Gana Misra
By Gana MisraCEO, Finrep
Thu Aug 06 2026

SOX 302 vs 404 Certification: The Complete Comparison Guide

Share
SOX 302 vs 404 Certification: The Complete Comparison Guide

SOX 302 vs 404 Certification: The Complete Comparison Guide

If your compliance team treats SOX 302 and SOX 404 as two names for the same obligation, you're carrying real risk. They share a common goal, but they impose different duties, operate on different cadences, cover different scopes, and carry different consequences when something goes wrong. This guide gives CFOs, controllers, and compliance teams the precise comparison they need to structure their program correctly and keep executives out of trouble.

Key takeaway: SOX 302 is a personal quarterly certification by the CEO and CFO covering all disclosures. SOX 404 is an annual assessment of internal controls over financial reporting, with an external auditor attestation requirement that only applies to accelerated and large accelerated filers.

SOX 302 vs 404 at a Glance

DimensionSOX 302SOX 404(a)SOX 404(b)
Who actsCEO and CFO personallyManagementIndependent registered public accounting firm
CadenceEvery periodic report (10-K and 10-Q)Annual (10-K only)Annual (10-K only)
ScopeDisclosure controls and procedures (DC&P)Internal controls over financial reporting (ICFR)ICFR (same as 404a)
Governing authoritySEC Release 33-8124SEC Release 33-8238PCAOB AS 2201
Who must complyAll SEC reporting companiesAll SEC reporting companiesLarge accelerated and accelerated filers only
Criminal penalty (knowing violation)Up to $1M fine / 10 yearsN/AN/A
Criminal penalty (willful violation)Up to $5M fine / 20 yearsN/AN/A

What SOX Section 302 Actually Requires

Section 302 requires the CEO and CFO to personally certify, in every 10-K and every 10-Q, that the filing is accurate and that disclosure controls are working. The certification language is not optional boilerplate. It is mandated word-for-word by SEC Rule 13a-14(a)/15d-14(a), and it commits the signing officer to five specific representations:

  1. They have reviewed the report.
  2. Based on their knowledge, the report contains no material misstatements or omissions.
  3. Based on their knowledge, the financial statements fairly present the company's financial condition and results of operations.
  4. They are responsible for designing, evaluating, and reporting on the effectiveness of disclosure controls and procedures (DC&P).
  5. They have disclosed to the audit committee and external auditors all significant deficiencies, material weaknesses, and any fraud involving management or employees with a significant role in internal controls.

The required language includes: "Based on my knowledge, this report does not contain any untrue statement of a material fact or omit to state a material fact necessary to make the statements made, in light of the circumstances under which such statements were made, not misleading with respect to the period covered by this report."

That "based on my knowledge" qualifier matters. The SEC's Compliance and Disclosure Interpretations clarify that it does not give executives a free pass for willful ignorance. Enforcement actions at Qwest Communications, HealthSouth, WorldCom, and QSGI Inc. (2014) all used 302 certifications as a basis for charging executives with securities fraud, even where subordinates executed the underlying misconduct.

The Sub-Certification Process

In large organizations, the CEO and CFO cannot personally verify every number in a 10-Q. In practice, most companies run a sub-certification cascade: business unit controllers, divisional CFOs, and key process owners sign internal certifications confirming the accuracy of their segment's data and the effectiveness of relevant controls. This process is not required by statute, but it is referenced in SEC staff guidance and has become standard practice. It is also the mechanism that makes the CEO/CFO certification defensible when the SEC comes asking.

What SOX Section 404 Actually Requires

Section 404 has two distinct sub-requirements that most compliance teams conflate. Getting the split wrong means either over-investing in audit work you don't need or under-investing in readiness before a threshold crossing.

SOX 404(a): Management's Assessment

Section 404(a) requires management to include in the annual 10-K an internal control report that:

  • States management's responsibility for establishing and maintaining adequate ICFR.
  • Contains an assessment, as of fiscal year-end, of the effectiveness of the company's ICFR.

Management must base its assessment on a recognized control framework. In practice, virtually every SEC registrant uses the COSO Internal Control Framework (2013), which COSO updated in 2023 to address technology and data analytics. The SEC's rules do not mandate COSO specifically, but no alternative has gained comparable acceptance.

404(a) applies to all public companies, regardless of size. There is no exemption.

SOX 404(b): The Auditor Attestation

Section 404(b) requires the company's independent registered public accounting firm to separately attest to and report on management's ICFR assessment. This is a distinct engagement from the financial statement audit, governed by PCAOB AS 2201.

AS 2201 sets out the auditor's objective plainly: "The auditor's objective in an audit of internal control over financial reporting is to express an opinion on the effectiveness of the company's internal control over financial reporting." The auditor does not simply review management's work. AS 2201 requires an independent, top-down, risk-based assessment: starting with entity-level controls, identifying significant accounts and disclosures, understanding likely sources of misstatement, and independently selecting and testing controls.

The PCAOB proposed amendments to AS 2201 in 2024 to address automated controls, IT general controls (ITGCs), and the use of data analytics in audits. Companies planning their 404(b) programs should monitor the PCAOB's active rulemaking, as the final standard will affect how auditors evaluate technology-dependent controls.

Does SOX 404(b) Apply to Your Company?

This is the most common practical question for mid-market companies, and the answer turns entirely on your SEC filer category.

The Dodd-Frank Act (Section 989G, 2010) permanently exempted non-accelerated filers from the 404(b) auditor attestation. The SEC's 2020 amendment to the accelerated filer definition (Release 33-10762) further narrowed the pool of companies subject to 404(b), removing certain low-revenue smaller reporting companies from the accelerated filer category. The SEC estimated that amendment would save affected companies approximately $55.4 million annually in external audit fees.

Filer CategoryPublic Float404(a) Required?404(b) Required?
Large Accelerated Filer$700M or moreYesYes
Accelerated Filer$75M to $700M (subject to revenue and filing history conditions)YesYes
Non-Accelerated FilerBelow $75MYesNo
Smaller Reporting Company (low-revenue)Below $250M float, or revenues below $100MYesNo

The 404(b) exemption for non-accelerated filers is permanent. It does not require annual renewal.

One group that often gets this wrong: companies approaching the accelerated filer threshold. An emerging growth company (EGC) aging out of JOBS Act accommodations, or a company whose public float crosses $75M, needs to plan for 404(b) readiness well before the threshold triggers. The first 404(b) audit is the hardest. Auditors will need documented control frameworks, evidence of operating effectiveness, and a scoped ICFR assessment that they can independently test. Building that infrastructure in the year before the threshold crosses is far less painful than scrambling after it. See our SEC filer status rulemaking playbook for the transition mechanics.

The Critical Scope Difference: DC&P vs. ICFR

This is the distinction that most compliance teams get wrong, and it matters for how you scope both your 302 certification process and your 404 assessment.

Section 302 covers disclosure controls and procedures (DC&P): all information required to be disclosed in SEC reports. That includes non-financial disclosures such as MD&A narratives, legal proceedings, risk factors, and related-party transactions. DC&P is a broad concept.

Section 404 covers internal controls over financial reporting (ICFR): controls specifically designed to provide reasonable assurance about the reliability of financial statements. ICFR is a subset of DC&P.

The relationship looks like this:

  • All ICFR controls are DC&P controls.
  • Not all DC&P controls are ICFR controls.

In practice, this means your 302 certification process must reach further than your 404 ICFR assessment. A control over the accuracy of your MD&A liquidity discussion, for example, is a DC&P control but may not be an ICFR control. If your 302 sign-off process only pulls from your 404 control inventory, you have a gap.

How a 404 Material Weakness Flows Into the 302 Certification

This is the most operationally important interaction between the two sections, and it is consistently missed in every top-ranking result on this topic.

If management concludes under 404(a) that there is a material weakness in ICFR, the consequences do not stop at the 10-K internal control report. They flow directly into the 302 certification.

Here is the chain:

  1. A material weakness is defined under PCAOB AS 2201.A7 as "a deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of the company's annual or interim financial statements will not be prevented or detected on a timely basis."
  2. Because ICFR is a component of DC&P, a material weakness in ICFR means DC&P is also not effective.
  3. The CEO and CFO therefore cannot certify under Section 302 that DC&P is effective. The 302 certification must reflect the negative conclusion.
  4. This negative conclusion appears in every subsequent 10-Q until the weakness is remediated and management can conclude it has been corrected.

The three-tier deficiency classification matters here:

  • Control deficiency: a design or operating gap, but not severe enough to rise to significant deficiency or material weakness. No required disclosure in the 10-K or 10-Q, but must be communicated to management.
  • Significant deficiency: a deficiency, or combination of deficiencies, less severe than a material weakness but important enough to merit attention by those responsible for financial reporting oversight. Must be communicated to the audit committee.
  • Material weakness: the highest tier. Must be disclosed publicly in the 10-K (404a report), reported to the audit committee (302 requirement), and will result in a negative 302 certification on DC&P effectiveness.

For a deeper walkthrough of the disclosure mechanics once a material weakness is identified, see our material weakness disclosure requirements guide.

The Penalty Structure: Personal Criminal Liability Under 302

Section 302 carries personal criminal liability for the signing executives. Section 404 does not, directly, but a 404 failure that produces a false 302 certification does.

The criminal penalties come from SOX Section 906 (18 U.S.C. § 1350), which supplements the Section 302 certification requirement:

  • Knowing violation: certifying a report that does not comply with the Exchange Act carries fines up to $1 million and imprisonment up to 10 years.
  • Willful violation: fines up to $5 million and imprisonment up to 20 years.

These are in addition to civil SEC enforcement actions, which can include disgorgement, bars from serving as an officer or director, and injunctions.

Section 404 failures, by contrast, do not carry direct criminal penalties. The enforcement consequence is typically SEC comment letters, restatements, civil penalties, and reputational damage. But the path from a 404 material weakness to a false 302 certification to criminal exposure is short and well-documented in the SEC's enforcement record.

The Compliance Calendar: Quarterly vs. Annual

The cadence difference is straightforward but frequently misunderstood in practice.

Section 302 timeline:

  • Certifications attach to every 10-K and every 10-Q.
  • For a calendar-year company, that means four certifications per year: Q1 (10-Q), Q2 (10-Q), Q3 (10-Q), and Q4 (10-K).
  • The sub-certification cascade from business unit controllers must complete before the CEO/CFO sign-off, so the process runs in parallel with the close.

Section 404 timeline:

  • Management's 404(a) assessment appears only in the 10-K.
  • The 404(b) auditor attestation is integrated with the financial statement audit and concludes at the same time.
  • For a calendar-year large accelerated filer, the 404(b) audit work runs throughout the year, with final testing and sign-off in Q4 and early Q1 of the following year.
  • IT general controls (ITGCs), covering logical access, change management, and computer operations, are among the highest-risk areas in 404 assessments. Deficiencies in ITGCs can have a pervasive effect on automated controls and system-generated reports, potentially elevating to material weakness. Plan ITGC testing early.

For the full quarterly milestone calendar and a control-by-control checklist, see our SOX 404 compliance checklist.

What Does 404(b) Cost?

Compliance costs remain substantial. Protiviti's 2024 Sarbanes-Oxley Compliance Survey found:

  • Median total SOX compliance costs for companies with revenues under $1 billion: $1.87 million.
  • Median total SOX compliance costs for companies with revenues between $1 billion and $5 billion: $2.91 million.

The 404(b) auditor attestation is the primary cost driver for accelerated and large accelerated filers. Non-accelerated filers, exempt from 404(b), carry materially lower compliance costs. The SEC's 2020 accelerated filer amendment was estimated to save newly exempt companies approximately $55.4 million annually in aggregate external audit fees, reflecting how significant the 404(b) engagement is relative to the 404(a) management assessment alone.

FAQ

What is the difference between SOX 302 and SOX 404 certification?

SOX 302 is a personal certification by the CEO and CFO, filed with every 10-K and 10-Q, that the report is accurate and disclosure controls are effective. SOX 404 is an annual assessment of internal controls over financial reporting, included only in the 10-K. Section 302 covers the broader category of disclosure controls; Section 404 is scoped specifically to financial reporting controls.

What is the difference between SOX 404(a) and SOX 404(b)?

404(a) is management's own annual assessment of ICFR effectiveness, required of all public companies. 404(b) is a separate attestation by the company's independent auditor, governed by PCAOB AS 2201, and required only for large accelerated filers and accelerated filers. Non-accelerated filers and most smaller reporting companies are permanently exempt from 404(b) under the Dodd-Frank Act.

Does a material weakness under 404 automatically affect the 302 certification?

Yes. Because ICFR is a component of DC&P, a material weakness in ICFR means management cannot conclude that DC&P is effective. The CEO and CFO must reflect that negative conclusion in their Section 302 certification. The negative certification continues in each subsequent 10-Q until the weakness is remediated.

What are the criminal penalties for a false SOX 302 certification?

Under SOX Section 906 (18 U.S.C. § 1350), a CEO or CFO who knowingly certifies a non-compliant report faces fines up to $1 million and imprisonment up to 10 years. Willful violations carry fines up to $5 million and imprisonment up to 20 years, in addition to civil SEC enforcement.

Is my company exempt from SOX 404(b)?

If your public float is below $75 million, you are a non-accelerated filer and permanently exempt from 404(b) under Dodd-Frank Section 989G. Smaller reporting companies with a public float below $250 million or revenues below $100 million are also exempt. The 2020 SEC amendment (Release 33-10762) further exempted certain low-revenue SRCs that previously fell in the accelerated filer category.

What does the external auditor actually do under 404(b)?

Under PCAOB AS 2201, the auditor conducts an independent, integrated audit of ICFR alongside the financial statement audit. The auditor uses a top-down, risk-based approach: assessing entity-level controls, identifying significant accounts, understanding likely sources of misstatement, and independently selecting and testing controls. The auditor forms its own opinion on ICFR effectiveness. It does not simply review management's 404(a) assessment.

Run your financial reporting on Finrep