Skip to main content
HR 5069 114th Congress House

Cybersecurity Systems and Risks Reporting Act

Official title: To amend the Sarbanes-Oxley Act of 2002 to protect investors by expanding the mandated internal controls reports and disclosures to include cybersecurity syste… Show full official titleShow less

Official title: To amend the Sarbanes-Oxley Act of 2002 to protect investors by expanding the mandated internal controls reports and disclosures to include cybersecurity systems and risks of publicly traded companies.

Introduced: April 26, 2016 See on congress.gov
Finance and Financial Sector Accounting and auditingAdministrative law and regulatory proceduresBanking and financial institutions regulationBusiness records
More subjectsShow fewer subjects
Computer security and identity theftCorporate finance and managementSecuritiesSecurities and Exchange Commission (SEC)
This bill died when the 114th Congress ended
It never became law before the 114th Congress (2015–2016) adjourned, and bills don't carry over to the next Congress. It would have to be reintroduced. You can still save it for reference, but it won't receive updates.
 Everywhere this bill has been 2 steps
Introduced
In committee
Reported out
Passed House
Passed Senate
To President
Became law
Apr 26, 2016
Referred to the House Committee on Financial Services.
Apr 26, 2016
Introduced in House
 Ask about this bill AI · grounded in the bill text

Have a question about what this bill does? Ask in plain English; the answer is drawn from the bill's actual text and official record, and it'll tell you when something isn't in the text rather than guess.

AI answers can be imperfect; always confirm against the full bill text.

 Latest action April 26, 2016

Referred to the House Committee on Financial Services.

 Plain-English summary Congressional Research Service

Cybersecurity Systems and Risks Reporting Act

This bill amends the Sarbanes-Oxley Act of 2002 to apply to cybersecurity systems and cybersecurity systems officers the same requirements regarding corporate responsibility for financial reports and managements assessments of internal control structures and procedures for financial reporting as apply to public companies subject to oversight by the Securities and Exchange Commission (SEC).

The SEC shall issue rules to define cybersecurity expert and require each issuer of securities to disclose whether or not (and if not, the reasons why) the issuer's audit committee has at least one member who is a cybersecurity expert.

The SEC shall review an issuer's information systems and cybersecurity systems statements. In scheduling the such reviews the SEC shall consider, among other things, issuers that have issued cybersecurity risks disclosures.

 Bill text 1 version

Source documents hosted by congress.gov.

 Committees of jurisdiction 1
Cite this page click to expand
APA
U.S. Congress. (2026). H.R. 5069: Cybersecurity Systems and Risks Reporting Act. 114th Congress. Open America. https://openamerica.io/bill/114-HR-5069/
MLA
"H.R. 5069: Cybersecurity Systems and Risks Reporting Act." 114th Congress, 2026, Open America, https://openamerica.io/bill/114-HR-5069/.
Bluebook (legal)
H.R. 5069, 114th Cong. (2026), https://openamerica.io/bill/114-HR-5069/.
Markdown link
[H.R. 5069: Cybersecurity Systems and Risks Reporting Act](https://openamerica.io/bill/114-HR-5069/)
Report a problem