Item 1B. Unresolved Staff Comments
Item 1B — Unresolved Staff Comments
None.
Item 1C — Cybersecurity
Managing Material Risks & Integrated Overall Risk Management
We have integrated cybersecurity risk management into our broader risk management framework to support a company-wide approach to managing cybersecurity risks. This integration is designed to help ensure that cybersecurity considerations are incorporated into our decision-making processes across the organization. Our Risk Management Team (see “Management’s Role in Managing Risk” below for additional information regarding the team members and scope) works closely with our Information Technology (“IT”) team, which is comprised of our IT Manager and other IT personnel with experience in information technology, to monitor and evaluate cybersecurity risks and implement measures designed to address those risks in alignment with our business objectives and operational needs .
Engage Third-parties on Risk Management
Due to the evolving nature of cybersecurity threats, we engage external experts, including cybersecurity consultants, to assist in evaluating and testing our cybersecurity risk management processes. These third parties may support activities such as risk assessments, security testing, and consultation regarding security enhancements.
Third-party Risk
We rely on certain third-party service providers in connection with our information systems and operations. As part of our risk management processes, we conduct security assessments of certain third-party providers prior to engagement and monitor certain third-party relationships on an ongoing basis. We also rely upon certain third-party software and cloud service providers to review and notify their customers of security vulnerabilities or data breaches affecting their systems. These processes are designed to help identify and mitigate risks associated with third-party service providers.
Risks from Cybersecurity Threats
We maintain a cybersecurity program designed to protect the integrity and availability of our information systems and data. In addition, we maintain cybersecurity insurance intended to help manage potential liabilities associated with certain cybersecurity incidents. However, there can be no assurance that our insurance coverage will be sufficient to cover all potential claims or that insurance proceeds will be received in a timely manner.
As of the date of this report, cybersecurity threats, including prior cybersecurity incidents, have not materially affected, and are not reasonably likely to materially affect our business, including our strategy, results of operations, or financial condition.
USA Rare Earth, Inc. | 2025 Annual Report (Form 10-K) | 46
Table of Contents
Governance
Board of Directors Oversight
The Board of Directors oversees management of risks associated with cybersecurity threats. The Audit Committee of the Board (the “ Audit Committee ”) is responsible for overseeing cybersecurity risk management. The Audit Committee receives periodic updates regarding cybersecurity risks and related risk management activities.
Management’s Role in Managing Risk
We have an internal management team comprising our Chief Financial Officer (“CFO”), Chief Legal Officer (“CLO”), VP, Corporate Controller, and VP, SEC Reporting & Technical Accounting (the “Risk Management Team”) responsible for informing the Audit Committee regarding cybersecurity risks.
The Risk Management Team works closely with the IT team to monitor cybersecurity risks and review the results of cybersecurity risk assessments and monitoring activities. The Risk Management Team and IT team meet periodically to discuss cybersecurity risks and threats, as well as the results of cybersecurity monitoring and risk assessment activities. The Risk Management Team provides updates to the Audit Committee periodically, with a minimum frequency of once per year.
These updates may include discussions regarding:
• the cybersecurity threat landscape and emerging risks;
• the status of cybersecurity initiatives;
• cybersecurity incidents, if any; and
• compliance with applicable regulatory requirements.
Risk Management Personnel
Our IT team has experience supporting our information systems and cybersecurity processes and supports the implementation of our cybersecurity strategies. The IT team supports cybersecurity governance processes, tests compliance with standards, remediates identified risks, and leads employee cybersecurity awareness and training activities.
The Risk Management Team works with the IT team in overseeing cybersecurity risk management, and the diverse background and experience of its members in risk management and internal control processes supports our cybersecurity risk management activities.
Monitor Cybersecurity Incidents
Our IT team monitors developments in cybersecurity threats and risk management practices and implements processes for the regular monitoring of our information systems. These processes are intended to support the prevention, detection, mitigation, and remediation of cybersecurity incidents.
In the event of a cybersecurity incident, we maintain an incident response process designed to support the identification, containment, and remediation of the incident and to reduce the risk of future occurrences.
USA Rare Earth, Inc. | 2025 Annual Report (Form 10-K) | 47
Table of Contents