Security
Incident response plans: what auditors actually check
Every company has a plan. Fewer can show it was exercised, followed and improved. Here is what SOC 2 and ISO 27001 auditors test, and the sections your plan needs.
Certifyi compliance team · Updated September 2026
Short answer. Auditors do not grade the prose of an incident response plan. They test whether it was approved, communicated, exercised at least annually, followed during real incidents, and improved afterwards. For SOC 2 that is CC7.3 to CC7.5 (evaluating, responding to and recovering from incidents); for ISO 27001:2022 it is controls A.5.24 to A.5.28 (planning, assessment, response, learning, evidence collection). The evidence is the plan with an approval record, an exercise report, incident tickets that show the plan being followed, and post-incident reviews with actions closed.
The sections a defensible plan contains
Plan template sections
- Purpose, scope and definitions: what counts as an event, an incident and a breach.
- Roles: incident commander, technical lead, communications, legal, executive sponsor, with named deputies.
- Severity levels with examples and the response time for each.
- Lifecycle: detection and reporting, triage, containment, eradication, recovery, closure.
- Notification matrix: customers, regulators, law enforcement, insurers, with the legal clocks.
- Evidence handling: what to preserve, chain of custody, where logs live.
- Communication templates: internal, customer, regulator, public.
- Post-incident review: format, timing, owner, how actions are tracked.
- Exercise programme: tabletop at least annually, scenarios, participants.
- Review cadence and version history.
The legal clocks your plan must encode
| Regime | Trigger | Deadline |
|---|---|---|
| GDPR | Personal data breach likely to risk individuals’ rights | Supervisory authority within 72 hours of awareness; individuals without undue delay if high risk |
| NIS 2 | Significant incident | Early warning 24 hours; notification 72 hours; final report one month |
| DORA | Major ICT-related incident | Initial notification 4 hours from classification / 24 hours from awareness; intermediate 72 hours; final one month |
| HIPAA | Breach of unsecured PHI | Individuals within 60 days; HHS within 60 days (annually if under 500 affected) |
| SEC (US listed) | Material cybersecurity incident | Form 8-K within four business days of materiality determination |
| Customer contracts | As defined | Often 24 to 72 hours; check every enterprise contract |
What the auditor samples
Expect the auditor to pick incidents from the period and walk each one through the plan: when was it detected, who was notified, was severity assigned per the matrix, was containment recorded, were customers or regulators told within the deadline, was a post-incident review held and were its actions closed. If you had no incidents, the auditor will lean harder on the tabletop exercise and on near-misses, so run the exercise properly and keep the report.
Running a tabletop that counts as evidence
Choose a scenario that stresses the plan, such as a ransomware note on a production host or a leaked API key found on a public repository. Include the people named in the roles, not only the security team. Time the decisions, note where the plan was unclear, and write a short report with attendees, timeline, gaps and actions. Close the actions and update the plan version. That single document satisfies the exercise requirement for both frameworks.
Where Certifyi fits
The incident management module records incidents against the severity matrix, tracks the notification clocks per regime, stores the evidence with hashes and timestamps, and links post-incident actions to the controls they change. Tabletop reports and plan approvals are stored as evidence against CC7.3 to CC7.5 and A.5.24 to A.5.28, and the board report shows incidents by severity and time to contain.
Incident response, answered
How often must we test the plan?
At least annually for both SOC 2 and ISO 27001, and after significant changes to systems or the organisation. Many companies run two tabletops a year with different scenarios.
Does a phishing email count as an incident?
A reported phishing email is a security event. It becomes an incident if credentials were entered or malware ran. Your definitions section should make this distinction so triage is consistent.
Do we have to notify customers of every incident?
Only as your contracts and applicable laws require. Your notification matrix should say who decides, on what criteria, and within what time.
What if we had no incidents during the audit period?
The auditor will test the exercise, the near-miss and event log, and the plan’s approval and communication. Zero recorded events can itself be a finding if detection is weak.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.