United States 116th Congress Status: In Committee 1 D cosponsors

S 592 — Cybersecurity Disclosure Act of 2019

Last action — Committee on Banking, Housing, and Urban Affairs. Hearings held. Hearings printed: S.Hrg. 116-118.

  1. ✓
    Introduced
  2. 2
    In Committee
  3. 3
    Passed Senate
  4. 4
    Passed House
  5. 5
    To Executive
  6. 6
    Enacted

This bill died with 116th Congress. It reached “In Committee” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.

This bill is no longer active — its legislative session has ended, so there is no live prognosis. It would have to be reintroduced in the current session to move again.

Summary

Cybersecurity Disclosure Act of 2019 This bill directs the Securities and Exchange Commission to issue final rules requiring a registered issuer to disclose in its mandatory annual report or annual proxy statement whether any member of its governing body has expertise or experience in cybersecurity; and if no member has such expertise or experience, describe what other company cybersecurity aspects were taken into account by the persons responsible for identifying and evaluating nominees for the governing body.

Bill Text

How this bill changes current law

1 change Share ↗

Compared against current U.S. Code AI-generated reading aid — verify against the official bill.

The bill adds a new requirement for publicly traded companies to disclose cybersecurity expertise on their governing bodies.

  • 15 U.S.C. § 78n

    SEC. 14C. CYBERSECURITY TRANSPARENCY. (a) Definitions.--In this section-- (1) the term `cybersecurity' means any action, step, or measure to detect, prevent, deter, mitigate, or address any cybersecurity threat or any potential cybersecurity threat; (2) the term `cybersecurity threat'-- (A) means an action, not protected by the First Amendment to the Constitution of the United States, on or through an information system that may result in an unauthorized effort to adversely impact the security, availability, confidentiality, or integrity of an information system or information that is stored on, processed by, or transiting an information system; and (B) does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement; (3) the term `information system'-- (A) has the meaning given the term in section 3502 of title 44, United States Code; and (B) includes industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers; (4) the term `NIST' means the National Institute of Standards and Technology; and (5) the term `reporting company' means any company that is an issuer-- (A) the securities of which are registered under section 12; or (B) that is required to file reports under section 15(d). (b) Requirement To Issue Rules.--Not later than 360 days after the date of enactment of this section, the Commission shall issue final rules to require each reporting company, in the annual report of the reporting company submitted under section 13 or section 15(d) or in the annual proxy statement of the reporting company submitted under section 14(a)-- (1) to disclose whether any member of the governing body, such as the board of directors or general partner, of the reporting company has expertise or experience in cybersecurity and in such detail as necessary to fully describe the nature of the expertise or experience; and (2) if no member of the governing body of the reporting company has expertise or experience in cybersecurity, to describe what other aspects of the reporting company's cybersecurity were taken into account by any person, such as an official serving on a nominating committee, that is responsible for identifying and evaluating nominees for membership to the governing body. (c) Cybersecurity Expertise or Experience.--For purposes of subsection (b), the Commission, in consultation with NIST, shall define what constitutes expertise or experience in cybersecurity using commonly defined roles, specialties, knowledge, skills, and abilities, such as those provided in NIST Special Publication 800-181, entitled `National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework', or any successor thereto.

    This creates new requirements for reporting companies to disclose their governing body's cybersecurity expertise.

Action History

  1. Introduced in Senate

  2. Read twice and referred to the Committee on Banking, Housing, and Urban Affairs. (Sponsor introductory remarks on measure: CR S1595-1596)

  3. Committee on Banking, Housing, and Urban Affairs. Hearings held.

  4. Committee on Banking, Housing, and Urban Affairs. Hearings held. Hearings printed: S.Hrg. 116-118.

Sponsors

Sponsorship breakdown

Export CSV (upgrade) →

1 sponsors · 0 co-sponsors · 546 not signed on

Sponsors (1)

Co-sponsors (0)

None.

Not signed on (546)

546 members have not signed on to this bill.

Show all 546 →

"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.

Whip count is in markup. Polling the chamber and every recorded vote this session. Only the first open is slow. It’s instant for you after this. Calling the roll · Tallying · Engrossing

Subjects

Cross-referencing the record. Reading this bill against every other bill in the corpus by meaning, not keywords. Only the first open is slow. It’s instant for you after this. Matching · Ranking · Engrossing

Frequently asked questions

What does S 592 do?
Cybersecurity Disclosure Act of 2019 This bill directs the Securities and Exchange Commission to issue final rules requiring a registered issuer to disclose in its mandatory annual report or annual proxy statement whether any member of its governing body has expertise or experience in cybersecurity; and if no member has such expertise or experience, describe what other company cybersecurity aspects were taken into account by the persons responsible for identifying and evaluating nominees for the governing body.
Who sponsors S 592?
S 592 is sponsored by Reed, Jack (Democratic).
What is the current status of S 592?
This bill died with 116th Congress. It reached “In Committee” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.
Where can I track S 592?
Track S 592 free on One Click Politics — get push/email alerts when it moves.

Make your voice heard on S 592

Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.

Stay ahead of S 592

Last checked for changes 3 months ago · updated continuously

One Click Politics tracks every bill in Congress and all 50 states.

Track this bill →