Scrutineer · By framework
SOX readiness assessment software for IPO and 404(a)
SOX readiness means getting internal control over financial reporting documented, tested and evidenced before the SEC deadlines arrive. They arrive in a fixed order: Section 302 certifications with your first 10-Q, management's 404(a) report in your second 10-K, and the auditor's 404(b) attestation only once you are an accelerated filer and no longer an emerging growth company.
Scrutineer is the software side of a SOX readiness assessment: one risk and control matrix, evidence collected every period, deficiencies tracked to close. Your advisors and auditor do the judging.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with SOX readiness
The auditor attestation is the part of SOX the SEC proposed to shrink
Most SOX readiness programs are sold as 404(b) readiness. On May 21, 2026 the SEC proposed, in Federal Register document 2026-10222 (RIN 3235-AN40), to collapse filer status into large accelerated filers and non-accelerated filers, raise the large accelerated threshold from $700 million to $2 billion of public float, require 60 consecutive months of reporting before a company can become one, and drop the ICFR auditor attestation for every non-accelerated filer. Comments closed July 20, 2026 and no final rule had been published as of October 2026. Emerging growth companies are already exempt from 404(b) for up to five years. If the proposal is adopted, a typical new issuer would not face an auditor attestation for at least five years.
Section 404(a) and the evidence rule do not change under any proposal
What every public company still owes is management's own annual report on internal control over financial reporting under Item 308(a) of Regulation S-K: a stated framework, an assessment as of fiscal year end, and disclosure of any material weakness. Management may not call ICFR effective if a material weakness exists. Instruction 2 to Item 308 adds the rule readiness projects underrate: the registrant must maintain evidential matter, including documentation, that reasonably supports management's assessment. That is a records obligation, and it starts the year you test.
The first 10-K buys you one year, and the dry run belongs in it
Instruction 1 to Item 308 lets a newly public company skip the management report and the attestation in its first annual report, provided it includes the SEC's prescribed sentence explaining the transition period for newly public companies. The second 10-K carries the first real 404(a) report. Teams that spend the transition year documenting rather than testing reach that report with controls that were designed but never shown to operate, which is where first-year material weaknesses come from.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Holds the risk and control matrix in one place: each financial statement risk, the control that covers it, the owner, frequency and the evidence the test needs
- Maps ITGCs for access, change management and operations to every in-scope financial system, including the ERP, the close tool and the data warehouse behind your reporting
- Collects dated evidence every period from identity, ticketing and cloud tools, so the dry-run year produces the evidential matter Item 308 asks management to keep
- Tracks each deficiency from identification to remediation and retest, with the severity call recorded, so nothing found in the gap assessment resurfaces in the second 10-K
- Shows coverage by assertion and by process, so a missing revenue or close control shows up before your auditor or your IPO consultants find it
- Runs user access reviews and segregation of duties checks on a schedule, the two ITGC areas where first-year findings cluster
- Keeps quarterly sub-certification records behind the CEO and CFO Section 302 certifications, starting with the first 10-Q
- Reuses the same controls for SOC 1, SOC 2 or ISO 27001 if customers ask, so a pre-IPO SaaS company does not run two control programs
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
SOX obligations by filing event
What SOX requires at each filing after an IPO, and what the 2026 proposal changes
Most SOX readiness guides sort the rules by filer status. A company going public lives them in time order, filing by filing, and the order shows that the evidence work is due well before any auditor attestation.
| Filing event | When it happens | What SOX requires | Evidence you need ready | Under the May 2026 SEC proposal |
|---|---|---|---|---|
| Registration statement (S-1) | Before the IPO | No ICFR report. Known material weaknesses are usually disclosed as risk factors | A list of known deficiencies and a dated remediation plan | No change |
| First quarterly report (10-Q) | The first quarter after the IPO | CEO and CFO certifications under Section 302 and an evaluation of disclosure controls | Disclosure committee minutes, sub-certifications, quarter close evidence | No change |
| First annual report (10-K) | First fiscal year end after the IPO | No management ICFR report, the Item 308 transition sentence instead, plus disclosure of material changes in ICFR | A full dry run of management testing on the real control set | No change |
| Second annual report (10-K) | Second fiscal year end after the IPO | Management report under 404(a): framework, assessment, every material weakness disclosed | Tested RCM, design and operating effectiveness results, evidential matter under Instruction 2 | No change |
| Auditor attestation (404(b)) | Once an accelerated or large accelerated filer and no longer an EGC | The audit firm attests to ICFR in the annual report | Population evidence and testing an auditor can rely on | Large accelerated filers only: $2 billion public float and 60 months of reporting |
| Leaving EGC status | Earliest of: fiscal year end after the fifth IPO anniversary, $1.235 billion revenue, $1 billion of non-convertible debt in 3 years, or large accelerated status | 404(b) applies if the company is also an accelerated filer | The same record, now tested by the auditor | Accommodations proposed for every non-accelerated filer |
| Smaller reporting company revenue test | Annual revenue under $100 million and public float under $700 million | Never an accelerated filer, so no 404(b); 404(a) still applies | Management testing only | Folded into the non-accelerated filer category |
Sources: 17 CFR 229.308 (Item 308 and its Instructions 1 and 2), 17 CFR 240.12b-2 (accelerated filer, large accelerated filer and smaller reporting company definitions) and 17 CFR 230.405 (emerging growth company), all read on the eCFR as of September 1, 2026; SEC proposed rule "Enhancement of Emerging Growth Company Accommodations and Simplification of Filer Status for Reporting Companies", Federal Register document 2026-10222, May 21, 2026, comments closed July 20, 2026, not final as of October 2026. Not legal advice; confirm filer status with securities counsel.
Good questions
Questions about SOX readiness
Keep reading
Guides for getting SOX ready
Explore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification