1---2name: sec-reporting-compliance-timeline3description: Compliance timeline assessment identifying obligations, errors, and gaps across multiple new SEC reporting requirements, including filer status classification, cybersecurity disclosures, and executive compensation clawback rules, using general rule-based analysis rather than scenario-specific conclusions.4---56# Skill: SEC Reporting Requirements Compliance Timeline Assessment78## 1. Subject-matter triage9- Treat this as a multi-issue regulatory timeline review across distinct SEC compliance tracks.10- First identify the universe of reporting obligations implicated by the source set, then sort them by regulatory area and triggering event.11- If the documents contain multiple fiscal periods, reporting entities, or triggering events, enumerate them before analysis and keep each timeline separate.12- If a single entity or period is actually in scope, say so explicitly and explain why the remaining materials do not create a separate track.1314## 2. Failure modes the skill is correcting15- Accepting a filer-status determination that rests on only one prong of the applicable test, which distorts every downstream filing deadline.16- Failing to validate compliance dates stated in internal guidance against the governing rule’s effective date and any phase-in schedule.17- Missing the restatement-to-clawback connection, especially where the lookback period reaches into prior periods not obvious from current management reporting.18- Overlooking cybersecurity governance or incident disclosure gaps because the annual-report discussion is partial, outdated, or mismatched to the company’s risk profile.19- Treating policy existence as enough when the rule requires scope, approval, maintenance, and disclosure.20- Collapsing distinct disclosure obligations into one generic “SEC compliance” issue, which hides urgency and responsible ownership.21- Giving conclusions without naming the controlling rule, regulation, or authority supporting them.2223## 3. Legal frameworks / domain conventions that apply24- Filer status classification: apply the full multi-prong test for the relevant filer category, then use that category to determine periodic-report deadlines and related disclosure burdens.25- Periodic reporting deadlines: compute due dates from the relevant fiscal-year end or triggering event under the applicable SEC framework.26- Cybersecurity disclosure framework: assess required disclosure of cybersecurity risk management, strategy, governance, and incident reporting obligations for the filer category at issue.27- Clawback framework: evaluate whether a compliant policy exists for recovery of incentive-based compensation following an accounting restatement; confirm scope, governance, and disclosure mechanics.28- Restatement interaction: any prior-period restatement may require retrospective analysis of incentive-based compensation earned during the applicable lookback period.29- Internal-control and certification framework: determine which certifications, management assessments, and auditor-attestation requirements apply based on filer category and reporting status.30- Beneficial ownership disclosure framework: governance rights granted to a significant holder may alter the disclosure analysis when combined with equity ownership.31- Insider-trading policy framework: verify adoption, maintenance, approval, and required disclosure of a compliant insider-trading policy.32- Governing authority should be cited by name and section or part where feasible, including the relevant SEC rule, form item, or Exchange Act provision.3334## 4. Analytical scaffolds35- Build a regulatory matrix with one row per obligation track and columns for source document, governing authority, trigger, due date, current status, defect type, severity, and consequence.36- For filer status, test every required prong of the applicable classification and map the resulting category to all downstream filing deadlines.37- For cybersecurity, compare the document’s disclosures against the required categories: risk management, governance, strategy, and incident response/reporting.38- For clawback, test policy scope against the covered-person definition, then test any restatement against the applicable lookback period and recovery analysis.39- For timeline issues, distinguish between hard deadlines, conditional deadlines, and internal target dates; do not treat internal estimates as controlling unless they match the rule.40- For external guidance, cross-check each stated date or sequencing assumption against the governing rule and phase-in schedule before carrying it forward.41- For beneficial ownership, analyze governance rights separately from equity percentage and then assess the combined effect on disclosure and filing obligations.42- For insider-trading policy, verify existence, approval authority, disclosure location, and whether the policy is current and operative.43- For each issue, include: severity, governing authority, source document reference, why the document is wrong or incomplete, and the downstream compliance consequence.44- Use an ordinal severity scale defined once at the top of the memo and apply it consistently across all entries.45- Rank issues by urgency, with imminent filing or disclosure obligations ahead of structural policy gaps and standalone disclosure deficiencies.46- End each issue with a practical action tied to a responsible role and a timing anchor.4748## 5. Vertical / structural / temporal relationships49- An incorrect filer category cascades into incorrect filing deadlines, disclosure triggers, and potentially incorrect internal-control conclusions.50- Restatement and clawback are temporally linked to the restatement event, not to current-period awareness; the lookback may reach into prior compensation periods.51- A document’s internal compliance calendar is not controlling if it conflicts with the governing rule or phase-in schedule.52- Governance-rights analysis may depend on the combination of rights and equity holdings, so separate the rights package from the ownership percentage before concluding.53- Treat the timeline as forward-looking from the triggering event, but flag retrospective obligations where the rule reaches back into prior periods.54- If multiple obligations share the same trigger, preserve their distinct deadlines rather than merging them into a single “SEC due date.”5556## 6. Output structure conventions57- Write a compliance timeline memorandum organized by regulatory area, not as a free-form narrative.58- Start with a short executive summary that identifies the highest-risk gaps and the most time-sensitive obligations.59- Include a brief methodology note identifying the source set reviewed and the controlling authorities applied.60- For each issue, provide: severity, regulatory area, controlling authority, source document reference, obligation, defect/gap, deadline or trigger date, consequence, and recommended action.61- Use specific calendar dates where the source set and governing rule permit derivation; otherwise state the triggering event and explain the timing logic.62- Keep timeline entries chronological within each regulatory area when dates are known.63- Conclude with a prioritized action plan that assigns responsibility to the relevant officer, counsel, or business owner and states the timing anchor.64- Surface verbatim quotes from internal documents only when they are necessary to identify the exact language at issue; otherwise paraphrase and cite the source document.