The SOC 2 policy list, and why the count keeps changing

Published lists disagree because the standard never sets a number. Here is what the criteria actually ask for, and the thirteen documents that answer them.

How many SOC 2 policies do I need? There is no required number. SOC 2 names criteria, not documents1, so every published policy count is a packaging choice made by whoever wrote the list. Polara G.R.C. generates thirteen, listed in full below, because thirteen covers every Security criterion that expects something written without splitting one subject across three files.

The examination does not count your documents. It reads what they say, then tests whether you did it.

Search for a SOC 2 policy list and the answers disagree. One page names about a dozen. Another names more than two dozen and marks them all mandatory. Both are selling a template pack. Neither is lying, because the standard they are both describing never specifies a number.

Why no two lists agree

The Trust Services Criteria are written as criteria. Not as a table of contents. The Security category, which is the only scope Polara G.R.C. offers, says what has to be true about your access control, your change process, your incident handling and your vendors, and it says nothing at all about how many files that takes.

Packaging is the whole difference. Split access control into an access policy, a password policy, an authentication policy and a remote access policy, and you have four documents. Keep the same material in one document with four sections and you have one. The criteria are satisfied identically either way.

Longer lists photograph well in a sales deck. They are also more surface to keep current, and more places for two of your own documents to disagree with each other. That last one you created yourself.

The count is a packaging decision. The contents are what gets examined.

The criteria that expect something written

Some Security criteria are difficult to satisfy without a document, because they describe an expectation the company sets and then communicates.1 Read them as subject areas rather than as filenames, because the mapping from one to the other is yours to choose.

CC1.1 and CC1.4
Commitment to integrity and to competence. A code of conduct, and the hiring and training expectations behind it.
CC2.2
Internal communication of security responsibilities. Something written that a new hire can be pointed at on day one.
CC3.2
Risk identification and analysis. A stated method, a stated interval, and a named owner.
CC5.3
Control activities deployed through policies that establish what is expected. This is the criterion people mean when they say SOC 2 requires policies.
CC6.1 through CC6.8
Logical access, credentials, encryption, endpoints, and how data is handled and disposed of.
CC7.2 through CC7.5
Monitoring, incident identification, response, and recovery.
CC8.1
Change management, from code review through to deployment approval.
CC9.2
Vendor and business partner risk, before purchase and on a schedule after.

Eight groups. Thirteen documents is one reasonable way to cover them, twenty five is another, and six would be defensible if each one were current and genuinely followed. What you cannot do is leave a group unanswered and hope the auditor reads the gap as brevity.

The thirteen Polara writes, in full

Nothing here is gated, and the second column is what each document has to contain. Yours are written from your questionnaire answers and your own stack, so the contents differ from anyone else’s. The list does not.

PolicyWhat it has to contain
Information Security PolicyThe umbrella. Scope, the owner, how the other twelve sit under it, and who approves them.
Access Control PolicyProvisioning, review interval, removal on termination, privileged accounts, multi-factor.
Human Resources Security PolicyBackground checks, onboarding steps, security training and its frequency, offboarding timing.
Code of Conduct PolicyExpected conduct, conflicts of interest, the reporting channel, and what follows a breach of it.
Risk Management PolicyHow risks are identified, scored, assigned an owner, and re-reviewed, plus the interval.
Incident Response PolicySeverity tiers, who gets called, containment, notification duties, and the post-incident review.
Business Continuity and Disaster Recovery PolicyRecovery objectives, backup scope, restore testing, and who is allowed to declare an event.
Operations Security PolicyLogging, alerting, malware protection, patch windows, and capacity monitoring.
Secure Development PolicyBranch protection, code review, test gates, environment separation, deployment approval.
Cryptography PolicyWhat is encrypted at rest and in transit, who holds the keys, algorithms, rotation.
Data Management PolicyClassification, retention, deletion, and where regulated data is permitted to live.
Asset Management PolicyInventory of endpoints and cloud resources, ownership, disk encryption, disposal.
Third Party and Vendor Management PolicyHow a vendor is reviewed before purchase, and on what schedule it is reviewed again.

All thirteen are included in the Type 1 price of $4,000 one time, generated against your answers rather than handed over as a template pack, then approved and signed by someone at your company. A policy nobody signed is a draft. The evidence binder records who approved each one and when, which is the part that gets tested. What certification costs end to end covers what else sits inside that number.

ThirteenDocuments in the pack, written from your own answers
EightCriteria groups they have to answer between them
ZeroRequired by name anywhere in the criteria
Who actually reads them

The pack is reviewed by an independent partner auditor during the examination, alongside the evidence that each document is followed in practice. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.3

Cadence is where teams hurt themselves

Your approved policy is the standard you get measured against. Not the criteria. Not a benchmark. The document you wrote, in your own words, is what the examination holds you to2, and it is the only version of your controls that has your signature on it.

Writing quarterly access reviews when you can sustain annual ones does not read as diligence. It manufactures three extra chances a year to miss one, and a control you promised in writing and then skipped is how a deviation gets recorded against you. Promise the interval you will keep. Keep it. Raise it next year, once the habit exists.

The cadence you write is the cadence you are tested on

Quarterly beats annual only if quarterly happens four times. Pick the interval you can evidence without being chased for it. What happens when a control fails covers how a deviation reads in a finished report and what it costs you in a live deal.

How to decide your own number

Work from the criteria toward the documents, never the other way around. A template index tells you what someone else packaged. It cannot tell you what your company does.

  1. Map each criterion to the document that answers it. Any criterion with no document is a real gap. Any document mapped to nothing is a file you will maintain forever for no reason.
  2. Merge before you split. Two documents on one subject drift apart, and the drift is visible to anyone reading both.
  3. Write the interval you can keep, then put it on a calendar before the approval goes through, not after the first review is already late.
  4. Name an owner per document. Unowned policies are the first ones to go stale, because nobody has the review in their week.
  5. Get them signed and dated. Approval with a name and a date is the evidence that the policy exists at all.

Scope moves the count more than any list will. Security only, which is the fixed scope of Polara G.R.C., needs fewer documents than a report that also carries Availability or Confidentiality, because the extra criteria bring extra subject areas with them. Which criteria you should include walks that decision, and what Type 1 asks of a small team is the version written for companies under twenty people.

Type 2 sharpens the cadence question further, because every interval you wrote down has to fire during the 3-month observation window and leave a record behind it.

Questions

How many policies does SOC 2 require?
No specific number. The Trust Services Criteria describe outcomes your controls have to meet, not a table of contents, so any published count is a packaging choice by whoever wrote the list. Polara G.R.C. generates thirteen documents covering the Security criteria.
Which SOC 2 criteria actually expect a written policy?
The common criteria that describe an expectation the company sets and communicates. In practice that means the code of conduct and competence criteria, internal communication of security responsibilities, risk assessment, control activities deployed through policies, logical access, monitoring and incident response, change management, and vendor risk.
Can I merge SOC 2 policies into fewer documents?
Yes. A single access control document with sections on provisioning, credentials, review and removal satisfies the same criteria as four separate files. Fewer documents means fewer approvals to chase and fewer chances for two of your own policies to contradict each other.
Should my policy say quarterly or annual reviews?
Whichever interval you will actually keep. Your approved policy is the standard the examination tests you against, so promising quarterly access reviews and completing three of them creates a deviation that annual reviews would never have produced.
Do SOC 2 policy templates count?
Only if you edit them until they describe what your company really does and then get them approved and dated. A template that names a security team you do not have is worse than no document, because the evidence will not match it.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  3. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.

Get audit-ready without a compliance team.

$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Get started

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

polara labs

Polara Labs builds both sides of the small end of the compliance market: the readiness platform startups use to earn a SOC 2, and the practice software boutique firms use to run the examination. Prices are published on each product page.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.

Built by Surya Shetty