person, such as an official serving on a nominating committee, that is responsible for identifying and evaluating nominees for membership to the governing body.

(c)

Cybersecurity expertise or experience

For purposes of subsection (b), the Commission, in consultation with NIST, shall define what constitutes expertise or experience in cybersecurity using commonly defined roles, specialties, knowledge, skills, and abilities, such as those provided in NIST Special Publication 800–181, entitled National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework, or any successor thereto.

.