The short answer

Before a SOC 2, ISO 27001 or HITRUST assessment begins, an assessor requests specific documentation in a predictable sequence. Leadership must understand what gaps stop an assessment entirely, what can be addressed during fieldwork, and what delays certification. This article explains the documentation sequence, identifies who owns each category, and clarifies what adequate preparation looks like.

Compliance directors preparing for SOC 2, ISO 27001 or HITRUST assessments face a recurring question: what documents do assessors need first? The answer determines whether an assessment proceeds on schedule, suffers delays, or stops altogether. Understanding the sequence and the reasoning behind it allows leadership to allocate resources correctly and avoid last-minute scrambling.

1What Assessors Request and in What Order

The OSCAL assessment plan model, documented by NIST, describes assessment activities in the context of a specific system and specifies that an assessment plan must always be associated with a System Security Plan (SSP). This reflects a fundamental principle: assessors begin with the organization's definition of its own security posture before examining whether that definition is accurate and complete.

Assessors typically request documentation in three phases. The first phase establishes scope. The assessor needs to understand what is being assessed, where boundaries lie, and what controls the organization claims to have implemented. This phase includes the system security plan, the inventory of assets in scope, network diagrams, data flow documentation, and the organization chart showing who holds security responsibilities.

The second phase gathers governance artifacts. Once scope is clear, the assessor examines whether the organization has established the policies, standards and procedures it claims. This includes the information security policy, acceptable use policies, incident response plans, business continuity plans, vendor management procedures, and role descriptions for security personnel. If these documents do not exist or conflict with the SSP, the assessment cannot proceed as planned.

The third phase collects evidence of operation. Assessors examine whether documented controls are actually implemented and functioning. This includes access logs, change management records, vulnerability scan reports, penetration test results, training completion records, incident logs, and vendor assessments. Gaps in operational evidence can sometimes be addressed during the assessment if the control exists but was not logged. Gaps in design or implementation require remediation before certification.

2Why the Sequence Matters to the Business

The sequence reflects how assessors work. NIST assessment guidance establishes that assessors use checklists to ensure each organization receives comparable treatment. The NVLAP General Criteria Checklist, which addresses ISO/IEC 17025 requirements, exemplifies this approach. Assessors cannot complete checklist items for operational controls until they understand what the organization designed, and they cannot evaluate design until they understand scope.

When an organization presents incomplete scope documentation, the assessor cannot finalize the assessment plan. The OSCAL model specifies that local definitions fill gaps when the SSP is incomplete, but this extends the planning phase. When governance artifacts are missing or contradict the SSP, the assessor must decide whether the gap is a documentation deficiency or a control deficiency. Documentation deficiencies can be corrected during fieldwork. Control deficiencies require design, implementation, and a period of operation before they can be assessed.

The business consequence is schedule risk. Assessments that pause for remediation extend the timeline by weeks or months. Organizations that discover missing policies during fieldwork face a choice: delay certification or accept a qualified opinion with exceptions. Neither outcome serves the business objective that motivated the assessment.

3What Stops an Assessment Versus What Can Be Addressed During Fieldwork

Three categories of gaps stop an assessment. First, missing or materially incomplete scope documentation. An assessor cannot finalize an assessment plan without understanding what is in scope, who is responsible, and what controls the organization claims. Second, missing governance documentation for controls the organization states are implemented. An assessor cannot verify implementation of a control the organization never documented. Third, evidence that a claimed control was never implemented or has been inoperative for a substantial period.

Gaps that can be addressed during fieldwork include incomplete operational evidence for controls that clearly exist, minor inconsistencies between documents that do not change the control design, and documentation that is current but not yet updated to reflect recent organizational changes. Assessors distinguish between controls that were not documented and controls that were not implemented. The former is a documentation project. The latter is a control design and implementation project that requires time to operate before it can be assessed.

Organizations sometimes attempt to create governance documentation during the assessment. This approach fails because assessors evaluate whether controls operated during a defined period, not whether the organization can produce documentation on demand. A policy dated during the assessment period raises questions about when the control actually began operating. An incident response plan created in response to assessor questions cannot be used to evaluate how the organization responded to incidents that occurred before the plan existed.

4Who Owns This and What Adequate Ownership Looks Like

Compliance directors are accountable for assessment outcomes but rarely have authority over the resources that produce documentation. IT leadership owns technical diagrams, asset inventories and operational logs. Human resources owns personnel policies and training records. Legal owns contracts and vendor agreements. Finance owns budget and resource allocation. No single person below the executive team owns the complete set of artifacts an assessor needs.

Adequate ownership has four characteristics. First, a single executive who is accountable for readiness and authorized to coordinate across functions. Second, a documented inventory of required artifacts with clear ownership for each. Third, a review process that identifies gaps months before the assessment, not days. Fourth, authority to commission missing documentation and allocate resources to close gaps.

Organizations that lack this ownership produce documentation reactively. The compliance director discovers a gap, requests the missing document, waits for the responsible team to prioritize the work, and iterates when the first draft does not meet requirements. This pattern extends preparation timelines and increases the likelihood that gaps remain when the assessment begins. A vCISO provides the executive ownership that closes this coordination gap by holding strategy authority, making risk decisions, and reporting to leadership on readiness.

5How This Relates to Security Policy, Standards and Awareness

The documentation sequence reflects a hierarchy. Policy establishes what the organization requires. Standards specify how requirements are met. Procedures describe step-by-step activities. Operational records demonstrate that procedures were followed. Assessors move through this hierarchy in order because each level depends on the one above it.

Organizations sometimes confuse this hierarchy by creating detailed procedures without establishing the policy that justifies them, or by implementing controls without documenting the standard they satisfy. Assessors cannot evaluate a procedure if the policy it implements does not exist or does not clearly require the control. They cannot verify compliance with a standard if the organization never documented what compliance means in its environment.

Awareness programs demonstrate that the organization communicated requirements to personnel. An assessor examining access control procedures will request training records showing that personnel understand their responsibilities. An assessor reviewing incident response will request evidence that personnel know how to report incidents. Missing awareness documentation suggests that controls exist on paper but are not embedded in operations.

6Practical Implications for Leadership

Leadership should approach assessment preparation as a program, not a project. A project has a defined endpoint. Assessment preparation is ongoing because controls must operate continuously to be assessed. The question is not whether documentation exists, but whether it accurately reflects current operations and whether operations align with documented requirements.

Three decisions clarify the path forward. First, determine whether the organization has an accurate and current system security plan. If not, creating or updating the SSP is the first priority. Second, inventory governance documentation and identify gaps. Policy gaps stop assessments. Procedure gaps delay them. Operational evidence gaps may be acceptable if the control clearly exists. Third, assign executive accountability for readiness and authorize that person to coordinate across functions.

Organizations that wait until an assessment is scheduled to inventory documentation introduce unnecessary risk. Assessors provide a readiness review as part of scoping, but this review occurs weeks before fieldwork begins, not months. Gaps identified during scoping must be closed quickly or the assessment must be rescheduled. Leadership that wants a predictable outcome conducts readiness reviews independently, identifies gaps early, and closes them before engaging the assessor.

7What to Do Next

If your organization is preparing for an assessment, begin with an inventory of existing documentation mapped to the framework you are pursuing. Identify who owns each category and who is authorized to commission missing documents. Determine whether the system security plan is current and whether it accurately describes the environment as it operates today.

If gaps exist in governance documentation, prioritize closing them based on the assessment timeline and the assessor's expected sequence. Scope and governance artifacts should be complete before operational evidence collection begins. If no single executive is accountable for readiness, clarify accountability now rather than during the assessment.

For organizations without the internal resources to lead this effort, a virtual CISO provides the strategic oversight, governance authority and executive coordination that assessment preparation requires. Heights Consulting Group offers confidential consultations to compliance directors and executive teams evaluating their readiness posture. If this article describes your situation, contact us to discuss how executive security leadership would apply to your organization.

Related service: Security Policy, Standards and Awareness

Policies written to match how your organization actually operates, with the standards that make them workable and the training that makes them understood.

Read about Security Policy, Standards and Awareness