Gana Misra
By Gana MisraCEO, Finrep
Mon Sep 07 2026

SOX 302 Certification Requirements: 2026 Practitioner Walkthrough

Share
SOX 302 Certification Requirements: 2026 Practitioner Walkthrough

SOX 302 Certification Requirements: 2026 Practitioner Walkthrough

If you are a CFO or VP of Internal Audit at a U.S. public company, you sign a Section 302 certification every quarter. The question is not whether you sign it. The question is whether your process actually supports it.

This walkthrough covers the six certification elements word by word, how to structure the sub-certification cascade that makes signing defensible, where DC&P ends and ICFR begins, and the enforcement and comment-letter risks that most compliance teams underestimate. For a side-by-side comparison of Section 302 and Section 404 obligations, see SOX 302 vs 404 Certification: The Complete Comparison Guide.

Key takeaway: Section 302 is not a formality. It is a live governance mechanism that requires a substantive quarterly process. A signature without that process is an enforcement risk, not a technicality.

What Are the SOX 302 Certification Requirements?

Section 302 of the Sarbanes-Oxley Act of 2002 (15 U.S.C. § 7241) requires both the principal executive officer (PEO) and principal financial officer (PFO) to personally certify six specific elements in every annual and quarterly periodic report filed under the Exchange Act. The SEC implemented this through Rules 13a-14(a) and 15d-14(a), effective August 29, 2002. The certifications are filed as Exhibit 31.1 (PEO) and Exhibit 31.2 (PFO) and are "filed" not "furnished," meaning they carry Section 18 Exchange Act liability.

The six elements, drawn directly from SEC Final Rule Release No. 33-8124, are:

  1. Review: The certifying officer has reviewed the report.
  2. No material misstatements or omissions: Based on the officer's knowledge, the report contains no untrue statement of a material fact and omits no material fact necessary to make the statements not misleading.
  3. Fair presentation: Based on the officer's knowledge, the financial statements and other financial information fairly present in all material respects the financial condition, results of operations, and cash flows for the periods presented.
  4. DC&P responsibility and evaluation: The certifying officers are responsible for establishing and maintaining disclosure controls and procedures (DC&P), have designed them to ensure material information is made known to them, have evaluated their effectiveness, and have presented their conclusions in the report.
  5. Disclosure to auditors and audit committee: The certifying officers have disclosed to the auditors and audit committee all significant deficiencies and material weaknesses in ICFR, and any fraud, whether or not material, involving management or employees with a significant role in internal controls.
  6. Significant changes in ICFR: The certifying officers have indicated whether any significant changes in ICFR occurred during the most recent fiscal quarter that materially affected, or are reasonably likely to materially affect, ICFR.

Element 5 carries a detail that most articles miss: the fraud disclosure obligation covers any fraud involving management or key control personnel, even if immaterial. This is a standalone obligation, not a subset of the financial accuracy certification.

Which Reports Require a Section 302 Certification?

Section 302 certifications are required for periodic reports only, not current reports. The requirement applies to:

ReportFiler TypeFrequency
Form 10-KDomestic issuersAnnual
Form 10-QDomestic issuersQuarterly
Form 20-FForeign private issuers (FPIs)Annual only
Form 40-FCanadian issuers (MJDS)Annual only
Form N-CSRInvestment companiesSemi-annual

Forms 8-K and 6-K do not require Section 302 certifications, even when they contain financial statements. FPIs are a common source of confusion: because they do not file quarterly on Form 10-Q, they certify annually only, on Form 20-F or 40-F.

The certification is also required for transition period reports (short fiscal years due to a fiscal year change), for successor registrant reports, and for late-filed reports. There is no exemption for lateness.

Amendments matter. If you file a 10-K/A or 10-Q/A, new Section 302 certifications must accompany the amendment. The officers signing are those serving at the time of the amendment filing, not the original signatories. Per SEC C&DI guidance, paragraphs 1 and 2 of the certification must always accompany an amendment; paragraphs 3 through 5 may be omitted if the amendment contains no financial statements or ICFR/DC&P disclosure.

What Are Disclosure Controls and Procedures, and How Do They Differ from ICFR?

DC&P is broader than ICFR. This distinction matters operationally and is consistently underexplained.

Rules 13a-15(e) and 15d-15(e) define DC&P as controls and procedures designed to ensure that information required to be disclosed in Exchange Act reports is recorded, processed, summarized, and reported within the required time periods, and that such information is accumulated and communicated to management, including the PEO and PFO, to allow timely decisions regarding required disclosure.

ICFR, by contrast, covers controls over the reliability of financial reporting and the preparation of financial statements in accordance with GAAP.

The practical difference:

  • ICFR covers your financial close process, journal entry controls, account reconciliations, and financial statement preparation.
  • DC&P covers all of that, plus the controls over every other piece of material information in your SEC reports: MD&A disclosures, risk factors, legal proceedings, non-GAAP measures, cybersecurity disclosures, and executive compensation tables.

A control failure that lets a materially misleading non-GAAP measure appear in your 10-K is a DC&P failure, even if your ICFR is clean. The Section 302 certification covers both.

For a deeper look at how ICFR controls are designed and tested, see Design vs Operating Effectiveness Testing Under SOX: 2026 Practitioner Walkthrough.

How to Conduct the DC&P Evaluation: What "Evaluated" Actually Means

The SEC does not prescribe a specific evaluation methodology for DC&P. That flexibility is real, but it does not mean any process will do. The evaluation must be substantive, documented, and completed as of a date within the fiscal quarter covered by the report.

In practice, the vast majority of large U.S. public companies use the COSO Internal Control Integrated Framework (2013) as their evaluation basis. According to Audit Analytics data, over 90% of S&P 500 companies reference COSO in their annual reports. The framework's five components (Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring) map directly onto the DC&P design and operating effectiveness questions the certification requires.

A defensible DC&P evaluation process typically includes:

  1. Scoping: Identify all categories of material information required to be disclosed in the current report, including financial statements, MD&A, risk factors, and any new disclosure areas (see cybersecurity section below).
  2. Control mapping: Map existing controls to each disclosure category. Identify gaps where no control exists or where controls have not been tested.
  3. Testing: Assess operating effectiveness of key DC&P controls, not just ICFR controls. This includes controls over the review and approval of narrative disclosures.
  4. Deficiency assessment: Evaluate whether any identified control gaps rise to the level of a significant deficiency or material weakness.
  5. Conclusion: The PEO and PFO present their effectiveness conclusion in the body of the report (typically in Item 9A for a 10-K or Item 4 for a 10-Q).
  6. Documentation: Retain contemporaneous documentation of the evaluation process, including meeting minutes, testing workpapers, and sub-certification representations.

Step 6 is where many companies are exposed. The SEC's Division of Corporation Finance has issued comment letters citing inadequate description of the DC&P evaluation process. If your documentation does not show what you tested, when, and how you reached your conclusion, the evaluation is difficult to defend.

How the Sub-Certification Cascade Works in Practice

The sub-certification process is the mechanism by which CEOs and CFOs obtain the knowledge necessary to sign. It is not legally required by SEC rules, but it has become near-universal among large public companies, and auditors review it as part of the ICFR audit under PCAOB AS 2201.

Here is how a typical cascade works:

  1. Trigger: The close calendar sets a sub-certification deadline, typically 5 to 10 business days before the 10-Q or 10-K filing date.
  2. Questionnaire distribution: The controller or SOX compliance team distributes written sub-certification questionnaires to business unit controllers, divisional CFOs, legal counsel, and heads of material business processes. The questionnaire asks each recipient to confirm that: (a) all material transactions and events in their area have been captured and properly reported; (b) no material weaknesses or significant deficiencies exist in their area that have not been reported upward; (c) no fraud involving management or key control personnel has occurred; and (d) no significant changes in internal controls have occurred.
  3. Escalation: Respondents flag exceptions. Each exception is reviewed by the controller and, if material, escalated to the CFO and general counsel before the certification is signed.
  4. Disclosure committee review: Most large companies route the sub-certification results through a disclosure committee, which reviews the draft report and the sub-certification exceptions before the PEO and PFO sign.
  5. Sign-off: The CFO and CEO sign Exhibit 31.1 and 31.2, supported by the documented sub-certification record.

The sub-certification questionnaire should be tailored to the current quarter's risk areas, not recycled verbatim each quarter. A questionnaire that does not ask about a known risk area is a documentation gap waiting to become a comment letter.

For a step-by-step walkthrough of the full paragraph-by-paragraph certification process, see SOX Section 302 Certification Requirements: A Practitioner Walkthrough.

What Happens When a Material Weakness Is Identified?

A material weakness does not change the prescribed certification language. It changes the conclusion. This is a point that trips up compliance teams.

The certification text is fixed by SEC rule and cannot be modified. Adding qualifications, limitations, or explanatory language to the certification itself is not permissible and has drawn SEC comment letters. What changes when a material weakness exists is the effectiveness conclusion in the body of the report: the company discloses that DC&P was not effective as of the evaluation date, identifies the material weakness, and describes remediation steps.

According to Audit Analytics, U.S. public companies collectively disclose approximately 800 to 1,000 material weaknesses annually across all filers. Each one requires this disclosure in the 10-K or 10-Q body, and the Section 302 certification must be consistent with it.

A material weakness identified by the external auditor that was not previously disclosed in the 302 certification is a serious red flag, both for SEC enforcement and for auditor-management relations. The PEO and PFO's obligation under element 5 to disclose all material weaknesses to the auditors and audit committee is designed precisely to prevent this disconnect.

SOX 302 vs. SOX 906: What Is the Difference?

Section 302 and Section 906 are two separate certifications with different legal frameworks, different exhibits, and different penalty structures.

FeatureSection 302Section 906
Statutory basis15 U.S.C. § 7241 (Exchange Act)18 U.S.C. § 1350 (criminal code)
ExhibitExhibit 31.1 / 31.2Exhibit 32.1 / 32.2
Filed or furnishedFiledFurnished
EnforcementCivil (SEC)Criminal (DOJ)
Knowing violation penaltyCivil enforcement, injunction, disgorgementUp to $1 million fine, 10 years imprisonment
Willful violation penaltyCivil enforcement, officer/director barUp to $5 million fine, 20 years imprisonment
ScopeSix specific elements including DC&PReport "fully complies" with Exchange Act and "fairly presents" financial condition

Section 906 certifications are furnished, not filed, which means they do not carry Section 18 Exchange Act liability. But the criminal exposure under Section 906 is substantially higher. Both certifications must accompany every periodic report that contains financial statements. Neither replaces the other.

Who Must Sign: Interim Officers, Co-CEOs, and Edge Cases

The requirement applies to persons performing the equivalent functions of PEO and PFO, regardless of title. Per SEC C&DI guidance, several edge cases are resolved as follows:

  • Interim or acting officers: If an acting CFO is performing the PFO function at the time of filing, that person must sign. The fact that they did not serve for the full period covered by the report is irrelevant. They certify based on their knowledge as of the filing date.
  • Newly appointed officers: A CFO appointed mid-quarter who did not oversee the full period must still sign. The certification is forward-looking as of the filing date, not retrospective over the full quarter.
  • Co-CEOs or co-CFOs: Each must sign a separate certification.
  • One person performing both functions: If the same individual serves as both PEO and PFO, they must sign two separate certifications, one as PEO and one as PFO.
  • Vacant role: If the PFO role is vacant at the time of filing with no one performing equivalent functions, the company has a structural problem that goes beyond the certification. In practice, boards appoint an interim officer before the filing date to avoid this.

Cybersecurity and AI: The 2026 Frontier for DC&P Scope

The SEC's cybersecurity disclosure rules (Release Nos. 33-11216, 34-97989), effective September 5, 2023, directly expanded the scope of DC&P under Section 302. Compliance for annual reports was required beginning December 15, 2023.

Companies must now disclose material cybersecurity incidents on Form 8-K (Item 1.05) and annual cybersecurity risk management and governance information on Form 10-K (Item 1C). Because DC&P covers all material information required to be disclosed in Exchange Act reports, the 302 certification now implicitly covers whether the company has adequate controls to:

  • Identify a cybersecurity incident as potentially material.
  • Assess materiality within the four-business-day 8-K window.
  • Accumulate and communicate that assessment to the PEO and PFO in time for a disclosure decision.

A company that lacks a documented process for escalating cybersecurity incidents to the disclosure committee has a DC&P gap, even if its ICFR is fully effective. The SEC has focused on this in comment letters since 2024.

The AI dimension is newer and still developing. Companies using AI tools in their financial reporting, MD&A drafting, or disclosure processes must consider whether their DC&P covers the risk of AI-generated errors or hallucinations appearing in filed documents. The SEC has not issued specific guidance on AI and Section 302, but staff speeches and comment letters in 2025 have flagged AI-related disclosure controls as an area of active scrutiny. For a detailed look at how COSO's 2026 GenAI guidance affects SOX programmes, see COSO GenAI Guidance: The New Stand and AI-ICFR Framework: Key Controls for CFOs Explained.

Enforcement: What the SEC Actually Does with False Certifications

A false Section 302 certification is not a technical violation. It is an independent basis for SEC enforcement action. The SEC can seek injunctions, disgorgement, civil monetary penalties, and officer and director bars. In cases where the false certification is tied to securities fraud, the SEC has brought parallel charges under Rule 10b-5.

The SEC's enforcement history shows that officers cannot shelter behind "I relied on my team." The sub-certification process exists precisely to make that reliance documented and reasonable. An officer who signs without a substantive underlying process, or who ignores red flags surfaced by the sub-certification, is exposed.

Common SEC comment letter triggers related to Section 302 include:

  • Inadequate description of the DC&P evaluation methodology in the body of the report.
  • Inconsistency between the effectiveness conclusion in the report and the facts disclosed elsewhere (for example, disclosing a material weakness in one section but not reflecting it in the DC&P conclusion).
  • Failure to disclose a significant change in ICFR that occurred during the quarter.
  • Non-standard certification language, including additions or qualifications to the prescribed text.
  • Inadequate cybersecurity disclosure controls following the 2023 SEC cyber rules.

If the SEC issues a comment letter on your 302 certification, the response process is public. Other investors, plaintiffs' counsel, and journalists can read it. The reputational cost of a public comment letter exchange on certification adequacy often exceeds the compliance cost of getting the process right in the first place.

SOX 302 Certification Requirements: Common Pitfalls Checklist

Before the next filing, confirm:

  • Both PEO and PFO (or persons performing equivalent functions) are identified and will sign by the filing date.
  • The certification language matches the prescribed text exactly, with no additions, qualifications, or modifications.
  • The DC&P evaluation is documented, covers the current quarter's risk areas, and is completed as of a date within the quarter.
  • The sub-certification questionnaire has been updated to reflect current-quarter risks, including any cybersecurity incidents or AI-related disclosure processes.
  • All sub-certification exceptions have been reviewed and resolved or escalated before the PEO and PFO sign.
  • Any material weakness is disclosed in the body of the report and the DC&P effectiveness conclusion is consistent with it.
  • Any significant change in ICFR during the quarter is disclosed in the report.
  • If the report is an amendment (10-K/A or 10-Q/A), new certifications are prepared and signed by the officers serving at the time of the amendment filing.
  • Cybersecurity incident escalation controls are documented as part of DC&P scope.
  • If AI tools are used in the disclosure process, controls over AI-generated content are scoped into DC&P.

FAQ

Is SOX 302 compliance still required in 2026? Yes. Section 302 has been in continuous effect since August 29, 2002, and applies to every domestic issuer and foreign private issuer filing periodic reports under the Exchange Act. There is no exemption for company size, filer category, or emerging growth company status under Section 302, though Section 404(b) auditor attestation has EGC and non-accelerated filer exemptions.

Can the Section 302 certification language be modified or qualified? No. The SEC has stated that any alteration of the required language, including additions of qualifications or limitations, renders the certification non-compliant. This is a frequent source of SEC comment letters. The prescribed text must be used verbatim.

What is the difference between SOX 302 and SOX 404? Section 302 requires quarterly and annual CEO/CFO certification of DC&P effectiveness. Section 404 requires annual management assessment of ICFR (404(a)) and, for accelerated and large accelerated filers, an external auditor attestation (404(b)). DC&P under 302 is broader than ICFR under 404: it covers all material information in SEC reports, not just financial statements. See SOX 302 vs 404 Certification: The Complete Comparison Guide for the full comparison.

What is the difference between SOX 302 and SOX 906? Section 302 is a civil certification filed as Exhibit 31, implemented through SEC Exchange Act rules. Section 906 is a criminal certification furnished as Exhibit 32, embedded in the U.S. criminal code. Willful violations of Section 906 carry penalties up to $5 million and 20 years imprisonment. Both must accompany every periodic report containing financial statements.

Does a foreign private issuer have to comply with Section 302? Yes, but only annually. FPIs filing on Form 20-F or Form 40-F must include Section 302 certifications as exhibits. Because FPIs do not file quarterly on Form 10-Q, they certify once per year, not four times.

How should companies document the DC&P evaluation to withstand SEC scrutiny? Retain contemporaneous records of: the scoping exercise identifying all material disclosure categories; the control mapping and testing workpapers; sub-certification questionnaires and responses; disclosure committee meeting minutes; and the final effectiveness conclusion with supporting rationale. The documentation should be sufficient for an outside reviewer to reconstruct the evaluation without asking questions.

Run your financial reporting on Finrep