Skip to content

Policies SOC 2 expects

The policy set a SOC 2 auditor looks for, mapped to our document that satisfies it. Every one of these already exists in the ISMS — most need owner approval to move from draft to audit-ready.

Last built 2026-08-23.

What SOC 2 expects CC Our document
Information Security Policy CC2.1 isms5-informationsecuritypolicy.md
Code of Conduct / HR Security (incl. disciplinary) CC1.1 a05-hrsecuritypolicy.md
Confidentiality / NDA CC1.1 a06-non-disclosure-agreement.md
Employment contract security terms CC1.1 a06-guidelines-for-inclusion-in-employment-contracts.md
Roles & responsibilities (security owner) CC1.3 ISMS-DOC-05-2-roles-responsibilities-and-authorities.md
Employee screening CC1.4 a06-employee-screening-procedures.md
Security awareness & training CC2.2 ISMS-DOC-07-1-competence-awareness-and-training.md
Training log (records) CC2.2 ISMS-DOC-07-5-training-and-awareness-log.md
Event reporting / whistleblowing CC2.3 a06-information-security-event-reporting-procedure.md
Security objectives CC3.1 isms6-infosec-objectives-plan.md
Risk assessment process CC3.2 ISMS-DOC-06-2-risk-assessment-and-treatment-process.md
Risk assessment results CC3.2 ISMS-DOC-06-3-risk-assessment-report.md
Risk treatment plan CC3.2 risk-treatment-plan.md
Internal audit CC4.1 ISMS-DOC-09-2-procedure-for-internal-audits.md
Monitoring & measurement CC4.1 ISMS-DOC-09-1-monitoring-measurement-analysis-and-evaluation.md
Continuous control monitoring (automated) CC4.1 ISMS-DOC-09-6-continuous-control-monitoring-and-grc-architecture.md
Nonconformity & corrective action CC4.2 ISMS-DOC-10-1-nonconformity-and-corrective-action-procedure.md
Statement of Applicability (controls ↔ risks) CC5.1 ISMS-FORM-06-2-statement-of-applicability.md
Access control policy CC6.1 a05-access-control-policy.md
User access management (joiner/mover/leaver) CC6.2 ISMS-DOC-A05-18-1-user-access-management-process.md
Asset inventory CC6.1 ISMS-DOC-A05-9-2-information-asset-inventory.md
Asset management policy CC6.1 a05-asset-management-policy.md
Remote working (physical/device) CC6.4 a06-remote-working-policy.md
Clear desk & clear screen CC6.4 a07-clear-desk-and-clear-screen-policy.md
Records retention & protection CC6.5 a05-records-retention-and-protection-policy.md
Data deletion / disposal CC6.5 a08-10-information-deletion-policy.md
Network / cloud infrastructure security CC6.6 a08-network-security-policy.md
Cloud services policy CC6.6 a05-cloud-service-policy.md
Cryptography (in transit & at rest) CC6.7 a08-cryptographic-policy.md
Endpoint protection / anti-malware CC6.8 a08-anti-malware-policy.md
Device management (BYOD/mobile) CC6.8 a08-mobile-device-policy.md
Vulnerability & threat management CC7.1 a08-technical-vulnerability-management-policy.md
Configuration management CC7.1 a08-configuration-management-policy.md
Logging & monitoring CC7.2 a08-logging-and-monitoring-policy.md
Incident response CC7.4 ISMS-DOC-A05-26-1-information-security-incident-response-procedure.md
Personal data breach notification (GDPR) CC7.4 ISMS-DOC-A05-34-2-personal-data-breach-notification-procedure.md
Backup CC7.5 a08-backup-policy.md
Availability management CC9.1 a08-availability-management-policy.md
Change management CC8.1 isms8-change-management-process.md
Secure development (SDLC) CC8.1 a08-secure-development-policy.md
Supplier / vendor management CC9.2 a05-information-security-policy-for-supplier-relationships.md
Privacy & personal data protection CC9.2 a05-privacy-and-personal-data-protection-policy.md
Evidence collection & management CC4.1 ISMS-DOC-07-7-evidence-collection-and-management.md
Evidence register CC4.1 ISMS-FORM-07-2-evidence-register.md

Status of each document

The live status (draft / approved), owner and review date for every document is in the Document Register. Only approved documents count for certification — see the dashboard.

Not a policy — but the auditor will ask

Item Where it lives
System Description (required Type 1 deliverable) to write — inputs in Context & Scope
Penetration test report GetAgency engagement — pending
Backup restore test record pending — see Backup Policy
Sub-processor list & DPAs Asset inventory
Evidence for every control Evidence Register