Free SOC 2 templates

Every template here is free and is built in your browser: no signup, no email, nothing uploaded. Each one links to the criteria it supports and to the policy that documents it.

Policies

  • 22 SOC 2 policy templates (Markdown, Word per policy). The full governance set, mapped to the Trust Services Criteria. Generate all 22 from 23 answers, or download any single policy from its own page.
  • Policy acknowledgment form (Word). The signed form auditors ask for to show staff read the policies.
  • ISO 27001 mapping (CSV). The same 22 policies mapped to the 93 Annex A controls, with the gaps listed.

Registers and records

  • Risk register (Excel). Ten starter risks, unscored, with 1-5 likelihood and impact scales and the score and rating formulas in place.
  • User access review (Excel). A quarterly review sheet per system and a service account inventory, with the columns explained.
  • Vendor security questionnaire (Excel, CSV, Markdown). 35 questions tiered by vendor risk, with what a good answer looks like and a review summary sheet.
  • Data retention schedule (Excel, CSV, Markdown). Sixteen common record types with owner, trigger, disposal method and a disposal log. You set the periods.

Plans and pages

  • Incident response plan (Word, Markdown). Severity levels, roles, the five response phases, communication drafts, an evidence log and a tabletop checklist.
  • Business continuity and disaster recovery plan (Word, Markdown). Critical services with RTO and RPO, a dependency map, scenario playbooks, communication drafts and a restore test log.
  • Public security page (HTML, Markdown). A trust page that states only what you tick, for customers who ask before you have a report.

Checklists

  • SOC 2 checklist (Markdown, printable). Twenty readiness items with why each matters and what to do. Score yourself with the interactive check.
  • SOC 2 evidence checklist (CSV). The evidence typically requested for each of the 38 criteria, and the policy that documents it.

Free templates or the Audit Kit

The templates are generic starting points that you edit. The Audit Kit produces the same documents filled in from your stack. The 22 policies are rewritten to name your actual tools, and you get Word files, the registers pre-filled, a criteria crosswalk, acknowledgment forms and a review calendar, in one ZIP. Not sure which you need? See free templates vs paid vs compliance platforms.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.