Security

Incident response plans: what auditors actually check

Every company has a plan. Fewer can show it was exercised, followed and improved. Here is what SOC 2 and ISO 27001 auditors test, and the sections your plan needs.
Certifyi compliance team · Updated September 2026
Short answer. Auditors do not grade the prose of an incident response plan. They test whether it was approved, communicated, exercised at least annually, followed during real incidents, and improved afterwards. For SOC 2 that is CC7.3 to CC7.5 (evaluating, responding to and recovering from incidents); for ISO 27001:2022 it is controls A.5.24 to A.5.28 (planning, assessment, response, learning, evidence collection). The evidence is the plan with an approval record, an exercise report, incident tickets that show the plan being followed, and post-incident reviews with actions closed.

The sections a defensible plan contains

Plan template sections

The legal clocks your plan must encode

RegimeTriggerDeadline
GDPRPersonal data breach likely to risk individuals’ rightsSupervisory authority within 72 hours of awareness; individuals without undue delay if high risk
NIS 2Significant incidentEarly warning 24 hours; notification 72 hours; final report one month
DORAMajor ICT-related incidentInitial notification 4 hours from classification / 24 hours from awareness; intermediate 72 hours; final one month
HIPAABreach of unsecured PHIIndividuals within 60 days; HHS within 60 days (annually if under 500 affected)
SEC (US listed)Material cybersecurity incidentForm 8-K within four business days of materiality determination
Customer contractsAs definedOften 24 to 72 hours; check every enterprise contract

What the auditor samples

Expect the auditor to pick incidents from the period and walk each one through the plan: when was it detected, who was notified, was severity assigned per the matrix, was containment recorded, were customers or regulators told within the deadline, was a post-incident review held and were its actions closed. If you had no incidents, the auditor will lean harder on the tabletop exercise and on near-misses, so run the exercise properly and keep the report.

Running a tabletop that counts as evidence

Choose a scenario that stresses the plan, such as a ransomware note on a production host or a leaked API key found on a public repository. Include the people named in the roles, not only the security team. Time the decisions, note where the plan was unclear, and write a short report with attendees, timeline, gaps and actions. Close the actions and update the plan version. That single document satisfies the exercise requirement for both frameworks.

Where Certifyi fits

The incident management module records incidents against the severity matrix, tracks the notification clocks per regime, stores the evidence with hashes and timestamps, and links post-incident actions to the controls they change. Tabletop reports and plan approvals are stored as evidence against CC7.3 to CC7.5 and A.5.24 to A.5.28, and the board report shows incidents by severity and time to contain.

Incident response, answered

At least annually for both SOC 2 and ISO 27001, and after significant changes to systems or the organisation. Many companies run two tabletops a year with different scenarios.

A reported phishing email is a security event. It becomes an incident if credentials were entered or malware ran. Your definitions section should make this distinction so triage is consistent.

Only as your contracts and applicable laws require. Your notification matrix should say who decides, on what criteria, and within what time.

The auditor will test the exercise, the near-miss and event log, and the plan’s approval and communication. Zero recorded events can itself be a finding if detection is weak.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.
Scroll to Top