<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-16-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>3235-AN15</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202410</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>3235</CODE>
            <NAME>Securities and Exchange Commission</NAME>
            <ACRONYM>SEC</ACRONYM>
        </AGENCY>
        <RULE_TITLE>Cybersecurity Risk Management Rules for Broker-Dealers, Clearing Agencies, MSBSPs, the MSRB, National Securities Associations, National Securities Exchanges, SBSDRs, SBS Dealers, and Transfer Agents</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The Division is considering recommending that the Commission adopt amendments to require that market entities address cybersecurity risks, to improve the Commission&rsquo;s ability to obtain information about significant cybersecurity incidents impacting market entities, and to improve transparency about cybersecurity risk in the U.S. securities markets.&nbsp; The Commission proposed a new rule and form and amendments to existing recordkeeping rules to require broker-dealers, clearing agencies, major security-based swap participants, the Municipal Securities Rulemaking Board, national securities associations, national securities exchanges, security-based swap data repositories, security-based swap dealers, and transfer agents to address cybersecurity risks through policies and procedures, immediate notification to the Commission of the occurrence of a significant cybersecurity incident and, as applicable, reporting detailed information to the Commission about a significant cybersecurity incident, and public disclosures that would improve transparency with respect to cybersecurity risks and significant cybersecurity incidents. In addition, the Commission proposed amendments to existing clearing agency exemption orders to require the retention of records that would need to be made under the proposed cybersecurity requirements. Finally, the Commission proposed amendments to address the potential availability to security-based swap dealers and major security-based swap participants of substituted compliance in connection with those requirements.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Substantive, Nonsignificant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Final Rule Stage</RULE_STAGE>
        <MAJOR>Undetermined</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>17 CFR 232.101</CFR>
            <CFR>17 CFR 240.3a71-6</CFR>
            <CFR>17 CFR 240.17a-4</CFR>
            <CFR>17 CFR 240.17Ad-7</CFR>
            <CFR>17 CFR 240.18a-6</CFR>
            <CFR>17 CFR 240.18a-10</CFR>
            <CFR>17 CFR 242.10</CFR>
            <CFR>17 CFR 249.624</CFR>
            <CFR>...</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>15 U.S.C. 77c</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 77f</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 77g</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 77h</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 77j</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 77s(a)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 77z-3</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 77sss(a)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 78c(b)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 78l</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 78m</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 78n</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 78o(d)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 78o-10</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 78w(a)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 78ll</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 80a-6(c)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 80a-8</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 80a-29</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 80a-30</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 80a-37</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 80b-4</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 80b-10</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 80b-11</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 7201 et seq.</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>18 U.S.C. 1350</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>...</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>No</RPLAN_ENTRY>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>04/05/2023</TTBL_DATE>
                <FR_CITATION>88 FR 20212</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Comment Period End</TTBL_ACTION>
                <TTBL_DATE>06/05/2023</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Final Action</TTBL_ACTION>
                <TTBL_DATE>12/00/2024</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>YES</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>None</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <PRINT_PAPER>Yes</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Nina</FIRST_NAME>
                <LAST_NAME>Kostyukovsky</LAST_NAME>
                <TITLE>Attorney</TITLE>
                <AGENCY>
                    <CODE>3235</CODE>
                    <NAME>Securities and Exchange Commission</NAME>
                    <ACRONYM>SEC</ACRONYM>
                </AGENCY>
                <PHONE>202 551-8833</PHONE>
                <EMAIL>kostyukovskyn@sec.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>100 F Street NE,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20549</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
