All guides

Policies and compliance

Which security policies do you need for SOC 2?

SOC 2 does not hand you a list of policies, but auditors expect written policies behind your controls. Here are the ones most small companies write, and what each covers.

Updated October 2026 ยท 7 min read

SOC 2 is an audit report, based on the AICPA's Trust Services Criteria, that shows customers how you protect their data. It does not prescribe a fixed set of policies. Instead, an auditor checks that you have controls meeting the criteria, and written policies are how you show those controls are defined, approved and communicated.

NoteYour auditor has the final say. Use this list as a starting point, and confirm scope with them early.

The policies most small companies write

PolicyWhat it covers
Information security policyThe top-level policy: who is responsible, how security is managed, and how the other policies fit together
Access controlWho gets access to what, approval, multi-factor authentication, reviews, and removing access when people leave
Acceptable useWhat staff may and may not do with company devices, accounts and data
Risk assessment and managementHow you find, rate and treat risks, and how often you review them
Change managementHow changes to systems and code are requested, reviewed, tested and approved
Incident responseHow incidents are reported, handled, escalated and reviewed
Business continuity and disaster recoveryBackups, recovery targets, and how you keep running during an outage
Vendor managementHow you assess and monitor suppliers who handle your data
Data classification and retentionHow data is labelled, handled, kept and destroyed
Encryption and key managementWhen data must be encrypted, and how keys are protected
Logging and monitoringWhat is logged, who reviews it, and how alerts are handled
Vulnerability and patch managementScanning, patch timelines and tracking fixes
Human resources securityBackground checks, onboarding, training and offboarding

Making policies pass an audit

  • Match reality.Auditors test that you do what the policy says. A policy promising quarterly access reviews you never run creates a finding.
  • Name owners and approvers.Each policy needs a version, an owner, an approval date and a review date.
  • Review them yearly.Keep a change history so you can show the review happened.
  • Communicate them.Staff should acknowledge the policies that apply to them, typically at onboarding and once a year.
  • Keep them short.A clear, five-page policy people read beats a forty-page one nobody opens.

Type 1 or Type 2?

A Type 1 report checks your controls are designed properly at a single point in time. A Type 2 report checks they actually operated over a period, commonly three to twelve months. Many small companies start with Type 1 to unblock sales, then move to Type 2. Either way, the policies need to be in place first.

General information, not legal advice. Laws, contracts and provider processes change; check the linked sources for current details.

Sign in