Blog

SOX for Newly Public Companies

Subscribe now to join the Risk Register community:

Your controls don't change the day you go public. What changes is who finds out when they fail.

That's the whole shift, and it's the part that doesn't show up on any readiness checklist. The reconciliation that ran a week late last quarter was an internal annoyance. The same reconciliation, running a week late next quarter, is a conversation with your auditor about whether the control operated, and possibly a disclosure describing your control environment as ineffective.

Same control. Same people. Completely different consequence.

Most newly public finance teams know a deadline is coming. What catches them is that the deadline they're watching isn't the one that matters most.

Three Obligations Arrive on Three Different Dates

Most first-year confusion comes from collapsing three separate obligations into a single mental deadline. They're distinct, and only one of them is far away.

Your first periodic report carries the Section 302 and Section 906 certifications. Your CEO and CFO sign personally, confirming they've reviewed the report, that it contains no untrue statement of material fact, and that they've disclosed every significant deficiency to the auditors and the audit committee. Section 906 attaches criminal exposure to a knowing false certification. This is the obligation that arrives fastest and gets underestimated most.

Your second annual report is generally where management's Section 404(a) assessment of internal control over financial reporting first appears. The SEC's transition period lets a newly public company omit both the management report and the auditor attestation from that first annual report, and Item 308 even supplies the sentence you use to say so. Worth knowing: the relief applies once. It isn't a grace period you can extend by explaining that the program isn't ready yet.

Then there's 404(b), the auditor attestation, which turns on filer status. The statute exempts emerging growth companies outright, and exempts any issuer that's neither a large accelerated filer nor an accelerated filer. Emerging growth company status itself runs out on the earliest of four triggers: revenue crossing a threshold the SEC indexes for inflation, the fifth anniversary of your first registered common equity sale, more than a billion dollars of non-convertible debt issued over three years, or becoming a large accelerated filer.

Notice what that means. Filer status is recomputed as your float and revenue move, so "exempt" describes where you are this year, not a permanent condition. One good year can take you from outside 404(b) to inside it.

The planning rule that follows is simple enough to put on a wall: build for the year you'll be subject to 404(b), not the year you're exempt from it. Retrofitting a program under audit pressure costs a multiple of building it properly the first time.

The Controls You Inherited Were Designed for Somebody Else

If you came out of a spin-off, a divestiture, or a carve-out, you're carrying a version of this problem that nobody warns you about.

You didn't build your control environment. You received it, the way you receive a furnished apartment. Everything's there, none of it was chosen for you, and some of it is bolted to the wall.

The specifics are consistent across every carve-out we see. Controls reference a parent treasury function, tax group, or IT operations center that has no owner inside your entity on day one. Process narratives describe reporting into a consolidation that isn't yours, with materiality thresholds set against financial statements many times the size of your own. The testing cadence was sized for the parent's filer status, so you're paying for coverage calibrated to somebody else's risk. And the key control designations reflect the parent's reliance decisions, which tell you nothing about which controls matter for your financial statements.

The failure mode here isn't a bad decision. It's the absence of one. The inherited population becomes the default, year one validates it, and a decade later you're still testing a control environment nobody designed for your company.

Treat the inherited matrix as a starting draft. It was never a standard.

Which raises a question worth sitting with before your first testing calendar gets set: if you had to justify each of those controls to your own audit committee, on your own materiality, how many would survive?

Year One Sets Your Cost for Years Three Through Ten

First-year decisions are disproportionately expensive, and the reason isn't the one most teams assume.

Under AS 2201, your external auditor may use work performed by internal audit and others to reduce the testing they do themselves, after assessing competence and objectivity. That reliance shows up directly in the fee.

Newly public companies almost always start at zero reliance. Your auditor has no history with your team, your documentation standards, or your evidence discipline, so everything gets tested by them because nothing else has been demonstrated yet.

Moving from zero to meaningful reliance takes two to three years, and the foundation is the quality of your year-one workpapers. Which produces a genuinely uncomfortable conclusion: the cheapest year of SOX you'll ever have is determined by decisions you make during the most expensive one.

Three things earn reliance, and none of them happen by accident. Workpapers built to your auditor's reliance standard rather than to your own internal comfort level. Scope, timing, and sampling agreed with the auditor before fieldwork, so selections can be shared instead of duplicated. And tester competence and objectivity you can actually evidence when the question comes.

One ceiling to know about. AS 2201 also provides that as the risk associated with a control increases, the need for the auditor to do their own work on that control increases. So your highest-risk controls get auditor testing regardless of how good your documentation is. Reliance is real, and it's strongest exactly where the controls are routine.

Six Priorities, and the Order Matters More Than the Effort

Rationalize before you test. Map every inherited control to the risk and assertion it actually covers for your entity, retire the duplicates, reassign the orphans, and correct the key designations. Testing an unrationalized population means paying to validate somebody else's judgment. More on control rationalization.

Establish standalone ownership. Every control needs a named owner inside your entity who can both perform it and evidence it. Controls that pointed at a parent function need a new owner or a redesign, and "we'll figure it out at testing" isn't either one.

Fix the evidence pipeline early. Email threads and spreadsheet trackers are the largest hidden cost in a first-year program, because they consume control owner time rather than audit budget, which means nobody's watching the meter. Structured evidence collection is far easier to build before habits set.

Coordinate the auditor relationship deliberately. Agree scope, materiality, timing, and reliance intentions in year one. Discovering a scope disagreement during fieldwork is expensive and entirely avoidable.

Test design before you test operation. A control that fails design evaluation doesn't need operating effectiveness testing. It needs redesign. Sequencing these correctly keeps you from testing controls you're about to replace.

Build certification support, not certification assurance. Your CEO and CFO are signing personally, under both Sections 302 and 906. They should be signing against evidence, not against a verbal report that the program is on track. Full stop.

Six Things That Go Wrong in Year One

These recur often enough to be predictable, which also makes them avoidable.

The transition relief gets read as permission to start late. It isn't. Your auditor's reliance posture, your documentation standards, and your control ownership are all being set during exactly the period when the assessment isn't yet required.

Caution turns into over-scoping. A newly public company scoping like a large accelerated filer pays for coverage its materiality doesn't justify, and then can't reduce it later without explaining the change to an auditor who's already seen the bigger number.

Information produced by the entity gets treated as secondary. The reports, queries, and spreadsheets your control operators rely on have to be tested for completeness and accuracy, and untested IPE is among the most common reasons first-year workpapers get rejected.

Internal audit gets under-resourced. Many newly public companies stand up a function of one, then hand that person the entire SOX program plus an audit plan. This never fails loudly. It fails through thin documentation that surfaces a year later.

Disclosure controls get confused with internal control over financial reporting. Section 302 covers disclosure controls and procedures. Section 404 covers ICFR. They overlap substantially, they're evaluated separately, and they run on different timelines.

IT general controls get skipped. Automated controls are only as reliable as the access, change management, and operations controls over the systems running them. First-year programs routinely test the automated control and leave the foundation underneath it untouched.

Building the Program Without a Full Internal Audit Function

Most newly public companies don't have the internal audit capacity a first-year SOX program demands, and hiring to peak demand is the wrong answer, because the demand is seasonal. You'd be buying a snowplow for a city that gets three storms a year.

Two models work, and they're both about capability rather than headcount.

A defined project gives you a scope with an end: a rationalization review of the inherited population, a readiness assessment, or a single year of testing. This fits when what you need is a reset rather than ongoing coverage.

A co-sourced arrangement keeps your function owning scope and conclusions while an outside team supplies testing capacity that scales with your testing calendar instead of your org chart. The reason to think about it as renting rather than buying is that a hire locks you into a fixed cost across a workload that isn't fixed. More on internal audit co-sourcing.

Under either model, management keeps the 404(a) assessment and the 302 certifications. That responsibility never moves. What moves is execution.

What's Coming Next Is Worth Watching

One more thing belongs on a 2026 planning agenda, and it's the reason to hold your filer-status assumptions loosely.

In May 2026 the SEC proposed simplifying the filer categories: raising the large accelerated filer threshold from $700 million to $2 billion in public float, eliminating the accelerated filer and smaller reporting company statuses, and extending to all non-accelerated filers the accommodation of not requiring an ICFR auditor attestation. Emerging growth company status would be untouched, since it's statutory.

To be precise about status: this is a proposed rule. The comment period closed in July 2026. Nothing has been adopted, there's no effective date, and nothing about your current obligations has changed.

But if it were adopted broadly as proposed, a meaningful number of companies now inside 404(b) would sit outside it. That doesn't make the work optional. Your 404(a) assessment, your 302 certifications, and your audit committee's expectations all survive intact, and a company that skipped the foundation because attestation looked unlikely would still be signing certifications against a control environment nobody tested. It does mean the calculus behind "build for the year you'll be subject to 404(b)" deserves a fresh look this planning cycle rather than a copy-forward.

The rules underneath SOX have moved before and they'll move again. The programs that handle it well are the ones built on their own risk, not on the current shape of the phase-in.

If you're standing up a first-year program, or working out what to do with a control environment you inherited rather than chose, that's a conversation worth having before your testing calendar is set. Explore our SOX and internal controls practice, or reach out and we'll talk it through.

Cherry Hill Advisory is a global practitioner-built internal audit and risk advisory firm, led by former CAEs and Big Four alumni, delivering co-sourced internal audit, EQA conformance, SOC 2 readiness, ERM, fraud risk management, SOX compliance, cybersecurity, and AI governance. IIA Authorized Licensee. NASBA-accredited CPE provider.

This article is general information, not accounting, legal, or audit advice. Filer status determinations and phase-in timing depend on facts specific to your company and should be confirmed with your advisors.

Frequently Asked Questions

When does SOX apply after an IPO?

Sections 302 and 906 certifications apply from the first periodic report filed after going public. Management's Section 404(a) assessment of internal control over financial reporting is generally first required in the second annual report. The auditor attestation under Section 404(b) applies based on filer status, and the statute exempts emerging growth companies as well as issuers that are neither large accelerated nor accelerated filers.

Is a newly public company exempt from SOX 404 in its first year?

A newly public company generally isn't required to include management's report on internal control over financial reporting in its first annual report after the IPO, and the SEC's transition period covers the auditor attestation as well. That relief is limited to the first annual report. It doesn't touch the Section 302 certifications, which apply immediately.

How long are emerging growth companies exempt from the auditor attestation?

Emerging growth company status ends on the earliest of four triggers: revenue crossing a threshold the SEC indexes for inflation, the last day of the fiscal year following the fifth anniversary of the first registered sale of common equity, issuing more than a billion dollars of non-convertible debt over a three-year period, or qualifying as a large accelerated filer. Confirm current status against the SEC's definitions rather than the figures in effect when you filed.

What should a company do first after a carve-out or spin-off?

Rationalize the inherited control population before testing it. Controls designed for a parent entity frequently reference shared services that no longer exist, reflect the parent's materiality rather than yours, and carry key designations based on the parent's reliance decisions. Testing an unrationalized inherited matrix commits you to somebody else's program design.

How many key controls does a newly public company need?

There's no correct number and no requirement to hit. The size of a population reflects your materiality, process complexity, systems landscape, and key designation decisions. Inherited populations are frequently larger than the entity's own risk profile warrants, which is why rationalizing before the first year of testing matters more here than almost anywhere else.

Can a newly public company get outside help with SOX testing?

Yes. Management can bring in outside capacity for the execution of testing while keeping ownership of the conclusions and the certifications. A co-sourced arrangement works alongside your internal audit function rather than in place of it, and the certification responsibility stays with management either way.

What is the difference between disclosure controls and internal control over financial reporting?

Disclosure controls and procedures, covered by Section 302, address whether information required in SEC filings is recorded, processed, summarized, and reported on time. Internal control over financial reporting, covered by Section 404, addresses the reliability of financial reporting and the preparation of financial statements. They overlap substantially, and they're evaluated separately on different timelines.

Subscribe now to join the Risk Register community:

Nk it'