The SOC 2 policy checklist: 18 policies that cover all 38 criteria

SOC 2 doesn't publish a required document list — auditors test the 2017 Trust Services Criteria and expect your policy set to demonstrably address each one. That vagueness is why teams either over-write (fifty thin documents nobody follows) or under-write (gaps discovered mid-audit). Mapped properly, 18 well-constructed policies cover all 38 criteria for the security, availability and confidentiality categories.

Criteria-to-policy map

Criteria familyWhat auditors testCovering policies
CC1 — Control environmentIntegrity, board oversight, structure, competence, accountabilityInformation Security, Human Resources Security, Acceptable Use (+ a governance charter for CC1.2/1.3 board evidence)
CC2 — CommunicationQuality of information, internal & external communicationInformation Security, HR Security, Incident Response, Risk Assessment
CC3 — Risk assessmentObjectives, risk identification, fraud, changeRisk Assessment & Treatment, Information Security, Change Management
CC4 — MonitoringEvaluations of controls, deficiency handlingInformation Security, Vulnerability Management, Risk Assessment
CC5 — Control activitiesMitigating controls, technology controls, deployment via policiesInformation Security, Business Continuity & DR, Third-Party Management
CC6 — Access controlsLogical & physical access, disposal, boundaries, transmissionAccess Control, Password, Cryptography & Key Management, Asset & Media, Classification & Handling
CC7 — OperationsVulnerabilities, anomalies, incidents, recoveryVulnerability Management, Logging & Monitoring, Incident Response, Malware Protection
CC8 — ChangeInfrastructure, data and software change managementChange Management, Vulnerability Management, Asset & Media
CC9 — Risk mitigationDisruption risk, vendor & partner riskBusiness Continuity & DR, Third-Party & Vendor Management, Risk Assessment
A1 — AvailabilityCapacity, environmental protection, recovery testingBackup & Recovery, Business Continuity & DR, Logging & Monitoring
C1 — ConfidentialityIdentification, protection, disposal of confidential dataInformation Classification & Handling, Data Retention & Disposal

The conditional criteria

Two criteria series only apply if they're in your report's scope: processing integrity (PI1.1–PI1.5), addressed by a dedicated Processing Integrity Policy, and privacy (P1–P8), addressed by a Data Protection Policy covering notice, consent, data-subject rights, disclosure records and breach notification. Don't pad your core set with them unless your auditor scopes them in.

What matters more than the list

Auditors sample consistency: the same defined terms in every document, one severity scheme, one set of retention values, and policy statements written as testable obligations rather than aspirations. A pack of policies that contradicts itself on the 15-minute session timeout fails the smell test on day one. Whatever set you adopt, verify the cross-references before your auditor does.

Shortcut: the MeerLock Starter pack is exactly this 18-policy set — verified line-by-line against all 38 criteria, one doctrine throughout, and every policy carries the annex table showing the criteria it satisfies. See what's inside →

Skip the blank page

18 core policies, 38/38 criteria, ISMS Toolkit included — €590 one-time. Or get a free sample policy first.

Get a sample policy →