Every policy on the shelf, unpacked.

Thirty audit-ready policies, three tiers, one verified doctrine — plus the 24-artifact toolkit that closes the certification document list, 27 with the PCI Bundle and Complete.

30 policies · 3 tiers 24-artifact ISMS Toolkit · 27 with the PCI Bundle and Complete 1,781 control statements 662 rendered pages · 30 diagrams
Start here

Which pack do you need?

SOC 2 audit

Starter. The 18 Core policies cover all 38 criteria on their own.

ISO 27001 certification

Professional — Full ISMS. Toolkit included. Building software? Add Engineering.

PCI DSS v4.0.1

PCI Bundle — all 250 requirements. Engineering for payment pages, Cloud for cloud CDEs.

GDPR / CCPA exposure

Add the Privacy module — RoPA and DPIA templates included.

Or answer three questions and we'll point you.

Packaging

Bundles & tiers

One-time prices, editable sources, covered by the Fix-It Promise.

Starter — Audit Essentials

FIRST SOC 2 AUDIT · SMALL ORGS

  • 18 Core policies + customization guides
  • ISMS Toolkit included — 24 templates & registers
  • All 38 SOC 2 criteria covered outright

€590 one-time · toolkit included

Get Starter →

Professional — Full ISMS

MOST SMEs & MID-MARKET

  • Core + 4 standard extensions — 22 policies
  • ISMS Toolkit included — SoA, risk register, audit programme
  • With Engineering add-on: 93/93 ISO 27001 Annex A controls

€1,390 one-time · toolkit included

Get Professional →

PCI Bundle

MERCHANTS & SERVICE PROVIDERS

  • Professional + the PCI DSS Compliance Policy
  • All 250 PCI DSS v4.0.1 requirements + Appendices A1/A2
  • Scoping workbook & periodic evidence register in the toolkit

€1,490 one-time · toolkit included

Get PCI Bundle →

Complete

REGULATED / MULTI-MODEL ORGS

  • All 30 policies — every extension and every module
  • ISMS Toolkit included
  • One doctrine: shared terms, one severity scheme, zero contradictions

€1,990 one-time · saves €543 vs parts

Get Complete →

All bundles include free revisions within current framework versions.

The Fix-It Promise. If your auditor or assessor challenges the content of a pack policy, tell us what they said and we amend the document at no charge — for you and for every other customer. It covers our documents, not your own implementation, evidence or configuration.
Early-stage programme. Under 25 employees? Apply for the −20% code — a 30-second check, then use it when you order. Starter comes to €472.
Add-on modules · €149 each Engineering · software development Cloud · IaaS/PaaS/SaaS Privacy · GDPR/CCPA Virtualization · hypervisors Ethics · Code of Conduct Capacity · IT operations Processing Integrity · SOC 2 PI series

The PCI DSS Compliance Policy is not one of these: it ships inside the PCI Bundle and Complete, and is not sold separately.

Verified coverage

Mapped to the frameworks auditors actually test

Each control traced to the exact policy section that satisfies it (matrix v2.3, August 2026).

38 / 38

SOC 2 criteria — Core tier alone

Security, availability and confidentiality (2017 TSC) fully covered by the 18 Core policies. Processing-integrity and privacy series covered by conditional add-ons.

93 / 93

ISO 27001:2022 Annex A

78 controls in Core, 11 in the standard extensions, 4 secure-development controls in the Engineering add-on. Zero uncovered; clause-level policy requirements satisfied.

250 / 250

PCI DSS v4.0.1 requirements

Requirement-level coverage incl. Appendices A1/A2 via the PCI Bundle, with all future-dated v4.0.1 requirements treated as mandatory.

The honest limits, up front: no template pack can pre-write your network diagrams, per-platform configuration standards, ASV attestations, training records or the executed SAQ/ROC. Our policies mandate each of these, the guides say who produces them, and the toolkit templates the recurring evidence — but they remain yours to complete.

Why this pack

It's not paper. It's 1,781 decisions already made.

Every control statement in the pack is a decision someone on your team would otherwise research, draft, debate and defend to an auditor. What that costs without a pack:

100+ hourswriting 18+ policies from scratch — ≈€5,000+ of founder or engineer payroll
€5,000–€15,000a consultant drafting them for you
≈€1,000+ / yeara GRC platform subscription — with thinner documents, forever
€590 oncethe Starter pack, toolkit included, deployable in weeks, not quarters
The alternatives

Free templates, a GRC platform, or MeerLock?

Free template collections

  • Mixed authorship — terms, defaults and severity schemes contradict across documents
  • No framework traceability; the gaps surface during your audit, at the worst moment
  • Mapping, versioning and maintenance are all on you

GRC platform subscriptions

  • Strong evidence automation — but bundled policies are thin templates behind a recurring fee
  • Document depth is rarely audit-grade on its own
  • Works best on top of a real policy layer; it doesn't replace one

MeerLock packs

  • One doctrine: shared defined terms, one severity scheme, zero contradictions — verified pack-wide
  • Line-by-line traceability to ISO 27001, SOC 2 and PCI DSS, re-verified at every revision
  • One-time price, fully editable sources, and a toolkit that closes the certification document list
The full shelf

All 30 policies, by tier

PolicyTierWhat it covers
Information Security PolicyCoreMaster policy — the governance spine every other policy hangs from
Risk Assessment & Treatment PolicyCoreRisk engine: ISO Cl. 6/8, SOC 2 CC3, PCI 12.3 targeted risk analyses
Acceptable Use PolicyCoreAll-staff umbrella every auditor requests (ISO A.5.10)
Access Control PolicyCoreISO A.5.15–A.8.5, PCI Req 7–8, SOC 2 CC6 — always tested
Password PolicyCoreAll-staff authentication rules; PCI Req 8 parameters pre-filled
Human Resources Security PolicyCoreScreening-to-exit lifecycle incl. sanctions; ISO A.6, PCI 12.7
Asset & Media Management PolicyCoreInventory + media controls; ISO A.5.9–A.7.14, PCI Req 9.4
Information Classification & Handling PolicyCoreThe handling scheme other policies reference; ISO A.5.12–A.5.13
Data Retention & Disposal PolicyCoreRecords lifecycle; ISO A.5.33/A.7.14, PCI 3.2.1, SOC 2 C-series
Cryptography & Key Management PolicyCoreISO A.8.24, PCI Req 3–4, SOC 2 CC6.7 — always in scope
Logging & Monitoring PolicyCoreISO A.8.15–A.8.17, PCI Req 10, SOC 2 CC7 — always tested
Malware Protection PolicyCoreISO A.8.7, PCI Req 5, SOC 2 CC6.8
Vulnerability Management PolicyCoreScanning, patching, pen testing; ISO A.8.8, PCI Req 6/11
Change Management PolicyCoreISO A.8.32, PCI 6.5, SOC 2 CC8 — always tested
Incident Response PolicyCoreISO A.5.24–A.5.28, PCI 12.10, SOC 2 CC7.3–7.5 — most-referenced policy in the pack
Backup & Recovery PolicyCoreISO A.8.13; the availability baseline in any audit
Business Continuity & DR PolicyCoreISO A.5.29–A.5.30, SOC 2 A-series/CC9.1
Third-Party & Vendor Management PolicyCoreISO A.5.19–A.5.23, PCI 12.8, SOC 2 CC9.2 — always tested
Physical & Environmental Security PolicyExtensionWherever premises exist; ISO A.7, PCI Req 9 — remote-first orgs keep a slim version
Network Security PolicyExtensionSelf-managed network/Wi-Fi/VPN estates; ISO A.8.20–22, PCI Req 1
Mobile & Teleworking Security PolicyExtensionRemote/hybrid workforce and corporate mobile devices; ISO A.6.7/A.8.1
Electronic Communications PolicyExtensionEmail/IM conduct depth beyond the AUP
PCI DSS Compliance PolicyPCI BundlePayment-card policy for merchants/TPSPs — ships in the PCI Bundle and Complete, never sold as a separate add-on module; pairs with pre-set PCI switches pack-wide
Cloud Security & Compliance PolicyAdd-onAny organisation consuming IaaS/PaaS or significant SaaS
Virtualization Security PolicyAdd-onHypervisor and container estates, on-prem or hosted
Secure Software Development PolicyAdd-onEngineering module; ISO A.8.25, A.8.27, A.8.28, A.8.30, PCI Req 6 development parts
Data Protection PolicyAdd-onPrivacy module for GDPR/CCPA exposure; SOC 2 P-series
Processing Integrity PolicyAdd-onConditional module for SOC 2 processing-integrity criteria (PI1.1–PI1.5)
Code of ConductAdd-onEthics/HR module — often board-owned; standalone-capable
Capacity Management PolicyAdd-onIT-operations module; ISO A.8.6, SOC 2 A1.1 availability commitments
The document layer

The ISMS Toolkit — 24 artifacts that close the document list · included with every bundle, 27 with the PCI Bundle and Complete

Auditors ask for the documents around the policies — the toolkit ships all of them, pre-aligned.

Govern

  • Statement of Applicability — pre-populated from the pack's annex tables
  • ISMS scope & objectives statement
  • Security governance charter (board oversight, reporting calendar)
  • Exception register (12-month cap enforced)

Risk & audit

  • Risk register & treatment workbook
  • Targeted risk analysis (TRA) register
  • Internal audit programme & procedure
  • Management review minutes template
  • Nonconformity & corrective-action log

Operate

  • Incident-response runbooks (six scenario classes incl. PAN discovery)
  • Access provisioning procedure (lifecycle + swimlane)
  • Backup & restoration procedure
  • Data retention schedule — green baselines pre-filled
  • Asset inventory & vendor registers
  • Network & data-flow diagram samples with editable sources
  • Key custodian acknowledgment form

Continuity

  • Business impact analysis (BIA) workbook
  • Business continuity plan template with scenario action cards
  • Exercise & test register with its record template
  • Training & acknowledgment register (incl. phishing campaigns)

Privacy

  • RoPA register — jurisdiction-neutral records of processing
  • DPIA template (screening + full assessment)

PCI DSS · PCI Bundle & Complete only

  • PCI scope confirmation workbook (seven tabs, worked examples)
  • PCI periodic evidence register (BAU schedule + review logs)
  • TPSP responsibility matrix
See inside before you buy

Get a full policy and its customization guide

The Information Security Policy exactly as it ships, plus the guide that walks you through adapting it clause by clause.

One email with both documents attached, nothing else.

We use your details only to answer you. Privacy notice.

Questions

Answered plainly

Do the 18 Core policies cover SOC 2?

Yes. The Core tier alone covers all 38 SOC 2 criteria for security, availability and confidentiality (2017 TSC). Processing-integrity and privacy criteria are covered by the conditional Processing Integrity and Data Protection add-on policies.

What do I need for ISO 27001:2022 certification?

The Professional bundle covers 89 of 93 Annex A controls; the remaining four secure-development controls (A.8.25, A.8.27, A.8.28, A.8.30) live in the Engineering add-on and only apply if you develop software. Its ISMS Toolkit (included) ships the Statement of Applicability, risk register and audit programme the certifier asks for. No Annex A control is left uncovered.

Does the pack cover PCI DSS v4.0.1?

Yes — the PCI Bundle (Professional plus the PCI DSS Compliance Policy, toolkit included) provides requirement-level coverage of all 250 PCI DSS v4.0.1 requirements plus Appendices A1/A2. Add Engineering if you develop payment pages, Cloud if your CDE is cloud-hosted. Assessors will still ask for artifacts only you can produce — network diagrams, configuration standards, ASV attestations, the executed SAQ/ROC — which the policies mandate and the toolkit templates.

How customizable are the policies?

Every policy ships with its own customization guide, 622 pre-filled recommended defaults (highlighted, changeable), conditional applicability switches for PCI/cloud/development contexts, and a consistent set of shared defined terms — one severity scheme, one retention doctrine, zero contradictions across the pack.

What is included in the ISMS Toolkit?

24 artifacts in every bundle: a pre-populated Statement of Applicability, an ISMS scope and objectives statement, a security governance charter, a risk register and treatment workbook, a targeted risk analysis register, an internal audit programme and procedure, a management review minutes template, a corrective-action log, an exception register, incident-response runbooks, an access provisioning procedure, a backup and restoration procedure, a BIA workbook, a business continuity plan template, an exercise and test register, an exercise and test record template, an asset inventory register, a vendor register, a data retention schedule, a training and acknowledgment register, a RoPA register, a DPIA template, a key custodian acknowledgment form, and editable network and data-flow diagram samples. The PCI Bundle and Complete add three payment-card workbooks, for 27 in total: the PCI scope confirmation workbook, the PCI periodic evidence register and the TPSP responsibility matrix.

What if my auditor rejects one of the policies?

We design against it: every policy is traced control-by-control to its framework. If your auditor or assessor challenges the content of a pack policy, tell us what they said and we amend the document at no charge — for you and for every other customer. That's the Fix-It Promise. It covers our documents, not your organisation's own implementation, evidence or configuration, and a challenged document is fixed rather than refunded (sections 3 and 5 of the terms). And if you're under 25 employees, apply for the early-stage code — 20% off any bundle after a quick check.

Ready to stock your armory?

Tell us your framework and operating model — we'll confirm the exact bundle and modules you need before you spend anything.

We read every message and reply personally · Back to the burrow

We use your details only to answer you. Privacy notice.