We had an incident mid-certification. Do we have to disclose it?
Yes, disclosure of an incident occurring mid-certification is generally required or strongly advisable for both SOC 2 and ISO 27001. For SOC 2, incidents impacting the Trust Services Criteria within the audit period must be disclosed to the auditor, as they directly affect the accuracy of management's assertion and the auditor's opinion. For ISO 27001, such incidents must be reported to the certification body, demonstrating the organisation's adherence to corrective action processes and the effectiveness of its Information Security Management System (ISMS) as per Clause 10.2.
For SOC 2 engagements, the auditor's opinion covers a specific period, and management provides an assertion regarding the effectiveness of controls throughout that entire timeframe. An incident occurring during this period directly challenges that assertion, particularly if it compromises the Trust Services Criteria (e.g., security, availability, confidentiality). Failure to disclose such an event can lead to a qualified or adverse opinion, or even withdrawal of the report, as the auditor relies on complete and accurate information. Practitioners often err by assuming only 'material' incidents require disclosure; however, any incident that tests the effectiveness of controls relevant to the Trust Services Criteria should be brought to the auditor's attention to ensure the report accurately reflects the control environment.
Under ISO 27001, the certification process assesses the establishment, implementation, maintenance, and continual improvement of an ISMS. An incident during the certification audit period is not merely a setback but an opportunity to demonstrate the ISMS's resilience and conformity with requirements such as Clause 10.2 (Nonconformity and corrective action). Concealing an incident undermines the integrity of the certification process and can be viewed as a breach of trust with the certification body. Organisations sometimes mistakenly believe that disclosing an incident will automatically prevent certification; however, demonstrating effective incident response, root cause analysis, and corrective actions often strengthens the case for certification by proving the ISMS is operational and effective in practice.
Sources
- AICPA Guide for Service Organizations: Reporting on Controls at a Service Organization
- ISO/IEC 27001:2022, Clause 10.2 (Nonconformity and corrective action)