Does SOX Apply to Private Companies?
Section 404 of the Sarbanes-Oxley Act does not apply to your private company, and that is the least interesting sentence in this article. Two other pieces of the same Act were written into the federal criminal code and apply to "whoever": 18 U.S.C. 1519, added by SOX section 802, makes knowingly altering, destroying, concealing or falsifying a record with intent to impede or obstruct the investigation or proper administration of any federal matter punishable by up to twenty years, and 18 U.S.C. 1513(e), added by section 1107, makes knowing retaliation against a person for giving truthful information to a law enforcement officer about a possible federal offense punishable by up to ten years. Neither one contains the word issuer. The contrarian part is smaller and sharper: the Act's own definition of issuer at 15 U.S.C. 7201(7) already covers a company "that files or has filed a registration statement that has not yet become effective ... and that it has not withdrawn", so a private company crosses into issuer status on the day its S-1 reaches EDGAR, not on the day its stock trades.
This piece separates the parts of SOX that need an issuer from the parts that do not, explains the two ways a company with no listed stock ends up inside the definition anyway, and covers the commercial reasons private companies build these controls with no statute pointing at them.
Key takeaways
- Section 404 is issuer-only. So are the officer certifications, and so is everything a first-time filer thinks of as "SOX".
- SOX 802 and SOX 1107 are criminal statutes of general application. 18 U.S.C. 1519 and 18 U.S.C. 1513(e) reach any person or company, public or private, and carry twenty-year and ten-year maximums respectively.
- SOX 806 reaches your contractors' employees. 18 U.S.C. 1514A protects "any officer, employee, contractor, subcontractor, or agent" of a covered company, and the Supreme Court read it in 2014 to shelter employees of private contractors as well.
- "Private" is not the same as "not an issuer". Registered debt brings Section 15(d) reporting, and filing a registration statement that has not gone effective is enough on its own under 7201(7).
- Most private-company ITGC work is contractual, not statutory, and should be scoped and priced as such rather than as compliance with a law that does not apply.
The part that genuinely needs an issuer
Section 404 of the Act, codified at 15 U.S.C. 7262, requires annual reports to contain management's internal control report, and requires the registered public accounting firm to attest to that assessment for issuers other than emerging growth companies and other than issuers that are neither accelerated nor large accelerated filers. The obligation hangs off the annual report. No annual report, no Section 404.
The certification rules work the same way. Rule 13a-14 attaches certifications to reports filed on Form 10-Q and Form 10-K under Section 13(a), and Rule 15d-14 to reports filed under Section 15(d). Both are about filings. A company that files nothing certifies nothing.
So when a board member asks whether SOX applies, and means the control matrix, the testing programme, the external auditor's opinion and the quarterly certifications, the honest answer for a genuinely private company is no. What follows is why that answer is incomplete often enough to be dangerous.
The definition of issuer is wider than "listed"
Section 2 of the Act defines an issuer as an issuer whose securities are registered under Section 12 of the Exchange Act, or that is required to file reports under Section 15(d), or that files or has filed a registration statement that has not yet become effective under the Securities Act of 1933 and has not withdrawn it.
Two of those three limbs catch companies that nobody in the building calls public.
Registered debt. A company with no publicly traded equity but with registered bonds or notes carries a Section 15(d) reporting obligation, and the Act's definition names 15(d) directly. Private-equity-owned issuers and companies that did a registered debt exchange land here regularly, and the surprise is usually discovered by a new CFO rather than by the finance team that arranged the debt.
The pending registration statement. The third limb is the one worth reading twice. It does not say effective. A company that has filed an S-1 and has not withdrawn it is inside the Act's definition of issuer while it waits, which is exactly the window in which a company is least likely to think of itself as subject to anything.
If you are heading for a listing, our companion piece on when to start SOX preparation before an IPO works through the calendar that follows from crossing this line.
The provisions that never asked whether you are public
Three, in descending order of how often they matter to a private company.
SOX 802, at 18 U.S.C. 1519. "Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry in any record, document, or tangible object with the intent to impede, obstruct, or influence the investigation or proper administration of any matter within the jurisdiction of any department or agency of the United States or any case filed under title 11, or in relation to or contemplation of any such matter or case, shall be fined under this title, imprisoned not more than 20 years, or both." It was added by the Sarbanes-Oxley Act in 2002 and it is now simply part of the federal obstruction toolkit. It has no issuer limitation, no materiality threshold, and no requirement that any securities be involved.
The practical translation for an ordinary private company is unglamorous: your document retention policy, your legal hold process, and whether the person who administers your email tenant knows what to do when a preservation notice arrives. Those are the controls 1519 actually touches, and almost nobody thinks of them as SOX controls.
SOX 1107, at 18 U.S.C. 1513(e). "Whoever knowingly, with the intent to retaliate, takes any action harmful to any person, including interference with the lawful employment or livelihood of any person, for providing to a law enforcement officer any truthful information relating to the commission or possible commission of any Federal offense, shall be fined under this title or imprisoned not more than 10 years, or both." Again, no issuer limitation. Any company that has ever had an employee report something to a federal agency is inside the reach of this provision.
SOX 806, at 18 U.S.C. 1514A. This one is issuer-anchored on its face and reaches private companies through the back. It applies to a company with a class of securities registered under Section 12 or required to file reports under Section 15(d), and it protects "any officer, employee, contractor, subcontractor, or agent of such company". In Lawson v. FMR LLC, decided March 4, 2014, the Supreme Court held that the provision shelters employees of private contractors and subcontractors just as it shelters employees of the public company they serve. If your private company is a fund administrator, an outsourced accounting provider, a payroll processor or any other contractor to a public company, your own employees may be within the protection, and your retaliation exposure is not a public-company problem you can wave off.
Why private companies build these controls anyway
None of the above is why most private companies end up with an ITGC programme. The real drivers are commercial, and they are worth naming precisely so you can scope to them rather than to a statute.
Your customers' auditors. If you provide a service that touches your customers' financial reporting, their external auditors will want assurance over your controls, and the instrument for that is a SOC 1 report rather than anything called SOX. The distinction matters because the two have different scopes and different report users, which our guide to SOC 1 versus SOC 2 versus SOC 3 works through in detail. Selling "SOX compliance" to a customer who needs a SOC 1 is a mis-scope that costs a quarter.
Lenders and sponsors. Credit agreements and sponsor reporting packages routinely require internal control representations and, occasionally, an audit right. Those are contract terms. They can be negotiated, they can be scoped, and they do not carry the SEC's definitions with them unless the drafting imports them.
An exit that is not an IPO. In a trade sale to a public acquirer, your controls become their controls, and the acquirer's own 404 assessment has to cover the acquired business, usually with a grace period the acquirer's auditors will define. Diligence teams look at exactly the four control domains a SOX programme would have built.
The one that gets underrated. A close process nobody can evidence is a valuation problem before it is a compliance problem. If you cannot reproduce last April's revenue cut-off decisions, that is not a SOX finding, because you have no SOX. It is a diligence finding, which is worse, because there is no remediation window.
The honest limits of this answer
Three caveats, and the third is the one we would most want a reader to take.
Filer and issuer status is a legal determination, not a self-assessment. We are a compliance consultancy, not a law firm. Whether a particular financing brought a Section 15(d) obligation, whether a registration statement is still pending, and how any criminal provision applies to specific conduct are questions for securities and white-collar counsel, and we work alongside them rather than in place of them.
"SOX compliant" is not a status a private company can hold. There is no certificate, no registry, no assessor, and no examination. A private company can hold a SOC 1 or a SOC 2 report, or an internal audit opinion, or an attestation over a specific process. It cannot hold SOX compliance, and a vendor offering to certify you against SOX is describing something that does not exist.
Most of the general-application provisions are lawyer-owned, not consultant-owned. Retention schedules, legal hold, and whistleblower channels have technical components we can help build, but the obligations sit with counsel. If a consultancy pitches you a "SOX 802 readiness programme", ask which parts of it are anything other than a document retention policy and a legal hold procedure.
Where Top Floor fits
Our SOX practice exists mostly for companies that are heading for a listing or that already are issuers. For a private company, the work is usually a different shape: a SOC 1 or SOC 2 readiness engagement through our audit and assurance practice when the pressure is coming from customers' auditors, or a general control build through compliance as a service when the pressure is coming from a lender, a sponsor or a diligence process.
Where a legal hold or retention obligation is the real driver, we build the technical half, meaning retention configuration, immutable storage, access logging and the process that runs when a preservation notice arrives, and your counsel owns the rest. We are explicit about that split at scoping time because the alternative is billing you for advice we are not qualified to give.
How to decide this week
First, settle the status question with counsel rather than internally. Registered debt, a pending registration statement and any Exchange Act registration each change the answer, and each is a documented fact rather than an opinion.
Second, find out where the pressure is actually coming from. Read the clause. A customer contract asking for a SOC 1, a credit agreement asking for a control representation and a sponsor asking for a diligence pack are three different projects, and only one of them looks like a SOX programme.
Third, check the two obligations that already apply to you: a document retention schedule that someone owns, and a legal hold procedure your IT administrators have actually rehearsed. Those are cheap, they are the concrete surface of SOX 802 for a private company, and almost nobody has tested them.
Fourth, if a listing is genuinely on the table inside two years, read the timing piece linked above and put the two anchor dates in front of your board. The transition period is generous, and it is generous in a way that misleads people who have not read it.
Frequently asked questions
Does SOX apply to private companies?
Partly, and not the part people mean. Section 404, the officer certifications and the rest of the reporting machinery apply to issuers, which a genuinely private company is not. But two provisions the Act inserted into the federal criminal code apply to anyone: 18 U.S.C. 1519, added by section 802, on destroying or falsifying records with intent to obstruct a federal matter, carrying up to twenty years, and 18 U.S.C. 1513(e), added by section 1107, on retaliating against someone for giving truthful information to law enforcement, carrying up to ten years. Neither contains an issuer limitation.
When does a pre-IPO company become an issuer under SOX?
On filing, not on effectiveness. 15 U.S.C. 7201(7) defines an issuer to include a company that files or has filed a registration statement that has not yet become effective under the Securities Act of 1933 and that it has not withdrawn, alongside companies with securities registered under Section 12 and companies required to file reports under Section 15(d). A company that has filed an S-1 and left it pending is inside the definition while it waits. Whether any particular obligation attaches at that moment is a question for securities counsel.
Do our public-company customers make us subject to SOX?
Not directly, with one important exception. Serving public companies does not make you an issuer and does not bring Section 404 with it; what it usually brings is a request for a SOC 1 report, because your customers' auditors need assurance over the controls at your organisation that affect their financial reporting. The exception is 18 U.S.C. 1514A, which protects any officer, employee, contractor, subcontractor or agent of a covered company, and which the Supreme Court held in Lawson v. FMR LLC in 2014 to shelter the employees of private contractors and subcontractors as well.
Can a private company be SOX compliant?
No, in the sense that there is nothing to be compliant with and nothing to hold. SOX 404 obligations attach to annual reports that a private company does not file, and there is no certification scheme, assessor body or registry attached to the Act. A private company can hold a SOC 1 or SOC 2 report, can obtain an internal audit opinion over a process, and can build the same IT general controls a public company builds. Any vendor offering to certify a private company against SOX is selling an artifact that does not exist.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.