ITGC · SOX 404 · EVIDENCE
SOX compliance software: Sarbanes Oxley software, SOX compliance tools and internal controls software for the ITGC half of SOX 404
Most of what a SOX 404 program asks an engineering team for is access reviews, change approvals and evidence with dates on it. That part you can run from the day you decide to go public.
From $79/mo · Prices published · No sales call · Monthly billing
Audit readiness
0 %
Built for teams of 5 to 200
What SOX compliance software is, and the split that decides which one you buy
SOX compliance software helps a company document, test and evidence the internal controls over financial reporting that the Sarbanes-Oxley Act requires, and the category splits cleanly in two. One half is the financial-process side: the risk and control matrix, management testing workflow, walkthrough documentation, journal entry testing, segregation of duties inside your ERP, and the 302 and 404 certification sign-offs. That is what Optro (the platform formerly called AuditBoard, which redirected auditboard.com to optro.ai after its March 2026 rebrand), Workiva and Pathlock are built for, and if you run a real internal audit function you should buy one of them. The other half is IT general controls, usually shortened to ITGC: who has access to the systems that produce the numbers, how code and configuration changes get approved before they reach production, and whether backups and jobs actually ran. ITGC is where most first-year SOX programs lose time, because the evidence lives in Okta, GitHub, AWS and your ticketing system rather than in the finance close. Complies covers that ITGC half for teams of 5 to 200: quarterly user access reviews with named reviewers, change approvals pulled from GitHub, cloud configuration evidence from AWS, and every obligation carrying an owner and a due date, at published prices of $79 to $499 a month. It does not do the financial-process half, and this page says so in the table below rather than burying it. Two facts change who needs what. SOX 404(a), the management assessment, applies to every filer from its second annual report onward, so a newly public company gets one 10-K of grace and no more. SOX 404(b), the external auditor attestation, only applies to accelerated and large accelerated filers, and emerging growth companies are exempt for up to five years after IPO. On May 19, 2026 the SEC proposed raising the large accelerated filer threshold from $700 million of public float to $2 billion and limiting 404(b) to large accelerated filers alone, which by the SEC's own estimate would exempt roughly 81 percent of public companies. The comment period closed on July 20, 2026 and the proposal has not been adopted, so plan against today's rules and watch that docket.
Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.
Last updated August 2026
The three ITGC domains an auditor tests, and where the evidence actually comes from
Access to programs and data
Who can reach the systems behind the financial statements, whether their access still matches their job, and whether leavers were removed on time. The test is almost always a quarterly user access review with a named reviewer and a dated sign-off. Complies pulls the user list from Okta and Google Workspace, assigns the review, and keeps the completed record instead of the screenshot someone saved to a laptop.
automated evidence collectionProgram change
Whether changes to in-scope systems were reviewed, approved and tested by somebody other than the person who wrote them. Auditors sample changes and ask to see the approval that preceded the deploy. Pull request approvals and merge history from GitHub answer that directly, which is why change management is usually the cheapest ITGC domain to automate and the most embarrassing one to fail.
control mapping softwareComputer operations
Whether scheduled jobs, backups and monitoring ran, and what happened when they did not. This is the domain most teams under-document, because the systems do the work reliably and nobody keeps the proof. Complies holds each operational control as an obligation with an owner and a recurring due date, so the record exists before the auditor asks for a year of it at once.
obligation tracking softwareWho has to do what under SOX 404, including the change the SEC proposed in May 2026
The single question that decides how much SOX program you need is your filer status, and almost no vendor page states it plainly. Section 404(a) is management's own assessment of internal control over financial reporting. Section 404(b) is the external auditor's separate attestation on that control environment, and it is the expensive one. Here is who owes which today, and what the SEC has proposed changing. Everything in this table is read from SEC rules and the May 2026 proposing release rather than from a vendor summary.
| Filer category | Public float and revenue test | SOX 404(a) management assessment | SOX 404(b) auditor attestation |
|---|---|---|---|
| Large accelerated filer | Public float of $700 million or more | Required | Required |
| Accelerated filer | Float of $75 million to under $700 million, with annual revenue of $100 million or more | Required | Required |
| Non-accelerated filer | Float under $75 million, or float under $700 million with revenue under $100 million | Required | Exempt |
| Emerging growth company | Up to five years after IPO, while revenue stays under $1.235 billion and float under $700 million | Required | Exempt for the EGC window |
| Any filer, first annual report | The first 10-K filed after going public, whatever the float | Not required until the second annual report | Not required until the second annual report |
| Proposed: large accelerated filer | Float of $2 billion or more, plus 60 months of seasoning | Required if adopted | Required if adopted |
| Proposed: non-accelerated filer | Everyone else, about 81 percent of public companies by the SEC estimate | Required if adopted | Exempt if adopted |
Read the last two rows carefully, because they are a proposal and not the law. The SEC issued the filer status overhaul on May 19, 2026 and the comment period closed on July 20, 2026; nothing has been adopted, and until it is, the first five rows govern. The practical planning point is unchanged either way: 404(a) never goes away for anyone, so the management assessment and the ITGC evidence behind it are work you will do regardless of which way the docket lands. Compare the enterprise end of this market in detail on AuditBoard alternatives, Hyperproof alternatives and MetricStream alternatives.
SOX compliance software compared on which half of SOX 404 it actually covers
Roundups in this category list ten vendors and grade them on the same feature checklist, which hides the only distinction that matters: whether a tool works the financial-process side of SOX or the IT general controls side. Very few do both well, and buying the wrong half is the common expensive mistake. Below is what each vendor states in its own material as of August 2026, read first-hand. Where no rate card is published we say so rather than repeating a third-party estimate as fact.
| Vendor | Which half of SOX it serves | Covers ITGC evidence | Published pricing (August 2026) |
|---|---|---|---|
| Complies | ITGC only: access reviews, change approvals, operations evidence, obligations with owners | Yes, pulled from Okta, GitHub, AWS and Google Workspace on a schedule | Published: $79, $199 and $499 a month at the yearly rate |
| Optro (formerly AuditBoard) | Both, built around the financial-process side: RCM, testing workflow, issue tracking, certifications | Yes, as part of a full enterprise GRC and internal audit suite | Quote-only, no figures published |
| Workiva | Financial process, tied through to the SEC filing itself | Partially, as documentation rather than automated collection | Quote-only, no figures published |
| Pathlock | Financial process, specifically ERP access governance and segregation of duties | Deep inside SAP and other ERPs, narrow outside them | No public rate card for the platform |
| Hyperproof | Controls and evidence across frameworks, with SOX as one of them | Yes, through integrations and control mapping | Quote-only, no figures published |
| Vanta, Drata, Secureframe, Sprinto | Neither, in the strict sense: built for SOC 2 and ISO 27001 audit readiness | Yes for security controls, which overlap ITGC substantially | Quote-led and annual-first |
| Spreadsheets and a shared drive | Whatever you have the discipline to maintain | Only if a person remembers to screenshot it every quarter | Free, until the first year of evidence has to be reconstructed |
Two honest notes on that table. Optro and Workiva are the right answer for a company with an internal audit function running a mature 404(b) program, and Complies will feel thin next to them; we are not going to pretend otherwise to win a search result. And the last row is not a joke: spreadsheets are genuinely fine for a pre-IPO company in its first year of control design, and they stop being fine the moment somebody has to produce four quarters of dated access reviews that were never actually run.
What Complies covers when SOX lands on an engineering team
Quarterly access reviews that leave a record
The most-sampled ITGC test is user access review. Complies pulls the current user list from Okta and Google Workspace, routes it to a named reviewer, and stores the dated sign-off with the decisions attached. What auditors reject is not the review, it is a screenshot with no reviewer and no date.
Change approvals straight from GitHub
Program change controls ask whether someone other than the author approved a change before it shipped. Pull request approvals and merge history answer that without anyone writing a memo, and the sample the auditor picks is already documented.
One control library across SOX, SOC 2 and ISO 27001
ITGC overlaps heavily with what SOC 2 and ISO 27001 already ask for. Access control is SOC 2 CC6.1, ISO 27001 A.5.15 and a SOX access-to-programs-and-data control at the same time. Map it once and it counts in all three, instead of running three evidence collections.
Obligations with a name and a date
Every recurring control becomes a row with an owner and a due date, chased on a calendar. This is the difference between a control that operated and a control you can prove operated, and in SOX only the second one counts.
Evidence collected before the year closes
SOX tests operating effectiveness across a period, not a moment. Evidence gathered on a schedule through the year survives that test; evidence assembled in the two weeks before fieldwork does not, because the gaps are visible in the timestamps.
A price you can read before a sales call
Starter is $79 a month, Growth $199, Scale $499, published. Every other platform on this page is quote-only, which for a pre-IPO team means a procurement cycle before you can even scope the work.
Standing up the ITGC layer before your first 10-K
Scope the systems that touch the numbers
List the systems that produce, transmit or store financial data, plus the infrastructure and identity layer underneath them. That list, not your whole estate, is your ITGC scope, and keeping it short is the single biggest cost control in a first-year program.
Connect identity, code and cloud
Point Complies at Okta or Google Workspace, GitHub and AWS. It reads configuration and access, not your customer data, and the first readiness view lands the same day rather than after an implementation project.
Give every ITGC control an owner and a cadence
Access reviews quarterly, change sampling continuously, operations checks monthly. Each becomes an obligation with a named human and a recurring due date, so the record builds through the year instead of being reconstructed from memory.
Export the period evidence for your auditor
When fieldwork starts, export the organized pack: who reviewed what and when, which changes were approved by whom, and which scheduled controls ran. Hand your external auditor dated records instead of a folder of screenshots.
Who this is for, and who it is not
A GOOD FIT WHEN
- You are pre-IPO and building the control environment before your first annual report.
- You are a newly public emerging growth company, exempt from 404(b) but still owing the 404(a) assessment.
- ITGC landed on an engineering or IT team that does not have an internal audit function to lean on.
- You already run SOC 2 or ISO 27001 and refuse to collect the same access and change evidence twice.
- You want the ITGC half handled at a published price while finance runs the process side elsewhere.
LOOK ELSEWHERE WHEN
- You are an accelerated or large accelerated filer running a mature 404(b) program with an internal audit team.
- You need a risk and control matrix, management testing workflow, or 302 and 404 certification sign-offs.
- You need journal entry testing or segregation of duties analysis inside an ERP like SAP, NetSuite or Oracle.
- You want SOX documentation to flow straight through into your SEC filing, which is what Workiva is for.
SOX compliance software questions buyers actually ask
SOX compliance software helps a company document, test and evidence the internal controls over financial reporting required by the Sarbanes-Oxley Act. In practice it does one or both of two jobs: managing the financial-process controls (risk and control matrix, testing workflow, certifications) or managing IT general controls (access, change and operations evidence). Most tools are noticeably stronger at one of the two, so match the tool to the half you are struggling with.
ITGC stands for IT general controls, the controls over the systems that produce financial data rather than over the transactions themselves. They group into three domains: access to programs and data, program change, and computer operations. Auditors test them first because if access and change controls are weak, no application-level control on top of them can be relied on, and the whole testing plan expands.
Section 404(a) is management's own annual assessment of internal control over financial reporting, and it applies to every filer from the second annual report onward. Section 404(b) is a separate attestation on those controls by your external auditor, and it only applies to accelerated and large accelerated filers. 404(b) is the expensive one, which is why filer status is the first thing to establish.
The 404 internal control requirements do not apply to private companies. Two caveats matter. The criminal provisions on document destruction and retaliation against whistleblowers apply to any company. And private companies preparing to go public, or expecting to be acquired by a filer, are routinely asked to demonstrate a SOX-ready control environment well before the first 10-K, which is why pre-IPO teams start early.
Not immediately, but the timing is tighter than it looks. Management's 404(a) report is required from your second annual report, and it has to cover a full period, so the controls need to be operating and evidenced well before the report is written. Companies that wait until after the IPO usually spend the first year reconstructing evidence for controls that were technically in place but never documented.
A workable SOX tool needs to hold the control set with owners and testing frequency, collect or store evidence against each control on a schedule, track deficiencies and remediation to closure, and produce a period record an external auditor can sample. For the ITGC half specifically, it needs integrations with your identity provider, code repository and cloud, otherwise evidence collection stays manual.
Access is the most heavily tested ITGC domain. A SOX program expects provisioning to be approved, access to match the role, privileged access to be restricted and monitored, leavers to be removed promptly, and the whole population to be reviewed periodically by someone accountable. The recurring deliverable is a dated user access review with a named reviewer, which auditors sample directly.
That changes to in-scope systems are authorized, tested and approved by someone other than the developer before reaching production, and that emergency changes get reviewed after the fact. Auditors pick a sample of production changes and ask for the approval that preceded each one. Teams already using pull request reviews usually satisfy this with evidence they are producing anyway.
Only for development that touches systems in financial reporting scope, and then it is the change control around the work rather than the coding itself. The practical requirements are separation between who writes and who approves, an environment split between development and production, restricted production deployment rights, and a record of approvals. Development outside that scope is unaffected.
SOX is US federal law governing internal control over financial reporting at public companies, enforced by the SEC. SOC 2 is a voluntary attestation about security and related criteria that companies obtain because customers ask for it. They are different in purpose but overlap heavily in the IT controls underneath, so access and change evidence collected for one usually serves the other.
It depends which half you need. For a mature program with an internal audit function, Optro (formerly AuditBoard) and Workiva are the established choices, and Pathlock if your risk concentrates in ERP access and segregation of duties. For a pre-IPO or newly public team where ITGC has landed on engineering, Complies covers access reviews, change approvals and operations evidence at a published price. Anyone claiming one tool is best for every filer has not asked what your filer status is.
The enterprise SOX platforms are quote-only, so no honest public number exists for them, and the total is usually driven by modules and user counts negotiated per deal. Complies publishes its full range at $79, $199 and $499 a month. Budget the external audit separately, because for an accelerated filer the 404(b) attestation fee is typically the largest line in the whole program.
Not yet, and not for everyone. The proposal issued on May 19, 2026 would raise the large accelerated filer threshold from $700 million of public float to $2 billion and limit 404(b) attestation to large accelerated filers, which the SEC estimates would exempt about 81 percent of public companies. The comment period closed July 20, 2026 and the rule has not been adopted, so current thresholds still apply and 404(a) is unaffected either way.
Frameworks and guides
SOC 2 compliance software
ISO 27001ISO 27001 compliance software
ACCESSUser Access Review: Process, Checklist, Frequency
GRCContinuous Control Monitoring Software and CCM Tools
CROSSWALKControl Mapping: SOC 2, ISO 27001, HIPAA, PCI DSS
CROSS-FRAMEWORKAudit Evidence Examples: What Auditors Actually Ask For
Run the ITGC half of SOX without an internal audit department
Prices published, $79 to $499 a month. Monthly billing. Start today, no sales call.