SOC 2 policies: which ones you need.

Policies are where SOC 2 starts, because the auditor tests you against what your own policies say. Here are the ones most audits expect and how to keep them honest.

SOC 2 guide · By Elevated Vibration · Updated October 2026

Why policies matter

SOC 2 does not hand you a rulebook. You state how your company handles security, and the auditor checks that you do what you stated. A policy that promises more than you do creates a finding. A policy that describes reality passes.

The policies most audits expect

  • Information security: the overall program and who is responsible.
  • Access control: how access is granted, reviewed and removed.
  • Acceptable use: what employees may do with company systems and data.
  • Change management: how changes to your product are reviewed and released.
  • Incident response: what happens when something goes wrong.
  • Business continuity and disaster recovery: how you keep operating and restore data.
  • Risk management: how risks are identified and reviewed.
  • Vendor management: how vendors are assessed and monitored.
  • Data classification and retention: what data you hold, how it is labeled and how long it is kept.
  • HR security: onboarding, training, conduct and offboarding.
  • Asset management: how devices and systems are tracked.
  • Vulnerability management: how weaknesses are found and fixed, and how quickly.

Your auditor and your scope determine the exact list.

How to make them match reality

  • Start from templates, then read every sentence and ask whether it is true today.
  • Replace specific promises you can't keep. If the template says access is removed within one day and you take three, change the policy or the practice.
  • Name roles, not people, as owners.
  • Keep them short enough that employees will read them.

Approval and acceptance

Each policy needs an approver, an approval date and a review at least once a year. Every employee needs to accept the relevant policies, and new hires need to do so as part of onboarding. Both leave records the auditor will ask to see.

Policies are not procedures

A policy says what must happen. A procedure says how it is done here, step by step. You need both. See how to write an SOP.

We write and roll out the policies, then make sure practice matches them. See SOC 2 readiness and audit management.

Related articles

How to Set Up Vanta for SOC 2

What to connect, configure and assign when you set up Vanta, in the order that saves rework.

How to Write an SOP People Will Actually Follow

How to document a process so that someone else can do it without asking you.

The Systems You Need to Be Compliant, by Department

The systems to have in place across HR, Finance, IT, Web, Operations and RevOps, and what each one proves.

Common questions

Straight answers.

How many policies does SOC 2 require?

SOC 2 does not set a number. Most companies end up with roughly a dozen to twenty policies, depending on scope and how they are grouped.

Can we use policy templates for SOC 2?

Yes, as a starting point. Each one must be edited to describe what your company actually does, because the auditor tests you against the text.

How often should SOC 2 policies be reviewed?

At least once a year, and whenever the way you work changes.

Need policies that match how you work?

Tell us where things stand. We'll tell you what it will take.

Book a free call