Playbook · Track 3 · Lesson 7 of 10 · 3 min

SOC 2 policies for startups: what your first audit needs

Short answer

SOC 2 does not give you a list of named policies, but auditors expect written, approved policies that cover the controls you describe. Most startups end up with 10 to 20 policies. The trap is copying templates that describe processes you do not follow.

Which policies do auditors usually expect?

Names vary, but a first SOC 2 policy set commonly covers: information security (the umbrella policy), acceptable use, access control, change management, incident response, business continuity and disaster recovery, backup, data classification and retention, encryption, vendor management, risk assessment, human resources security (onboarding, offboarding, training), physical security where relevant, and a code of conduct. Your auditor and your tool will map them to the criteria you chose.

Why do template policies cause problems?

The auditor tests whether you do what your policies say. A template that promises quarterly access reviews, when you plan to do them twice a year, creates an exception in a Type II report. Edit every template to match reality, then change reality where the policy is right and the practice is not.

How do tools help with policies?

Most tools in this guide ship policy templates. Several add AI or expert help: Vanta's AI agent drafts policies; Scytale lists an AI Policy Generator as 'Coming soon' and pairs its platform with a dedicated compliance expert; Secureframe lists policy management in its Fundamentals plan.

Who should approve the policies?

Leadership. Auditors look for evidence that policies were approved and communicated, and that people acknowledged them. Keep the approval date and the acknowledgement records; tools usually track both.

How often do policies need review?

Your policies should say how often they are reviewed, and then you review them on that schedule. Once a year is common. Record each review, even when nothing changes.

What does a good startup policy look like?

Short, specific and true. A good access control policy names the systems it covers, who approves access, how often access is reviewed and what happens when someone leaves. It avoids promises the team cannot keep, such as reviews every month when nobody has time. One to three pages is enough for most startup policies. Write in plain language so that the engineers who follow the policy can read it without a translator.

How do policies connect to evidence?

Every commitment in a policy creates something the auditor can ask to see. If the policy says new hires complete security training within 30 days, the auditor may sample new hires and ask for training records. Before approving a policy, list the evidence each sentence creates and check that someone will produce it. Tools that link policies to controls and controls to evidence make this easier to see.

What should you read next?

Next lesson · 8 of 10

SOC 2 evidence collection and integrations, explained for startups

Questions founders ask

Can we use AI to write SOC 2 policies?

AI drafts save time, but someone who knows how your company works must edit and approve them. The auditor tests practice against the text.