Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SOX for newly public companies IPO compliance timeline

SOX for Newly Public Companies: IPO Timeline 2026

SOX for newly public companies works on a phased schedule, and confusing the phases is the most common planning mistake after an IPO. The certifications under Section 302 start almost immediately, while management’s report on internal control and the auditor’s attestation arrive later, on timelines that depend on filer status.

This guide sets out what applies when, what the SEC transition period covers, how filer status changes the auditor’s role, and a readiness sequence you can start before the listing. For the underlying requirements, see our SOX compliance guide.

The transition period in SOX for newly public companies

Instruction 1 to Item 308 of Regulation S-K gives a newly public company a transition period. It need not include management’s report on internal control over financial reporting, or the auditor’s attestation report, until it has either been required to file an annual report for the prior fiscal year or has already filed one. In practice the first annual report after the IPO can omit both. The company must say so, using a statement that the annual report does not include either report because of a transition period established by SEC rules for newly public companies.

That transition is a deferral of reporting, not of the work. The first annual report that must include management’s assessment will arrive within roughly two years of listing, and an assessment needs a full year of documented, operating controls behind it. Companies that treat the transition as breathing space often reach that report with untested controls.

RequirementWhen it starts for a newly public company
Section 302 certifications by CEO and CFOFrom the first periodic report, with no grace period
Disclosure controls and proceduresMust exist and be evaluated from the first periodic report
Management’s report on ICFR (Section 404(a))After the transition period, generally the second annual report
Auditor attestation (Section 404(b))After the transition, and only if the company is not exempt

One point to confirm with your securities counsel is the exact wording of the 302 certification during the transition, because the SEC staff has addressed how the internal-control language is treated in that period.

What applies immediately: certifications and disclosure controls

From the first 10-Q or 10-K, the CEO and CFO sign certifications about the accuracy of the report and the effectiveness of disclosure controls. Those officers cannot sign with comfort unless there is a process to gather, review and escalate the information behind the filing. A sub-certification cascade, where business unit and function heads confirm their areas each quarter, is the usual mechanism. Our SOX 302 vs 404 comparison explains how the two sections differ.

This is where SOX for newly public companies bites first. Build this before the roadshow. A disclosure committee with a charter, a calendar, a checklist for each filing and clear rules on materiality will be tested within weeks of listing, and a first-quarter misstep is visible to investors.

Filer status and the auditor attestation for SOX for newly public companies

Whether the external auditor must attest to internal control depends on the company’s filer category and on any emerging growth company status.

  • Large accelerated filers (public float of $700 million or more) are subject to the auditor attestation once the transition ends.
  • Accelerated filers (float of $75 million or more but under $700 million) are also subject to it, unless the 2020 amendments to the definition exclude them because annual revenue is under $100 million.
  • Non-accelerated filers are not required to obtain an attestation.
  • Emerging growth companies are exempt from the attestation for as long as they keep that status, up to five years after the IPO, and it ends earlier if they lose the status.

A newly public company cannot be an accelerated filer in its first year, because the definition requires 12 months of Exchange Act reporting and at least one annual report. Public float is measured at the end of the second fiscal quarter, so a large market move can change your status for the following year. Model your status each year rather than assuming it.

Emerging growth company limits

The emerging growth designation is capped by revenue, currently $1.235 billion and indexed periodically, by the issuance of more than $1 billion in non-convertible debt over three years, by becoming a large accelerated filer, and by the fifth anniversary of the IPO. Losing the status before the anniversary brings the attestation forward, so a fast-growing company should plan for the earlier date.

A readiness plan for SOX for newly public companies

Start 18 to 24 months before the listing if you can, and treat the sequence below as a working plan and not a fixed calendar.

  1. Model filer status. Estimate float, revenue and emerging growth eligibility, and mark the date the attestation is likely to begin.
  2. Scope the financial statements. Identify significant accounts, disclosures and the processes behind them. Our SOX scoping guide covers this step.
  3. Document processes and controls. Write narratives, flowcharts and a risk and control matrix for each in-scope process.
  4. Fix the IT general controls. Access, change management and operations are frequent trouble spots. See SOX ITGC.
  5. Test the controls. Run a dry run of management’s assessment well before it is required. See SOX control testing.
  6. Track deficiencies to closure. Log each one, classify its severity and assign an owner and a date.
  7. Engage the auditor early. Agree scope, timing and walkthroughs before the first attestation year.

A hypothetical timeline for SOX for newly public companies

Consider a software company that lists in March and has a December year end. It files its first 10-Q for the March quarter within the deadline for new registrants, and the CEO and CFO sign 302 certifications that day. Its first 10-K, covering the year to December, includes the transition-period statement and no ICFR report. The following year’s 10-K is the first to carry management’s assessment, and, if the company is neither an emerging growth company nor otherwise exempt, the auditor’s attestation as well. The example is illustrative and the dates in your case depend on your fiscal year and filer status.

Working backwards from that second annual report gives the real deadline for control design and testing. Controls should be in place and operating from the start of that fiscal year, so remediation of known gaps has to finish in the year before it, not in the last quarter.

Who should sit on the programme team

The audit committee oversees the effort, and the CFO usually sponsors it. A programme lead, often in finance or internal audit, keeps the plan and the deficiency log. Process owners in revenue, procurement, payroll, treasury and IT confirm the controls in their areas. Legal owns the disclosure committee process and the review of certifications. Where the company lacks an internal audit function, an outside adviser can perform the independent testing, provided the roles are kept separate from the design of the controls.

Programme governance for SOX for newly public companies should be light but regular: a monthly status report, a deficiency summary for the audit committee each quarter, and a clear line from any significant deficiency to the CFO. Investors will judge the company partly on how it handles its first control issues.

Common mistakes after the IPO

Several patterns repeat in SOX for newly public companies. Finance runs the programme alone when IT, procurement and HR own controls that feed the numbers. The scope grows to cover everything instead of the material risks. Documentation is written just before the assessment, so controls have no operating history. Spreadsheets used in the close have no access or change controls. And accounting resources are stretched, which is a leading cause of the material weaknesses that newly listed companies report. A short remediation window before the first assessment date is rarely enough to show a control operating effectively.

Getting the documentation in place faster

Much of the work is producing a consistent set of records: scoping memos, process narratives, control matrices, test plans, deficiency logs and sign-off forms. The SOX Compliance Toolkit provides ICFR templates for these, which you can tailor to your processes. Whatever you use, keep the structure identical across processes so testers, management and the auditor can read them the same way. For the official wording, see Item 308 of Regulation S-K.

SOX for newly public companies FAQ

Do newly public companies need to comply with SOX right away?

Partly. Section 302 certifications and disclosure controls apply from the first periodic report, while management’s ICFR report and the auditor attestation follow after a transition period.

When is the first management report on internal control due?

Generally in the second annual report after the IPO, once the company has been required to file an annual report for the prior fiscal year or has filed one.

Does an emerging growth company avoid all SOX requirements?

No. It is exempt from the auditor attestation while it keeps the status, but the certifications, disclosure controls and management’s assessment still apply.

When should SOX readiness start?

Ideally 18 to 24 months before the listing, so controls have an operating history before the first assessment.

Who is responsible for SOX after an IPO?

Management, led by the CEO and CFO, with oversight from the audit committee. Finance, IT and business process owners each own controls in their areas.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.