Complies

ITGC · SOX 404 · EVIDENCE

SOX compliance software: Sarbanes Oxley software, SOX compliance tools and internal controls software for the ITGC half of SOX 404

Most of what a SOX 404 program asks an engineering team for is access reviews, change approvals and evidence with dates on it. That part you can run from the day you decide to go public.

See pricing

From $79/mo · Prices published · No sales call · Monthly billing

SOC 2 · TRUST SERVICES CRITERIA

Audit readiness

0 %

Your auditor makes the final call

Built for teams of 5 to 200

AWS GitHub Google Workspace Slack Jira Azure Okta
SOX

What SOX compliance software is, and the split that decides which one you buy

SOX compliance software helps a company document, test and evidence the internal controls over financial reporting that the Sarbanes-Oxley Act requires, and the category splits cleanly in two. One half is the financial-process side: the risk and control matrix, management testing workflow, walkthrough documentation, journal entry testing, segregation of duties inside your ERP, and the 302 and 404 certification sign-offs. That is what Optro (the platform formerly called AuditBoard, which redirected auditboard.com to optro.ai after its March 2026 rebrand), Workiva and Pathlock are built for, and if you run a real internal audit function you should buy one of them. The other half is IT general controls, usually shortened to ITGC: who has access to the systems that produce the numbers, how code and configuration changes get approved before they reach production, and whether backups and jobs actually ran. ITGC is where most first-year SOX programs lose time, because the evidence lives in Okta, GitHub, AWS and your ticketing system rather than in the finance close. Complies covers that ITGC half for teams of 5 to 200: quarterly user access reviews with named reviewers, change approvals pulled from GitHub, cloud configuration evidence from AWS, and every obligation carrying an owner and a due date, at published prices of $79 to $499 a month. It does not do the financial-process half, and this page says so in the table below rather than burying it. Two facts change who needs what. SOX 404(a), the management assessment, applies to every filer from its second annual report onward, so a newly public company gets one 10-K of grace and no more. SOX 404(b), the external auditor attestation, only applies to accelerated and large accelerated filers, and emerging growth companies are exempt for up to five years after IPO. On May 19, 2026 the SEC proposed raising the large accelerated filer threshold from $700 million of public float to $2 billion and limiting 404(b) to large accelerated filers alone, which by the SEC's own estimate would exempt roughly 81 percent of public companies. The comment period closed on July 20, 2026 and the proposal has not been adopted, so plan against today's rules and watch that docket.

Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.

Last updated August 2026

ACCESS · CHANGE · OPERATIONS

The three ITGC domains an auditor tests, and where the evidence actually comes from

01

Access to programs and data

Who can reach the systems behind the financial statements, whether their access still matches their job, and whether leavers were removed on time. The test is almost always a quarterly user access review with a named reviewer and a dated sign-off. Complies pulls the user list from Okta and Google Workspace, assigns the review, and keeps the completed record instead of the screenshot someone saved to a laptop.

automated evidence collection
02

Program change

Whether changes to in-scope systems were reviewed, approved and tested by somebody other than the person who wrote them. Auditors sample changes and ask to see the approval that preceded the deploy. Pull request approvals and merge history from GitHub answer that directly, which is why change management is usually the cheapest ITGC domain to automate and the most embarrassing one to fail.

control mapping software
03

Computer operations

Whether scheduled jobs, backups and monitoring ran, and what happened when they did not. This is the domain most teams under-document, because the systems do the work reliably and nobody keeps the proof. Complies holds each operational control as an obligation with an owner and a recurring due date, so the record exists before the auditor asks for a year of it at once.

obligation tracking software
COMPARE

Who has to do what under SOX 404, including the change the SEC proposed in May 2026

The single question that decides how much SOX program you need is your filer status, and almost no vendor page states it plainly. Section 404(a) is management's own assessment of internal control over financial reporting. Section 404(b) is the external auditor's separate attestation on that control environment, and it is the expensive one. Here is who owes which today, and what the SEC has proposed changing. Everything in this table is read from SEC rules and the May 2026 proposing release rather than from a vendor summary.

Filer category Public float and revenue test SOX 404(a) management assessment SOX 404(b) auditor attestation
Large accelerated filer Public float of $700 million or more Required Required
Accelerated filer Float of $75 million to under $700 million, with annual revenue of $100 million or more Required Required
Non-accelerated filer Float under $75 million, or float under $700 million with revenue under $100 million Required Exempt
Emerging growth company Up to five years after IPO, while revenue stays under $1.235 billion and float under $700 million Required Exempt for the EGC window
Any filer, first annual report The first 10-K filed after going public, whatever the float Not required until the second annual report Not required until the second annual report
Proposed: large accelerated filer Float of $2 billion or more, plus 60 months of seasoning Required if adopted Required if adopted
Proposed: non-accelerated filer Everyone else, about 81 percent of public companies by the SEC estimate Required if adopted Exempt if adopted

Read the last two rows carefully, because they are a proposal and not the law. The SEC issued the filer status overhaul on May 19, 2026 and the comment period closed on July 20, 2026; nothing has been adopted, and until it is, the first five rows govern. The practical planning point is unchanged either way: 404(a) never goes away for anyone, so the management assessment and the ITGC evidence behind it are work you will do regardless of which way the docket lands. Compare the enterprise end of this market in detail on AuditBoard alternatives, Hyperproof alternatives and MetricStream alternatives.

FINANCIAL PROCESS OR ITGC

SOX compliance software compared on which half of SOX 404 it actually covers

Roundups in this category list ten vendors and grade them on the same feature checklist, which hides the only distinction that matters: whether a tool works the financial-process side of SOX or the IT general controls side. Very few do both well, and buying the wrong half is the common expensive mistake. Below is what each vendor states in its own material as of August 2026, read first-hand. Where no rate card is published we say so rather than repeating a third-party estimate as fact.

Vendor Which half of SOX it serves Covers ITGC evidence Published pricing (August 2026)
Complies ITGC only: access reviews, change approvals, operations evidence, obligations with owners Yes, pulled from Okta, GitHub, AWS and Google Workspace on a schedule Published: $79, $199 and $499 a month at the yearly rate
Optro (formerly AuditBoard) Both, built around the financial-process side: RCM, testing workflow, issue tracking, certifications Yes, as part of a full enterprise GRC and internal audit suite Quote-only, no figures published
Workiva Financial process, tied through to the SEC filing itself Partially, as documentation rather than automated collection Quote-only, no figures published
Pathlock Financial process, specifically ERP access governance and segregation of duties Deep inside SAP and other ERPs, narrow outside them No public rate card for the platform
Hyperproof Controls and evidence across frameworks, with SOX as one of them Yes, through integrations and control mapping Quote-only, no figures published
Vanta, Drata, Secureframe, Sprinto Neither, in the strict sense: built for SOC 2 and ISO 27001 audit readiness Yes for security controls, which overlap ITGC substantially Quote-led and annual-first
Spreadsheets and a shared drive Whatever you have the discipline to maintain Only if a person remembers to screenshot it every quarter Free, until the first year of evidence has to be reconstructed

Two honest notes on that table. Optro and Workiva are the right answer for a company with an internal audit function running a mature 404(b) program, and Complies will feel thin next to them; we are not going to pretend otherwise to win a search result. And the last row is not a joke: spreadsheets are genuinely fine for a pre-IPO company in its first year of control design, and they stop being fine the moment somebody has to produce four quarters of dated access reviews that were never actually run.

CAPABILITIES

What Complies covers when SOX lands on an engineering team

Quarterly access reviews that leave a record

The most-sampled ITGC test is user access review. Complies pulls the current user list from Okta and Google Workspace, routes it to a named reviewer, and stores the dated sign-off with the decisions attached. What auditors reject is not the review, it is a screenshot with no reviewer and no date.

Change approvals straight from GitHub

Program change controls ask whether someone other than the author approved a change before it shipped. Pull request approvals and merge history answer that without anyone writing a memo, and the sample the auditor picks is already documented.

One control library across SOX, SOC 2 and ISO 27001

ITGC overlaps heavily with what SOC 2 and ISO 27001 already ask for. Access control is SOC 2 CC6.1, ISO 27001 A.5.15 and a SOX access-to-programs-and-data control at the same time. Map it once and it counts in all three, instead of running three evidence collections.

Obligations with a name and a date

Every recurring control becomes a row with an owner and a due date, chased on a calendar. This is the difference between a control that operated and a control you can prove operated, and in SOX only the second one counts.

Evidence collected before the year closes

SOX tests operating effectiveness across a period, not a moment. Evidence gathered on a schedule through the year survives that test; evidence assembled in the two weeks before fieldwork does not, because the gaps are visible in the timestamps.

A price you can read before a sales call

Starter is $79 a month, Growth $199, Scale $499, published. Every other platform on this page is quote-only, which for a pre-IPO team means a procurement cycle before you can even scope the work.

HOW TO START

Standing up the ITGC layer before your first 10-K

01

Scope the systems that touch the numbers

List the systems that produce, transmit or store financial data, plus the infrastructure and identity layer underneath them. That list, not your whole estate, is your ITGC scope, and keeping it short is the single biggest cost control in a first-year program.

02

Connect identity, code and cloud

Point Complies at Okta or Google Workspace, GitHub and AWS. It reads configuration and access, not your customer data, and the first readiness view lands the same day rather than after an implementation project.

03

Give every ITGC control an owner and a cadence

Access reviews quarterly, change sampling continuously, operations checks monthly. Each becomes an obligation with a named human and a recurring due date, so the record builds through the year instead of being reconstructed from memory.

04

Export the period evidence for your auditor

When fieldwork starts, export the organized pack: who reviewed what and when, which changes were approved by whom, and which scheduled controls ran. Hand your external auditor dated records instead of a folder of screenshots.

FIT

Who this is for, and who it is not

A GOOD FIT WHEN

  • You are pre-IPO and building the control environment before your first annual report.
  • You are a newly public emerging growth company, exempt from 404(b) but still owing the 404(a) assessment.
  • ITGC landed on an engineering or IT team that does not have an internal audit function to lean on.
  • You already run SOC 2 or ISO 27001 and refuse to collect the same access and change evidence twice.
  • You want the ITGC half handled at a published price while finance runs the process side elsewhere.

LOOK ELSEWHERE WHEN

  • You are an accelerated or large accelerated filer running a mature 404(b) program with an internal audit team.
  • You need a risk and control matrix, management testing workflow, or 302 and 404 certification sign-offs.
  • You need journal entry testing or segregation of duties analysis inside an ERP like SAP, NetSuite or Oracle.
  • You want SOX documentation to flow straight through into your SEC filing, which is what Workiva is for.
QUESTIONS

SOX compliance software questions buyers actually ask

SOX compliance software helps a company document, test and evidence the internal controls over financial reporting required by the Sarbanes-Oxley Act. In practice it does one or both of two jobs: managing the financial-process controls (risk and control matrix, testing workflow, certifications) or managing IT general controls (access, change and operations evidence). Most tools are noticeably stronger at one of the two, so match the tool to the half you are struggling with.

ITGC stands for IT general controls, the controls over the systems that produce financial data rather than over the transactions themselves. They group into three domains: access to programs and data, program change, and computer operations. Auditors test them first because if access and change controls are weak, no application-level control on top of them can be relied on, and the whole testing plan expands.

Section 404(a) is management's own annual assessment of internal control over financial reporting, and it applies to every filer from the second annual report onward. Section 404(b) is a separate attestation on those controls by your external auditor, and it only applies to accelerated and large accelerated filers. 404(b) is the expensive one, which is why filer status is the first thing to establish.

The 404 internal control requirements do not apply to private companies. Two caveats matter. The criminal provisions on document destruction and retaliation against whistleblowers apply to any company. And private companies preparing to go public, or expecting to be acquired by a filer, are routinely asked to demonstrate a SOX-ready control environment well before the first 10-K, which is why pre-IPO teams start early.

Not immediately, but the timing is tighter than it looks. Management's 404(a) report is required from your second annual report, and it has to cover a full period, so the controls need to be operating and evidenced well before the report is written. Companies that wait until after the IPO usually spend the first year reconstructing evidence for controls that were technically in place but never documented.

A workable SOX tool needs to hold the control set with owners and testing frequency, collect or store evidence against each control on a schedule, track deficiencies and remediation to closure, and produce a period record an external auditor can sample. For the ITGC half specifically, it needs integrations with your identity provider, code repository and cloud, otherwise evidence collection stays manual.

Access is the most heavily tested ITGC domain. A SOX program expects provisioning to be approved, access to match the role, privileged access to be restricted and monitored, leavers to be removed promptly, and the whole population to be reviewed periodically by someone accountable. The recurring deliverable is a dated user access review with a named reviewer, which auditors sample directly.

That changes to in-scope systems are authorized, tested and approved by someone other than the developer before reaching production, and that emergency changes get reviewed after the fact. Auditors pick a sample of production changes and ask for the approval that preceded each one. Teams already using pull request reviews usually satisfy this with evidence they are producing anyway.

Only for development that touches systems in financial reporting scope, and then it is the change control around the work rather than the coding itself. The practical requirements are separation between who writes and who approves, an environment split between development and production, restricted production deployment rights, and a record of approvals. Development outside that scope is unaffected.

SOX is US federal law governing internal control over financial reporting at public companies, enforced by the SEC. SOC 2 is a voluntary attestation about security and related criteria that companies obtain because customers ask for it. They are different in purpose but overlap heavily in the IT controls underneath, so access and change evidence collected for one usually serves the other.

It depends which half you need. For a mature program with an internal audit function, Optro (formerly AuditBoard) and Workiva are the established choices, and Pathlock if your risk concentrates in ERP access and segregation of duties. For a pre-IPO or newly public team where ITGC has landed on engineering, Complies covers access reviews, change approvals and operations evidence at a published price. Anyone claiming one tool is best for every filer has not asked what your filer status is.

The enterprise SOX platforms are quote-only, so no honest public number exists for them, and the total is usually driven by modules and user counts negotiated per deal. Complies publishes its full range at $79, $199 and $499 a month. Budget the external audit separately, because for an accelerated filer the 404(b) attestation fee is typically the largest line in the whole program.

Not yet, and not for everyone. The proposal issued on May 19, 2026 would raise the large accelerated filer threshold from $700 million of public float to $2 billion and limit 404(b) attestation to large accelerated filers, which the SEC estimates would exempt about 81 percent of public companies. The comment period closed July 20, 2026 and the rule has not been adopted, so current thresholds still apply and 404(a) is unaffected either way.

GO DEEPER

Frameworks and guides

Run the ITGC half of SOX without an internal audit department

Prices published, $79 to $499 a month. Monthly billing. Start today, no sales call.