An empty list is a disclosure. It gets graded like one.
The common read: Nothing got breached, so there is nothing to report.
It does not hold, and the customer data is not why. DC4 covers identified system incidents that, verbatim, "(a) were the result of controls that were not suitably designed or operating effectively or (b) otherwise resulted in a significant failure in the achievement of one or more of those service commitments and system requirements". Two triggering conditions, and an incident reaches the criterion by clearing EITHER one.
An automated renewal that stopped producing certificates is a control that was not operating effectively, so the outage it caused sits inside the first condition on its own. Harm to customer data is not a condition anywhere in that sentence. An empty list is not a violation either, which is the half most readiness decks have backwards: the implementation guidance says that if there have been no significant incidents that require disclosure, management may disclose that fact.
So the empty list has a sanctioned form, and what changes is what it claims. "No identified system incidents" asserts that the entity's own detection and declaration criteria ran across the whole of 2026-01-01 to 2026-06-30 and produced zero results. For each incident that does clear a condition the criterion asks for its nature, the timing surrounding it, and its extent or effect and disposition. The zero gets no discount for being short.
It arrives as an evidence request the team returns incomplete: the pager history, the ticket queue and the status-page record, and the answer covers three weeks of retention. The dead renewal is a control that was not operating, and how it tested is a separate question. What the entity cannot support is the zero, so the finding lands on the description, and the auditor will likely say so in the opinion on it. Raising the retention to cover the period is one configuration change and one invoice line.
