−Removed: Unresolved Staff Comments.
−Removed: Cybersecurity.
−Removed: Risk management and strategy
−Removed: We rely on our technology network infrastructure
−Removed: and information systems to operate our business, interact with vendors and customers, and collect and make payments, among other functions.
−Removed: Our internally developed infrastructure and systems, as well as those systems and processes provided by third-party vendors, may be susceptible
−Removed: to damage or interruption from cybersecurity threats and incidents, which include any unauthorized access to our information systems that
−Removed: may result in adverse effects on the confidentiality, integrity or availability of such systems or related information.
−Removed: Such attacks have become more sophisticated over
−Removed: time, especially as threat actors have become increasingly well-funded by or themselves include governmental actors with significant
−Removed: We expect that the sophistication of cyber-threats will continue to evolve as threat actors increase their use of AI and machine-learning
−Removed: technologies.
−Removed: The Company experiences cyber threats in the normal course of its business, and computer viruses, hackers, employee
−Removed: misconduct and other external hazards could expose our information systems to security breaches, cybersecurity incidents or other
−Removed: disruptions, any of which could materially and adversely affect our business.
−Removed: Refer to Item 1A.
−Removed: Risk Factors, for additional details on
−Removed: cybersecurity risks that could potentially materially affect the Company.
−Removed: We manage our risks from cybersecurity threats
−Removed: through our overall enterprise risk management process, which is overseen by the Board.
−Removed: Our cybersecurity risks are considered individually
−Removed: as part of our enterprise risk management process alongside other risks, and priorities and discussed with our Board.
−Removed: The Company seeks
−Removed: to prioritize the management of cybersecurity risk and the protection of confidential information and systems.
−Removed: Under the supervision
−Removed: of the Chief Executive Officer (“ CEO ”) and VP of Business Operations and Strategy, we work to identify all computing
−Removed: assets including hardware, software, and network infrastructure in order to conduct a risk assessment.
−Removed: We consider threats that may
−Removed: originate from both internal and external sources and maintain technical security controls internally.
−Removed: We are putting in place plans for
−Removed: our employees to receive mandatory recurring cybersecurity training and phishing exercises.
−Removed: The Company’s VP of Business Operations
−Removed: and Strategy reports directly to the CEO and leads the Information Technology team (collectively, the “ IT Security Team ”).
−Removed: The IT Security Team is responsible for the strategic oversight of cybersecurity risk management and strategy including the identification
−Removed: and assessment of cybersecurity threats and incidents.
−Removed: Periodically, the Company’s VP of Business Operations and Strategy is also
−Removed: responsible , alongside the Chief Financial Officer (“ CFO ”) and senior management, to keep the Audit Committee of the
−Removed: Board of Directors informed and briefed with respect to cybersecurity risks and risks.
−Removed: Our VP of Business Operations and Strategy has
−Removed: extensive experience of over 20 years in various IT roles across a range of cyber technologies, processes and strategies and is supported
−Removed: by the IT Security Team and the wider IT team, to support the Company’s cyber risk management processes, including the prevention,
−Removed: detection and mitigation of cybersecurity threats and incidents, and any required response to and remediation of such cybersecurity threats
−Removed: or incidents.
−Removed: The Audit Committee is responsible for providing
−Removed: governance and oversight over the Company’s operational cybersecurity program, risk management and incident response on behalf of
−Removed: On a periodic basis, management will report the results of any risk assessments, including the evaluation of any cybersecurity
−Removed: risks, and the actions that the Company has taken to mitigate these risks.
−Removed: This includes assessing the measures and controls in
−Removed: place to mitigate cybersecurity risks and providing oversight of the response of any significant cybersecurity threats and incidents.
−Removed: For information regarding the properties of USARE, reference is made
−Removed: to the disclosure set forth above in Item 1.
−Removed: Business of this Annual Report under the heading “ USARE’s Facilities ,”
−Removed: which is incorporated herein by reference.
+Added: Item 1B — Unresolved Staff Comments
+Added: Item 1C — Cybersecurity
+Added: Managing Material Risks & Integrated Overall Risk Management
+Added: We have integrated cybersecurity risk management into our broader risk management framework to support a company-wide approach to managing cybersecurity risks.
+Added: This integration is designed to help ensure that cybersecurity considerations are incorporated into our decision-making processes across the organization.
+Added: Our Risk Management Team (see “Management’s Role in Managing Risk” below for additional information regarding the team members and scope) works closely with our Information Technology (“IT”) team, which is comprised of our IT Manager and other IT personnel with experience in information technology, to monitor and evaluate cybersecurity risks and implement measures designed to address those risks in alignment with our business objectives and operational needs .
+Added: Engage Third-parties on Risk Management
+Added: Due to the evolving nature of cybersecurity threats, we engage external experts, including cybersecurity consultants, to assist in evaluating and testing our cybersecurity risk management processes.
+Added: These third parties may support activities such as risk assessments, security testing, and consultation regarding security enhancements.
+Added: Third-party Risk
+Added: We rely on certain third-party service providers in connection with our information systems and operations.
+Added: As part of our risk management processes, we conduct security assessments of certain third-party providers prior to engagement and monitor certain third-party relationships on an ongoing basis.
+Added: We also rely upon certain third-party software and cloud service providers to review and notify their customers of security vulnerabilities or data breaches affecting their systems.
+Added: These processes are designed to help identify and mitigate risks associated with third-party service providers.
+Added: Risks from Cybersecurity Threats
+Added: We maintain a cybersecurity program designed to protect the integrity and availability of our information systems and data.
+Added: In addition, we maintain cybersecurity insurance intended to help manage potential liabilities associated with certain cybersecurity incidents.
+Added: However, there can be no assurance that our insurance coverage will be sufficient to cover all potential claims or that insurance proceeds will be received in a timely manner.
+Added: As of the date of this report, cybersecurity threats, including prior cybersecurity incidents, have not materially affected, and are not reasonably likely to materially affect our business, including our strategy, results of operations, or financial condition.
+Added: USA Rare Earth, Inc.
+Added: | 2025 Annual Report (Form 10-K) | 46
+Added: Board of Directors Oversight
+Added: The Board of Directors oversees management of risks associated with cybersecurity threats.
+Added: The Audit Committee of the Board (the “ Audit Committee ”) is responsible for overseeing cybersecurity risk management.
+Added: The Audit Committee receives periodic updates regarding cybersecurity risks and related risk management activities.
+Added: Management’s Role in Managing Risk
+Added: We have an internal management team comprising our Chief Financial Officer (“CFO”), Chief Legal Officer (“CLO”), VP, Corporate Controller, and VP, SEC Reporting & Technical Accounting (the “Risk Management Team”) responsible for informing the Audit Committee regarding cybersecurity risks.
+Added: The Risk Management Team works closely with the IT team to monitor cybersecurity risks and review the results of cybersecurity risk assessments and monitoring activities.
+Added: The Risk Management Team and IT team meet periodically to discuss cybersecurity risks and threats, as well as the results of cybersecurity monitoring and risk assessment activities.
+Added: The Risk Management Team provides updates to the Audit Committee periodically, with a minimum frequency of once per year.
+Added: These updates may include discussions regarding:
+Added: • the cybersecurity threat landscape and emerging risks;
+Added: • the status of cybersecurity initiatives;
+Added: • cybersecurity incidents, if any;
+Added: • compliance with applicable regulatory requirements.
+Added: Risk Management Personnel
+Added: Our IT team has experience supporting our information systems and cybersecurity processes and supports the implementation of our cybersecurity strategies.
+Added: The IT team supports cybersecurity governance processes, tests compliance with standards, remediates identified risks, and leads employee cybersecurity awareness and training activities.
+Added: The Risk Management Team works with the IT team in overseeing cybersecurity risk management, and the diverse background and experience of its members in risk management and internal control processes supports our cybersecurity risk management activities.
+Added: Monitor Cybersecurity Incidents
+Added: Our IT team monitors developments in cybersecurity threats and risk management practices and implements processes for the regular monitoring of our information systems.
+Added: These processes are intended to support the prevention, detection, mitigation, and remediation of cybersecurity incidents.
+Added: In the event of a cybersecurity incident, we maintain an incident response process designed to support the identification, containment, and remediation of the incident and to reduce the risk of future occurrences.
+Added: USA Rare Earth, Inc.
+Added: | 2025 Annual Report (Form 10-K) | 47
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.