SOX 302/906: The CEO Certification That Can Send You to Prison
The CEO's name is on every Form 10-Q and 10-K certification. Section 302 is civil. Section 906 is criminal: up to $5 million in fines and 20 years in prison for a willful false certification. Jerry Dale Cash already drew 9 years.
In brief: SOX Section 302 makes the CEO personally responsible for the accuracy of every financial report filed with the SEC. Section 906 adds criminal penalties: up to $1 million and 10 years prison for knowing violations, $5 million and 20 years for willful ones. Jerry Dale Cash, former CEO of Quest Resource Corporation, was sentenced in 2010 to 108 months (9 years) in federal prison for a false SOX certification (later reduced to 39 months in 2013). The CEO signs the document. The CEO is the defendant. A versioned, four-eyes-approved definition record for the terms in MD&A and financial statements is one concrete controls-over-disclosure-process artifact the CEO can point to.
Why the CEO is the one in the charge sheet
Most securities regulation is written against the company. Sarbanes-Oxley is not. Section 302 names the CEO and CFO individually as the certifying officers. Section 906 attaches criminal liability — with statutorily defined prison terms — to the act of signing.
The operative statutory text is direct. 15 U.S.C. § 7241 (Section 302) requires the CEO and CFO to personally certify review, absence of material misstatements, and responsibility for internal controls. 18 U.S.C. § 1350 (Section 906) imposes the criminal penalties: $1,000,000 and ten years for a knowing violation (§ 1350(c)(1)); $5,000,000 and twenty years for a willful violation (§ 1350(c)(2)). Implementation under SEC Rule 13a-14.
Read together, the structure is plain. The CEO certifies the report and the internal control structure. If that certification is knowingly false, a 10-year ceiling applies. Willfully false, the ceiling is 20 years. The defendant is the CEO, not the company.
Nine years, federal prison: the named case
The precedent most CEOs either do not know or choose not to think about is Jerry Dale Cash, the former CEO of Quest Resource Corporation. Cash was sentenced on November 12, 2010 to 108 months (9 years) in federal prison for a false Sarbanes-Oxley certification (FBI Oklahoma City press release). The sentence was later reduced to 39 months in a 2013 post-conviction proceeding, but the published record stands: a CEO was sentenced to nine years for a SOX 906 violation.
The statute reads like a headline — twenty years, five million dollars — but the realized outcome has already been a multi-year federal sentence for a single named executive. Prosecutors have used the certification, and judges have imposed sentences.
What this costs the CEO personally
Statutory personal exposure:
- SOX Section 906, knowing: up to $1 million in fines and 10 years in prison.
- SOX Section 906, willful: up to $5 million in fines and 20 years in prison.
- SOX Section 302: civil responsibility for the accuracy, documentation, and submission of all financial reports and the internal control structure to the SEC.
- Realized sentence: Jerry Dale Cash, former CEO of Quest Resource Corporation — sentenced Nov 12, 2010 to 108 months (9 years) federal prison for a false SOX certification; reduced to 39 months in a 2013 post-conviction proceeding.
- Cadence: the certification is filed every quarter with Form 10-Q and annually with Form 10-K. The exposure recurs on the SEC filing calendar.
The civil track adds the SEC's officer-and-director bar tool kit, disgorgement, and shareholder derivative litigation on top of the criminal track. D&O policies typically advance defense costs but do not indemnify a final criminal judgment — a CEO's personal assets are exposed once the criminal conduct is adjudicated. An SEC charge against a CEO is also a disclosable, press-release-level event that often ends the CEO's tenure regardless of the final outcome.
The board meeting question
Every audit committee chair who has done the job for a cycle asks the same question before the 10-K certification is signed: what has changed in our disclosure process, and how do you know your certifications are still supportable? The CEO who answers "I think we are fine" lost the room before the sentence ended.
The answers the audit committee wants are concrete: the disclosure controls were tested on this date, the MD&A terminology was reviewed and approved on this date, material-weakness remediation tracked through these approvals. Every item is a document, a log, or a versioned record. A CEO who produces those artifacts on demand can certify with a clean conscience. A CEO who cannot is the CEO whose name will be on the charge sheet if the reviewers find something the process missed.
The private-company path to the same exposure
SOX 302 and 906 apply to US-listed public companies. An EU-domiciled issuer on NASDAQ or NYSE is in scope — domicile does not shield the CEO. Pre-IPO private companies are out of scope for the SOX certification itself, but the CEO is not insulated from equivalent criminal exposure. SEC Rule 10b-5 securities-fraud enforcement reaches private-placement materials and investor communications, and DOJ has shown it will bring parallel criminal charges. The Joonko (Ilit Raz) and Nate Inc. (Albert Saniger) AI-washing prosecutions both ran through the private-company path, with the same 20-years-per-count criminal ceiling as a SOX 906 willful violation. For a CEO raising venture capital, the statute just changes name.
How terminology governance helps — and what it does not do
Compliance Glossary for Confluence is not a SOX program. It does not replace ICFR, the disclosure-controls framework, or the work done with the external auditor. What it is: a time-stamped, four-eyes-approved, version-controlled record of terminology that appears in the MD&A, the financial statements, and the footnotes. In SOX 302 taxonomy that record sits under "controls over the disclosure process." When a certification is challenged, the question a prosecutor or plaintiff's expert asks is: what evidence exists that the certifying officer exercised reasonable care over the language filed? A versioned governance record is one of the answers.
- Four-eyes approval. Every financial or disclosure term — "material weakness", "ICFR", "reasonable assurance", "significant deficiency", internal segment and non-GAAP labels — moves from draft to approved only with a second named signer. Submitter cannot be approver.
- Version history. Every definition carries a full audit trail of who edited what, when, and why. When a reviewer asks how a term was defined on the date of a historical filing, the record is the answer.
- Audit trail with timestamps. Every write operation generates a dated, attributable entry before the change is committed, so the sequence of decisions is preserved.
- Compliance scanner. Deterministic regex scanning flags where Confluence pages use a deprecated variant or a synonym for an approved disclosure term. This closes the loop between the approved definition and the language that reaches the filing.
- CSV export with full version history (PDF audit-package export on the 2026 roadmap). Full term set, approvals, and versions exported on demand for audit committee reviews, external auditor requests, or SEC inquiries.
No SOX pack ships pre-loaded — the SOX disclosure vocabulary is specific to each issuer's filings, so the company defines and approves its own terms inside the governance workflow.
None of this guarantees a zero-prosecution outcome. It is not a legal shield. It is a reasonable-care artifact — one of the records a disciplined disclosure process produces and one of the records a CEO's defense counsel asks for on day one of any certification challenge.
The economics
For current pricing, see the Atlassian Marketplace.
Frequently asked questions
What are SOX Section 302 and Section 906?
Section 302 of the Sarbanes-Oxley Act makes the CEO and CFO directly responsible for the accuracy, documentation, and submission of all financial reports and the internal control structure to the SEC. Section 906 is the criminal companion: the CEO and CFO sign a certification that is filed with every periodic report. Knowing false certification carries up to $1 million in fines and 10 years in prison. Willful false certification carries up to $5 million and 20 years.
Has a CEO actually gone to prison for a false SOX certification?
Yes. Jerry Dale Cash, former CEO of Quest Resource Corporation, was sentenced on November 12, 2010 to 108 months (9 years) in federal prison for a false Sarbanes-Oxley certification, per the FBI Oklahoma City press release. The sentence was later reduced to 39 months in a 2013 post-conviction proceeding, but the published record stands: a CEO was sentenced to nine years for a SOX 906 violation. The 20-year willful-violation ceiling is statutory and has been used.
Does SOX apply to a pre-IPO or EU-domiciled company?
SOX Sections 302 and 906 apply to US-listed public companies, including EU-domiciled issuers listed on NASDAQ or NYSE. Pre-IPO private companies are not in scope for the SOX certification itself, but the CEO still faces SEC Rule 10b-5 securities fraud exposure for similar misrepresentations in private placement materials. The Joonko and Nate AI-washing cases show the private-company route to the same criminal exposure.
Does Compliance Glossary replace a SOX program?
No. Compliance Glossary does not replace ICFR, disclosure controls, or the SOX audit program run with your external auditor. What it does is produce a time-stamped, four-eyes-approved, version-controlled record of the financial and disclosure terminology the management body has formally endorsed. That record is one component of the controls-over-the-disclosure-process artifact and a reasonable-care indicator if a certification is ever challenged.
Install the governance artifact before the next 10-Q signature
For current pricing, see the Atlassian Marketplace.
Evaluate in Confluence Read the Security WhitepaperRelated reading
- Compliance for Confluence — approved terms, page scanning, and audit evidence for CEO-level compliance oversight in Confluence
- AI-washing: the CEO's criminal exposure — Saniger, Raz, and the private-company path to the same 20-year ceiling
- AI securities class actions: the CEO named defendant — 53 AI SCAs since 2020, CEOs named individually
- NIS2 Article 32: when a court can suspend the CEO — sibling EU personal-liability exposure
- Security Whitepaper — Forge architecture, data-residency, and audit posture