The SOC 2 policy checklist: 18 policies that cover all 38 criteria
SOC 2 doesn't publish a required document list — auditors test the 2017 Trust Services Criteria and expect your policy set to demonstrably address each one. That vagueness is why teams either over-write (fifty thin documents nobody follows) or under-write (gaps discovered mid-audit). Mapped properly, 18 well-constructed policies cover all 38 criteria for the security, availability and confidentiality categories.
Criteria-to-policy map
| Criteria family | What auditors test | Covering policies |
|---|---|---|
| CC1 — Control environment | Integrity, board oversight, structure, competence, accountability | Information Security, Human Resources Security, Acceptable Use (+ a governance charter for CC1.2/1.3 board evidence) |
| CC2 — Communication | Quality of information, internal & external communication | Information Security, HR Security, Incident Response, Risk Assessment |
| CC3 — Risk assessment | Objectives, risk identification, fraud, change | Risk Assessment & Treatment, Information Security, Change Management |
| CC4 — Monitoring | Evaluations of controls, deficiency handling | Information Security, Vulnerability Management, Risk Assessment |
| CC5 — Control activities | Mitigating controls, technology controls, deployment via policies | Information Security, Business Continuity & DR, Third-Party Management |
| CC6 — Access controls | Logical & physical access, disposal, boundaries, transmission | Access Control, Password, Cryptography & Key Management, Asset & Media, Classification & Handling |
| CC7 — Operations | Vulnerabilities, anomalies, incidents, recovery | Vulnerability Management, Logging & Monitoring, Incident Response, Malware Protection |
| CC8 — Change | Infrastructure, data and software change management | Change Management, Vulnerability Management, Asset & Media |
| CC9 — Risk mitigation | Disruption risk, vendor & partner risk | Business Continuity & DR, Third-Party & Vendor Management, Risk Assessment |
| A1 — Availability | Capacity, environmental protection, recovery testing | Backup & Recovery, Business Continuity & DR, Logging & Monitoring |
| C1 — Confidentiality | Identification, protection, disposal of confidential data | Information Classification & Handling, Data Retention & Disposal |
The conditional criteria
Two criteria series only apply if they're in your report's scope: processing integrity (PI1.1–PI1.5), addressed by a dedicated Processing Integrity Policy, and privacy (P1–P8), addressed by a Data Protection Policy covering notice, consent, data-subject rights, disclosure records and breach notification. Don't pad your core set with them unless your auditor scopes them in.
What matters more than the list
Auditors sample consistency: the same defined terms in every document, one severity scheme, one set of retention values, and policy statements written as testable obligations rather than aspirations. A pack of policies that contradicts itself on the 15-minute session timeout fails the smell test on day one. Whatever set you adopt, verify the cross-references before your auditor does.
Shortcut: the MeerLock Starter pack is exactly this 18-policy set — verified line-by-line against all 38 criteria, one doctrine throughout, and every policy carries the annex table showing the criteria it satisfies. See what's inside →
Skip the blank page
18 core policies, 38/38 criteria, ISMS Toolkit included — €590 one-time. Or get a free sample policy first.
Get a sample policy →