We found a serious gap before the auditor did. Do we tell them?
Yes, proactively disclosing a serious gap discovered before an auditor is generally advisable for both SOC 2 and CMMC. This approach demonstrates transparency, control over the narrative, and a mature risk management posture. It allows the organisation to present the finding with a documented remediation plan, potentially influencing the auditor's perspective and the final report's language, rather than having the gap discovered independently, which can reflect poorly on internal controls.
Proactive disclosure of a serious control gap before an auditor identifies it offers significant advantages. It allows the organisation to control the narrative surrounding the finding, presenting it as part of an ongoing internal improvement process rather than a failure of oversight. When management identifies a gap, documents it, and initiates a remediation plan, it demonstrates a robust control environment and a commitment to continuous improvement, which auditors typically view favourably. This approach can lead to the gap being noted as a management finding with an active remediation plan, potentially mitigating its impact on the final audit opinion or CMMC certification status, especially if the remediation is well underway or completed by the audit conclusion.
A common misstep is to conceal findings in hopes they will go unnoticed. This strategy carries substantial risk; if an auditor independently discovers the gap, it can undermine trust and suggest a weaker control environment or even an attempt to mislead. Instead, practitioners should focus on preparing a comprehensive remediation plan, including timelines, assigned responsibilities, and evidence of actions taken or planned. For SOC 2, this aligns with the Trust Services Criteria related to risk assessment and control activities. For CMMC, it demonstrates the institutionalisation of practices required at higher maturity levels. While neither framework explicitly mandates pre-audit disclosure of internal findings, transparent communication, coupled with a clear path to resolution, is a hallmark of effective governance, risk, and compliance programmes.
Sources
- AICPA, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (TSP Section 100)
- Cybersecurity Maturity Model Certification (CMMC) Model v2.0
- CMMC Assessment Process (CAP) v2.0