A US public company (or pre-IPO / S-1)? GreatCTO auto-attaches sec-cyber-pack for the SEC 2023 Cybersecurity Rule: Form 8-K Item 1.05 (4-business-day clock from the materiality determination, not discovery), Reg S-K Item 106 in the 10-K, a defined materiality decision process, vendor-breach attribution, and the CIRCIA 72-hour critical-infrastructure clock — all mapped to your incident-response tooling.
public company · 10-K · 8-K · S-1 · IPO · material incident · incident response · SIEM · PagerDuty · CIRCIA
The pack rides on top of your base archetype (web-service, ai-system, fintech, …) — it doesn't replace it. Auto-injects reviewer agents into the pipeline + opens human gates listed below.
SEC 8-K Item 1.05 + 10-K Item 106 + materiality process + CIRCIA dual-clock + vendor attribution
gate:plan + gate:ship.| Gate | Owner | Trigger |
|---|---|---|
gate:cyber-disclosure-readiness | security-officer | pre-implementation — IR path must produce disclosure artifacts |
Each EVAL has ≥5 test cases, pass threshold, regression interpretation, cross-refs to TM + gates. Run via your existing test framework.
EVAL-seccyber-disclosure-clock.mdpacks: in PROJECT.md./migrate to re-run detection with updated rules.$ npx great-cto init