What policies do I need for SOC 2?
SOC 2 has no fixed policy checklist, but auditors expect a core set: information security, access control, change management, risk assessment, incident response, business continuity, vendor management, data classification, acceptable use, and HR security policies.
The full answer
SOC 2 does not ship with an official list of required policies. It is built on the AICPA's Trust Services Criteria, which describe control objectives, so the policies you need are the ones that document how you meet those objectives. In practice, auditors expect a recognizable core set that maps to the common criteria.
That core usually includes an information security policy, access control and identity management, change management, risk assessment and treatment, incident response, business continuity and disaster recovery, vendor and third-party risk management, data classification and handling, acceptable use, and HR or personnel security covering onboarding and offboarding. If you scoped additional categories like availability or confidentiality, add policies that address them.
Policies only matter if you follow them. Under the AICPA's SSAE No. 18 attestation standards, auditors test whether controls operated, so a polished document with no matching evidence is a gap. Write policies you can actually execute, then keep the tickets, logs, and reviews that prove people follow them.
You do not have to draft everything from scratch. GRC platforms such as Vanta, Drata, and Secureframe ship policy templates mapped to SOC 2 and track approvals and reviews. Tailor each template to how your company really operates, get them formally approved, and re-review them so they stay accurate through your report period, which for a Type 2 spans an observation window of three to twelve months.
Go deeper
Short answer not enough? These pages cover the full picture:
Get matched with the right auditor
Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.
Get instant pricing →Talk to auditors who handle this every week
Every firm on AuditNex is listed on identical terms — placement cannot be bought, and credentials are independently checked.
Related questions
Can a two-person startup get SOC 2?
Yes. SOC 2 has no minimum headcount; a two-person startup can earn a report. Controls simply scale to your size — the auditor assesses whether your controls fit your operations, not whether you have a large team.
Do I need a penetration test for SOC 2?
Not strictly. The AICPA's SOC 2 framework never names a penetration test as a required control, but most auditors and enterprise buyers expect one as evidence of vulnerability management, so in practice it is nearly standard.
Does SOC 2 cover remote work and BYOD?
Yes. SOC 2's Security criteria apply wherever your team works, so remote work and BYOD fall in scope. Auditors expect controls like endpoint protection, encryption, MDM or access policies, and secure authentication regardless of device location.
Does SOC 2 require MFA?
Effectively yes, though not by name. SOC 2's Trust Services Criteria require strong logical access controls without naming MFA, but auditors and customers treat multi-factor authentication as the baseline, so nearly every SOC 2 program enables it.
Does SOC 2 require a vendor management program?
Yes, in practice. SOC 2's Common Criteria include managing risks from vendors and subservice organizations, so auditors expect a vendor management process — inventory, risk-based due diligence, and monitoring — even though no single rule dictates its exact form.
Does SOC 2 require annual security training?
Not by a named rule. SOC 2's Trust Services Criteria require security awareness training but never specify a frequency; auditors and customers treat training at onboarding plus at least annually as the standard, so most companies run it yearly.
Sources: AICPA Trust Services Criteria (2017, rev. 2022); AICPA SSAE No. 18 attestation standards. Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.