How many policies SOC 2 needs, and the thirteen we write

No standard sets a number, so the count is a choice you make. What gets tested is whether you do what the documents say.

How many SOC 2 policies do I need? No number is required. The Trust Services Criteria describe outcomes, not a folder of files1, so any count you see online is somebody’s packaging. A small company can answer every Security criterion that needs writing with about a dozen documents. We use thirteen. Eight could work too.

The auditor does not count pages. They read what your documents promise and then check that you kept the promise.

So the real question is not how many. It is how few you can keep current, honest and signed, because every document you add is work you repeat each year.

Each policy is a cost you pay every year

A policy is quick to write once and expensive to own, because the writing happens one time and the upkeep happens every year after it. Every document needs an owner, an approval with a name and a date, a review on the interval it names, and evidence that people follow it. Double the documents and you roughly double that upkeep.

That is why the count matters so much to a small team with no security hire to absorb the extra work. Consultants bill by the hour to draft long policy sets, and template packs are sold by the dozen. A longer list looks thorough in a proposal. It also leaves you more files to review, and more chances for two of your own documents to disagree. Nobody else created that problem. You did, by buying volume.

Buy coverage of the criteria. Do not buy page count.

Start from the criteria, not from a template index

Some Security criteria are hard to meet without a document, because they describe an expectation the company sets and then shares with staff.1 Treat each one below as a subject you must cover. How you split the subjects into files is up to you.

CC1.1 and CC1.4
Integrity and competence. In practice: a code of conduct, plus the hiring and training rules that back it.
CC2.2
Telling staff what their security duties are. A document you can hand a new hire.
CC3.2
Finding and analyzing risk. A method, an interval, and an owner, all written down.
CC5.3
Control activities put in place through policies. This is the line behind the idea that SOC 2 requires policies.
CC6.1 through CC6.8
Logical access, credentials, encryption, devices, and how data is handled and destroyed.
CC7.2 through CC7.5
Monitoring, spotting incidents, responding, and recovering.
CC8.1
Change management, from review of the code to approval of the release.
CC9.2
Risk from vendors and partners, checked before purchase and again on a schedule.

That is eight groups. Thirteen files is one sensible way to cover them, and twenty five is another. Six would be fine if every one stayed current and was really followed by the people it names. What does not work is leaving a group empty. An auditor will not read a missing subject as a short policy set. They will read it as a gap.

Why the published lists disagree

Take access control as the example, since it splits into pieces so easily. You can write it as one document with four sections: granting, passwords, review and removal. Or you can write four separate policies. The criteria are met the same way in both cases, and the only real difference is how many approvals, reviews and signatures you have to chase each year.

A list of twenty or more has split subjects this way. A list of ten or twelve has merged them. Neither is wrong. Both are describing a standard that never set a number.

The thirteen documents we generate

Here is the full set, with nothing hidden behind a form or an email gate, and the right column says what each one has to cover. Your copy is written from your own questionnaire answers and your own tools, so the wording is yours. The list of subjects is the same for everyone.

DocumentWhat it must cover
Information Security PolicyThe parent document. What is in scope, who owns security, and who approves the other twelve.
Access Control PolicyGranting access, multi-factor, privileged accounts, how often access is reviewed, removal at exit.
Human Resources Security PolicyScreening, onboarding, training and how often it repeats, and the offboarding deadline.
Code of Conduct PolicyExpected behavior, conflicts of interest, where to report a concern, and the consequences.
Risk Management PolicyHow a risk is found, scored and given an owner, and when the register is reviewed again.
Incident Response PolicySeverity levels, who is called, containment, notice duties, and the review afterward.
Business Continuity and Disaster Recovery PolicyRecovery targets, what is backed up, restore tests, and who can declare a disaster.
Operations Security PolicyLogging, alerts, malware protection, patching windows, and capacity checks.
Secure Development PolicyProtected branches, peer review, test gates, separate environments, release approval.
Cryptography PolicyEncryption at rest and in transit, key custody, approved algorithms, and key rotation.
Data Management PolicyData classes, how long each is kept, how it is deleted, and where sensitive data may live.
Asset Management PolicyThe laptop and cloud inventory, owners, disk encryption, and safe disposal.
Third Party and Vendor Management PolicyThe check before a vendor is bought, and how often that vendor is checked again.

All thirteen are part of the software. That is $199 a month, cancel any time, or $2,189 a year, pay for eleven months, get twelve. There is no separate policy fee and no consultant hours. Someone at your company still has to approve and sign each one, since an unsigned policy is only a draft. The evidence binder records who approved what and when. What SOC 2 costs from start to finish shows the rest of the costs around this line.

ThirteenDocuments we generate from your answers
EightCriteria groups those documents answer
ZeroPolicies the criteria name as required
Who reads the finished set

During the examination, an independent partner auditor reviews these documents next to the evidence that you follow them. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.3

Promise only the review cycle you will run

Here is the part that costs money later. Once approved, your policy becomes the yardstick. The auditor tests you against your own words2, not against a generic best practice.

Say you write quarterly access reviews and then manage three in the year. That missed quarter is a deviation, recorded in the report your buyers read. Annual reviews, done on time, would have produced a clean line. Write the interval you can keep. Put it on a calendar. Tighten it next year once the habit is real and you have a full cycle of records to show for it.

Your wording sets the test

Quarterly only beats annual if it happens four times. Choose an interval you can prove without reminders. How a failed control shows up in the report explains what a deviation looks like to a buyer.

Five steps to your own list

Work from the criteria toward the files. A template index only tells you how someone else split the subjects, and it knows nothing about how your company runs.

  1. Match every criterion to a document. A criterion with no document is a gap. A document that answers no criterion is upkeep with no return.
  2. Merge first. Two files on one subject drift apart over time, and anyone who reads both will see it.
  3. Pick intervals you can keep, and book them before the approval, not after the first review is late.
  4. Give each document an owner. A policy with no owner is the first to go stale.
  5. Sign and date them. The approval record is the proof the policy exists.

Scope changes the number more than any list

A Security only report, which is the fixed scope in our product, needs fewer documents than one that adds Availability or Confidentiality. Each extra category brings its own subjects. Choosing your criteria walks through that choice, and SOC 2 for a small SaaS team covers what a company under twenty people really needs.

Type 2 makes intervals matter even more. Every review you promised has to happen inside the 3-month observation window, and each one has to leave a record.

See your own gaps before you spend anything

You do not need to buy a policy pack to learn which subjects you already cover. The free readiness assessment takes about 15 minutes and gives you a score, a gap list and one free AI sample policy. Nothing is charged. Start the free assessment, then compare the plans on our pricing when you know what is missing.

Questions

Is there a minimum number of SOC 2 policies?
No. The criteria describe what must be true about your controls and never list documents. A list of twelve and a list of twenty five can both satisfy the same criteria. We generate thirteen because that covers the Security criteria without splitting one subject into several files.
Which parts of SOC 2 need a written document?
The criteria where the company sets an expectation and tells people about it. That covers conduct and competence, communicating security duties, risk assessment, control activities set through policy, logical access, monitoring and incidents, change management, and vendor risk.
Is it fine to combine several policies into one?
Yes. One access document with sections for granting, reviewing and removing access meets the same criteria as four separate files. It also means fewer approvals each year and less chance that two of your own documents say different things.
What review interval should a policy promise?
The one you will really keep. The auditor tests you against your own approved text, so a quarterly promise you meet three times produces a deviation that an annual promise would not.
Can I just download a policy template pack?
You can start from one, but it only counts once it describes what your company actually does and someone has approved and dated it. A template that describes a security team you do not have creates a mismatch with your evidence.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  3. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.