Get Reg S-P ready →

Reg S-P guide › The withdrawn cybersecurity rule

Is there an SEC cybersecurity rule for RIAs? The proposal is gone. The obligations mostly are not.

Published September 26, 2026 · primary sources linked below

If you run a small SEC-registered advisory firm, you may remember 2022's proposed cybersecurity rule for advisers — written cyber policies, a new confidential incident report to the SEC, new cyber disclosure in the Form ADV brochure. You may also have read that it was withdrawn, and concluded that the SEC dropped cybersecurity for advisers. The first half is true. The conclusion is not, and the gap between them is where small firms get caught.

In one sentence: the SEC withdrew the proposed adviser cybersecurity rule and the proposed outsourcing rule on June 12, 2025 — but amended Regulation S-P was already a final rule, was not on the withdrawal list, and has applied to smaller advisers since June 3, 2026. It carries narrower versions of several things the withdrawn proposals would have required.

What was actually withdrawn

The SEC's Notice of Withdrawal of Proposed Regulatory Actions (Release No. IA-6885; 90 FR 25531), dated June 12, 2025 and published June 17, 2025, withdrew fourteen proposals. Two of them were aimed at investment advisers' operations and would have reached small firms:

Withdrawn proposalWhat it would have done (per the SEC's own descriptions)
Cybersecurity Risk Management — proposed Rule 206(4)-9, proposed Rule 204-6 and Form ADV-C (87 FR 13524, published March 9, 2022)Written policies and procedures "reasonably designed to address cybersecurity risks"; confidential reporting of significant cybersecurity incidents to the SEC on a new Form ADV-C; cyber risk and incident disclosure in Form ADV Part 2A; related books and records.
Outsourcing by Investment Advisers — proposed Rule 206(4)-11 (87 FR 68816, published November 16, 2022)Would have prohibited advisers from outsourcing certain "covered functions" without first meeting due-diligence and monitoring requirements, plus related Form ADV disclosure about those service providers.

The notice's own language on what happens next: the Commission "does not intend to issue final rules with respect to these proposals," and if it pursues regulatory action in any of these areas, "it will issue a new proposed rule." In practice that means there is no Form ADV-C, no adviser-wide Rule 206(4)-9, and no Rule 206(4)-11 — and anything that replaces them would have to go through a fresh proposal and comment period first.

What was not on the list — and why it matters

Every item withdrawn was a proposal. The Regulation S-P amendments (Release No. 34-100155) were adopted in May 2024 and were not a proposal by June 2025, so they could not have been withdrawn by that notice, and they were not. Compliance dates ran December 3, 2025 for larger entities and June 3, 2026 for smaller ones. For a small SEC-registered adviser, amended Reg S-P is currently in force.

Two older obligations also sit entirely outside the withdrawal:

Where the surviving rule overlaps the withdrawn ones — and where it stops

This is the part most summaries skip. Amended Reg S-P covers part of the ground the two withdrawn proposals would have covered, but its scope is keyed to customer information, not to cybersecurity risk in general and not to every outsourced function. The comparison below is our reading of the rule texts and the SEC's descriptions, not SEC guidance:

TopicWithdrawn proposal would have requiredWhat binds a small SEC-registered RIA now
Written security policiesCyber policies addressing cybersecurity risks across the adviser's operations (206(4)-9)Reg S-P safeguards policies for customer records and information, now including a written incident response program. Broader operational cyber risk falls back on 206(4)-7's general "reasonably designed" standard.
Incident reportingConfidential report to the SEC on Form ADV-CNo SEC report. Reg S-P requires notice to affected individuals within 30 days when sensitive customer information was, or is reasonably likely to have been, accessed without authorization (breach notice). State breach laws may add regulator or attorney-general notices.
Client-facing disclosureCyber risks and incidents described in Form ADV Part 2ANo Reg S-P brochure requirement. Your existing duty for Form ADV to be accurate still applies; whether a specific incident must be disclosed there is a facts question for counsel.
Vendor oversightDue diligence and monitoring before outsourcing any "covered function" (206(4)-11)Reg S-P requires written policies for oversight of service providers, including a vendor notice to you within 72 hours of a breach of a customer information system — but only for providers with access to customer information, not all outsourced functions.
RecordsNew cyber-specific books and records under Rule 204-2Reg S-P's own recordkeeping requirements for the IRP, notices, and vendor oversight.
The practical trap: a firm that read "cyber rule withdrawn" and paused its security work in mid-2025 was, in most cases, pausing the same work Reg S-P would require of it twelve months later: an incident response program, a vendor inventory with notice clauses, and a customer-notification process. The label went away; for customer data, most of the work did not.

Is a new adviser cybersecurity rule coming?

We cannot verify that one is. The withdrawal notice commits only that any future rule would start as a new proposal. The Spring 2026 regulatory agenda, as summarized by one law firm we read (Sidley, July 13, 2026), describes a largely deregulatory program. Its highlighted adviser items include amendments to Rule 204-2 (books and records) and the custody rule, not a cybersecurity rule. We have not read the full agenda entry-by-entry, so treat "no cyber item" as unconfirmed. The 204-2 item is worth watching, because Reg S-P's records sit alongside that rule, but we are not predicting what it will change.

What a small RIA can do with this

A practical frame, not legal advice:

  1. Remove "the cyber rule" as a planning item — there isn't one for SEC-registered advisers — and re-label the work under the rules that exist: Reg S-P (customer information, IRP, vendors, notices), Reg S-ID (red flags, if it applies to you), and 206(4)-7 (policies reasonably designed for your risks, reviewed annually).
  2. Check any policy documents drafted in 2022–2023 against the proposal. A few firms wrote to the proposed 206(4)-9. Those documents may cite a rule that does not exist, or lack elements Reg S-P specifically requires, like the 30-day customer notice or the 72-hour vendor clause. Citing a non-existent rule is the kind of gap an annual review should catch.
  3. Decide deliberately how far past customer information you go. Reg S-P's scope is customer information. Ransomware that locks your trading systems without touching client data may fall outside it, but it still sits under your 206(4)-7 business-continuity expectation. The line between the two is yours to document.
  4. If you are state-registered, none of this is your rulebook. See why the FTC Safeguards Rule applies instead.

The rule that survived is the one with deadlines. AdviserLedger keeps a small RIA's Reg S-P pieces in one place: the vendor inventory and 72-hour clauses, the incident response steps, the 30-day notice clock, and the records an examiner asks for.

See how it works →

What we did not assert

Related guides

The full Reg S-P guide for small RIAs · does Reg S-P apply to my firm? · writing the incident response program · service-provider oversight · the September 2026 risk alert on annual compliance reviews · what the FY2026 exam priorities say · Regulation S-ID

Official sources