Can we fix a control while the audit is already running?
Generally, fixing a control while an audit is actively running is not possible for the period or scope under review, as audits assess the control's effectiveness during a defined historical period or at a specific point in time. For SOC 2, controls must have been effective throughout the entire audit period. For CMMC, non-conformities identified during the assessment will be documented, often requiring a Plan of Action and Milestones (POAM) and subsequent re-assessment rather than immediate fixes altering the initial assessment outcome.
For SOC 2 audits, the auditor assesses the effectiveness of controls over a defined "period of performance," typically 3 to 12 months. If a control was not operating effectively for any part of this historical period, fixing it during the audit fieldwork does not retroactively change its effectiveness for the period under review. The auditor will report this as an exception or deficiency. While organisations are expected to develop remediation plans for identified issues, these plans address future control effectiveness and do not alter the findings for the historical audit period. The audit report will reflect the control's state during the period of performance, often with a management response outlining corrective actions.
CMMC assessments are generally a "snapshot in time" evaluation of an organisation's compliance with the model's practices and processes. If an assessor identifies a non-conformity during the assessment, it will be noted. For minor non-conformities, an assessor may allow immediate remediation during the assessment, provided it can be fully demonstrated and documented within the assessment timeframe. However, for significant non-conformities, the organisation will typically be required to develop a Plan of Action and Milestones (POAM) to address the deficiencies. Achieving certification then requires successful remediation and a subsequent re-assessment of the non-conforming controls. The initial assessment report will reflect the non-conformities found.
Sources
- AICPA Trust Services Criteria, Description Criteria DC 200.00
- CMMC Assessment Process (CAP) Guide, Section 3.2.3