SOX is often viewed as a finance or accounting regulation. In practice, SOX compliance depends heavily on IT systems, cybersecurity controls, and access governance.
If financial data flows through your systems, IT is part of your SOX control environment.
The Sarbanes-Oxley Act (SOX) is a U.S. federal law designed to protect investors by ensuring the accuracy, integrity, and reliability of financial reporting for publicly traded companies.
SOX is Public Law 107-204, enacted July 30, 2002 in response to major corporate accounting scandals. Its long title states the purpose plainly: "To protect investors by improving the accuracy and reliability of corporate disclosures made pursuant to the securities laws." Title I of the Act created the Public Company Accounting Oversight Board (PCAOB), which oversees the audits of public companies.
The Act focuses on internal controls, accountability, and auditability - and the SEC administers its disclosure requirements.
SOX applies to public companies and, through their control environments, to the organizations that support them.
Public companies:
Organizations supporting public companies:
If your organization hosts, processes, or supports systems involved in financial reporting, you are part of the SOX risk chain - which is why public-company customers ask you for SOC 1 reports.
A scoping fact that changes the picture for smaller companies: issuers eligible to be smaller reporting companies with annual revenues under $100 million are excluded from the accelerated-filer definitions - which means they are not required to obtain the independent auditor's ICFR attestation under §404(b) (SEC small-entity compliance guide). They remain fully subject to §404(a) management assessment and §302 certifications. The controls still have to work; the outside auditor's opinion on them is what falls away.
SOX focuses on financial reporting and the systems that support it, including:
From an IT perspective, SOX is about preventing unauthorized changes, errors, or manipulation of financial data.
SOX aligns closely with the COSO Internal Control Framework, the NIST Cybersecurity Framework, ISO 27001, SOC 1 (financial reporting controls at service organizations), and SOC 2 (security and availability).
SOX and SOC 1 cover overlapping ground from opposite sides: SOX makes public companies responsible for internal control over financial reporting; SOC 1 is how their service organizations prove the outsourced slice of that control environment.
Organizations that manage cyber risk well typically have strong SOX outcomes, because the same fundamentals apply.
SOX does not prescribe specific technologies. It requires strong, auditable controls around systems that impact financial reporting - and two sections drive most of the IT work.
Section 302 - executive accountability. The principal executive officer and principal financial officer (in practice, the CEO and CFO) must certify in each annual and quarterly report that internal controls are effective, financial reports are accurate, and deficiencies are disclosed (P.L. 107-204 §302). That certification puts direct pressure on the IT controls behind reporting accuracy.
Section 404 - internal control over financial reporting (ICFR). Organizations must design and maintain effective internal controls, test control effectiveness, and document and remediate deficiencies. Management's assessment is §404(a); the independent auditor's attestation is §404(b) - required for accelerated filers, not for smaller reporting companies with revenues under $100 million. Most SOX IT work exists under Section 404.
The IT control areas auditors test:
Access controls and identity management. Role-based access to financial systems, least-privilege permissions, segregation of duties, formal provisioning and deprovisioning, and regular access reviews. Unauthorized access is a major SOX risk.
Change management controls. Formal change approval, testing before production, separation between development and production access, and logging of system and configuration changes. Uncontrolled changes can directly impact financial integrity.
Logging, monitoring, and audit trails. System activity logging, user access logging, change logs, and retention of audit evidence. Auditors must be able to trace financial data back to controlled systems.
Data integrity and backup controls. Protection against unauthorized modification, secure backups, recovery testing, and controls ensuring completeness and accuracy.
Outsourced systems and vendors. SOX does not name vendors - no provision of the Act imposes vendor-management requirements. But outsourced processes that affect financial reporting remain inside your §404 ICFR scope, which is why auditors ask for SOC 1 reports on your service organizations. Outsourcing the process never outsources the control responsibility.
SOX compliance often breaks down for structural reasons, especially in growing companies:
As companies grow, what worked informally no longer holds up under audit scrutiny.
SOX rewards exactly what good cyber risk management already builds: controlled access, controlled change, complete audit trails, and tested recovery.
A company that runs a real security program does not build SOX controls from scratch - it maps existing controls to ICFR and closes the documentation gap.
That is also the efficient order of operations: security first, compliance evidence second.
Here is the key takeaway: SOX compliance is not about perfection. It is about control, visibility, and accountability.
Commonly reported deficiency areas are consistent: weak access governance, poor change control, missing documentation, and IT-finance coordination gaps.
Strong fundamentals prevent most issues. The companies that struggle are the ones improvising at audit time.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment evaluates the IT general controls behind your financial reporting - access, change management, and audit trails - the way a §404 auditor will.
Document the systems supporting financial reporting, data flows between them, users and roles, and vendors with access. ICFR scope starts with an honest inventory.
Ensure controls exist for access management, change management, incident handling, backup and recovery, and logging and monitoring. Controls must be documented and repeatable - an undocumented control fails testing by default.
Validate that controls operate as designed, evidence can be produced, and exceptions are tracked and remediated. Testing is central to SOX - do it before the auditor does.
Ensure no single user can create, approve, and post transactions, administrative access is limited and monitored, and compensating controls exist where separation is not possible.
Confirm vendor responsibilities are clear, controls over outsourced processes are tested, and SOC 1 and SOC 2 reports are collected and actually reviewed. Outsourced processes stay inside your ICFR scope.
Directly, only if you are a public company, a foreign issuer listed on a U.S. exchange, or a subsidiary rolling into public filings. Indirectly, SOX reaches you whenever a public-company customer's financial reporting depends on your systems - that is when the SOC 1 requests start.
Internal control over financial reporting - the system of controls ensuring financial statements are accurate and reliable. Section 404 requires management to assess it annually (§404(a)), and larger filers to obtain an independent auditor's attestation on it (§404(b)). The IT controls beneath ICFR are where most of the technical work lives.
Not from SOX - from one piece of it. Issuers eligible to be smaller reporting companies with annual revenues under $100 million are not required to obtain the §404(b) auditor attestation. Management's own §404(a) assessment and the §302 CEO/CFO certifications still fully apply.
The principal executive officer and principal financial officer - the CEO and CFO - certify in each annual and quarterly report that controls are effective, reports are accurate, and deficiencies are disclosed (§302). Personal certification is what makes SOX an executive issue, not a departmental one.
Auditable IT general controls over financially relevant systems: role-based access with segregation of duties, formal change management with dev/production separation, activity and change logging with retained evidence, and data integrity and backup controls. No specific technologies - specific, provable outcomes.
SOX never mentions vendors. But outsourced processes affecting financial reporting stay inside your §404 ICFR scope, so you remain responsible for controls you have outsourced. That is why auditors ask for SOC 1 reports on your payroll processor, billing platform, and hosting provider.
It depends on filer status, system complexity, and how much control documentation already exists. We publish no pricing because honest numbers require that context. Firm quote before any work begins. The conversation costs nothing.
Start where the auditors will: scope. Our Cyber Risk & Compliance Gap Assessment identifies your financially relevant systems, evaluates the IT general controls around them, and delivers a prioritized remediation roadmap you can hand to IT and finance on the same day.
Official source: U.S. Securities and Exchange Commission
Secondary source: govinfo, Public Law 107-204
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25