SOC 2 tabletop exercise
If your SOC 2 audit window is coming up and nobody has run an incident response test this year, you are in good company. This page sets out what the criteria actually say, what auditors usually want to see, and how to run one this week.
What SOC 2 says about testing
SOC 2 at a glance
- Framework
- SOC 2 (AICPA Trust Services Criteria)
- References
- CC7.4, CC7.5; A1.3 where Availability is in scope
- Where testing comes up
- CC7.4 and CC7.5 points of focus: periodic evaluation of incident response, and recovery-plan testing that includes scenarios where key personnel are unavailable. A1.3 when Availability is in scope.
- Does the text require it?
- A1.3: yes, if Availability is in scope. CC7: through points of focus, which are guidance rather than requirements. Auditors expect to see it.
- How often
- “Periodic”. Annual is a common auditor and platform convention, not the text.
Note: Calmdrill is designed to support your SOC 2 evidence. It cannot guarantee an audit outcome. Confirm your auditor’s expectations early.
SOC 2 uses the AICPA’s Trust Services Criteria. Testing comes up in three places.
- CC7.4, responding to incidents. A point of focus says the effectiveness of incident response should be evaluated periodically.
- CC7.5, recovering from incidents. A point of focus on incident-recovery plan testing, run periodically, covering realistic scenarios and scenarios where key personnel are unavailable.
- A1.3, in the Availability category, if it is in scope. The criterion itself says recovery plan procedures are tested.
Points of focus are guidance rather than hard requirements, so the text does not literally say “run an annual tabletop”. In practice, most auditors and compliance platforms (Vanta, Drata, Secureframe) expect an incident response test at least once a year, and a documented tabletop is the most common way teams meet that expectation.
What auditors usually ask for
Five things, and each has a place in the evidence pack. That is the shape of a Calmdrill After-Action Report, plus the exercise plan, attendance record and improvement tracker in the Kit.
| The auditor asks for | Where it is |
|---|---|
| The incident response plan you tested, with its version and date | Exercise plan: plans and documents under test |
| The scenario and objectives | Exercise plan, and sections 2 and 3 of the report |
| Who took part, and in what roles | Attendance record, and section 1 of the report |
| A record of what happened and what you decided | Exercise log, and the timeline in section 4 of the report |
| Lessons learned, with owned actions, and evidence that you updated the plan | Sections 6 to 9 of the report, and the improvement tracker |
How the report words it
Section 10 of every report says what the exercise tested and which criteria it is intended to support. It never claims compliance.
This is the sample report’s, word for word. It comes from an internal scripted playtest of CD-01 at Harbourline, a fictional company.
- This report (signed)
- Attendance record
- Exercise log / transcript
- Improvement actions entered in the tracker
- Updated plan or runbooks (if any)
Which scenario for SOC 2
Match the scenario to the criterion you want to show. A tabletop tests decisions. Backup and restore controls need technical evidence as well.
| If you want to show | Run |
|---|---|
| Security incident response (CC7.3 to CC7.4) | CD-07 Keys in the Wild, or CD-08 The Friendly Admin |
| Recovery with key people unavailable (CC7.5) | CD-11 Nobody Home, or CD-01 The 02:14 Certificate |
| Availability and recovery (A1.2 to A1.3) | CD-03 Region Grey, or CD-04 The Restore That Wasn’t. Pair it with a real restore test for backup controls. |
Running it in about 70 minutes
The Kit has all twelve scenarios, the Game Master and the evidence templates. $149 once, for your whole organisation.
- Load the Calmdrill Game Master into a Claude or ChatGPT project. It takes about 10 minutes.
- Get three to eight people from engineering, security, support and leadership into a room or a call.
- Say “let’s drill”, choose the scenario, and tell the Game Master it is for SOC 2. It notes that in the report header.
- Play for 40 to 45 minutes, debrief for 15, then type
/report. - Review the report, sign it, file it with the attendance record, and log the actions.