Platform module
Incidents handled, timed and evidenced
Every framework asks the same three things about incidents: did you detect it, did you respond within your own policy, and can you prove both. Certifyi records the timeline, the impact assessment and the actions on one trail, and links the incident to the controls it tested.
What incident management means in a compliance program. An incident is any event that threatens the confidentiality, integrity or availability of systems or data. Frameworks require a documented process, a record of each incident with severity, timeline, root cause and corrective action, and evidence that the process was exercised. Regulations add clocks: 72 hours under GDPR and HIPAA breach rules, 24 hours early warning under NIS2, and contractual timelines under DORA.
What it does
Record
Incident register
Each incident with severity, owner, detection and response timestamps, affected assets and data, and current status.
Assess
Impact assessment
A structured assessment of who and what is affected, whether personal data is involved, and which notification clocks apply.
Trail
Timeline and actions
Every action, decision and communication logged with time and person, so the post-incident review and the auditor read the same story.
Improve
Root cause and CAPA
Root cause recorded, corrective and preventive actions tracked to closure and linked to the risks and controls they change.
Comply
Evidence for auditors
Incidents map to SOC 2 CC7.3 to CC7.5, ISO 27001 A.5.24 to A.5.28 and HIPAA §164.308(a)(6), with the tabletop-exercise record auditors ask for.
Detect
Vulnerability and advisory feed
Vulnerabilities and security advisories feed the same queue, so a critical advisory becomes an incident with an owner before it becomes a breach.
How it works
The same record your auditor, your vendors and your team already use.
Step 1
Detect
From monitoring alerts, a vulnerability advisory, a user report or a customer email.
Step 2
Triage
Severity, scope and notification clocks set in the impact assessment. Owner assigned.
Step 3
Respond
Actions logged as they happen. Communications and customer notifications attached.
Step 4
Review
Root cause, corrective actions and lessons feed the risk register and policies.
Questions about this module
Do we need to notify customers of every incident?
No. The impact assessment determines whether personal data, regulated data or a contractual commitment is involved. The register records the decision and the reasoning either way, which is what a regulator or auditor asks for.
What evidence do auditors want for incident management?
The documented process, the incident register for the period, at least one exercised or real incident with a full timeline and post-incident review, and proof that corrective actions were completed.
Can incidents link to vendors?
Yes. A vendor-caused incident is recorded against the supplier in the vendor register and triggers a re-assessment.
Keep reading
See it on your own scope
Twenty minutes with a compliance lead. Bring your stack; we will show the module against your controls.