Although the SEC guidance is not mandatory, the SEC is likely to make certain cyber incident reporting requirements mandatory in the future and corporations should be ready to meet such requirements.
FORBES: Disclosing Cyber Security Incidents: The SEC Weighs In