Template

Incident Response Plan

A short, usable plan: who to call, what to do first, what to write down, and who must be notified.

Intended audience
Program owners, managers, and responders
Difficulty
Intermediate
Estimated time
40 minutes
Access
Free
NIST SP 800-61
NIST SP 800-171
CMMC
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • List the incident lead, backup, and external contacts your plan needs before an incident happens.
  • Walk through the five phases: detect and report, triage, contain, eradicate and recover, and review.
  • Identify which contractual, regulatory, insurer, and customer notification timelines apply to your organization.
  • Determine what information every incident record must capture for later review.

1. Roles and contacts

  • Incident lead and backup.
  • Technical support contact.
  • Legal, insurance, and law-enforcement contacts.

2. Phases

  • Detect and report: how anyone raises an incident.
  • Triage: severity levels and who decides.
  • Contain: disable accounts, isolate devices, preserve evidence.
  • Eradicate and recover: restore from known-good state.
  • Review: after-action notes and improvements.

3. Notification obligations

List contractual, regulatory, insurer, and customer notification timelines that apply to you.

4. Record keeping

What each incident record must include: timeline, systems, people, actions, and outcome.

Key takeaways

  • An incident response plan is only usable if it names an incident lead, a backup, and specific contacts in advance.
  • The five phases — detect and report, triage, contain, eradicate and recover, review — give responders a consistent sequence to follow under pressure.
  • Notification timelines vary by contract, regulator, insurer, and customer, so they must be identified and listed before an incident, not during one.
  • Every incident record should capture a timeline, affected systems, people involved, actions taken, and the outcome for later review.
  • The after-action review step turns each incident into an improvement to the plan rather than a one-time fire drill.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This template is provided for readiness and educational purposes. Organizations should review and adapt it for their environment.

Matched on shared frameworks, topics, and program packs.

Quick reference

Incident Response Timeline — One Page

What to do in the first hour, first day, and first week of a suspected incident.

Intermediate
5 min
Free
NIST SP 800-61
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Exercise

Build a Sample SSP Section

Draft one System Security Plan section end to end, using the narrative pattern assessors expect.

Advanced
25 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Checklist

CMMC Readiness Checklist

Work through the preparation steps most small contractors miss before a CMMC assessment: scope, system boundary, documentation, and evidence.

Intermediate
45 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Checklist

Government Contractor Startup Checklist

What to put in place before your first federal award creates security obligations you cannot meet.

Intermediate
40 min
Free
FAR
DFARS

Published · v1.0.0 · 2026-08-01

Exercise

Identify CUI Examples

Practice separating CUI from FCI and from ordinary business information.

Advanced
15 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Checklist

NIST SP 800-171 Preparation Checklist

A plain-language preparation pass across the requirement families, focused on what a small business must produce and prove.

Advanced
60 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.