Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The SEC’s proposed 48-hour cybersecurity incident reporting plan for investment advisers and funds did not become an effective requirement on the strength of the February 2022 vote. The Commission voted 3-1 to approve a recommendation to publish a proposal for public comment; the SEC’s rulemaking index later listed file S7-04-22 in a June 12, 2025 action titled “Withdrawal of Proposed Regulatory Actions.” That index entry is a withdrawal signal, not enough by itself to establish the precise legal effect on every proposed provision.

What the SEC voted on in February 2022

On February 9, 2022, the Securities and Exchange Commission voted 3-1 to approve a recommendation for a cybersecurity proposal covering investment advisers and funds. The contemplated next step was a public-comment period. This was a procedural step toward considering a rule—not a final rule, nor a new legal duty. CyberScoop’s contemporaneous account described the vote and the proposal’s reported terms.

SEC Chair Gary Gensler said the proposed rules and amendments were intended to enhance cybersecurity preparedness and could improve investor confidence in advisers’ and funds’ resilience. Commissioner Hester Peirce cautioned that detailed prescriptions could become an enforcement hook even when a firm had made reasonable efforts to comply. Their statements reflected a policy debate, not a determination that the proposed requirements had taken effect.

What the reported 48-hour requirement would have covered

As CyberScoop described the proposal in 2022, covered advisers and funds would have had to submit a confidential report to the SEC within 48 hours after a significant cybersecurity incident. The 48-hour period was a proposed reporting deadline in that account, not a current, generally applicable obligation established by the vote.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The account also described proposed baseline cybersecurity program elements:

  • Assess cybersecurity risks.
  • Use user security and access controls.
  • Protect information and monitor for unauthorized use.
  • Conduct an annual written review of cybersecurity risks and policies for board review.

These are high-level descriptions of the 2022 proposal. The proposed-rule text is the relevant primary source for definitions, covered entities, exceptions, and reporting mechanics; the news account should not be treated as a substitute for those details. SEC proposed-rule PDF.

SEC reporting and investor disclosure were separate questions

The proposal’s reported confidential incident report to the SEC was distinct from telling investors about cybersecurity risks or incidents. CyberScoop reported that commissioners sought input on the scope and timing of investor-facing disclosures, and that the proposal as described did not specify their timing or extent. The 48-hour figure therefore should not be presented as an investor-notification deadline.

What the SEC’s later withdrawal entry establishes

The SEC’s rulemaking activity index lists a June 12, 2025 final action titled “Withdrawal of Proposed Regulatory Actions,” and the entry includes file S7-04-22. This makes the 2022 headline historical: the index records a later withdrawal action associated with the file. Because the entry groups multiple proposed actions, it does not, on its own, spell out which individual provisions were withdrawn or the exact legal consequences for each part of the 2022 proposal. SEC rulemaking activity index.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not confuse it with the SEC’s 2023 public-company rule

The SEC also adopted a related but distinct cybersecurity rule in 2023 for public companies. That rulemaking is not the adviser-and-fund proposal described above, and its final-rule text should not be used to infer what the 2022 proposal required or what happened to its provisions. SEC 2023 final-rule PDF.

Measure Entities in view Status reflected in the cited material
2022 proposal, file S7-04-22 Investment advisers and funds Proposal recommendation approved 3-1 in February 2022; SEC index later lists the file under a June 12, 2025 withdrawal action.
Related 2023 final rule Public companies A separate final rule; it is not the adviser-and-fund proposal.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this means for readers

The February 2022 vote did not itself create a 48-hour reporting duty. The SEC index’s 2025 entry signals later withdrawal activity involving S7-04-22, but the index description alone does not resolve the status of every proposed element. Firms assessing current obligations should rely on the applicable regulations and the text of the SEC’s underlying actions, not on the 2022 headline or a summary of the proposal.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.