The SOC 2 policy list, and why the count keeps changing
Published lists disagree because the standard never sets a number. Here is what the criteria actually ask for, and the thirteen documents that answer them.
How many SOC 2 policies do I need? There is no required number. SOC 2 names criteria, not documents1, so every published policy count is a packaging choice made by whoever wrote the list. Polara G.R.C. generates thirteen, listed in full below, because thirteen covers every Security criterion that expects something written without splitting one subject across three files.
The examination does not count your documents. It reads what they say, then tests whether you did it.
Search for a SOC 2 policy list and the answers disagree. One page names about a dozen. Another names more than two dozen and marks them all mandatory. Both are selling a template pack. Neither is lying, because the standard they are both describing never specifies a number.
Why no two lists agree
The Trust Services Criteria are written as criteria. Not as a table of contents. The Security category, which is the only scope Polara G.R.C. offers, says what has to be true about your access control, your change process, your incident handling and your vendors, and it says nothing at all about how many files that takes.
Packaging is the whole difference. Split access control into an access policy, a password policy, an authentication policy and a remote access policy, and you have four documents. Keep the same material in one document with four sections and you have one. The criteria are satisfied identically either way.
Longer lists photograph well in a sales deck. They are also more surface to keep current, and more places for two of your own documents to disagree with each other. That last one you created yourself.
The criteria that expect something written
Some Security criteria are difficult to satisfy without a document, because they describe an expectation the company sets and then communicates.1 Read them as subject areas rather than as filenames, because the mapping from one to the other is yours to choose.
- CC1.1 and CC1.4
- Commitment to integrity and to competence. A code of conduct, and the hiring and training expectations behind it.
- CC2.2
- Internal communication of security responsibilities. Something written that a new hire can be pointed at on day one.
- CC3.2
- Risk identification and analysis. A stated method, a stated interval, and a named owner.
- CC5.3
- Control activities deployed through policies that establish what is expected. This is the criterion people mean when they say SOC 2 requires policies.
- CC6.1 through CC6.8
- Logical access, credentials, encryption, endpoints, and how data is handled and disposed of.
- CC7.2 through CC7.5
- Monitoring, incident identification, response, and recovery.
- CC8.1
- Change management, from code review through to deployment approval.
- CC9.2
- Vendor and business partner risk, before purchase and on a schedule after.
Eight groups. Thirteen documents is one reasonable way to cover them, twenty five is another, and six would be defensible if each one were current and genuinely followed. What you cannot do is leave a group unanswered and hope the auditor reads the gap as brevity.
The thirteen Polara writes, in full
Nothing here is gated, and the second column is what each document has to contain. Yours are written from your questionnaire answers and your own stack, so the contents differ from anyone else’s. The list does not.
| Policy | What it has to contain |
|---|---|
| Information Security Policy | The umbrella. Scope, the owner, how the other twelve sit under it, and who approves them. |
| Access Control Policy | Provisioning, review interval, removal on termination, privileged accounts, multi-factor. |
| Human Resources Security Policy | Background checks, onboarding steps, security training and its frequency, offboarding timing. |
| Code of Conduct Policy | Expected conduct, conflicts of interest, the reporting channel, and what follows a breach of it. |
| Risk Management Policy | How risks are identified, scored, assigned an owner, and re-reviewed, plus the interval. |
| Incident Response Policy | Severity tiers, who gets called, containment, notification duties, and the post-incident review. |
| Business Continuity and Disaster Recovery Policy | Recovery objectives, backup scope, restore testing, and who is allowed to declare an event. |
| Operations Security Policy | Logging, alerting, malware protection, patch windows, and capacity monitoring. |
| Secure Development Policy | Branch protection, code review, test gates, environment separation, deployment approval. |
| Cryptography Policy | What is encrypted at rest and in transit, who holds the keys, algorithms, rotation. |
| Data Management Policy | Classification, retention, deletion, and where regulated data is permitted to live. |
| Asset Management Policy | Inventory of endpoints and cloud resources, ownership, disk encryption, disposal. |
| Third Party and Vendor Management Policy | How a vendor is reviewed before purchase, and on what schedule it is reviewed again. |
All thirteen are included in the Type 1 price of $4,000 one time, generated against your answers rather than handed over as a template pack, then approved and signed by someone at your company. A policy nobody signed is a draft. The evidence binder records who approved each one and when, which is the part that gets tested. What certification costs end to end covers what else sits inside that number.
The pack is reviewed by an independent partner auditor during the examination, alongside the evidence that each document is followed in practice. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.3
Cadence is where teams hurt themselves
Your approved policy is the standard you get measured against. Not the criteria. Not a benchmark. The document you wrote, in your own words, is what the examination holds you to2, and it is the only version of your controls that has your signature on it.
Writing quarterly access reviews when you can sustain annual ones does not read as diligence. It manufactures three extra chances a year to miss one, and a control you promised in writing and then skipped is how a deviation gets recorded against you. Promise the interval you will keep. Keep it. Raise it next year, once the habit exists.
Quarterly beats annual only if quarterly happens four times. Pick the interval you can evidence without being chased for it. What happens when a control fails covers how a deviation reads in a finished report and what it costs you in a live deal.
How to decide your own number
Work from the criteria toward the documents, never the other way around. A template index tells you what someone else packaged. It cannot tell you what your company does.
- Map each criterion to the document that answers it. Any criterion with no document is a real gap. Any document mapped to nothing is a file you will maintain forever for no reason.
- Merge before you split. Two documents on one subject drift apart, and the drift is visible to anyone reading both.
- Write the interval you can keep, then put it on a calendar before the approval goes through, not after the first review is already late.
- Name an owner per document. Unowned policies are the first ones to go stale, because nobody has the review in their week.
- Get them signed and dated. Approval with a name and a date is the evidence that the policy exists at all.
Scope moves the count more than any list will. Security only, which is the fixed scope of Polara G.R.C., needs fewer documents than a report that also carries Availability or Confidentiality, because the extra criteria bring extra subject areas with them. Which criteria you should include walks that decision, and what Type 1 asks of a small team is the version written for companies under twenty people.
Type 2 sharpens the cadence question further, because every interval you wrote down has to fire during the 3-month observation window and leave a record behind it.
Questions
How many policies does SOC 2 require?
Which SOC 2 criteria actually expect a written policy?
Can I merge SOC 2 policies into fewer documents?
Should my policy say quarterly or annual reviews?
Do SOC 2 policy templates count?
Sources
Get audit-ready without a compliance team.
$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Get startedPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.