June 29, 2026 · 4 min read · The RegFile team

Who can certify the OSHA 300A annual summary?

The OSHA 300A annual summary must be certified by a company executive before it is posted or submitted. In practice, that means the signer should be an owner, corporate officer, highest-ranking official at the establishment, or that official's immediate supervisor.

The certification is more than permission to file. Under 29 CFR 1904.32, the executive is saying they examined the OSHA 300 Log and reasonably believe the annual summary is correct and complete based on how the information was recorded.

Who OSHA allows to sign

OSHA's rule lists four categories of company executive:

  • An owner of the company, if the company is a sole proprietorship or partnership
  • An officer of the corporation
  • The highest-ranking company official working at the establishment
  • The immediate supervisor of the highest-ranking company official working at the establishment

For a single-site business, this is usually straightforward: the owner, president, plant manager, general manager, or another senior on-site leader can fit the rule.

For a multi-site company, the answer can vary by establishment. A corporate EHS manager can prepare the records, but the certification should still come from a person who fits one of OSHA's executive categories for that establishment or supervises that person.

What the signer is certifying

The signer is not certifying that no injuries happened. They are certifying that the 300A summary reflects the OSHA 300 Log after a reasonable review.

Before signing, the executive should be able to answer:

  • Does the summary cover the correct calendar year?
  • Do the totals match the OSHA 300 Log?
  • Were recordable cases classified consistently?
  • Are average employee count and total hours worked reasonable?
  • Were temporary, seasonal, and part-time workers handled consistently with the recordkeeping process?
  • If the establishment had zero recordable cases, were zeros entered rather than leaving totals blank?

That review matters because the 300A is the public-facing summary employees see during the posting window and, for covered establishments, the data OSHA receives electronically.

Certification, posting, and filing are separate steps

The 300A workflow has three related deadlines:

  1. Review the OSHA 300 Log and create the annual summary after the calendar year ends.
  2. Certify and post the 300A summary from February 1 through April 30.
  3. If the establishment is covered by 29 CFR 1904.41, electronically submit the required injury and illness data by March 2.

Posting the certified 300A does not automatically submit it to OSHA. Electronic submission does not replace the posting requirement. Most covered employers handle both from the same reviewed summary, but they are distinct compliance steps.

Common certification mistakes

The most common problems are procedural, not mathematical:

  • The wrong person signs. A safety coordinator or HR generalist can prepare the packet, but the certifying executive should still match OSHA's signer categories.
  • Corporate signs without checking the establishment. Headquarters can help file, but the numbers should still get establishment-level review.
  • The 300A is signed before the 300 Log is reconciled. OSHA's certification language points back to examining the log.
  • Zero-case years are treated as "nothing to sign." If the employer must keep records, the 300A still requires totals, certification, and posting even when the totals are zero.
  • The signer changes after a rework. If corrections materially change totals, keep a clean evidence trail showing what changed before the filing was authorized.

What to keep in the audit packet

Keep a short packet with the annual summary so the certification is explainable later:

  • Certified OSHA 300A summary
  • Final OSHA 300 Log used to prepare it
  • Establishment name, address, industry classification, EIN, and employee-count support
  • Notes for any late case reclassification or correction
  • The name and title of the certifying executive
  • Posting evidence, such as a date-stamped photo or internal notice record
  • Electronic submission confirmation, if the establishment had to file through OSHA's Injury Tracking Application

OSHA's 2026 maximum penalty page lists up to $16,550 per serious, other-than-serious, or posting-requirement violation, so it is worth making the signature and evidence trail boring and complete.

How RegFile handles it

RegFile keeps preparation and authorization separate. The workflow computes the 300A totals from the uploaded log, highlights fields for review, and keeps the human signer in the authorization step before submission. The signer remains responsible for reviewing the summary, but the evidence trail keeps the review, authorization, and filing confirmation together.

If you are not sure whether a specific establishment owes an electronic filing, start with the filing checker. If the checker says it is covered, RegFile shows what it prepares before the signer authorizes it.

Start the filing checker ->

This is informational, not legal advice - verify against your adopted rule.

Check the filings for your business

One dated result card from the filing checker.

Start the filing checker →