Platform module

Incidents handled, timed and evidenced

Every framework asks the same three things about incidents: did you detect it, did you respond within your own policy, and can you prove both. Certifyi records the timeline, the impact assessment and the actions on one trail, and links the incident to the controls it tested.
What incident management means in a compliance program. An incident is any event that threatens the confidentiality, integrity or availability of systems or data. Frameworks require a documented process, a record of each incident with severity, timeline, root cause and corrective action, and evidence that the process was exercised. Regulations add clocks: 72 hours under GDPR and HIPAA breach rules, 24 hours early warning under NIS2, and contractual timelines under DORA.

What it does

Record

Incident register

Each incident with severity, owner, detection and response timestamps, affected assets and data, and current status.

Assess

Impact assessment

A structured assessment of who and what is affected, whether personal data is involved, and which notification clocks apply.

Trail

Timeline and actions

Every action, decision and communication logged with time and person, so the post-incident review and the auditor read the same story.

Improve

Root cause and CAPA

Root cause recorded, corrective and preventive actions tracked to closure and linked to the risks and controls they change.

Comply

Evidence for auditors

Incidents map to SOC 2 CC7.3 to CC7.5, ISO 27001 A.5.24 to A.5.28 and HIPAA §164.308(a)(6), with the tabletop-exercise record auditors ask for.

Detect

Vulnerability and advisory feed

Vulnerabilities and security advisories feed the same queue, so a critical advisory becomes an incident with an owner before it becomes a breach.

How it works

The same record your auditor, your vendors and your team already use.

Step 1

Detect

From monitoring alerts, a vulnerability advisory, a user report or a customer email.

Step 2

Triage

Severity, scope and notification clocks set in the impact assessment. Owner assigned.

Step 3

Respond

Actions logged as they happen. Communications and customer notifications attached.

Step 4

Review

Root cause, corrective actions and lessons feed the risk register and policies.

Questions about this module

No. The impact assessment determines whether personal data, regulated data or a contractual commitment is involved. The register records the decision and the reasoning either way, which is what a regulator or auditor asks for.

The documented process, the incident register for the period, at least one exercised or real incident with a full timeline and post-incident review, and proof that corrective actions were completed.

Yes. A vendor-caused incident is recorded against the supplier in the vendor register and triggers a re-assessment.

See it on your own scope

Twenty minutes with a compliance lead. Bring your stack; we will show the module against your controls.
Scroll to Top