/

  / How to Build an Incident Reporting Process That Holds Up in a SOC 2 Audit

How to Build an Incident Reporting Process That Holds Up in a SOC 2 Audit

A SOC 2 auditor will not ask whether you have an incident reporting policy. They will ask you to pull a specific incident from the last twelve months and walk them through it: when it was detected, who classified it, when it was escalated, who was notified, and how it was closed. The policy is the easy part. The part that fails audits is the gap between what the document says and what the timestamps actually show.

Incident reporting sits at the center of the SOC 2 System Operations criteria, and it is one of the most frequently exception-flagged areas in Type 2 reports. The reason is consistent: teams treat reporting as paperwork generated after the fire is out, rather than as a controlled process that produces evidence at every step. This guide breaks down how to build a reporting process that an auditor can test, sample, and sign off on without a finding.

SOC 2 Incident Reporting

What Is the Incident Reporting Process in SOC 2?

The incident reporting process is the documented, repeatable sequence your organization follows from the moment a security event is detected to the moment the incident is formally closed and archived. It governs how events are logged, classified, escalated, communicated, and recorded. Reporting is not a single notification email. It is the connective tissue that links detection, response, and post-incident review into an auditable chain.

How SOC 2 Defines a Security Incident

SOC 2 does not hand you a rigid statutory definition. It works through the AICPA’s Trust Services Criteria, which frame an incident around a failure, or potential failure, of the system to meet the organization’s service commitments and security objectives. In practice, a security incident is any event that compromises, or could compromise, the confidentiality, integrity, or availability of systems or data. The criteria expect you to define this threshold yourself and apply it consistently, which is precisely what auditors test against.

What Qualifies as a Reportable Security Incident Under SOC 2?

An event becomes reportable when it crosses the threshold your own policy sets. The distinction matters. A blocked phishing email is a security event. A user who clicked the link and entered credentials is a reportable incident. SOC 2 rewards organizations that draw this line explicitly, because a clear definition is what makes consistent triage possible. Vague language like “significant events will be reported” invites the auditor to ask who decides what counts as significant, and on what basis.

Examples of Security Incidents Relevant to SOC 2

Common reportable incidents include unauthorized access to production systems, credential compromise, malware or ransomware infection, data exfiltration or accidental disclosure, denial-of-service events affecting availability, lost or stolen devices holding company data, and misconfigurations that expose data to the public. Vendor and subprocessor breaches that touch your data belong on this list, too, since the criteria extend your responsibility into the supply chain.

How Incident Severity Levels Are Established and Classified

Severity classification drives everything downstream: how fast you respond, who gets pulled in, and which notification clocks start ticking. Most mature programs use a tiered scheme tied to business impact rather than technical noise. The point is not the labels you choose but the fact that the labels map to defined response times and escalation paths, and that the mapping is documented before an incident occurs, not invented during one.

Auditors quietly judge your maturity by how few P1s you declare and how consistently you apply the tiers. A program that labels everything critical looks panicked; one that never escalates looks asleep. The strongest signal is a severity matrix with response-time SLAs next to each tier, and ticket history showing the tiers were actually applied as written.

Reach SOC 2 Compliance in 6 Weeks or Less

Schedule Your Free SOC 2 Assessment Today

SOC 2 Incident Reporting Requirements

There is no single “incident reporting requirement” in SOC 2. The obligation is distributed across several Common Criteria, and the auditor assembles a picture from all of them. Understanding which criteria govern reporting tells you exactly what evidence to keep.

Which SOC 2 Trust Services Criteria Govern Incident Reporting?

Incident reporting lives mainly in the CC7 (System Operations) series.

  • CC7.2 covers monitoring system components to detect anomalies that may signal an incident.
  • CC7.3 requires you to evaluate detected events to determine whether they are incidents and to take action.
  • CC7.4 governs the response itself, including containment, eradication, and communication.
  • CC7.5 addresses recovery and remediation.

Communication obligations also reach into CC2.2 and CC2.3, which deal with internal and external information flow, and third-party incidents implicate CC9.2 on vendor risk. These are points of focus, not a checklist, but auditors use them to frame their testing. For a deeper look at how these criteria map to your broader compliance program, see our SOC 2 compliance guide.

What Evidence Do Auditors Expect From Your Incident Reporting Process?

Auditors want artifacts with time references, not assertions. That means incident tickets showing detection and closure timestamps, severity classifications with the name of who assigned them, escalation records, communication logs, and post-incident review notes. In a Type 2 examination they will trace one real incident end to end. Evidence pulled from a staging environment, or any artifact with no clear date, gets challenged immediately.

Who Is Responsible for Reporting Security Incidents?

Everyone reports; a defined role decides. SOC 2 expects that all staff know how to raise a suspected incident, and that a named function, often a security lead or incident commander, owns the determination of severity and the decision to escalate. The auditor will look for evidence that this ownership is real: a RACI chart is fine, but ticket history showing the right person actually classified and closed incidents is better.

Step-by-Step SOC 2 Incident Reporting Process

The following sequence maps cleanly to the lifecycle in NIST’s Computer Security Incident Handling Guide (SP 800-61), which auditors widely recognize as authoritative. NIST withdrew Revision 2 in April 2025 and released Revision 3, which reorganizes the lifecycle around the six functions of the Cybersecurity Framework 2.0. The underlying steps below remain the same; the framing simply shifts toward continuous risk management.

Step 1: Detect and Log the Incident

Detection comes from monitoring tools, alerts, or a human report. The moment that matters for the audit is when the event enters your system of record. Log it immediately with a timestamp, the source of detection, and an initial description. The first entry sets the clock that every later step is measured against.

Step 2: Classify Incident Severity and Scope

Apply your severity matrix and record the rationale. Scope means identifying which systems, data, and users are affected. Classification is a decision point, so capture who made it. This is the field auditors check most often, because it determines whether your response time was appropriate.

Step 3: Identify Notification and Escalation Requirements

Severity and data type together determine who must be told and how fast. A P1 involving personal data triggers a different set of obligations than a P3 affecting internal logs. Map these triggers in advance so the on-call responder is reading a decision tree, not improvising under pressure.

Step 4: Trigger the Incident Notification Workflow

Execute the notifications your triggers call for: internal leadership, affected customers, regulators, and partners as required. Record each notification with a timestamp and recipient. The notification itself is a control; the record of it is the evidence.

Step 5: Contain and Investigate the Incident

Containment stops the bleeding; investigation establishes what happened. Document actions as you take them, not from memory afterward. Contemporaneous notes carry far more weight than a tidy narrative reconstructed days later.

Step 6: Preserve Evidence and Document Findings

Preserve logs, forensic images, and artifacts in a way that maintains their integrity. Findings should answer what was affected, how, and what was done. This documentation feeds both the audit and any potential legal or regulatory process.

Important: The single most common documentation failure is the after-the-fact rewrite. Teams resolve an incident, then clean up the ticket to look orderly, overwriting the messy real-time timeline. Auditors can usually tell, because timestamps stop matching the sequence of events. Capture the timeline live, however ugly, and never edit history. An honest, imperfect record beats a polished, implausible one every time.

Step 7: Communicate With Internal and External Stakeholders

Communication continues through the incident, not just at the trigger point. Keep internal stakeholders updated on status and external parties informed per your commitments and obligations. Consistency between what you told customers and what your records show is itself a tested control.

Step 8: Close the Incident and Archive All Evidence

Formal closure requires a documented decision that the incident is resolved, the resolution, and a pointer to the post-incident review. Archive the complete record so it can be retrieved during the audit window. An incident that is fixed but never formally closed reads as an open finding.

Reach SOC 2 Compliance in 6 Weeks or Less

Schedule Your Free SOC 2 Assessment Today

Key Roles and Responsibilities in the SOC 2 Incident Reporting Process

Defining Ownership Within Your Incident Response Team

Clear roles prevent the two failure modes auditors see most: everyone assuming someone else owns the response, or several people acting without coordination. Define an incident commander or lead, technical responders, a communications owner, and an executive escalation point. Smaller organizations can combine these roles, provided the responsibilities are still named and assigned.

How Responsibilities Map to SOC 2 Controls

CC7.4’s points of focus explicitly call for assigned roles and responsibilities for the design, implementation, and execution of the incident response program, including the use of external resources where needed. Mapping each role to the criteria it supports gives the auditor a clean line from your org chart to the control objective, and saves you scrambling during fieldwork. Our SOC 2 compliance guide includes a sample role-to-criteria mapping you can adapt for your organization.

 

Documentation and Evidence Requirements for SOC 2 Audit Readiness

What Records Must Be Maintained Throughout the Reporting Process?

Maintain incident tickets, severity classifications, escalation and notification logs, investigation notes, evidence preservation records, post-incident reviews, and closure approvals. Each record needs a timestamp and an owner. The complete set, in sequence, is what auditors call the evidence chain.

How to Build an Audit-Ready Evidence Chain

An evidence chain links each step to the next so an auditor can follow one incident from detection to closure without gaps. Use a single system of record where possible. When a ticket references a notification, link to the actual message. When a closure references a review, link to the document. Traceability is the property auditors test, and broken links are the most common reason a sample fails.

Build a one-page “incident binder” template per incident that links every artifact in order: detection log, classification, escalation, notifications, investigation notes, evidence, review, closure. When the auditor requests a sample, you hand over one self-contained package instead of hunting across Slack, email, and three ticketing tools. Teams that do this routinely cut audit fieldwork time substantially and almost never get evidence-gap findings.

Common Audit Findings Related to Incident Reporting Documentation

Recurring findings include incidents that were handled but never formally logged, classifications applied inconsistently, notifications made but not recorded, missing or unsigned post-incident reviews, and timestamps that contradict the stated timeline. Every one of these is a documentation failure rather than a response failure, which is the frustrating irony: teams often respond well and still take the exception because they cannot prove it.

Notification Requirements Within the SOC 2 Incident Reporting Process

When Must Incidents Be Reported to Affected Parties?

SOC 2 itself does not set a universal notification deadline. It requires that you honor the commitments you have made, which usually live in customer contracts and your own published policies. If your master service agreement promises notification within 48 hours of confirming a breach, that promise becomes the standard the auditor holds you to.

Regulatory and Contractual Notification Obligations

External law often imposes harder deadlines than SOC 2. The EU’s General Data Protection Regulation requires controllers to notify the supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it under Article 33, with affected individuals notified under Article 34 when the risk is high. The clock starts at awareness, not at the end of the investigation.

Regulators treat late notification as a separate violation: the Irish Data Protection Commission fined Bank of Ireland EUR 463,000 in March 2024 specifically for failing to report within the window. Your SOC 2 reporting process should encode these external deadlines as triggers, not leave them to be remembered mid-incident.

If your organization operates in the United States, the landscape is more fragmented. The HIPAA Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach, and the SEC’s cybersecurity incident disclosure rules require public companies to report material incidents within four business days. Each jurisdiction adds a layer your incident triggers must account for. Build a simple reference table inside your runbook that maps data type and geography to the applicable notification window, so the on-call responder never has to go looking for it at 2 a.m.

How to Document Notification Actions for Auditors

For each notification, record what was sent, to whom, when, and under which obligation it was made. Keep the actual notice, not just a log entry stating one was sent. Where a deadline was missed, document the reason, because regulators and auditors both accept a reasoned justification far more readily than silence.

Reach SOC 2 Compliance in 6 Weeks or Less

Schedule Your Free SOC 2 Assessment Today

Root Cause Analysis and Post-Incident Review

Conducting a Post-Incident Review That Satisfies SOC 2 Requirements

A post-incident review is the control that turns an incident into improvement, and auditors look for it specifically. Hold it within a defined window after closure, involve the people who responded, and document what happened, what worked, what did not, and what changes follow. The review should produce assigned action items with owners and dates, not just observations. A review that generates no action items is, at best, a missed opportunity and, at worst, a signal that the process is going through the motions.

How Root Cause Analysis Feeds Back Into the Reporting Process

Root cause analysis asks why the incident was possible, not merely what occurred. A useful framework here is the Five Whys technique, which systematically traces a surface-level failure back to its underlying cause. The findings should feed back into your controls: a recurring detection gap becomes a monitoring change, a slow escalation becomes a revised trigger. This feedback loop is what CC7.3’s expectation to evaluate the effectiveness of response procedures on a periodic basis is really asking for.

Using Lessons Learned to Improve Your Process Continuously

Track action items to completion and revisit them in the next review cycle. An auditor who sees that a lesson from one incident produced a documented control change, which then prevented or improved handling of a later incident, sees a process that genuinely operates. That narrative is more persuasive than any policy document.

 

Testing and Validating Your Incident Reporting Process

How to Use Tabletop Exercises to Test the Reporting Workflow

A tabletop exercise walks a realistic scenario through your process without touching production. Pull stakeholders from engineering, security, legal, communications, and leadership, then run a scenario and observe whether detection, classification, escalation, and notification actually flow as written. Most SOC 2 auditors expect at least one incident response tabletop per year, with an agenda, attendee list, and documented outcomes. The Cybersecurity and Infrastructure Security Agency (CISA) publishes free tabletop exercise packages that are a reasonable starting point for organizations building this practice for the first time.

What Auditors Look for When Reviewing Tested Processes

Auditors want proof the test happened and that it produced something. The agenda and attendance list show it occurred; the findings and resulting action items show it mattered. A tabletop that surfaces no gaps and changes nothing reads as theater. One that exposes a weak escalation path and triggers a fix demonstrates a living process.

How Often Should the Incident Reporting Process Be Reviewed?

Review the process at least annually, and again after any significant incident or material change to your systems or organization. Annual review is the baseline most auditors expect; event-driven review is what distinguishes a mature program. Record the review with a date and the reviewer’s name so the activity itself is auditable.

 

Common Mistakes in SOC 2 Incident Reporting Processes

Unclear Escalation Paths and Notification Triggers

When escalation depends on someone’s judgment in the moment, response times become inconsistent and the auditor finds it. Encode triggers explicitly: this severity level, this data type, this system means these people are notified within this window. Ambiguity in the runbook becomes inconsistency in the ticket history, and inconsistency is exactly what auditors sample for.

Insufficient Documentation and Evidence Gaps

Strong response with weak records still fails. If the ticket lacks timestamps, the classification lacks an owner, or the notification lacks a saved copy, the control is effectively unprovable. Treat documentation as part of the response, not an afterthought.

Failure to Test or Update the Reporting Process

A process written once and never exercised drifts away from how the team actually operates. Tools change, people leave, and the runbook quietly goes stale. Untested processes are a frequent source of exceptions because the documented flow no longer matches reality. According to Verizon’s Data Breach Investigations Report, the gap between capability on paper and capability in practice is one of the most consistent contributors to delayed detection and response — the exact failure mode a live tabletop exercise is designed to expose.

Staff Unfamiliarity With Reporting Procedures

If responders do not know how to raise or classify an incident, the best-designed process never engages. Train staff on reporting procedures, keep the runbook accessible, and capture training records, since the auditor may ask for them under the communication criteria. Awareness training does not need to be elaborate; a fifteen-minute annual session with a sign-off sheet is enough to demonstrate the program is active.

Reach SOC 2 Compliance in 6 Weeks or Less

Schedule Your Free SOC 2 Assessment Today

How Auditors Evaluate Your SOC 2 Incident Reporting Process

What Auditors Specifically Test During a SOC 2 Review

The depth of testing depends on report type. A Type 1 report assesses whether controls are designed effectively at a single point in time. A Type 2 report assesses whether they operated effectively across a period, usually three to twelve months, and that is where reporting processes face real scrutiny.

In a Type 2 review, auditors define the population of incidents over the period, select samples weighted toward higher-risk cases, and trace each one through your records. A single exception in a high-risk area can produce a finding on its own, so consistency across every incident matters more than excellence on a chosen few. There is no credit for handling nine incidents perfectly if the tenth has no post-incident review and a missing escalation log.

How to Demonstrate a Functioning Reporting Process to Auditors

Lead with the system of record, not the policy. Show one real incident end to end, then show how you detect failures and remediate them. Have your population list, sample evidence, timestamps, and remediation proof ready before fieldwork begins.

The organizations that sail through are not the ones with the most incidents or the fewest; they are the ones whose records tell a complete, consistent, time-stamped story for every incident the auditor picks. For a full breakdown of how to prepare your evidence package ahead of a Type 2 examination, see our SOC 2 compliance guide.

 

Conclusion

A SOC 2-ready incident reporting process is less about the elegance of your policy and more about the integrity of your evidence trail. Define an incident clearly, classify it consistently, encode your escalation and notification triggers in advance, document every step with timestamps and owners, close incidents formally, and feed lessons learned back into the controls.

Map all of it to the CC7 criteria, test it with a tabletop at least once a year, and keep the records traceable from detection to closure. Do that, and when the auditor asks you to walk through an incident from last quarter, the answer is already written down.

Frequently Asked Questions

What triggers the incident reporting process under SOC 2?

The process triggers when a detected security event crosses the threshold your policy defines for a reportable incident, meaning it compromises, or could compromise, the confidentiality, integrity, or availability of systems or data. The exact threshold is yours to set, but it must be applied consistently. Auditors will test that consistency by sampling multiple incidents and checking whether similar events received similar classifications.

SOC 2 sets no universal deadline; it holds you to the commitments in your contracts and policies. External regulations may impose firm limits, such as GDPR’s 72-hour notification window to a supervisory authority. Encode those external deadlines into your internal triggers so they are never left to memory during a live incident.

Effectively yes. The Trust Services Criteria expect documented procedures for evaluating and responding to incidents, and auditors will ask for the policy as a starting point. Design without documentation cannot be tested, so a written policy is the practical baseline.

The response plan is the broader playbook covering how you contain, eradicate, and recover from incidents. The reporting process is the subset focused on logging, classifying, escalating, communicating, and recording. Reporting produces much of the evidence an auditor samples, which is why it deserves its own documented attention rather than a paragraph buried inside a larger plan.

Detection is identifying that an event has occurred, through tools, alerts, or human observation. Reporting is the documented process that follows: capturing the event in your system of record, classifying it, escalating it, and tracking it to closure. Detection without reporting leaves no audit trail, which means the event effectively did not happen as far as a Type 2 examination is concerned.

Yes, when a vendor or subprocessor incident affects your data or systems. The criteria extend your responsibility into the supply chain through CC9.2, so your reporting process should include a path for receiving, assessing, and recording vendor-reported incidents. This is an area that catches organizations off guard, particularly when a vendor notifies them informally and no formal intake record is ever created.

Log each incident in a consistent system of record with a detection timestamp, source, severity classification and the name of the person who assigned it, scope, escalation and notification records, investigation notes, and a formal closure entry. Every field should carry a time reference and an owner so the full chain is traceable during sampling. Gaps in any of these fields are the most common cause of evidence exceptions in Type 2 reviews.

Axipro Author

Picture of Pedro Dias

Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

Blog Highlights

Explore More Articles

Compliance software collects the evidence. A consultant builds the system that evidence is meant to prove. That’s the real difference in the ISO 27001 consultant vs software decision, and most teams only figure it out after they’ve bought one and realized they still need the other. Below, we compare what each route covers, where it breaks down, and what it costs you in time, money, and your team’s hours. Short version: software on its own works for a small group of companies. For most SaaS and tech scale-ups trying to get an enterprise deal over the line, consultant-led implementation on a compliance platform is the faster and safer path to a certificate. Quick Answer: Consultant, Software, or Both? Software-only works if you already have an in-house security lead who’s taken a company through ISO/IEC 27001 before and has the time to own the project. Consultant-only still makes sense if you run mostly on-premise or legacy systems that platforms barely integrate with. For everyone else, which means most cloud-native companies under a few hundred people, a hybrid works best: a platform to handle evidence and monitoring, and a consultant to build the management system and stand behind it in front of an auditor. Here’s why. What an ISO 27001 Consultant Handles ISO/IEC 27001:2022 is a management system standard. Clauses 4 to 10 cover how you run information security, and Annex A lists 93 controls you pick from based on risk. Almost none of it is box-ticking. Most of it comes down to judgment calls about your business, and that’s what you’re paying a consultant for. Scoping, Gap Analysis and Risk Assessment Scope is the first decision you make, and the most expensive one to get wrong. Go too wide and you’ll spend months on controls for systems no customer asks about. Go too narrow and the certificate won’t get through the procurement review it was supposed to pass. A consultant scopes around the deals you’re trying to close, runs a gap analysis, and builds a risk assessment based on your real assets and threats. That’s the document auditors dig into hardest. ISMS Documentation and Policy Writing The standard asks for a specific set of documents: the ISMS scope, information security policy, risk assessment and treatment methodology, Statement of Applicability, risk treatment plan, and evidence of competence, monitoring, internal audit, and management review. A consultant writes these around how your company works day to day, instead of how a template imagines it works. Auditors check whether you follow your own procedures, so a mismatch shows up fast. Internal Audit and Certification Audit Support You need an internal audit before certification, and Clause 9.2 says the auditor has to be objective and impartial. In a small company, the people who built the ISMS can’t credibly audit it, so most teams outsource it through ISO 27001 internal audit services. A good consultant also gets your team ready for the Stage 1 and Stage 2 audits, joins the conversations that matter, and handles corrective actions if the auditor raises nonconformities.  What ISO 27001 Compliance Software Handles Compliance automation platforms, often called GRC platforms, have changed how cloud-native companies get certified. They’re very good at the repetitive, evidence-heavy side of the work. Automated Evidence Collection and Continuous Control Monitoring The platform plugs into your cloud provider, identity provider, code repos, HR system, and device management tools, then pulls evidence on its own. It’ll flag an unencrypted storage bucket, an ex-employee who still has access, or a laptop without disk encryption. For technical controls, that saves weeks of screenshots and spreadsheet tracking. Policy Templates and Annex A Control Mapping Most platforms come with a policy library and map each control to the ISO 27001 clauses and Annex A. You get a starting point and a clear view of which controls have evidence and which don’t. Auditor Access and Ongoing Compliance Tracking Auditors can log in and review evidence themselves, which cuts down fieldwork. After you’re certified, dashboards show when controls slip between surveillance audits, so you aren’t rebuilding evidence from scratch every year. Where Each Approach Falls Short Neither route covers everything by itself. The good news is that the ways each one fails are predictable, so you can plan around them. Limits of Compliance Automation Platforms A platform can tell you a control is failing. It can’t decide your scope, run your risk assessment, write a policy that matches your operations, convince your CTO to change the offboarding process, or explain to an auditor why you excluded a control from your Statement of Applicability. Templates can also make you feel further along than you are. A dashboard at 90% can hide an ISMS that won’t survive Stage 1, because the missing 10% is the management system itself. Insider Note: The Stage 1 problem we see most on software-only projects is a risk assessment copied straight from the platform’s default risk library. The risks are generic, the scores are almost identical, and nothing ties back to the company’s own assets. Auditors notice within minutes, and it weakens the Statement of Applicability that’s built on it. The other problem is ownership. Software assumes someone inside the company will drive the project. At most startups that’s a CTO or ops lead who already has a full-time job, and the subscription renews whether the work gets done or not. Limits of a Consultant-Only Approach A consultant working without automation spends billable days on things a platform does for free, like chasing screenshots, updating evidence trackers, and collecting the same proof again before every surveillance audit. You pay more and wait longer. You also end up with a program that’s only accurate on the day it’s handed over. Once the engagement ends, the evidence goes stale and year-two surveillance turns into a scramble. ISO 27001 Consultant vs Software: Side-by-Side Comparison Factor Consultant only Software only Hybrid (consultant + platform) Time to audit readiness 3 to 6+ months Highly variable; depends on internal expertise As little as 6 weeks for well-scoped

Uzbekistan regulates artificial intelligence through two documents. The first is Law ZRU-1115, signed on 21 January 2026. It amends existing legislation to define AI, stops anyone from basing decisions about people’s rights on AI output alone, and fines companies that process personal data unlawfully with AI. The second is the set of Ethical Rules approved by Order No. 3787, in force since 17 June 2026, which spell out what developers, implementers, and users actually have to do. Uzbekistan hasn’t passed a standalone AI act, and its rules don’t sort systems into risk tiers or require conformity assessments. The framework is short and blunt, and it’s already enforceable. Below we walk through what each document requires, who it applies to, how it stacks up against the EU AI Act, and what a company using AI in Uzbekistan should do next. Uzbekistan AI Regulation at a Glance (TL;DR) Instrument Date What it does Who it binds Law ZRU-1115 Signed 21 January 2026 Defines AI in law, sets general rules for AI-built information resources and systems, bans legally significant decisions based only on AI, adds fines for unlawful AI processing of personal data State bodies, organizations, website owners, anyone processing personal data with AI Order No. 3787 (Ethical Rules) Registered 14 March 2026, in force 17 June 2026 Sets eight mandatory ethical principles and lists rights and obligations for developers, implementers, and users Individuals and companies developing, implementing, or using AI in Uzbekistan Law No. 1125 (Personal Data amendments) Adopted 26 March 2026 Limits data localization to biometric, genetic, and local telecom user data, and allows cross-border transfers under conditions Personal data operators, including AI providers AI Strategy until 2030 (RP-358) 14 October 2024 Sets national targets for AI adoption, infrastructure, and skills Government bodies What Is Law ZRU-1115? The law’s official title is a mouthful: “On making additions and changes to certain legislative acts of the Republic of Uzbekistan in connection with the regulation of relations arising from the use of artificial intelligence.” Put simply, it’s an amending law. Instead of creating a new AI code, it writes AI into laws that were already on the books. When It Was Signed and When It Took Effect The Legislative Chamber of the Oliy Majlis adopted the bill on 12 August 2025, and the Senate approved it on 1 November 2025. President Shavkat Mirziyoyev signed it on 21 January 2026. You can read the official text in Lex.uz, Uzbekistan’s national legislation database. The law set out the principles and the penalties. The day-to-day detail arrived later with the Ethical Rules, which came into force on 17 June 2026. For compliance planning, treat mid-June 2026 as the point when the whole framework started applying. Why Uzbekistan Amended Existing Laws Instead of Passing a Standalone AI Act Uzbekistan wants more AI, not less. Its national strategy sets numeric targets for adoption, investment, and local computing capacity, and a heavy EU-style act would have worked against them. So lawmakers kept it light. They defined AI, drew two hard lines (human control over decisions that affect people’s rights, and protection of personal data), and left the Ministry of Digital Technologies to fill in the rest through secondary rules. Businesses get less legal certainty, and the government gets to move faster. Which Laws ZRU-1115 Changes For businesses, two amendments matter most. The Law “On Informatization” (ZRU-560-II, 2003) now contains a legal definition of AI, a new article on using AI in information resources and systems, duties for website owners, and updated powers for the ministry in charge. The Code on Administrative Liability now includes an offense for processing and spreading personal data unlawfully using AI. The Legal Definition of Artificial Intelligence in Uzbekistan Under the amended Law “On Informatization,” AI is a set of technological solutions that imitate human cognitive functions, including learning on their own and solving problems, and that produce results on specific tasks comparable to what a person could do. That’s deliberately broad. It covers generative AI, machine learning classifiers, recommendation engines, and most agentic systems. The Ethical Rules add a narrower term, the AI system: software built on AI that can find, collect, store, analyze, process, evaluate, and use data, and make decisions on its own based on that data. If your product makes a decision from data, or shapes one, assume it counts. Key Rules Introduced by Law ZRU-1115 General Principles for Using AI in Information Systems and Resources The new article in the Law “On Informatization” starts from harm. Information resources created with AI, and information systems running on AI, must not harm people’s life, health, freedom, honor, or dignity, or violate their other inalienable rights. The standard is short and open-ended. It gives regulators something to enforce against without saying in advance what counts as harm. Principle-based rules like this deserve to be taken seriously precisely because the edges are undefined. Human Oversight: No Decisions on Rights and Freedoms Based Solely on AI Most coverage leads with this provision, and it’s easy to see why. When someone makes a legally significant decision that affects human rights and freedoms, they can’t rely only on conclusions produced by AI systems or AI-built information resources. AI can feed into the decision, but a person has to make it. That applies to loan denials, benefit eligibility, hiring rejections, licensing outcomes, and disciplinary action. In each case, someone needs to look at the AI output and own the final call. Insider Note: In AI governance engagements, teams rarely struggle to show that a review step exists. What they struggle to show is that the reviewer could disagree, and sometimes did. If a human clicks “approve” on every AI recommendation and nobody ever records an override, auditors will see automation with a signature on top. Build the override path and log when people use it, starting on day one. Powers of the Authorized State Body (Ministry of Digital Technologies) ZRU-1115 makes the Ministry of Digital Technologies the authorized state body for AI. Among its new jobs, it’s

You can get a SaaS company ready for a SOC 2 audit in six weeks, but you’ll feel every one of them. Most published timelines say three to six months. For a company with no project owner, no identity provider, and nothing written down, that’s about right. A cloud-native startup that already has the basics in place and can protect some time is a different story, and it can fit the work into six hard weeks. This plan walks through that route one week at a time. Each week has an owner, an hour estimate, and a clear test for when it’s finished. The free Google Sheet version turns the plan into a tracker you can hand out to owners and update in your weekly standup. Before you start, know what you’re signing up for. At the end of week 6 you’ll be audit-ready, which isn’t the same as holding a Type II report. Nobody can get you a Type II in six weeks. This is also the do-it-yourself route, and it takes a lot of hours. We’ll show you where those hours go and what the faster option looks like. Is Six Weeks Realistic for Your Company? Six weeks works when most of the plumbing already exists and your job is to formalize it, fill the gaps, and prove it all works. It falls apart when you’re building the foundations and documenting them at the same time. Go through this table honestly before you promise a customer a date. Six weeks is realistic if… Plan for 10 to 16 weeks if… Your product runs on a major cloud provider You host on-premise or across several data centers You already use an identity provider with SSO Every tool has its own login and password You have fewer than about 50 employees You have multiple offices, subsidiaries, or products in scope One named person owns the project with 10 to 15 hours a week Compliance is “everyone’s job,” so in practice nobody owns it An engineer can give you 15 to 20 hours in weeks 3 and 4 Engineering is fully committed to a launch You only need the Security criteria You need Availability, Confidentiality, or Privacy on day one Landing mostly in the right-hand column doesn’t mean you should throw the plan out. Give each week two weeks instead of one and follow the same order. What “SOC 2 Ready” Means at the End of Week 6 SOC 2 doesn’t give you a certificate. An independent CPA firm examines your controls against the AICPA Trust Services Criteria and writes a report, and which of the two report types you go for decides what you can show a buyer after week 6. A Type I report checks whether your controls are designed properly on a single date. Once you’re ready, a Type I audit can start almost right away. A Type II report checks whether those controls kept working over an observation period of at least three months, and usually six to twelve. Most enterprise procurement teams want Type II in the end. Being “ready” at the end of this plan means your in-scope controls are in place, you can pull evidence for any of them on request, and your auditor is booked. From there you either start a Type I audit or open your Type II observation window. Plenty of buyers will sign with a Type I report plus a letter from your auditor saying the Type II period is underway. Important: The Type II clock doesn’t start until your controls are running. If readiness slips by a week, your Type II report slips by a week too. Founders who tell a prospect “we’ll have SOC 2 in Q3” often forget this and end up renegotiating the deal. Before Week 1: Four Decisions to Make First Settle these before the clock starts. If you change any of them halfway through, you’ll redo work. Scope. Decide which systems, teams, and data the report covers. For most SaaS companies that’s the production environment, the code repository, the identity provider, customer data stores, and any support tools that touch customer data. Corporate systems that never see customer data can usually stay out. Trust Services Criteria. Security (also called the Common Criteria) is mandatory. Availability, Confidentiality, Processing Integrity, and Privacy are optional. Report type. Pick Type I if a deal is blocked right now and the buyer will accept it. If there’s no deadline, go straight to Type II. You’ll need it eventually, and skipping Type I saves you an audit fee. Owner and tooling. Name one person who’s accountable for the plan, and decide where your controls and evidence will live. The tooling choice gets its own section below. Pro Tip: Adding Criteria Only add optional criteria when a customer contract or security questionnaire asks for them. Each one brings more controls to set up and more evidence to collect, and you can widen the scope in next year’s audit. Spreadsheet or Compliance Software: Choosing Your Tracking Tool Every SOC 2 program needs a system of record, meaning one place where each control, its owner, its status, and its evidence live. You can run it yourself in a spreadsheet or a GRC platform, or have a consultant implement it for you. The right choice depends mostly on which report you’re after and how much of your team’s time you can spare. A spreadsheet is free and familiar. It also makes you understand your own environment before you automate any of it. For a Type I, or for a small team with a tight scope, a well-built spreadsheet can take you all the way to the audit. Axipro’s free GRC workbook for SOC 2 and ISO 27001 covers all 33 SOC 2 Common Criteria plus the optional criteria, with evidence, risk, policy, and gap trackers built in. It has no macros and opens straight in Google Sheets or Excel. A GRC platform connects to your cloud, identity provider, code repository, and HR system.