When an enterprise deal stalls in procurement with "send us your SOC 2," the work that actually gets you unblocked is mostly paperwork. SOC 2 is not a law or a certification — it is an independent attestation that your company does the security things it claims to do, and the way you claim them is through a written policy set. Auditors do not grade prose; they check that each policy is specific to your company, that it maps to a control, and that you have evidence the control actually operated. Get the documentation right and the rest of the audit is mostly sampling. Get it wrong and you pay a consultant $10,000–$15,000 to tell you what was missing.
This guide lists the policies auditors expect for a Security-scope SOC 2 in 2026, explains what each must contain, and shows where templates save real time and where you still have to do the thinking. If you only have an afternoon, start with the table below and the audit-prep kit.
The SOC 2 policy set (2026)
The list below is the set we see on virtually every first-time Security-scope audit. The Trust Services Criteria column shows which criterion each policy primarily supports — almost everything maps to CC (the Security "common criteria" that every SOC 2 includes), with a few touching Availability, Confidentiality or Privacy if you add those criteria to your scope.
| Policy / document | What it must cover | TSC mapping |
|---|---|---|
| Information Security Policy | The master document: security objectives, roles, and how every other policy ties together. Auditors read this first. | CC1–CC2 |
| Access Control Policy | Provisioning, least-privilege, role-based access, MFA, and quarterly access reviews with offboarding. | CC6 |
| Change Management Policy | How code and infrastructure changes are reviewed, approved, tested and deployed (PR review, CI/CD gates). | CC8 |
| Incident Response Policy | Detection, severity classification, escalation, communication and post-incident review; named owners. | CC7 |
| Business Continuity & Disaster Recovery | RTO/RPO targets, backup strategy, failover, and a tested recovery plan. | CC7 / A1 |
| Risk Assessment Policy | How you identify, score and treat risks at least annually, with a documented risk register. | CC3 |
| Vendor / Third-Party Management | How subprocessors are vetted, monitored and reviewed (their SOC 2s, DPAs, criticality ratings). | CC9 |
| Data Classification & Handling | How data is labeled (public / internal / confidential) and the handling rules for each tier. | CC6 / C1 |
| Encryption / Cryptography Policy | Encryption in transit and at rest, key management, and approved algorithms. | CC6 |
| Acceptable Use Policy | Rules for company devices, accounts and data that every employee acknowledges. | CC1 / CC6 |
| Secure SDLC Policy | Security in the development lifecycle: code review, dependency scanning, secrets handling, testing. | CC8 |
| Logging & Monitoring Policy | What is logged, retention period, alerting thresholds, and who reviews alerts. | CC7 |
| Data Retention & Disposal | How long each data type is kept and how it is securely destroyed when no longer needed. | CC6 / C1 |
| HR Security & Awareness | Background checks, onboarding/offboarding, and annual security-awareness training records. | CC1 |
Adding the Availability, Confidentiality, Processing Integrity or Privacy criteria layers on extra policies (e.g. a capacity/availability plan or a formal privacy notice). Most first-time companies scope to Security only and add criteria later as customers require them.
SOC 2 Audit Prep Kit for SaaS Founders
Every policy in the table above, written to the standard auditors expect, editable for your stack — plus the control mappings and evidence checklists that turn a folder of documents into a defensible audit. It's the fastest way to skip the $10,000–$15,000 consultant gap assessment and route that deal-blocking "send us your SOC 2" request now.
- 14 core security policy templates (the full set above)
- Trust Services Criteria control mapping
- Evidence-collection checklist per control
- Access-review & vendor-tracking trackers
- Incident-response & change-management runbooks
- Auditor-question prep prompts
SOC2Guide sells this digital product directly. It's a documentation accelerator, not legal or audit advice — your CPA firm issues the actual report. One-time purchase, instant download, free updates.
Templates vs. consultant vs. platform — how to choose
There are three ways to get a complete, audit-ready policy set. They differ by an order of magnitude in cost, and the right one depends on your stage and how soon a customer needs proof.
| Path | Typical 2026 cost | Best for |
|---|---|---|
| Free templates, DIY | $0 + 2–4 weeks of your time | Pre-revenue teams with time but no budget; expect heavy rewriting and no control mapping. |
| Curated audit-prep kit | One-time, low hundreds | Founders who need to move this week — complete, auditor-aligned, customizable in a few days. |
| Consultant gap assessment | $10,000 – $15,000 | Funded teams that want a human to own readiness; overkill for a first Security-scope report. |
| Compliance platform library | $7,000+ / yr (bundled) | Teams ready to buy continuous monitoring; templates come with the subscription. |
A few things matter more than which path you pick. Specificity beats polish: an auditor will fail a beautiful generic policy that doesn't match your real access-review cadence, and pass a plain one that does. Policies need owners: every document should name who is accountable, because the auditor will ask. And policies without evidence are worthless for a Type II — the report samples proof that each control operated over the observation window, so build the evidence trail (access reviews, training logs, change tickets) the day you adopt the policy, not the week before the audit.
If you'd rather automate the evidence
Policies are step one; gathering evidence every quarter is the grind. If you expect to maintain SOC 2 year over year, a compliance platform connects to your cloud, identity and HR systems to collect evidence automatically and ships its own policy library. The three leaders are broadly comparable on core SOC 2 work — the differences are price, framework breadth and how hands-on the onboarding is.
Useful once you're ready for continuous monitoring. Pricing is quote-based and scales with headcount. Pair a platform with the kit above if you want audit-ready policies today and automation later.
Some links on this page are affiliate or partner links and we may earn a commission if you sign up, at no extra cost to you. As an Amazon Associate we also earn from qualifying purchases. We only list tools we consider genuinely useful, and these links never change our pricing or recommendations.
Read the full Vanta vs Drata vs Secureframe comparison → — pricing, integrations, frameworks and audit support side by side, with an interactive picker.
Keep going
Cost & timeline estimator
Get a tailored SOC 2 cost range and month estimate for your situation.
SOC 2 readiness checklist
The 12 control areas and 24 steps to audit-ready, with a free interactive checklist.
SOC 2 cost breakdown
Every line item and realistic 2026 all-in totals for startups and mid-market.
Vanta vs Drata vs Secureframe
How the three leading automation platforms compare for SaaS teams.
SOC 2 audit-prep kit
The full policy set, control mapping and evidence checklists — ready to edit.
SOC 2 FAQ
Type I vs II, ISO 27001, timelines and budget questions answered.
Stop staring at a blank policy folder
Start from the full auditor-aligned set, customize it for your stack, and walk into the audit prepared.
Get the audit-prep kitFrequently asked questions
What policies do you need for SOC 2?
Auditors expect roughly 12–16 written policies for a Security-scope SOC 2. The core set is information security, access control, change management, incident response, business continuity/DR, risk assessment, vendor management, data classification, encryption, acceptable use, secure SDLC, logging & monitoring, data retention/disposal and HR security/awareness. The full table above shows what each must cover and how it maps to the Trust Services Criteria.
Are free SOC 2 policy templates good enough to pass an audit?
They're a starting point, not a finish line. Auditors test whether a policy is specific to your company and whether you actually do what it says — so a generic free template needs heavy rewriting and rarely comes with control mappings or evidence checklists. A curated kit that's already aligned to the criteria saves far more time than a loose pile of free files.
Do compliance platforms like Vanta or Drata include policy templates?
Yes — Vanta, Drata and Secureframe all ship a policy library with their subscription. The trade-off is that it's bundled into a $7,000+/year platform, and the templates still need customization. Many founders use a standalone kit to get audit-ready now and adopt a platform later for continuous monitoring.
How long does it take to write SOC 2 policies from scratch?
Two to four weeks of focused work for a founder or ops lead, and that's before the evidence trail. The slow part is knowing what each policy must contain to satisfy an auditor. Starting from a complete, auditor-aligned set usually compresses that to a few days of customization.
What's the difference between a policy and evidence in SOC 2?
A policy is the written rule ("we review access quarterly"); evidence is proof it happened (the dated access-review record). Type II is ultimately an evidence audit — the policies define the controls and the auditor samples evidence over the observation window. That's why a good kit includes evidence-collection checklists, not just documents.