3 unchanged sentences
The Trust does not have any officers, directors or employees.
−Removed: The Sponsor, an indirect subsidiary of BlackRock, is responsible for the oversight and overall management of the Trust.
+Added: The Sponsor, a consolidated subsidiary of BlackRock, is responsible for the oversight and overall management of the Trust.
The Sponsor relies on BlackRock’s ERM framework for the Trust’s cybersecurity risk management and strategy.
5 unchanged sentences
Cybersecurity represents an important component of BlackRock’s approach to ERM.
−Removed: BlackRock leverages a multi-lines-of-defense model with cybersecurity operational processes executed by global information security and other teams and dedicated internal audit technology and technology risk management (“TRM”) teams that independently review technology risks.
−Removed: BlackRock’s cybersecurity program is fully integrated into its ERM framework and is aligned with recognized frameworks, including NIST CSF, FFIEC CAT, FedRAMP, SOC 1/2, ISO 27001/2 and others.
+Added: BlackRock leverages a multi-layered defense model in which cybersecurity operational processes are executed by global information security and other firmwide teams, supported by dedicated internal audit and technology risk management (“TRM”) teams that independently review technology risks.
+Added: BlackRock’s cybersecurity program is fully integrated into its ERM framework and is aligned with recognized frameworks, such as NIST Cybersecurity Framework, Cyber Risk Institute Profile, ISO/IEC 27001/27001, and other leading frameworks.
BlackRock aims to inform and continuously improve its cybersecurity program through engagement with regulatory, client, insurer, vendor, partner, peer, government and industry organizations and associations, as well as external audit, technology risk, information security and other assessments.
−Removed: BlackRock seeks to address cybersecurity risks through a global, multilayered strategy of control programs that is designed to preserve the confidentiality, integrity and availability of the information that BlackRock collects and stores by identifying, preventing and mitigating cybersecurity threats and incidents.
+Added: BlackRock seeks to address cybersecurity risks through a global, multilayered strategy of control programs that are designed to preserve the confidentiality, integrity and availability of the information that BlackRock collects and stores by identifying, preventing and mitigating cybersecurity threats and incidents.
As one of the critical elements of BlackRock’s overall ERM framework, BlackRock’s cybersecurity program is focused on the following key areas:
3 unchanged sentences
BlackRock has implemented a global, cross-functional approach to identifying, preventing, and mitigating cybersecurity threats and incidents, while also implementing layered preventative, detective, reactive and recovery controls to identify and manage cybersecurity risks.
−Removed: BlackRock deploys a range of people, process and technical controls that are designed to protect BlackRock’s information systems from cybersecurity threats, which may include, among others:
−Removed: physical security controls; perimeter controls, including technical assessments, firewalls, network segregation, intrusion detection and prevention; tabletop exercises, ongoing vulnerability and patch management; vendor due diligence; multi-factor authentication; device encryption; application security, code testing and penetration testing; endpoint security, including anti‑malware protection, threat intel and response, managed detection and response, security configuration management, portable storage device lockdown, restricted administrative privileges; employee awareness, training, and phishing testing; data loss prevention program and monitoring; information security incident reporting and monitoring; and layered and comprehensive access controls.
+Added: BlackRock deploys a range of people, processes and technical controls that are designed to protect BlackRock’s information systems from cybersecurity threats, which may include, among others:
+Added: physical security controls;
+Added: perimeter controls, including technical assessments, firewalls, network segregation and intrusion detection and prevention;
+Added: tabletop exercises, ongoing vulnerability and patch management;
+Added: vendor due diligence;
+Added: multi-factor authentication;
+Added: device encryption;
+Added: application security, code testing and penetration testing;
+Added: endpoint security, including anti‑malware protection, threat intel and response, managed detection and response, security configuration management, portable storage device lockdown and restricted administrative privileges;
+Added: employee awareness, training, and phishing testing;
+Added: a data loss prevention program and monitoring;
+Added: information security incident reporting and monitoring;
+Added: and layered and comprehensive access controls.
Incident Response and Recovery Planning:
−Removed: BlackRock has established and maintains incident response and recovery plans that address BlackRock’s response to a cybersecurity incident, including processes designed to assess, escalate, contain, investigate and remediate the incident, as well as to comply with applicable legal obligations and mitigate potential reputational damage.
−Removed: Such plans are evaluated on a periodic basis.
+Added: BlackRock has established and maintains incident response and recovery plans that address BlackRock’s response to a cybersecurity incident, including processes designed to assess, escalate, contain, investigate and remediate an incident, as well as to comply with applicable legal obligations and mitigate potential reputational damage.
+Added: These plans are evaluated on a periodic basis.
Third-Party Risk Management:
BlackRock maintains a risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers, counterparties and clients, as well as the systems of third parties that could significantly and adversely impact BlackRock’s business in the event of a cybersecurity incident affecting those third -party systems.
+Added: Operational incidents can arise as a result of failures by third parties with which BlackRock does business, such as failures by internet, communication technology and cloud service providers or other vendors to adequately follow processes and procedures, safeguard their systems, or prevent system disruptions or cyber-attacks.
Third-party risks are included within BlackRock’s ERM framework, and risk identification and mitigation are supported by BlackRock’s cybersecurity program.
−Removed: BlackRock also performs diligence on certain third parties and monitors cybersecurity threats and risks identified through such diligence.
+Added: BlackRock also performs due diligence on certain third parties and monitors cybersecurity threats and risks identified through such diligence.
Education and Awareness:
1 unchanged sentence
BlackRock’s global information security team, in collaboration with the technology risk and internal audit teams, engages in the periodic assessment and testing of BlackRock’s cyber risks and cybersecurity program.
−Removed: These efforts may include a wide range of activities, including audits, assessments, wargames and “tabletop” exercises, threat modeling, vulnerability testing and other exercises focused on evaluating the effectiveness of our cybersecurity measures and planning.
+Added: These efforts may include a wide range of activities, including audits, assessments, war games and “tabletop” exercises, threat modeling, vulnerability testing and other exercises focused on evaluating the effectiveness of our cybersecurity measures and planning.
BlackRock also participates in financial services industry and government forums in an effort to improve both internal and sector cybersecurity defense.
1 unchanged sentence
The results of certain program and control assessments are reported to BlackRock’s Risk Committee, and BlackRock adjusts its cybersecurity program as appropriate based on the information provided by these assessments.
−Removed: As of December 31, 2024, cybersecurity risks have not materially affected BlackRock’s business strategy, results of operations or financial condition.
+Added: As of December 31, 2025, BlackRock is not aware of any cybersecurity risks that have materially affected or are reasonably likely to materially affect BlackRock’s business strategy, results of operations or financial condition.
BlackRock ’ s Cybersecurity Governance
−Removed: BlackRock’s Board is actively engaged in the oversight of BlackRock’s risk management program.
+Added: BlackRock’s Board of Directors is actively engaged in the oversight of BlackRock’s risk management program.
BlackRock’s Risk Committee assists BlackRock’s Board with its oversight of BlackRock’s levels of risk, risk assessment, risk management and related policies and processes, including risks arising from cybersecurity threats.
7 unchanged sentences
BlackRock’s cybersecurity risk management and strategy processes, which are discussed in greater detail above, are led by BlackRock’s CISO.
−Removed: As of December 31, 2024, the CISO had over 30 years of experience in information technology with a 25-year concentration in information security, including previously serving as the CISO at several global financial institutions, and held the Certified Information Systems Security Professional certification.
+Added: As of December 31, 2025, the CISO had over 31 years of experience in information technology with a 25-year concentration in information security, including previously serving as the CISO at several global financial institutions.
+Added: He also holds the Certified Information Systems Security Professional certification.
The CISO works closely with the leadership team and other subject matter experts in the global cybersecurity group, who collectively have extensive prior work experience in various roles involving managing information security, developing cybersecurity strategy, implementing effective information and cybersecurity programs and overseeing cybersecurity controls in technology risk and audit functions, as well as having relevant degrees and industry-leading certifications.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.