SMCI had 4 material weaknesses. They've remediated 3 of them this year.
The only one left is ITGC, which is basically user access and change controls around certain systems tied to financial reporting. SMCI says the new controls still need to operate long enough and pass effectiveness testing in FY27 before they can officially call it remediated.
That's not the same as saying "their systems are insecure" or "the financials are wrong." BDO still gave the actual financial statements an unqualified audit opinion.
And for perspective, even $Microsoft(MSFT)$ has been breached by sophisticated state-backed hackers and had internal systems and source-code repositories accessed. No control framework makes a company immune from cyberattacks.
To me the bigger story is that SMCI went from 4 weaknesses to 1, filed on time, and the remaining issue is now mostly about proving the new IT controls work consistently over time. If I were a betting man, I'd bet they do.
Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

