Incident response plan template (SOC 2), free and sized for five people

Two or three pages you can follow at 2am beat twenty you cannot. Here is the short version, ready to copy.

You can copy this whole plan for free. It is an incident response plan template SOC 2 examiners can test against a team of five, and it has four working parts: how serious is it, who does what, when you must tell people, and what you write down after. A fifth part, a yearly drill, gives you proof when nothing went wrong.

Two or three pages is the finished size. Fill in the names and numbers, then delete anything you would not actually do.

Why the short plan is the safe plan

Incident response lives inside the Security common criteria, which every SOC 2 report covers.1 The examination does not score your plan for ambition. It checks two things: that incidents in the period were handled the way your plan says, and that the plan was exercised.2

That flips the usual instinct. Each extra promise is one more thing to fail. A plan that pages someone within fifteen minutes turns every slow night into an exception printed in your report. Write the version you will follow when tired.

Part A: how serious is it

Base each level on something a person can see, not on a feeling. Customer data touched, production down, an outside party involved. Each level gets a trigger, a person to wake, and a clock. Test it by asking whether one engineer, alone at night, could pick the right level in one read.

LevelYou seeWho gets calledDeadline
P1An outsider reached customer data, or the product is down for everyoneThe lead, by phone, right awayContain today. The notice clock starts when P1 is declared
P2A safeguard broke and data could have leaked, or some customers are degradedThe lead, inside an hourContain today, review within five working days
P3One laptop, account or vendor affected, with no sign data was reachedA ticket for the next working dayClosed inside your normal fix window
Not an incidentAn unexploited scan result, a failed login, a phishing email nobody openedNo oneGoes to the vulnerability backlog

Part B: who does what when there are five of you

Big company plans list a commander, a scribe, a comms lead, a legal contact and a technical lead. You do not have five spare people at 2am. Merge the roles and say so in writing. One name in two roles is honest. A role with no name is a finding.

RoleOwnsSmall team version
LeadSets the level, runs the response, declares it overOne engineer plus one backup
FixerContainment, saving evidence, the repairSame person as the lead for P2 and P3
Customer contactStatus page, notices, the contract deadlineThe CEO, with the CTO as backup
Note takerTimes, decisions, who was toldWhoever is not fixing, or the lead afterwards

A single line in the plan covers it: below P1 the lead and the fixer are one person, and every role has a backup. The other controls that bend at this size are in SOC 2 for a small team.

Part C: when you must tell people

The criteria require that affected parties hear about security incidents. They do not set a number of hours, and your auditor will not pick one for you.1 The real deadline is already on paper somewhere. Find it in three places and keep the shortest.

  1. Your contracts. The security incident clause of each master agreement or data processing addendum. Deadlines vary by customer, so list the tightest.
  2. The law. Under Article 33 of the GDPR, a personal data breach goes to the supervisory authority within 72 hours. U.S. state breach laws carry their own timing. Ask a lawyer once and record the answer.
  3. Your own public words. Anything on your status page or trust page is a promise an examiner can read and test.

Write one number into the plan and name the person who sends the notice. A deadline with no owner will be missed.

Part D: the write up afterwards

Every incident gets a short review, held within a week while memories are fresh. Its job is the fix. Its record needs five fields so it survives being sampled:

  • When it was detected, and whether by alert, customer or a person noticing.
  • The level, and any change to it during the response.
  • Timestamps for detected, declared, contained, resolved and communicated.
  • Who was told outside the company, and when.
  • The cause, plus one follow up with an owner and a due date.

Then close that follow up. Examiners sample incidents and check whether the actions closed, and it shows up among the requests on a SOC 2 evidence list.

Part E: the yearly drill

If nothing ever went wrong, you still need proof the plan works. A one hour tabletop, once a year, is how a quiet company produces it. Invite the people the plan names and run a scenario your stack could really face, like a cloud key pushed to a public repository or a laptop left in a taxi. Say the level out loud, draft the customer notice, look up the contract deadline. Then record the date, attendees, scenario, what went wrong and the follow ups. Hold it inside your examination period, or it does not count for that period.

Cut these before you adopt it

Read every line and ask whether you could show proof of it next week. If the answer is no, delete it. Typical cuts from a borrowed plan:

  • A war room or bridge line you do not have.
  • Roles with no person behind them.
  • Response times you have never met.
  • A forensics firm you have not hired.
  • Anything that begins “the security team will”.

What remains is the whole document for a team your size. Your policy set and your scope get smaller by the same logic.

What it costs to get this written

Doing it yourself from this page costs an afternoon. Paying someone else to write it is usually part of a larger consulting job, and those are priced for bigger companies:

  • Comp AI states that a vCISO or compliance consultant might charge $150 to $400 an hour, which can total $20,000 to $50,000 for a full SOC 2 prep engagement. Source, checked 2026-07-30.

There is a middle path. The cybersoftware software drafts this plan with your names in it and tracks the reviews and drills that prove you follow it, at $199 a month, cancel any time. Begin with the free readiness assessment, which takes about 15 minutes, or see every plan on pricing.

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

What must a SOC 2 incident response plan cover?
Severity levels anyone on the team can apply, a named lead and a named backup, the deadline for telling customers and where that deadline comes from, and a short review after each incident with an owned follow up. That covers the requirement. Anything extra is a promise the examination will hold you to.
Can a five person company run an incident response plan?
Yes. The plan needs roles, not a large team. Name one lead and one backup, write down that one person covers several roles, and make sure no role is left without a name. An empty role is what an examiner flags.
What is the deadline for telling customers about a breach?
The Trust Services Criteria ask you to tell affected parties but set no number of hours. Your deadline comes from your customer contracts and from law. For personal data in scope of the GDPR, Article 33 gives 72 hours to notify the supervisory authority. Put the shortest deadline that applies to you into the plan as one number.
Is a tabletop exercise required if we never had an incident?
In practice yes, because the examination asks for proof the plan was used during the period, and a drill is the only proof a quiet year can produce. One hour, once a year, with the people the plan names, dated inside your period. Keep the attendee list, scenario, findings and follow ups.
Is it fine to start from a generic plan?
As a starting point, yes. Then remove every promise you cannot keep, such as response times you have never hit, a war room, or a forensics firm you have not retained. The examination checks whether you did what the plan says, so a shorter honest plan is the safer one.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.