SOX 302 vs 404 is the comparison between the two sections of the Sarbanes-Oxley Act that put an executive’s signature on internal control — and they are different obligations with different clocks, different subjects and different consequences.
Section 302, codified at 15 U.S.C. § 7241, requires the principal executive and principal financial officers to certify, in every quarterly and annual report, six things: that they have reviewed the report; that it contains no untrue statement or omission of a material fact; that the financial statements fairly present the company’s condition and results; that they are responsible for internal controls, have designed them, have evaluated their effectiveness and presented their conclusions; that they have disclosed to the auditors and the audit committee all significant deficiencies and material weaknesses and any fraud involving management or employees with a significant role in internal control; and whether there were significant changes in internal controls.
Section 404, at § 7262, requires the annual report to contain management’s internal control report and assessment of ICFR as of year end (404(a)), and the auditor to attest to that assessment (404(b)) unless the company is exempt. Section 906, a separate criminal provision at 18 U.S.C. § 1350, adds a written statement with fines up to $5 million and twenty years for wilful false certification. This guide sets the two certifications side by side on five differences, explains the disclosure controls that 302 rests on and the ICFR that 404 assesses, sets out who signs what and when, and describes how a company runs one quarterly process that supports both.

SOX 302 vs 404: what each section requires
| Section 302 (15 U.S.C. § 7241) | Section 404 (15 U.S.C. § 7262) | |
|---|---|---|
| Who acts | The principal executive officer(s) and principal financial officer(s) personally | Management (404(a)); the registered public accounting firm (404(b)) |
| When | In each annual or quarterly report — four times a year for a domestic filer | In each annual report — once a year |
| Subject | The report’s accuracy, the officers’ responsibility for and evaluation of internal controls, disclosure to the auditor and audit committee, and changes | Management’s responsibility for and assessment of the effectiveness of internal control over financial reporting as of the end of the fiscal year |
| Standard | A certification of the officers’ knowledge and actions | An assessment against a recognised framework — in practice COSO — with an auditor’s opinion under 404(b) |
| Exemptions | None; every issuer filing periodic reports | 404(b) does not apply to emerging growth companies or, under 404(c), to issuers that are neither large accelerated nor accelerated filers; 404(a) applies to all |
| Consequence of failure | A false certification is a securities law violation; section 906 adds criminal penalties for the accompanying written statement | An ineffective assessment is disclosed; a material weakness means an adverse auditor opinion under 404(b) |
Our guide to SOX 404 covers the filer-status thresholds behind the 404(b) exemption.
SOX 302 vs 404: the five differences
| Difference | Section 302 | Section 404 |
|---|---|---|
| 1. Frequency | Quarterly and annual | Annual |
| 2. Personal vs institutional | The CEO and CFO certify in their own names | Management reports; the auditor attests |
| 3. Scope of controls | Disclosure controls and procedures, and internal control over financial reporting — the certification covers both, and the SEC’s implementing rules made the distinction explicit | Internal control over financial reporting only |
| 4. Evaluation vs assessment | An evaluation of effectiveness supporting a conclusion in the report | A formal assessment against a framework, with documented testing, as of year end |
| 5. Auditor involvement | None on the certification itself; the officers must disclose deficiencies and fraud to the auditor | The auditor attests to management’s assessment under 404(b), in an integrated audit under PCAOB AS 2201 |
1. Frequency
The first SOX 302 vs 404 difference is the clock. 302 runs every quarter: the certifications are filed with each 10-Q and 10-K, and each one requires a fresh evaluation and a fresh statement about changes in internal control. 404 is the year-end event. A company that treats 302 as a signature block and 404 as the real work has three quarters a year in which the officers certify controls nobody has evaluated.
2. Personal vs institutional
302’s certifications are made by named officers based on their knowledge; the statute’s clauses repeat “based on the officer’s knowledge” and “the signing officers”. 404(a) is a report by management as a body and 404(b) an opinion by a firm. The sub-certification process — where process owners, controllers and IT leads certify to the CEO and CFO — exists to give the officers the knowledge 302 assumes.
3. Disclosure controls vs ICFR
The SEC’s rules under 302 define disclosure controls and procedures as the controls designed to ensure that information required in the company’s reports is recorded, processed, summarised and reported within the time periods specified, and accumulated and communicated to management to allow timely decisions about disclosure. ICFR is the subset — controls over the reliability of financial reporting and the preparation of financial statements. 302 covers both; 404 covers only ICFR. A disclosure failure outside the financial statements — a late 8-K, an undisclosed related-party transaction — is a 302 matter that 404 never reaches.
4 and 5. Evaluation, assessment and the auditor
The 302 evaluation supports a conclusion; the 404 assessment is the documented, tested, framework-based exercise that produces the internal control report, and under 404(b) the auditor tests it. 302 requires the officers to tell the auditor and audit committee about significant deficiencies, material weaknesses and fraud — which is why a 404 finding is also a 302 disclosure event.
SOX 302 vs 404 vs 906: the criminal layer
| Provision | Requirement | Penalty |
|---|---|---|
| 18 U.S.C. § 1350(a)–(b) | Each periodic report containing financial statements is accompanied by a written statement by the CEO and CFO certifying that the report fully complies with sections 13(a) or 15(d) of the Exchange Act and that the information fairly presents the financial condition and results | — |
| § 1350(c)(1) | Certifying knowing that the report does not comport with the requirements | Fine up to $1,000,000, imprisonment up to 10 years, or both |
| § 1350(c)(2) | Wilfully certifying knowing that it does not comport | Fine up to $5,000,000, imprisonment up to 20 years, or both |
906 is often described as part of the 302 process because the two statements are filed together, but it is a separate exhibit, a separate statute and a criminal one. Our guide to SOX compliance covers how the five-step ICFR cycle feeds all three.
SOX 302 vs 404: who signs what, and when
| Filing | 302 certification | 404(a) report | 404(b) attestation | 906 statement |
|---|---|---|---|---|
| 10-Q (each quarter) | CEO and CFO, Exhibit 31 | — | — | CEO and CFO, Exhibit 32 |
| 10-K (annual) | CEO and CFO, Exhibit 31 | Management’s report on ICFR | Auditor’s report on ICFR, unless exempt | CEO and CFO, Exhibit 32 |
Running one process for SOX 302 and 404
- Keep the control matrix and the disclosure controls inventory together. ICFR controls for 404; disclosure controls — disclosure committee, 8-K triggers, legal and contract review — for 302’s wider scope.
- Test on a quarterly rhythm. Interim testing of key controls each quarter gives the officers an evidenced basis for the 302 evaluation and spreads the 404 work across the year; roll-forward to year end under AS 2201 .55–.56.
- Run sub-certifications each quarter. Process owners, controllers, IT and legal certify to the CEO and CFO on their areas, listing deficiencies, changes and known frauds — the knowledge the 302 language assumes.
- Route every deficiency through one evaluation. Severity assessed once; a significant deficiency or material weakness goes to the auditor and audit committee under 302(a)(5) and into the 404 assessment.
- Record changes in internal control every quarter. 302(a)(6) requires the officers to state whether there were significant changes; a change log from the control matrix is the source.
- Close the year with the 404 assessment. The tested control set as of year end, management’s report, the auditor’s integrated audit where 404(b) applies, and the 302 and 906 certifications on the 10-K.
Frequently asked questions
What is the difference between SOX 302 and 404?
Section 302 requires the CEO and CFO to certify personally, in every quarterly and annual report, the accuracy of the report, their responsibility for and evaluation of internal controls, disclosure of deficiencies and fraud to the auditor and audit committee, and changes in internal control. Section 404 requires management’s annual report and assessment of internal control over financial reporting (404(a)) and, unless exempt, the auditor’s attestation (404(b)).
Does every company have to comply with both?
Every issuer filing periodic reports makes the 302 certifications and the 404(a) management assessment. The 404(b) auditor attestation does not apply to emerging growth companies or to issuers that are neither large accelerated nor accelerated filers.
What is section 906?
A separate criminal provision, 18 U.S.C. § 1350, requiring a written CEO and CFO statement with each periodic report that it complies with the Exchange Act and fairly presents the company’s condition, with fines up to $1 million and 10 years for knowing false certification and $5 million and 20 years for wilful.
Does 302 cover more than financial reporting controls?
Yes. It covers disclosure controls and procedures — everything required in the company’s reports — as well as internal control over financial reporting; 404 covers only ICFR.
How do the two connect?
A 404 deficiency is a 302 disclosure event: the officers must tell the auditor and audit committee about significant deficiencies and material weaknesses, and state changes in internal control each quarter. One quarterly testing and sub-certification process supports both.
Where this leaves you
Treat SOX 302 vs 404 as two obligations one process serves: quarterly testing and sub-certification give the officers the evidenced knowledge 302 requires four times a year, the same control matrix and deficiency evaluation feed the annual 404 assessment and the auditor’s attestation, and the disclosure controls inventory covers the ground 302 reaches and 404 does not — with 906’s criminal statement filed alongside as the reminder that the signatures are personal.
References
- 15 U.S.C. § 7241 — Sarbanes-Oxley Act section 302, Corporate responsibility for financial reports — The six certification elements.
- 15 U.S.C. § 7262 — Sarbanes-Oxley Act section 404, Management assessment of internal controls — 404(a), 404(b) and the 404(c) exemption.
- 18 U.S.C. § 1350 — Sarbanes-Oxley Act section 906, Failure of corporate officers to certify financial reports — The criminal certification and penalties.
More on SOX
- SOX 302 vs 404 — you are here
- SOX compliance: the five ICFR steps
- SOX 404: who needs the auditor attestation
- Material weakness vs significant deficiency
- SOX control testing and sample sizes
- SOX scoping and materiality
The 302 and 906 certification templates, the quarterly sub-certification form, the disclosure controls and procedures inventory, the changes-in-ICFR log and the management report on ICFR template are in the SOX Compliance Toolkit, or start with the free templates.