What Is SOX and Why It Matters

SOX is often viewed as a finance or accounting regulation. In practice, SOX compliance depends heavily on IT systems, cybersecurity controls, and access governance.

If financial data flows through your systems, IT is part of your SOX control environment.

What It Is

The Sarbanes-Oxley Act (SOX) is a U.S. federal law designed to protect investors by ensuring the accuracy, integrity, and reliability of financial reporting for publicly traded companies.

SOX is Public Law 107-204, enacted July 30, 2002 in response to major corporate accounting scandals. Its long title states the purpose plainly: "To protect investors by improving the accuracy and reliability of corporate disclosures made pursuant to the securities laws." Title I of the Act created the Public Company Accounting Oversight Board (PCAOB), which oversees the audits of public companies.

The Act focuses on internal controls, accountability, and auditability - and the SEC administers its disclosure requirements.

Who It Applies To

SOX applies to public companies and, through their control environments, to the organizations that support them.

Public companies:

  • U.S. publicly traded companies: the direct subjects of the Act.
  • Foreign companies listed on U.S. exchanges: listing brings SOX obligations.
  • Subsidiaries whose financials roll up into public filings: consolidated means covered.

Organizations supporting public companies:

  • SaaS and technology vendors: where their systems touch financial data.
  • ERP and financial system providers: the core of the reporting stack.
  • MSPs and IT providers: operating the systems under control.
  • Payroll, billing, and accounting platforms: processing transactions that become filings.
  • Cloud service providers: hosting financially relevant workloads.
  • Third parties with access to financial systems or data: inside the customer's ICFR scope.

If your organization hosts, processes, or supports systems involved in financial reporting, you are part of the SOX risk chain - which is why public-company customers ask you for SOC 1 reports.

A scoping fact that changes the picture for smaller companies: issuers eligible to be smaller reporting companies with annual revenues under $100 million are excluded from the accelerated-filer definitions - which means they are not required to obtain the independent auditor's ICFR attestation under §404(b) (SEC small-entity compliance guide). They remain fully subject to §404(a) management assessment and §302 certifications. The controls still have to work; the outside auditor's opinion on them is what falls away.

What Information Is Regulated

SOX focuses on financial reporting and the systems that support it, including:

  • General ledger and ERP platforms: where the numbers live.
  • Accounting and payroll systems: transaction sources feeding the ledger.
  • Revenue recognition tools: where judgment meets automation.
  • Financial reporting databases, warehouses, and integrations: every hop the data takes.
  • Change management and deployment systems: how financial logic gets modified.
  • User access to financial systems: who can touch the numbers, and how.

From an IT perspective, SOX is about preventing unauthorized changes, errors, or manipulation of financial data.

Relation to Other Frameworks

SOX aligns closely with the COSO Internal Control Framework, the NIST Cybersecurity Framework, ISO 27001, SOC 1 (financial reporting controls at service organizations), and SOC 2 (security and availability).

SOX and SOC 1 cover overlapping ground from opposite sides: SOX makes public companies responsible for internal control over financial reporting; SOC 1 is how their service organizations prove the outsourced slice of that control environment.

Organizations that manage cyber risk well typically have strong SOX outcomes, because the same fundamentals apply.

IT Requirements

SOX does not prescribe specific technologies. It requires strong, auditable controls around systems that impact financial reporting - and two sections drive most of the IT work.

Section 302 - executive accountability. The principal executive officer and principal financial officer (in practice, the CEO and CFO) must certify in each annual and quarterly report that internal controls are effective, financial reports are accurate, and deficiencies are disclosed (P.L. 107-204 §302). That certification puts direct pressure on the IT controls behind reporting accuracy.

Section 404 - internal control over financial reporting (ICFR). Organizations must design and maintain effective internal controls, test control effectiveness, and document and remediate deficiencies. Management's assessment is §404(a); the independent auditor's attestation is §404(b) - required for accelerated filers, not for smaller reporting companies with revenues under $100 million. Most SOX IT work exists under Section 404.

The IT control areas auditors test:

Access controls and identity management. Role-based access to financial systems, least-privilege permissions, segregation of duties, formal provisioning and deprovisioning, and regular access reviews. Unauthorized access is a major SOX risk.

Change management controls. Formal change approval, testing before production, separation between development and production access, and logging of system and configuration changes. Uncontrolled changes can directly impact financial integrity.

Logging, monitoring, and audit trails. System activity logging, user access logging, change logs, and retention of audit evidence. Auditors must be able to trace financial data back to controlled systems.

Data integrity and backup controls. Protection against unauthorized modification, secure backups, recovery testing, and controls ensuring completeness and accuracy.

Outsourced systems and vendors. SOX does not name vendors - no provision of the Act imposes vendor-management requirements. But outsourced processes that affect financial reporting remain inside your §404 ICFR scope, which is why auditors ask for SOC 1 reports on your service organizations. Outsourcing the process never outsources the control responsibility.

Why It Matters

SOX compliance often breaks down for structural reasons, especially in growing companies:

  • Overly broad system access: everyone can touch everything, and no one can prove otherwise.
  • Poorly documented controls: the control ran; the evidence does not exist.
  • Gaps between policy and reality: what the SOX binder says and what production does diverge.
  • Manual processes that do not scale: spreadsheet controls that worked at 50 people fail at 200.
  • Inadequate coordination between IT and finance: each assumes the other owns the control.

As companies grow, what worked informally no longer holds up under audit scrutiny.

How It Fits Into Cyber Risk Management

SOX rewards exactly what good cyber risk management already builds: controlled access, controlled change, complete audit trails, and tested recovery.

A company that runs a real security program does not build SOX controls from scratch - it maps existing controls to ICFR and closes the documentation gap.

That is also the efficient order of operations: security first, compliance evidence second.

How We Help With SOX Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment evaluates the IT general controls behind your financial reporting - access, change management, and audit trails - the way a §404 auditor will.

How to Prepare

  1. 01Identify financially relevant systems

    Document the systems supporting financial reporting, data flows between them, users and roles, and vendors with access. ICFR scope starts with an honest inventory.

  2. 02Define and document IT controls

    Ensure controls exist for access management, change management, incident handling, backup and recovery, and logging and monitoring. Controls must be documented and repeatable - an undocumented control fails testing by default.

  3. 03Test control effectiveness

    Validate that controls operate as designed, evidence can be produced, and exceptions are tracked and remediated. Testing is central to SOX - do it before the auditor does.

  4. 04Address segregation of duties

    Ensure no single user can create, approve, and post transactions, administrative access is limited and monitored, and compensating controls exist where separation is not possible.

  5. 05Manage vendors and outsourced systems

    Confirm vendor responsibilities are clear, controls over outsourced processes are tested, and SOC 1 and SOC 2 reports are collected and actually reviewed. Outsourced processes stay inside your ICFR scope.

Frequently Asked Questions

Does SOX apply to my business?

Directly, only if you are a public company, a foreign issuer listed on a U.S. exchange, or a subsidiary rolling into public filings. Indirectly, SOX reaches you whenever a public-company customer's financial reporting depends on your systems - that is when the SOC 1 requests start.

What is ICFR?

Internal control over financial reporting - the system of controls ensuring financial statements are accurate and reliable. Section 404 requires management to assess it annually (§404(a)), and larger filers to obtain an independent auditor's attestation on it (§404(b)). The IT controls beneath ICFR are where most of the technical work lives.

Are smaller companies exempt from SOX?

Not from SOX - from one piece of it. Issuers eligible to be smaller reporting companies with annual revenues under $100 million are not required to obtain the §404(b) auditor attestation. Management's own §404(a) assessment and the §302 CEO/CFO certifications still fully apply.

Who has to sign the certifications?

The principal executive officer and principal financial officer - the CEO and CFO - certify in each annual and quarterly report that controls are effective, reports are accurate, and deficiencies are disclosed (§302). Personal certification is what makes SOX an executive issue, not a departmental one.

What does SOX require from IT specifically?

Auditable IT general controls over financially relevant systems: role-based access with segregation of duties, formal change management with dev/production separation, activity and change logging with retained evidence, and data integrity and backup controls. No specific technologies - specific, provable outcomes.

Does SOX require us to manage our vendors?

SOX never mentions vendors. But outsourced processes affecting financial reporting stay inside your §404 ICFR scope, so you remain responsible for controls you have outsourced. That is why auditors ask for SOC 1 reports on your payroll processor, billing platform, and hosting provider.

What does SOX compliance cost?

It depends on filer status, system complexity, and how much control documentation already exists. We publish no pricing because honest numbers require that context. Firm quote before any work begins. The conversation costs nothing.

Where do we start?

Start where the auditors will: scope. Our Cyber Risk & Compliance Gap Assessment identifies your financially relevant systems, evaluates the IT general controls around them, and delivers a prioritized remediation roadmap you can hand to IT and finance on the same day.

Official source

Official source: U.S. Securities and Exchange Commission

Secondary source: govinfo, Public Law 107-204

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25