Quick Summary
The SEC has proposed raising the large accelerated filer threshold from $700 million to $2 billion in public float, a change that would exempt significantly more companies from SOX 404(b) auditor attestation over internal controls. As market capitalization becomes a less reliable indicator of ICFR risk, companies should consider strengthening internal audit and governance-based assurance rather than reducing oversight.
Background
In May 2026, the SEC proposed several changes to simplify the current filer classifications for companies and investors to encourage more companies to go public. Currently, there are five statuses:
- Large Accelerated
- Accelerated
- Non-Accelerated
- Smaller Reporting Companies
- Emerging Growth Companies
The proposal simplifies the number of statuses to two:
- Large accelerated (>$2B in public float)
- Non-accelerated (<$2B in public float)
The proposal also changes various thresholds and requirements:
- Public Float Threshold — The threshold of a large accelerated filer would increase from $700M to $2B.
- Auditor’s Attestation over Internal Control over Financial Reporting (ICFR) — commonly referred to as SOX 404(b)
- Non-accelerated filers will not be required to obtain this attestation
- The estimated impact would change from 35% of current annual filers who obtain 404(b) attestation to 19%
- Management’s assertion of an effective control environment will still be required, commonly referred to as SOX 404(a)
- Public Float Calculation — This would change from being calculated on the last day of the second fiscal quarter to the average stock price over the last 10 trading days of the second fiscal quarter.
- Public Float Threshold (duration) — Must be met for two consecutive years as opposed to one year.
- 60 Month On-Ramp — Any new registrants would have 60 months of calendar reporting before being subject to the large accelerated filer requirements.
- Non-Accelerated Filer Accommodations
- No say-on-pay or say-when-on-pay shareholder advisory votes
- No pay versus performance disclosure
- Scaled executive compensation disclosure
- Fewer years of financial statements and reduced presentation requirements
- New Subcategory of Non-Accelerated Filer — Total assets of $35M or less will have additional 30 days to file 10-K and 5 additional days to file 10-Q.
Feedback from SEC Comment Letters
The SEC has received 160+ comments to the proposal. Focusing on the auditor’s attestation over ICFR and SOX 404(b), many commenters support efforts to simplify the filer framework, although opinions vary regarding the scope of the proposed expansion of the 404(b) exemption.
Comments Supporting the Exemption of Auditor’s Attestation of ICFR
- 404(b) imposes disproportionate compliance costs for smaller registrants or less complex companies
- Limited evidence of incremental value from 404(b) attestation, especially for less complex companies
- Current attestation discourages IPO activity
- Resources devoted to 404(b) compliance could be used to support growth instead
- External audit methodologies and testing approaches may not scale sufficiently to smaller companies, resulting in overly high costs
- The $700M threshold was established years ago and should be updated based on inflation and overall market growth
Comments Opposing the Breadth of the Exemption of Auditor’s Attestation of ICFR
- Weakened investor protection
- Diminished financial reporting quality, especially for smaller issuers
- 404(b) exemption may reduce incentives for timely remediation of deficiencies, resulting in longer periods of ineffective controls (Ge, Koester & McVay)
- Exempt issuers may experience higher restatement rates (GAO)
- Increasing technology complexity strengthens the case for ICFR
- Management assertion through 404(a) is not equivalent to independent testing
- The costs of 404(b), such as audit fees and management time, are generally easier to quantify than many of its benefits — such as avoided losses, improved control environments, fraud detection, increased investor confidence, lower cost of capital and fewer restatements
Comments on Modification of Auditor’s Attestation of ICFR
- Eliminate 404(b) but strengthen management’s 404(a) assessment
- For 404(b)-exempted companies, consider enhancing the roles of audit committees, internal audit and governance
- Substitute external audit assurance with enhanced internal audit assurance, such as formal internal audit requirements, fraud risk assessments and compliance with the Global Internal Audit Standards
- In addition to public float thresholds, consider the use of other risk criteria such as revenue, industry complexity, technology environment, international activity, prior material weakness, restatements, regulatory environment and acquisition activity
- Increase the threshold to an amount below $2B
- Add various triggers for 404(b) if a company reports material weakness, repeated deficiencies or significant restatements
Schneider Downs’ Viewpoint
Although the proposal is framed as a debate over regulatory burden, the more important question is: is market capitalization still the most effective measure for ICFR risk? In today’s environment, control risk is more often driven by complex technology ecosystems, acquisitions, evolving regulatory requirements, global operations, cybersecurity threats and prior control deficiencies. Organizations should assess assurance needs based on risk characteristics rather than just regulatory requirements.
Key Insights from Proposal and Comments
1. Company size may not be the most appropriate proxy for ICFR risk
Is public float still the right gauge to determine ICFR risk? Other risk criteria may be more indicative of ICFR risk, such as revenue, industry complexity, technology environment, international activity, prior material weakness, restatements, regulatory environment and acquisition activity.
2. Alternative assurance
If external ICFR assurance declines, boards and investors may continue to expect confidence in financial reporting. This may be addressed by additional audit committee oversight, internal audit functions, strengthened management assessments, third-party reviews or governance enhancements. Strong assurance structures will likely gain credibility with stakeholders.
3. Key questions for audit committees
- Is ICFR risk reflected by public float alone?
- If 404(b) no longer applies, what level of assurance do our stakeholders expect?
- What role should internal audit have?
Whether or not the proposal is adopted, companies should avoid treating diminished 404(b) requirements as an opportunity to dramatically reduce oversight. Rather, companies should determine how much independent assurance stakeholders expect. Companies with strong governance, mature control environments, and effective risk oversight will be better positioned to maintain investor confidence.
Internal Audit Role Under Proposed Changes
Even if regulatory assurance decreases, stakeholder expectations for independent assurance will not disappear. Internal Audit is well positioned to fill that assurance gap through ongoing, risk-based oversight of financial reporting, operational, technology and governance risks.
1. Internal Audit Can Still Provide Cost-Effective Independent Assurance
Even if exempt from auditor attestation, management, audit committees and investors may still need comfort over ICFR and rely on internal audit for:
- Control testing to support management’s 404(a) assessment
- Control deficiency evaluations
- Remediation support and validation
- Fraud risk assessment
- SOX program quality reviews
- Strong overall governance (through the COSO framework)
2. Reallocation of Internal Audit Resources
If 404(b) compliance needs are reduced, internal audit can reallocate those resources to provide assurance on not only financial reporting, but expand to cover a broader spectrum of business risks, including:
- Operational effectiveness
- Data quality and governance
- Compliance
- Cybersecurity
- Technology
- Strategic objectives
- Third party risk
- Automation
- Analytics
- Process improvements
- Emerging risks
- Enterprise risk management (ERM)
If the proposal is adopted and external assurance decreases, Internal Audit’s role may transition from compliance to a trusted provider of independent assurance and risk insight. Internal Audit’s mission has always been to enhance and protect organizational value by providing risk-based and objective assurance, advice and insight. The proposed changes could be a great opportunity for companies to strengthen their capabilities by reinvesting internal audit’s compliance efforts into strategic priorities.
If you have questions about refining your SOX approach or want to discuss how to strengthen your internal processes, reach out to the Schneider Downs team.
Key Takeaways
- What changes are proposed? SEC proposed increasing large accelerated filer status from $700M to $2B public float.
- Why does it matter? Significant reduction in the number of companies subject to SOX 404(b) attestation. The estimated impact would change from 35% of current annual filers who obtain 404(b) attestation to 19%.
- Potential benefit? Reduced compliance costs and reporting burden.
- Potential risk? Reduced assurance over financial reporting.
- Key takeaway? Market capitalization is becoming a less reliable indicator of ICFR risk.
- What should companies consider? Maintain voluntary ICFR assurance through Internal Audit and enhanced governance activities.
About Schneider Downs Risk Advisory
Our team of experienced risk advisory professionals focus on collaborating with your organization to identify and effectively mitigate risks. Our goal is to understand not only the risks related to potential loss to the organization, but to drive solutions that add value to your organization and advise on opportunities to ensure minimal disruption to your business.
Explore our full Risk Advisory Services offerings or contact the team.
Related Posts
- Strengthen SOX Compliance: SOX IT General Controls and System-Dependent Controls
- Strengthen SOX Compliance: Balancing a Risk-Based SOX Program with External Auditor Needs
- Strengthen SOX Compliance: Assessing the Risk Materiality of AI Enablement
- Strengthen SOX Compliance: Implementing Continuous Auditing