SOC 2 policy templates: all 22, free and open source

Every policy a cloud company of 5 to 200 people needs for a SOC 2 examination, as templates that render with your company name, stack and owners filled in. Each one has a single owner role, nine numbered sections and a mapping to the Trust Services Criteria. Apache-2.0, no signup, nothing stored server-side.

The 22 policies

In pack order. The owner role is the template default; the intake lets you name the person who fills it. The criteria count comes from the crosswalk, and each policy page shows the full text rendered for a sample company.

  1. Information Security Policy

    Establishes the information security program, its objectives, its governance and who is accountable for it.

    P01 · Owner: Security Owner · 10 criteria: CC1.1, CC1.2, CC1.3, CC1.5, CC2.2, CC3.1, CC4.1, CC4.2, CC5.1, CC5.3

  2. Acceptable Use Policy

    Sets the rules every person must follow when using company accounts, devices, data, networks and third-party tools.

    P02 · Owner: Security Owner · 2 criteria: CC1.1, CC1.5

  3. Access Control Policy

    Defines how access to systems and data is requested, approved, provisioned, reviewed and removed.

    P03 · Owner: Security Owner · 5 criteria: CC3.3, CC5.2, CC6.1, CC6.2, CC6.3

  4. Authentication and Password Policy

    Sets the requirements for passwords, multi-factor authentication, sessions and secrets used by people and systems.

    P04 · Owner: Security Owner · 2 criteria: CC6.1, CC6.6

  5. Asset Management Policy

    Requires an accurate inventory of devices, cloud resources, software and data, with a named owner and a managed lifecycle for each.

    P05 · Owner: IT/Operations Lead · 3 criteria: CC2.1, CC6.5, C1.2

  6. Data Classification and Handling Policy

    Defines the four data classification levels and the storage, transmission, sharing and disposal rules that apply to each.

    P06 · Owner: Security Owner · 2 criteria: CC6.7, C1.1

  7. Data Retention and Disposal Policy

    Defines how long each category of data is kept and how data, media and devices are securely disposed of when they are no longer needed.

    P07 · Owner: Security Owner · 3 criteria: CC6.5, C1.1, C1.2

  8. Encryption and Key Management Policy

    Sets minimum encryption standards for data in transit and at rest and defines how cryptographic keys, secrets and certificates are generated, stored, rotated and retired.

    P08 · Owner: Engineering Lead · 2 criteria: CC6.1, CC6.7

  9. Change Management Policy

    Requires that every change to production code, infrastructure and security-relevant configuration is proposed, reviewed, tested, approved and deployed through a controlled and traceable process.

    P09 · Owner: Engineering Lead · 3 criteria: CC3.4, CC5.2, CC8.1

  10. Secure Software Development Policy

    Embeds security into how the product is designed, built, tested, dependency-managed and released so that vulnerabilities are prevented or found before they reach customers.

    P10 · Owner: Engineering Lead · 2 criteria: CC6.8, CC8.1

  11. Vulnerability and Patch Management Policy

    Establishes how vulnerabilities in code, dependencies, infrastructure, endpoints and vendor services are discovered, rated, remediated within defined timeframes and verified.

    P11 · Owner: Engineering Lead · 3 criteria: CC4.1, CC6.8, CC7.1

  12. Logging and Monitoring Policy

    Defines which security-relevant events are logged across the product, cloud and corporate systems, how logs are protected and retained, and how alerts are triaged and acted on.

    P12 · Owner: Engineering Lead · 5 criteria: CC2.1, CC7.1, CC7.2, CC7.3, A1.1

  13. Incident Response Policy

    Defines how security incidents are reported, classified by severity, contained, resolved and reviewed, including customer, regulator and vendor notification obligations.

    P13 · Owner: Security Owner · 7 criteria: CC2.2, CC2.3, CC4.2, CC7.2, CC7.3, CC7.4, CC7.5

  14. Business Continuity and Disaster Recovery Policy

    Sets recovery objectives by system tier, defines how a disaster is declared and recovered from, and requires the plan to be tested and maintained.

    P14 · Owner: Engineering Lead · 5 criteria: CC7.5, CC9.1, A1.1, A1.2, A1.3

  15. Backup and Recovery Policy

    Requires every data set that supports the product and the business to be backed up on a defined schedule, protected, monitored and proven restorable through regular tests.

    P15 · Owner: Engineering Lead · 4 criteria: CC7.5, CC9.1, A1.2, A1.3

  16. Vendor and Third-Party Risk Management Policy

    Requires vendors to be inventoried, tiered by the data and services they touch, assessed before onboarding, bound by contract, reviewed annually and offboarded cleanly.

    P16 · Owner: Security Owner · 3 criteria: CC2.3, CC3.2, CC9.2

  17. Risk Assessment and Management Policy

    Establishes a repeatable risk assessment, a scored risk register, treatment and acceptance authorities, and regular reporting so that security decisions are made on evidence.

    P17 · Owner: Security Owner · 11 criteria: CC1.2, CC1.3, CC2.1, CC3.1, CC3.2, CC3.3, CC3.4, CC4.1, CC4.2, CC5.1, CC9.1

  18. Human Resources Security Policy

    Sets the security requirements that apply to people before, during and after their engagement so that screening, access, training and accountability follow every personnel change.

    P18 · Owner: People/HR Lead · 7 criteria: CC1.1, CC1.4, CC1.5, CC2.2, CC3.3, CC5.3, CC6.2

  19. Endpoint and Workstation Security Policy

    Establishes the baseline configuration, protection and lifecycle requirements for every laptop, desktop and mobile device used to access company systems.

    P19 · Owner: IT/Operations Lead · 3 criteria: CC6.6, CC6.7, CC6.8

  20. Network and Infrastructure Security Policy

    Defines how the cloud networks, compute and supporting infrastructure behind the product are segmented, hardened, administered and monitored.

    P20 · Owner: Engineering Lead · 5 criteria: CC5.2, CC6.1, CC6.6, CC7.1, A1.1

  21. Physical and Remote Work Security Policy

    Covers the physical protection of people, equipment and information in offices, home offices, shared spaces and while travelling, including reliance on cloud providers for data centre security.

    P21 · Owner: IT/Operations Lead · 3 criteria: CC6.4, CC6.5, A1.2

  22. Privacy and Data Protection Policy

    Sets out how personal data handled through the product and the business is collected, used, shared, protected, retained and made available to the people it concerns.

    P22 · Owner: Security Owner · 4 criteria: CC2.3, CC9.2, C1.1, C1.2

What every template contains

The 22 policies share one structure so that owners, reviewers and auditors always know where to look:

  1. Purpose. Why the policy exists and what it protects, in two or three sentences.
  2. Scope. Which people, systems and data it applies to, naming your cloud, source control, identity provider and vendors.
  3. Roles and Responsibilities. The owner role, the approver, engineering, people operations and all personnel, with what each is accountable for.
  4. Policy Statements. Numbered statements management commits to. The section auditors read first.
  5. Procedures. Numbered procedures that produce evidence: reviews, tests, approvals and records, on a stated cadence.
  6. Exceptions. How an exception is requested, who approves it, how long it lasts and where it is recorded.
  7. Enforcement. What happens when the policy is not followed, for employees and for contractors.
  8. Review Cadence. How often the owner reviews the policy and what triggers an out-of-cycle review.
  9. Revision History. A version table with the date, author, approver and a summary of each change.

Sections 4 and 5 carry the substance and are the two sections the Audit Kit rewrites for your named tools. The intake’s conditional blocks (identity provider or none, MDM or none, PII, PHI or payment data, Availability and Confidentiality in or out of scope, remote or office) already shape the free output.

Trust Services Criteria covered

The crosswalk (TSC 2017 (2022 points of focus)) maps the policies to 38 criteria. Each page below explains the criterion in plain words, links to the policy sections that address it and lists evidence examples.

CC1: Control environment

CC2: Communication and information

CC3: Risk assessment

CC4: Monitoring activities

CC5: Control activities

CC6: Logical and physical access controls

CC7: System operations

CC8: Change management

CC9: Risk mitigation

A1: Availability

C1: Confidentiality

Tailored for your stack

The generator has presets for the tools that most often appear in a startup’s policies. Each page lists the policies that reference the tool and shows what the Audit Kit writes for it.

Cloud platforms: AWS, Google Cloud, Microsoft Azure, Vercel, Cloudflare

Source control and CI: GitHub, GitLab

Identity providers: Google Workspace, Okta, Microsoft 365

Vendors and subprocessors: Supabase, Clerk

Free templates and the Audit Kit

What you getFree generatorAudit Kit ($39)
All 22 policies with your answers filled inMarkdownMarkdown and Word
Sections 4 and 5 written for your named toolsTemplate text with your tool namesRewritten by Claude from your full intake
TSC crosswalk and evidence checklistOn this siteSpreadsheet, with an owner per row
Acknowledgment forms and review calendarCopy from the guidesWord forms and a calendar file
Where it runsYour browser or the CLIYour browser; the ZIP is built on your machine

The templates and CLI are on GitHub; the docs cover the template syntax and building the pack in CI. For which policies to write first and who should own them, read SOC 2 policies for startups; for other free sources, see the comparison of free template sets.

Frequently asked questions

Are the 22 templates really free?
Yes. The templates, the renderer and the command-line tool are published under Apache-2.0 on GitHub, and the web generator renders all 22 policies in your browser with your answers filled in. There is no signup and nothing is stored server-side. The paid Audit Kit is optional.
What does the Audit Kit add to the free templates?
AI tailoring: Claude rewrites section 4 (Policy Statements) and section 5 (Procedures) of each policy to describe your named tools. The kit also delivers Word documents for all 22 policies, the Trust Services Criteria crosswalk and an evidence checklist as a spreadsheet, acknowledgment forms and a review calendar, all zipped on your machine. It costs $39 one-time ($149 for the agency license) and refunds are available within 14 days on request.
Do these templates make a company SOC 2 compliant?
No template does. These are governance policy templates: management adopts them, operates the procedures they describe and keeps the evidence, and the CPA firm forms its own opinion during the examination. Policyseed is not legal advice and makes no claim about examination outcomes.
Which Trust Services Criteria do the templates cover?
The crosswalk maps the 22 policies to the 33 common criteria (Security, CC1 to CC9), the three Availability criteria (A1) and the two Confidentiality criteria (C1) of the 2017 Trust Services Criteria with the 2022 points of focus. Each criterion has its own page with a plain-words summary, the policy sections that address it and evidence examples.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.