Blog
SOC 2 incident-response tabletops: what an auditor actually expects
What SOC 2 asks for on incident response readiness, what evidence looks like, and what a tabletop proves (and does not prove) when you hand the packet to an auditor.
Security and compliance buyers often treat "we ran a tabletop" as a checkbox. Auditors do not. They want a credible record that your people practiced the plan under a realistic scenario, that attendance and decisions were captured, and that gaps were not papered over. This post is a practical guide to what that usually means for SOC 2 context, without pretending a vendor or a single exercise grades your controls.
What the control context is asking for
SOC 2 does not ship a single universal "tabletop form." Trust Services Criteria around security and availability expect you to maintain an incident response capability and to test or evaluate it in a way that is appropriate to the business. In practice, auditors look for a written IR plan, defined roles, a method for detecting and escalating incidents, and evidence that the plan has been exercised, not only written.
A tabletop is one common way teams produce that exercise evidence. It is a facilitated walkthrough: injects arrive on a clock, roles respond, decisions are attributed, and someone records what the room actually did versus what the plan said. It is not the only possible form of testing. It is a form auditors recognize when the record is complete and honest.
What evidence usually looks like
When an auditor asks "show me you tested incident response," they are rarely satisfied by a calendar invite and a slide deck title. Useful evidence typically includes:
- Who was invited and who was present (roles matter more than titles alone)
- When the exercise ran, and how long it lasted
- The scenario context at a level that shows it was not a generic movie plot
- Timed decisions and actions attributed to people in the room
- Gaps between the written plan and what the room actually did
- Follow-up owners for those gaps, if remediation was identified
Cross-references to framework language can help the reader orient, but citations are not grades. Listing "SOC 2" next to an exercise does not mean the control is satisfied. It means you are offering evidence of an exercise that may be relevant to how you argue the control.
What a tabletop does prove
A well-run tabletop proves that a defined group of people practiced decisions under a scenario, on a schedule, with a durable record. It can surface missing runbook steps, unclear ownership, notification clock confusion, and plan language that nobody can follow in real time. Those findings are valuable precisely because they are uncomfortable.
It also proves process hygiene: you can show an outsider that IR practice is not only tribal knowledge. That is often what the auditor is sampling for, not a cinematic victory over the scenario.
What a tabletop does not prove
A tabletop does not prove that production failover works. It does not prove backups restore. It does not prove detection rules fire. It does not prove that every control in your SOC 2 report is effective. It does not issue a compliance verdict, and no honest product should claim to issue one on your behalf.
If your IR plan depends on technical recovery steps, you still need technical tests for those steps. If your auditor asks for a DR or restore rehearsal, a conversation about ransomware injects is complementary evidence, not a substitute.
How to prepare so the packet is useful
Pick a scenario that stresses the real plan: ransomware with data exposure, credential compromise, business email compromise, or another path your IR plan actually covers. Invite the roles the plan names. Run on a clock so "we would have called legal eventually" cannot hide behind open discussion. Capture plan-says versus room-did gaps without grading them as pass or fail.
After the session, keep a self-contained record you can produce without reconstructing memory from chat threads. Hand that record to your auditor as evidence of the exercise. Your auditor decides whether it meets their sampling for the period. That separation (evidence versus verdict) is how serious programs stay credible.
Bottom line: SOC 2 context rewards honest IR practice records, not theatrical certainty. Run the tabletop, keep the evidence, refuse to over-claim what a conversation can prove, and keep technical tests on the technical path.