Section 302 certification, defined

Updated

Section 302 of the Sarbanes-Oxley Act requires a company's principal executive and financial officers — in practice the CEO and CFO — to personally certify each quarterly and annual report: that they reviewed it, that it is not materially misleading, and that disclosure controls and procedures are effective.

The certification is personal, recurring, and filed with the SEC alongside every 10-Q and 10-K. Because no two officers can personally verify every control in a company, §302 in practice drives two supporting structures: a sub-certification cascade that rolls assurance up from the people who actually run the controls, and a durable record of what the signers saw when they signed.

What Section 302 requires each quarter

Under §302 and the SEC rules implementing it, each certifying officer signs a prescribed set of statements with every quarterly and annual report. In substance, the officer certifies that:

The certifications are filed as exhibits to the report itself, so they are public, dated, and permanent. The language is largely fixed by rule — which means the substance of the exercise is not drafting the certification but being in a position to sign it honestly.

  • They have reviewed the report.
  • Based on their knowledge, it contains no untrue statement of a material fact and omits nothing needed to make it not misleading.
  • Based on their knowledge, the financial statements fairly present, in all material respects, the company's financial condition and results.
  • They are responsible for disclosure controls and procedures (and internal control over financial reporting), have designed them, evaluated their effectiveness as of period end, and presented their conclusions in the report.
  • They have disclosed to the auditors and the audit committee all significant deficiencies and material weaknesses in ICFR, and any fraud — material or not — involving management or others with a significant role in internal control.
  • They have indicated any change in ICFR during the period that has materially affected, or is reasonably likely to materially affect, it.

Who signs, and how §906 differs

The signers are the principal executive officer and principal financial officer — the CEO and CFO for almost every filer. The point of §302 is personal accountability: the officers cannot delegate the signature, and a certification later shown to be false exposes the signers personally to SEC enforcement. A companion provision, §906, adds a separate certification with criminal penalties for knowing or willful false certification. The two are often confused but are distinct requirements filed as distinct exhibits:

Section 302 vs Section 906 certifications
Section 302Section 906
What is certifiedReport reviewed; not misleading; fair presentation; disclosure controls and ICFR responsibilities, evaluation, and disclosuresReport complies with Exchange Act reporting requirements and fairly presents financial condition and results
Filed asExhibit 31 to the 10-Q or 10-KExhibit 32 to periodic reports containing financial statements
Enforcement regimeCivil — SEC enforcement against the certifying officersCriminal — penalties for knowing or willful false certification
Scope of statementsDetailed, prescribed clause by clause under SEC rulesShort, two-statement form under 18 U.S.C. § 1350

Sub-certification cascades

No CEO or CFO has personal knowledge of every control, account, and disclosure. Companies bridge that gap with sub-certifications: ahead of each filing, controllers, business-unit leaders, and IT and security owners certify their own areas — that their controls operated, that they know of no unreported deficiencies or fraud, that nothing material is missing from what they have reported upward. The officers then sign on top of a documented pyramid of assurance rather than on trust alone.

Cascades fail in predictable ways: sub-certifications become a quarterly rubber stamp nobody reads, the scope of what each person is certifying is never made explicit, and there is no record of what the sub-certifier actually reviewed before signing. A cascade that exists only as an email chain gives the officers a list of names, not a basis of assurance.

The durable-record problem

A §302 certification is a point-in-time personal attestation, but the questions about it arrive later — sometimes years later, in an SEC inquiry or litigation — and they are always the same: what did the signer know, what were they shown, and what was still open when they signed. If the answer has to be reconstructed from old email threads and meeting recollections, the certification stands on memory. A durable record answers structurally: what was presented to the signer, which exceptions and deficiencies were open at signing, and which sub-certifications the sign-off rested on.

What good looks like is running the §302 workflow as a recorded process rather than an email thread: the quarterly certification executed against a durable record of what each signer reviewed, on top of an append-only evidence trail and the deficiency state as of the signing date. When evaluating any tool or internal process for this, the questions that matter are whether it captures what was presented to the signer, which exceptions and deficiencies were open at signing, and which sub-certifications the sign-off rested on — and whether that record is still reproducible years later. The filing itself, and the judgment behind it, remain the officers' and counsel's; a sound process only makes the record of that judgment durable and retrievable.

Frequently asked questions

Who must sign the Section 302 certification?

The company's principal executive officer and principal financial officer — for nearly all filers, the CEO and the CFO. Each signs individually, the signature cannot be delegated, and the certifications are filed publicly as exhibits with every 10-Q and 10-K.

How often is a Section 302 certification required?

With every periodic report — each quarterly 10-Q and each annual 10-K. It is not an annual event: the officers re-certify the effectiveness of disclosure controls and the accuracy of the report every quarter.

What is the difference between Section 302 and Section 404?

§302 is the recurring quarterly certification by the CEO and CFO covering the report and disclosure controls. §404 is the annual management assessment of internal control over financial reporting, which for accelerated filers is also audited by the external auditor. §302 is an attestation workflow; §404 is a full assessment program.

What is a sub-certification?

An internal certification, not filed with the SEC, in which people below the officers — controllers, business-unit heads, IT owners — certify their own areas before each filing. The cascade gives the CEO and CFO a documented basis for their own §302 signature instead of unsupported trust.

What happens if a Section 302 certification turns out to be false?

The certifying officers are personally exposed: the SEC can bring enforcement actions against them under §302, and the parallel §906 certification carries criminal penalties for knowing or willful falsity. This personal exposure is why officers insist on sub-certification cascades and a record of what they were shown before signing.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.