Starter — Audit Essentials
FIRST SOC 2 AUDIT · SMALL ORGS
- 18 Core policies + customization guides
- ISMS Toolkit included — 24 templates & registers
- All 38 SOC 2 criteria covered outright
€590 one-time · toolkit included
Get Starter →Thirty audit-ready policies, three tiers, one verified doctrine — plus the 24-artifact toolkit that closes the certification document list, 27 with the PCI Bundle and Complete.
Starter. The 18 Core policies cover all 38 criteria on their own.
Professional — Full ISMS. Toolkit included. Building software? Add Engineering.
PCI Bundle — all 250 requirements. Engineering for payment pages, Cloud for cloud CDEs.
Add the Privacy module — RoPA and DPIA templates included.
One-time prices, editable sources, covered by the Fix-It Promise.
Online purchase opens soon — you can explore the packs and prices now; write to contact@meerlock.com.
FIRST SOC 2 AUDIT · SMALL ORGS
€590 one-time · toolkit included
Get Starter →MOST SMEs & MID-MARKET
€1,390 one-time · toolkit included
Get Professional →MERCHANTS & SERVICE PROVIDERS
€1,490 one-time · toolkit included
Get PCI Bundle →REGULATED / MULTI-MODEL ORGS
€1,990 one-time · saves €543 vs parts
Get Complete →All bundles include free revisions within current framework versions.
The PCI DSS Compliance Policy is not one of these: it ships inside the PCI Bundle and Complete, and is not sold separately.
Each control traced to the exact policy section that satisfies it (matrix v2.3, August 2026).
Security, availability and confidentiality (2017 TSC) fully covered by the 18 Core policies. Processing-integrity and privacy series covered by conditional add-ons.
78 controls in Core, 11 in the standard extensions, 4 secure-development controls in the Engineering add-on. Zero uncovered; clause-level policy requirements satisfied.
Requirement-level coverage incl. Appendices A1/A2 via the PCI Bundle, with all future-dated v4.0.1 requirements treated as mandatory.
The honest limits, up front: no template pack can pre-write your network diagrams, per-platform configuration standards, ASV attestations, training records or the executed SAQ/ROC. Our policies mandate each of these, the guides say who produces them, and the toolkit templates the recurring evidence — but they remain yours to complete.
Every control statement in the pack is a decision someone on your team would otherwise research, draft, debate and defend to an auditor. What that costs without a pack:
| Policy | Tier | What it covers |
|---|---|---|
| Information Security Policy | Core | Master policy — the governance spine every other policy hangs from |
| Risk Assessment & Treatment Policy | Core | Risk engine: ISO Cl. 6/8, SOC 2 CC3, PCI 12.3 targeted risk analyses |
| Acceptable Use Policy | Core | All-staff umbrella every auditor requests (ISO A.5.10) |
| Access Control Policy | Core | ISO A.5.15–A.8.5, PCI Req 7–8, SOC 2 CC6 — always tested |
| Password Policy | Core | All-staff authentication rules; PCI Req 8 parameters pre-filled |
| Human Resources Security Policy | Core | Screening-to-exit lifecycle incl. sanctions; ISO A.6, PCI 12.7 |
| Asset & Media Management Policy | Core | Inventory + media controls; ISO A.5.9–A.7.14, PCI Req 9.4 |
| Information Classification & Handling Policy | Core | The handling scheme other policies reference; ISO A.5.12–A.5.13 |
| Data Retention & Disposal Policy | Core | Records lifecycle; ISO A.5.33/A.7.14, PCI 3.2.1, SOC 2 C-series |
| Cryptography & Key Management Policy | Core | ISO A.8.24, PCI Req 3–4, SOC 2 CC6.7 — always in scope |
| Logging & Monitoring Policy | Core | ISO A.8.15–A.8.17, PCI Req 10, SOC 2 CC7 — always tested |
| Malware Protection Policy | Core | ISO A.8.7, PCI Req 5, SOC 2 CC6.8 |
| Vulnerability Management Policy | Core | Scanning, patching, pen testing; ISO A.8.8, PCI Req 6/11 |
| Change Management Policy | Core | ISO A.8.32, PCI 6.5, SOC 2 CC8 — always tested |
| Incident Response Policy | Core | ISO A.5.24–A.5.28, PCI 12.10, SOC 2 CC7.3–7.5 — most-referenced policy in the pack |
| Backup & Recovery Policy | Core | ISO A.8.13; the availability baseline in any audit |
| Business Continuity & DR Policy | Core | ISO A.5.29–A.5.30, SOC 2 A-series/CC9.1 |
| Third-Party & Vendor Management Policy | Core | ISO A.5.19–A.5.23, PCI 12.8, SOC 2 CC9.2 — always tested |
| Physical & Environmental Security Policy | Extension | Wherever premises exist; ISO A.7, PCI Req 9 — remote-first orgs keep a slim version |
| Network Security Policy | Extension | Self-managed network/Wi-Fi/VPN estates; ISO A.8.20–22, PCI Req 1 |
| Mobile & Teleworking Security Policy | Extension | Remote/hybrid workforce and corporate mobile devices; ISO A.6.7/A.8.1 |
| Electronic Communications Policy | Extension | Email/IM conduct depth beyond the AUP |
| PCI DSS Compliance Policy | PCI Bundle | Payment-card policy for merchants/TPSPs — ships in the PCI Bundle and Complete, never sold as a separate add-on module; pairs with pre-set PCI switches pack-wide |
| Cloud Security & Compliance Policy | Add-on | Any organisation consuming IaaS/PaaS or significant SaaS |
| Virtualization Security Policy | Add-on | Hypervisor and container estates, on-prem or hosted |
| Secure Software Development Policy | Add-on | Engineering module; ISO A.8.25, A.8.27, A.8.28, A.8.30, PCI Req 6 development parts |
| Data Protection Policy | Add-on | Privacy module for GDPR/CCPA exposure; SOC 2 P-series |
| Processing Integrity Policy | Add-on | Conditional module for SOC 2 processing-integrity criteria (PI1.1–PI1.5) |
| Code of Conduct | Add-on | Ethics/HR module — often board-owned; standalone-capable |
| Capacity Management Policy | Add-on | IT-operations module; ISO A.8.6, SOC 2 A1.1 availability commitments |
Auditors ask for the documents around the policies — the toolkit ships all of them, pre-aligned.
The Information Security Policy exactly as it ships, plus the guide that walks you through adapting it clause by clause.
Yes. The Core tier alone covers all 38 SOC 2 criteria for security, availability and confidentiality (2017 TSC). Processing-integrity and privacy criteria are covered by the conditional Processing Integrity and Data Protection add-on policies.
The Professional bundle covers 89 of 93 Annex A controls; the remaining four secure-development controls (A.8.25, A.8.27, A.8.28, A.8.30) live in the Engineering add-on and only apply if you develop software. Its ISMS Toolkit (included) ships the Statement of Applicability, risk register and audit programme the certifier asks for. No Annex A control is left uncovered.
Yes — the PCI Bundle (Professional plus the PCI DSS Compliance Policy, toolkit included) provides requirement-level coverage of all 250 PCI DSS v4.0.1 requirements plus Appendices A1/A2. Add Engineering if you develop payment pages, Cloud if your CDE is cloud-hosted. Assessors will still ask for artifacts only you can produce — network diagrams, configuration standards, ASV attestations, the executed SAQ/ROC — which the policies mandate and the toolkit templates.
Every policy ships with its own customization guide, 622 pre-filled recommended defaults (highlighted, changeable), conditional applicability switches for PCI/cloud/development contexts, and a consistent set of shared defined terms — one severity scheme, one retention doctrine, zero contradictions across the pack.
24 artifacts in every bundle: a pre-populated Statement of Applicability, an ISMS scope and objectives statement, a security governance charter, a risk register and treatment workbook, a targeted risk analysis register, an internal audit programme and procedure, a management review minutes template, a corrective-action log, an exception register, incident-response runbooks, an access provisioning procedure, a backup and restoration procedure, a BIA workbook, a business continuity plan template, an exercise and test register, an exercise and test record template, an asset inventory register, a vendor register, a data retention schedule, a training and acknowledgment register, a RoPA register, a DPIA template, a key custodian acknowledgment form, and editable network and data-flow diagram samples. The PCI Bundle and Complete add three payment-card workbooks, for 27 in total: the PCI scope confirmation workbook, the PCI periodic evidence register and the TPSP responsibility matrix.
We design against it: every policy is traced control-by-control to its framework. If your auditor or assessor challenges the content of a pack policy, tell us what they said and we amend the document at no charge — for you and for every other customer. That's the Fix-It Promise. It covers our documents, not your organisation's own implementation, evidence or configuration, and a challenged document is fixed rather than refunded (sections 3 and 5 of the terms). And if you're under 25 employees, apply for the early-stage code — 20% off any bundle after a quick check.
Tell us your framework and operating model — we'll confirm the exact bundle and modules you need before you spend anything.
Online purchase opens soon — you can explore the packs and prices now; write to contact@meerlock.com.
✓ All seven modules are already inside Complete — nothing to add, nothing to pay.
Online purchase opens very soon. Leave your email and we will tell you when it opens. For anything else, write to contact@meerlock.com and we will reply personally.