SOC 2 policy templates: all 22, free and open source
Every policy a cloud company of 5 to 200 people needs for a SOC 2 examination, as templates that render with your company name, stack and owners filled in. Each one has a single owner role, nine numbered sections and a mapping to the Trust Services Criteria. Apache-2.0, no signup, nothing stored server-side.
The 22 policies
In pack order. The owner role is the template default; the intake lets you name the person who fills it. The criteria count comes from the crosswalk, and each policy page shows the full text rendered for a sample company.
- Information Security Policy
Establishes the information security program, its objectives, its governance and who is accountable for it.
P01 · Owner: Security Owner · 10 criteria: CC1.1, CC1.2, CC1.3, CC1.5, CC2.2, CC3.1, CC4.1, CC4.2, CC5.1, CC5.3
- Acceptable Use Policy
Sets the rules every person must follow when using company accounts, devices, data, networks and third-party tools.
P02 · Owner: Security Owner · 2 criteria: CC1.1, CC1.5
- Access Control Policy
Defines how access to systems and data is requested, approved, provisioned, reviewed and removed.
P03 · Owner: Security Owner · 5 criteria: CC3.3, CC5.2, CC6.1, CC6.2, CC6.3
- Authentication and Password Policy
Sets the requirements for passwords, multi-factor authentication, sessions and secrets used by people and systems.
P04 · Owner: Security Owner · 2 criteria: CC6.1, CC6.6
- Asset Management Policy
Requires an accurate inventory of devices, cloud resources, software and data, with a named owner and a managed lifecycle for each.
P05 · Owner: IT/Operations Lead · 3 criteria: CC2.1, CC6.5, C1.2
- Data Classification and Handling Policy
Defines the four data classification levels and the storage, transmission, sharing and disposal rules that apply to each.
P06 · Owner: Security Owner · 2 criteria: CC6.7, C1.1
- Data Retention and Disposal Policy
Defines how long each category of data is kept and how data, media and devices are securely disposed of when they are no longer needed.
P07 · Owner: Security Owner · 3 criteria: CC6.5, C1.1, C1.2
- Encryption and Key Management Policy
Sets minimum encryption standards for data in transit and at rest and defines how cryptographic keys, secrets and certificates are generated, stored, rotated and retired.
P08 · Owner: Engineering Lead · 2 criteria: CC6.1, CC6.7
- Change Management Policy
Requires that every change to production code, infrastructure and security-relevant configuration is proposed, reviewed, tested, approved and deployed through a controlled and traceable process.
P09 · Owner: Engineering Lead · 3 criteria: CC3.4, CC5.2, CC8.1
- Secure Software Development Policy
Embeds security into how the product is designed, built, tested, dependency-managed and released so that vulnerabilities are prevented or found before they reach customers.
P10 · Owner: Engineering Lead · 2 criteria: CC6.8, CC8.1
- Vulnerability and Patch Management Policy
Establishes how vulnerabilities in code, dependencies, infrastructure, endpoints and vendor services are discovered, rated, remediated within defined timeframes and verified.
P11 · Owner: Engineering Lead · 3 criteria: CC4.1, CC6.8, CC7.1
- Logging and Monitoring Policy
Defines which security-relevant events are logged across the product, cloud and corporate systems, how logs are protected and retained, and how alerts are triaged and acted on.
P12 · Owner: Engineering Lead · 5 criteria: CC2.1, CC7.1, CC7.2, CC7.3, A1.1
- Incident Response Policy
Defines how security incidents are reported, classified by severity, contained, resolved and reviewed, including customer, regulator and vendor notification obligations.
P13 · Owner: Security Owner · 7 criteria: CC2.2, CC2.3, CC4.2, CC7.2, CC7.3, CC7.4, CC7.5
- Business Continuity and Disaster Recovery Policy
Sets recovery objectives by system tier, defines how a disaster is declared and recovered from, and requires the plan to be tested and maintained.
P14 · Owner: Engineering Lead · 5 criteria: CC7.5, CC9.1, A1.1, A1.2, A1.3
- Backup and Recovery Policy
Requires every data set that supports the product and the business to be backed up on a defined schedule, protected, monitored and proven restorable through regular tests.
P15 · Owner: Engineering Lead · 4 criteria: CC7.5, CC9.1, A1.2, A1.3
- Vendor and Third-Party Risk Management Policy
Requires vendors to be inventoried, tiered by the data and services they touch, assessed before onboarding, bound by contract, reviewed annually and offboarded cleanly.
P16 · Owner: Security Owner · 3 criteria: CC2.3, CC3.2, CC9.2
- Risk Assessment and Management Policy
Establishes a repeatable risk assessment, a scored risk register, treatment and acceptance authorities, and regular reporting so that security decisions are made on evidence.
P17 · Owner: Security Owner · 11 criteria: CC1.2, CC1.3, CC2.1, CC3.1, CC3.2, CC3.3, CC3.4, CC4.1, CC4.2, CC5.1, CC9.1
- Human Resources Security Policy
Sets the security requirements that apply to people before, during and after their engagement so that screening, access, training and accountability follow every personnel change.
P18 · Owner: People/HR Lead · 7 criteria: CC1.1, CC1.4, CC1.5, CC2.2, CC3.3, CC5.3, CC6.2
- Endpoint and Workstation Security Policy
Establishes the baseline configuration, protection and lifecycle requirements for every laptop, desktop and mobile device used to access company systems.
P19 · Owner: IT/Operations Lead · 3 criteria: CC6.6, CC6.7, CC6.8
- Network and Infrastructure Security Policy
Defines how the cloud networks, compute and supporting infrastructure behind the product are segmented, hardened, administered and monitored.
P20 · Owner: Engineering Lead · 5 criteria: CC5.2, CC6.1, CC6.6, CC7.1, A1.1
- Physical and Remote Work Security Policy
Covers the physical protection of people, equipment and information in offices, home offices, shared spaces and while travelling, including reliance on cloud providers for data centre security.
P21 · Owner: IT/Operations Lead · 3 criteria: CC6.4, CC6.5, A1.2
- Privacy and Data Protection Policy
Sets out how personal data handled through the product and the business is collected, used, shared, protected, retained and made available to the people it concerns.
P22 · Owner: Security Owner · 4 criteria: CC2.3, CC9.2, C1.1, C1.2
What every template contains
The 22 policies share one structure so that owners, reviewers and auditors always know where to look:
- Purpose. Why the policy exists and what it protects, in two or three sentences.
- Scope. Which people, systems and data it applies to, naming your cloud, source control, identity provider and vendors.
- Roles and Responsibilities. The owner role, the approver, engineering, people operations and all personnel, with what each is accountable for.
- Policy Statements. Numbered statements management commits to. The section auditors read first.
- Procedures. Numbered procedures that produce evidence: reviews, tests, approvals and records, on a stated cadence.
- Exceptions. How an exception is requested, who approves it, how long it lasts and where it is recorded.
- Enforcement. What happens when the policy is not followed, for employees and for contractors.
- Review Cadence. How often the owner reviews the policy and what triggers an out-of-cycle review.
- Revision History. A version table with the date, author, approver and a summary of each change.
Sections 4 and 5 carry the substance and are the two sections the Audit Kit rewrites for your named tools. The intake’s conditional blocks (identity provider or none, MDM or none, PII, PHI or payment data, Availability and Confidentiality in or out of scope, remote or office) already shape the free output.
Trust Services Criteria covered
The crosswalk (TSC 2017 (2022 points of focus)) maps the policies to 38 criteria. Each page below explains the criterion in plain words, links to the policy sections that address it and lists evidence examples.
CC1: Control environment
CC2: Communication and information
CC3: Risk assessment
CC4: Monitoring activities
CC5: Control activities
CC6: Logical and physical access controls
CC7: System operations
CC8: Change management
CC9: Risk mitigation
A1: Availability
C1: Confidentiality
Tailored for your stack
The generator has presets for the tools that most often appear in a startup’s policies. Each page lists the policies that reference the tool and shows what the Audit Kit writes for it.
Cloud platforms: AWS, Google Cloud, Microsoft Azure, Vercel, Cloudflare
Source control and CI: GitHub, GitLab
Identity providers: Google Workspace, Okta, Microsoft 365
Vendors and subprocessors: Supabase, Clerk
Free templates and the Audit Kit
| What you get | Free generator | Audit Kit ($39) |
|---|---|---|
| All 22 policies with your answers filled in | Markdown | Markdown and Word |
| Sections 4 and 5 written for your named tools | Template text with your tool names | Rewritten by Claude from your full intake |
| TSC crosswalk and evidence checklist | On this site | Spreadsheet, with an owner per row |
| Acknowledgment forms and review calendar | Copy from the guides | Word forms and a calendar file |
| Where it runs | Your browser or the CLI | Your browser; the ZIP is built on your machine |
The templates and CLI are on GitHub; the docs cover the template syntax and building the pack in CI. For which policies to write first and who should own them, read SOC 2 policies for startups; for other free sources, see the comparison of free template sets.
Frequently asked questions
- Are the 22 templates really free?
- Yes. The templates, the renderer and the command-line tool are published under Apache-2.0 on GitHub, and the web generator renders all 22 policies in your browser with your answers filled in. There is no signup and nothing is stored server-side. The paid Audit Kit is optional.
- What does the Audit Kit add to the free templates?
- AI tailoring: Claude rewrites section 4 (Policy Statements) and section 5 (Procedures) of each policy to describe your named tools. The kit also delivers Word documents for all 22 policies, the Trust Services Criteria crosswalk and an evidence checklist as a spreadsheet, acknowledgment forms and a review calendar, all zipped on your machine. It costs $39 one-time ($149 for the agency license) and refunds are available within 14 days on request.
- Do these templates make a company SOC 2 compliant?
- No template does. These are governance policy templates: management adopts them, operates the procedures they describe and keeps the evidence, and the CPA firm forms its own opinion during the examination. Policyseed is not legal advice and makes no claim about examination outcomes.
- Which Trust Services Criteria do the templates cover?
- The crosswalk maps the 22 policies to the 33 common criteria (Security, CC1 to CC9), the three Availability criteria (A1) and the two Confidentiality criteria (C1) of the 2017 Trust Services Criteria with the 2022 points of focus. Each criterion has its own page with a plain-words summary, the policy sections that address it and evidence examples.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.