Business professionals collaborating in a modern office meeting with a laptop discussing corporate strategy

SEC Filer Status Proposal Would Narrow 404(b), Retain 404(a) 

7/22/2026

The SEC’s proposed filer status reforms could exempt many public companies from obtaining external auditor attestation on ICFR. However, management’s responsibility for effective internal control, executive certifications, and reliable financial reporting would remain unchanged.

In under a minute

On May 19, 2026, the Securities and Exchange Commission (SEC) proposed amendments that would expand the number of public companies classified as nonaccelerated filers (NAFs). If adopted, the proposal would exempt many companies from obtaining external auditor attestation on internal control over financial reporting (ICFR) under Sarbanes-Oxley Act (SOX) Section 404(b) through increasing the public float threshold that triggers auditor ICFR attestation to $2 billion and providing a five-year exemption from auditor attestation on ICFR for all newly public companies.

The proposal could reduce compliance costs for many issuers, but key management responsibilities would remain unchanged, including:

  • Establishing and maintaining adequate ICFR
  • Assessing ICFR effectiveness annually under SOX 404(a), generally beginning with the second Form 10-K after becoming public
  • Disclosing and remediating material weaknesses
  • Supporting CEO and CFO certifications under SOX Sections 302 and 906
  • Executing audit committee oversight of financial reporting

Based on the SEC filer status proposal, the practical question for management teams is not whether controls still matter. It is how to establish and maintain adequate ICFR upon becoming a public company, preserve sufficient evidence for management’s ICFR assessment under SOX Section 404(a), support executive certifications, and allow for sufficient audit committee oversight.

What the SEC filer status proposal would change

The proposal would simplify SEC filer categories to two primary categories: large accelerated filers (LAFs) and NAFs. It also would increase the LAF public float threshold to $2 billion from $700 million and establish a subcategory of small NAFs with additional time to file annual and quarterly reports.

Two provisions determine how a company moves between categories:

  • Newly public companies: Regardless of public float, a company would be exempt from LAF status for five years after becoming subject to Securities Exchange Act of 1934 reporting requirements. Because attestation is tied to LAF status, this on-ramp also means there is no ICFR auditor attestation requirement under 404(b) during that period.
  • Established companies: A company’s public float would need to meet, exceed, or fall below the $2 billion threshold for two consecutive years before it transitions into or out of LAF status. A single year’s fluctuation would not change filer status.

Together, these proposed provisions give companies more time to transition into or out of external auditor attestation requirements based on changes in market capitalization, growth, acquisitions, divestitures, or broader market conditions.

According to the proposal, the amendments would expand by 26.7% the number of current registrants that would not be subject to an ICFR auditor attestation requirement.

Public company reporting risks remain

Public companies operate under a heightened standard of transparency. Investors, regulators, lenders, analysts, boards of directors, and other stakeholders rely on periodic filings to make capital allocation and governance decisions.

When financial reporting contains material errors, omissions, or misstatements, the consequences can extend well beyond restoring compliance: restatements, regulatory inquiries, shareholder litigation, reputational damage, increased cost of capital, management distraction, loss of investor confidence, and personal liability for CEOs and CFOs. None of these change with the SEC proposal.

Crowe observation: All companies still must maintain documentation of controls sufficient to support management’s own 404(a) assessment. Because filer status can shift with public float, companies near the proposed $2 billion public float threshold should watch for fluctuations in public float that could affect their requirements under 404(b). Advance discussions with internal control specialists can guide a company’s transition planning for auditor attestation under 404(b) and reduce the risk of transition surprises.

Management responsibility for ICFR remains foundational

Under Regulation S-K Item 308, management’s annual report on ICFR must describe management’s responsibility for establishing and maintaining adequate ICFR, identify the framework used to evaluate ICFR, and provide management’s assessment of ICFR effectiveness.

Management may not conclude that ICFR is effective if one or more material weaknesses exist. As a result, management must continue to develop and maintain evidence supporting its assessment of internal control effectiveness, regardless of whether an external auditor is required to issue a separate ICFR opinion.

Crowe observation: External auditor attestation provides an additional layer of independent assurance. Even if external auditor attestation requirements are reduced, management remains accountable for maintaining an effective control environment and providing reliable disclosures.

Executive certifications raise the stakes

SOX Sections 302 and 906 require principal executive and financial officers to certify periodic reports filed with the SEC. Section 302 requires CEOs and CFOs to certify, among other matters, that they are responsible for establishing and maintaining internal controls, have evaluated the effectiveness of those controls, and have disclosed material weaknesses and significant control deficiencies.

Section 906 requires CEOs and CFOs to certify that each periodic report containing financial statements complies with the Securities Exchange Act of 1934 and that the financial information fairly presents, in all material respects, the company’s financial condition and results of operations.

These certifications are not merely procedural. They represent direct executive accountability for the accuracy and completeness of financial reporting. For CEOs and CFOs, the control environment serves as critical infrastructure supporting their ability to certify that filings are complete, accurate, and not misleading.

Weak controls can quickly become governance and disclosure concerns and can increase personal liability risk for executives when material information is omitted or reported inaccurately.

AI and automation add new reporting risks

AI, automation, and advanced analytics can improve financial reporting efficiency, but they also introduce risks related to data quality, model governance, access, change management, and human review. Those risks can affect controls when AI-supported outputs are used in account analyses, forecasting, reconciliations, disclosure preparation, or management reviews.

Management needs a disciplined process for identifying where automated outputs are used, validating the completeness and accuracy of the underlying data, and retaining evidence of review.

Crowe observation: As AI adoption accelerates, companies should consider whether their existing ICFR framework adequately addresses emerging risks associated with automated decision-making, data lineage, model governance, and information used in performing a control.

Companies considering going public should not delay control readiness

The responsibility to produce reliable financial information begins immediately upon becoming a public company. Although newly public companies generally receive a transition period before management must formally assess ICFR effectiveness, companies considering an IPO should work toward establishing a SOX-capable system of internal controls before beginning the offering process. Section 13(b)(2) of the Securities Exchange Act of 1934, which applies upon completion of an IPO, requires public issuers to maintain accurate books and records and a system of internal accounting controls sufficient to provide reasonable assurance that transactions are properly authorized, recorded, and accounted for.

Delaying creation of a SOX-capable system of internal controls creates avoidable risks as the offering approaches, including undocumented controls, insufficient evidence, immature review processes, segregation-of-duties conflicts, unremediated deficiencies, and resource constraints. Material weaknesses discovered in the lead up to an IPO typically are disclosed in the offering documents. Building a SOX-capable system of internal controls early allows for timely identification and remediation instead.

Crowe observation: Companies that build a SOX-capable control environment early often experience a smoother transition to public-company reporting. Establishing governance structures, documentation standards, evidence retention practices, and management review controls before they become mandatory can reduce remediation costs and avoid resource-intensive catch-up efforts later.

What comes next

The SEC’s proposed filer status reforms remain subject to public comment and have not yet been adopted. Final rules could be adopted as proposed, modified, or not adopted at all.

Regardless of the outcome, public companies should continue evaluating the effectiveness of their internal control environments and how they obtain assurance over financial reporting risks. Management remains responsible for ICFR, executives remain responsible for certifications, audit committees remain responsible for oversight, and investors continue to expect reliable financial information. A reduced auditor attestation requirement might change the nature of compliance, but it does not change accountability.

Navigate changing SEC reporting requirements with confidence


Our professionals can help you evaluate the potential impact of the SEC’s proposed filer status reforms and strengthen your internal control and reporting strategy.

Lori Wilson Charlebois
Lori W. Charlebois
Partner, Consulting,
Crowe Advisory LLC
Paul Elggren
Paul Elggren
Partner, Consulting,
Crowe Advisory LLC
Justin Mahoney
Justin Mahoney
Senior Manager, Consulting,
Crowe Advisory LLC

Related insights

loading gif
Business professionals discuss cyber resilience and navigating an evolving threat landscape.
Cyber Resilience Priorities for a Complex Threat Landscape
Crowe cyber specialists discuss why cyber resilience is a critical business priority for meeting the challenges of an accelerating threat landscape.
Business professionals collaborating during a strategic meeting, discussing business planning, leadership, and organizational goals.
EBSA Cybersecurity Guidance for Retirement Plan Committees
Explore practical guidance to help retirement plan committees strengthen cybersecurity oversight and support prudent fiduciary governance.
Crowe specialist discusses proposed regulations affecting the Section 250 deduction.
Section 250 Sale Exclusion Proposed Rules
Recently issued proposed regulations would clarify the rules for the DEI exclusion under OBBBA changes to the Section 250 deduction.
Business professionals discuss cyber resilience and navigating an evolving threat landscape.
Cyber Resilience Priorities for a Complex Threat Landscape
Crowe cyber specialists discuss why cyber resilience is a critical business priority for meeting the challenges of an accelerating threat landscape.
Business professionals collaborating during a strategic meeting, discussing business planning, leadership, and organizational goals.
EBSA Cybersecurity Guidance for Retirement Plan Committees
Explore practical guidance to help retirement plan committees strengthen cybersecurity oversight and support prudent fiduciary governance.
Crowe specialist discusses proposed regulations affecting the Section 250 deduction.
Section 250 Sale Exclusion Proposed Rules
Recently issued proposed regulations would clarify the rules for the DEI exclusion under OBBBA changes to the Section 250 deduction.