AuditXYZ

Lesson 2 of 5

SOX Section 302 and 906: Executive Certifications Explained

12 min readIntermediate

SOX Section 302 and 906 Certifications

Sections 302 and 906 require the CEO and CFO to personally certify the accuracy of financial reports filed with the SEC. These certifications are the mechanism that converted corporate financial reporting from an institutional responsibility into a personal one: the two most senior officers sign their names, every quarter, to specific statements about the report and the controls behind it — with civil liability under 302 and criminal liability under 906 for getting it wrong.

For compliance leads, the job is to make those signatures defensible: to build the machinery — disclosure controls, sub-certifications, a disclosure committee, escalation paths — that lets executives sign honestly and with evidence.

Section 302: The Quarterly Certification

Section 302 (implemented through SEC Exchange Act Rules 13a-14 and 15d-14) requires the principal executive officer and principal financial officer to each sign a certification filed as Exhibits 31.1 and 31.2 to every 10-Q and 10-K. The wording is prescribed by rule — you may not edit it — and it contains six substantive statements. Paraphrased, each signer certifies that:

  1. They reviewed the report.
  2. No material misstatements or omissions: based on their knowledge, the report contains no untrue statement of material fact and omits nothing needed to make it not misleading.
  3. Fair presentation: the financial statements and other financial information fairly present, in all material respects, the financial condition, results of operations, and cash flows.
  4. Responsibility for controls: they are responsible for establishing and maintaining disclosure controls and procedures and (for most filers) internal control over financial reporting; they designed them (or supervised their design); and they evaluated the effectiveness of disclosure controls as of the end of the period and disclosed their conclusions.
  5. Disclosure to auditors and the audit committee: they have disclosed all significant deficiencies and material weaknesses in ICFR, and any fraud (material or not) involving management or employees with a significant role in internal control.
  6. Changes in ICFR: the report discloses any change in ICFR during the most recent quarter that materially affected, or is reasonably likely to materially affect, ICFR.

Note the quarterly rhythm hiding in item 4: disclosure control effectiveness must be evaluated each quarter, not annually. The full 404 ICFR assessment is annual, but the 302 evaluation and the "changes in ICFR" disclosure recur every filing.

Section 906: The Criminal Certification

Section 906 (codified in the federal criminal code at 18 U.S.C. 1350) requires a separate, shorter certification — filed as Exhibit 32 — stating that the periodic report fully complies with the requirements of the Exchange Act and that the information fairly presents, in all material respects, the financial condition and results of operations of the company.

The differences from 302 matter:

AttributeSection 302Section 906
Legal natureSEC rule; civil/administrative exposure (plus general securities fraud liability)Criminal statute
Filing status"Filed" exhibit (31.1/31.2) — full Exchange Act liabilityTypically "furnished" exhibit (32)
ContentSix detailed statements incl. controls responsibilityTwo statements: full compliance and fair presentation
Knowledge qualifierSeveral statements qualified "based on my knowledge"No qualifier in the statute; penalties keyed to state of mind
Penalty for falsitySEC enforcement, fines, officer/director barsKnowing violation: up to $1M fine and 10 years; willful violation: up to $5M and 20 years
Applies toQuarterly and annual reportsPeriodic reports containing financial statements

The practical effect of 906 is psychological as much as legal: prosecutions are rare, but every CEO and CFO knows the statute exists, which is precisely why certification support processes get executive attention that ordinary compliance programs do not.

Disclosure Controls vs. ICFR

Section 302 introduced a term that predates and is broader than the 404 machinery: disclosure controls and procedures (DCP). DCP are the controls ensuring that all information required to be disclosed in SEC reports — financial and non-financial — is recorded, processed, summarized, and reported within SEC timeframes, and accumulated and communicated to management in time for decisions about disclosure.

ICFR is a subset-with-overlap: it covers the reliability of the financial statements specifically. DCP additionally covers things like material contracts, legal proceedings, risk factor changes, cybersecurity incidents requiring disclosure, segment developments, and subsequent events. A company can have effective ICFR and still miss a required non-financial disclosure — that is a DCP failure, and it is what the quarterly 302 evaluation is designed to catch.

Building the Certification Support Process

Executives cannot personally verify thousands of transactions and disclosures. A defensible certification rests on layered machinery:

1. Sub-certifications. Each quarter, controllers, business unit leaders, and functional heads (legal, HR, tax, IT, sales operations) sign internal representations covering their domains: figures submitted are accurate, controls operated, no known fraud, no undisclosed liabilities or side agreements, nothing material withheld. Design tips: tailor questionnaires to the role rather than sending generic forms; require explicit yes/no answers with an exceptions box; route exceptions to the disclosure committee, not into a folder; and keep signed copies as evidence — plaintiffs' counsel and the SEC will ask for them if things go wrong.

2. A disclosure committee. Most public companies charter a management-level committee — typically the controller, general counsel, head of internal audit, investor relations, and key operations leaders — that meets each quarter before filing to review the draft report, the sub-certification results, identified deficiencies, and any judgment calls on materiality and disclosure. The committee's minutes and materials become part of the record showing the executives' evaluation was real.

3. Deficiency and fraud escalation. Statement 5 of the 302 certification requires disclosure of significant deficiencies, material weaknesses, and fraud to the auditors and audit committee. That only works if issues actually flow upward: your SOX testing results, whistleblower hotline output, and incident reports need a defined path to the disclosure committee each quarter.

4. The quarterly ICFR-change review. Statement 6 requires disclosing material changes in ICFR each quarter. In practice: a standing agenda item reviewing system implementations and migrations (a new ERP is the canonical material change), reorganizations, acquisitions, control remediations, and outsourcing changes during the quarter.

5. Executive review sessions. Before signing, the CEO and CFO should receive a certification package — draft filing, disclosure committee summary, sub-certification exception report, deficiency status — and hold a briefing where they can ask questions. Signing without this ritual is signing blind.

When Things Go Wrong

  • A material weakness exists at quarter-end. You can still certify — 302 does not require effective controls; it requires an honest evaluation and disclosure. The certification statements stand, and the 10-Q/10-K discloses the material weakness and concludes disclosure controls were not effective. What you cannot do is conclude "effective" while knowing of an unremediated material weakness.
  • An error is found after filing. Assess materiality; if the prior statements can no longer be relied upon, an Item 4.02 8-K and restatement follow, and the re-filed reports carry fresh certifications. Executives' prior certifications become exhibits in the inevitable scrutiny of what they knew and when — which is exactly why the contemporaneous support record matters.
  • An executive refuses to sign. This is a five-alarm governance event that companies must disclose in substance (a periodic report without required certifications is delinquent). In practice, refusal forces resolution of the underlying dispute before filing.
  • Clawback exposure. After a restatement, Section 304 permits the SEC to claw back the CEO's and CFO's bonuses and stock profits for the affected period — and exchange listing rules adopted under Dodd-Frank now require broader no-fault clawback policies. Certification failures and restatements are financially personal.

Certification Process Checklist

  • Exhibit 31 and 32 certifications use the exact prescribed wording, updated for current signers
  • Disclosure committee chartered, with quarterly meetings calendared ahead of each filing
  • Sub-certification questionnaires tailored by role, distributed and tracked each quarter
  • Exceptions from sub-certifications logged, investigated, and reported to the disclosure committee
  • Quarterly evaluation of disclosure controls documented, with a stated conclusion
  • Quarterly review of ICFR changes (systems, reorgs, acquisitions, remediation) documented
  • Deficiency reporting path from SOX testing and hotline to disclosure committee and audit committee operating
  • Certification package delivered to CEO/CFO with time for questions before signing
  • Signed certifications and supporting record retained per your Section 802 retention policy
  • New executives briefed on certification obligations before their first signing quarter

Frequently Asked Questions

Who exactly must sign 302 and 906 certifications?

The principal executive officer and principal financial officer — each signing individually. Titles do not control substance: if the founder functions as PEO without the CEO title, they sign. Co-CEOs each sign. A certification cannot be delegated to a deputy, though an interim or acting officer signs while serving in the role.

Do these certifications apply to smaller reporting companies and EGCs?

Yes, in full, from the first periodic report after going public. The 404(b) auditor-attestation relief that smaller companies and EGCs enjoy does not touch 302 or 906 — the certifications, the quarterly disclosure-controls evaluation, and the criminal exposure apply to every filer regardless of size.

What does "based on my knowledge" actually protect?

It scopes several 302 statements to the signer's actual knowledge, but courts and the SEC read it against a backdrop of duty: an executive cannot avoid knowledge by avoiding inquiry. A certification signed after ignoring red flags, skipping the disclosure committee output, or discouraging bad news is not protected by the qualifier — recklessness defeats it.

Are 906 prosecutions real or theoretical?

Rare but real — 906 charges have appeared in major fraud prosecutions alongside securities fraud counts, and the statute's presence changes executive behavior regardless of prosecution frequency. The more common consequences of certification failures are SEC civil actions under 302, officer-and-director bars, clawbacks, and private securities litigation quoting the certifications back at the signers.

Sub-certifications do not transfer the executives' liability downward — the CEO and CFO remain the certifying officers. What sub-certifications do is evidence a reasonable process: they show the executives built and used a system to surface problems. They also concentrate the minds of middle management, which is much of their practical value.

Do 302 evaluations replace the annual Section 404 assessment?

No — they complement it. Section 302 requires a quarterly evaluation of disclosure controls and quarterly disclosure of ICFR changes; Section 404 requires the annual, evidence-based assessment of ICFR effectiveness (and, for larger filers, the auditor's opinion). The quarterly 302 process typically leans on the 404 program's testing results as they accumulate through the year.

In the next lesson, we will cover Section 404 internal controls in detail.


Quarterly certifications run smoother when sub-certifications, deficiency logs, and evidence live in one system. AuditXYZ helps you compare compliance automation platforms and auditors to find tooling that supports SOX certification workflows.