Reg S-P guide › The withdrawn cybersecurity rule
If you run a small SEC-registered advisory firm, you may remember 2022's proposed cybersecurity rule for advisers — written cyber policies, a new confidential incident report to the SEC, new cyber disclosure in the Form ADV brochure. You may also have read that it was withdrawn, and concluded that the SEC dropped cybersecurity for advisers. The first half is true. The conclusion is not, and the gap between them is where small firms get caught.
The SEC's Notice of Withdrawal of Proposed Regulatory Actions (Release No. IA-6885; 90 FR 25531), dated June 12, 2025 and published June 17, 2025, withdrew fourteen proposals. Two of them were aimed at investment advisers' operations and would have reached small firms:
| Withdrawn proposal | What it would have done (per the SEC's own descriptions) |
|---|---|
| Cybersecurity Risk Management — proposed Rule 206(4)-9, proposed Rule 204-6 and Form ADV-C (87 FR 13524, published March 9, 2022) | Written policies and procedures "reasonably designed to address cybersecurity risks"; confidential reporting of significant cybersecurity incidents to the SEC on a new Form ADV-C; cyber risk and incident disclosure in Form ADV Part 2A; related books and records. |
| Outsourcing by Investment Advisers — proposed Rule 206(4)-11 (87 FR 68816, published November 16, 2022) | Would have prohibited advisers from outsourcing certain "covered functions" without first meeting due-diligence and monitoring requirements, plus related Form ADV disclosure about those service providers. |
The notice's own language on what happens next: the Commission "does not intend to issue final rules with respect to these proposals," and if it pursues regulatory action in any of these areas, "it will issue a new proposed rule." In practice that means there is no Form ADV-C, no adviser-wide Rule 206(4)-9, and no Rule 206(4)-11 — and anything that replaces them would have to go through a fresh proposal and comment period first.
Every item withdrawn was a proposal. The Regulation S-P amendments (Release No. 34-100155) were adopted in May 2024 and were not a proposal by June 2025, so they could not have been withdrawn by that notice, and they were not. Compliance dates ran December 3, 2025 for larger entities and June 3, 2026 for smaller ones. For a small SEC-registered adviser, amended Reg S-P is currently in force.
Two older obligations also sit entirely outside the withdrawal:
This is the part most summaries skip. Amended Reg S-P covers part of the ground the two withdrawn proposals would have covered, but its scope is keyed to customer information, not to cybersecurity risk in general and not to every outsourced function. The comparison below is our reading of the rule texts and the SEC's descriptions, not SEC guidance:
| Topic | Withdrawn proposal would have required | What binds a small SEC-registered RIA now |
|---|---|---|
| Written security policies | Cyber policies addressing cybersecurity risks across the adviser's operations (206(4)-9) | Reg S-P safeguards policies for customer records and information, now including a written incident response program. Broader operational cyber risk falls back on 206(4)-7's general "reasonably designed" standard. |
| Incident reporting | Confidential report to the SEC on Form ADV-C | No SEC report. Reg S-P requires notice to affected individuals within 30 days when sensitive customer information was, or is reasonably likely to have been, accessed without authorization (breach notice). State breach laws may add regulator or attorney-general notices. |
| Client-facing disclosure | Cyber risks and incidents described in Form ADV Part 2A | No Reg S-P brochure requirement. Your existing duty for Form ADV to be accurate still applies; whether a specific incident must be disclosed there is a facts question for counsel. |
| Vendor oversight | Due diligence and monitoring before outsourcing any "covered function" (206(4)-11) | Reg S-P requires written policies for oversight of service providers, including a vendor notice to you within 72 hours of a breach of a customer information system — but only for providers with access to customer information, not all outsourced functions. |
| Records | New cyber-specific books and records under Rule 204-2 | Reg S-P's own recordkeeping requirements for the IRP, notices, and vendor oversight. |
We cannot verify that one is. The withdrawal notice commits only that any future rule would start as a new proposal. The Spring 2026 regulatory agenda, as summarized by one law firm we read (Sidley, July 13, 2026), describes a largely deregulatory program. Its highlighted adviser items include amendments to Rule 204-2 (books and records) and the custody rule, not a cybersecurity rule. We have not read the full agenda entry-by-entry, so treat "no cyber item" as unconfirmed. The 204-2 item is worth watching, because Reg S-P's records sit alongside that rule, but we are not predicting what it will change.
A practical frame, not legal advice:
The rule that survived is the one with deadlines. AdviserLedger keeps a small RIA's Reg S-P pieces in one place: the vendor inventory and 72-hour clauses, the incident response steps, the 30-day notice clock, and the records an examiner asks for.
See how it works →The full Reg S-P guide for small RIAs · does Reg S-P apply to my firm? · writing the incident response program · service-provider oversight · the September 2026 risk alert on annual compliance reviews · what the FY2026 exam priorities say · Regulation S-ID