SOC 2 Type I is a point-in-time assessment that evaluates whether your security controls are suitably designed. It shares the same Trust Services Criteria as Type II but does not require an observation period, making it the ideal first step toward full SOC 2 compliance.
Startups and growing companies seeking their first SOC 2 certification before progressing to Type II.
22 policies required for SOC 2 Type I compliance, organized by category.
Establishes the overarching information security program and governance structure.
Defines requirements for managing user access based on least privilege.
Establishes password creation, management, and rotation requirements.
Defines data classification levels and handling requirements.
Structured approach for detecting, responding to, and recovering from security incidents.
Methodology for identifying, assessing, and managing security risks.
Physical access controls and environmental protections.
Defines acceptable and prohibited uses of company systems and data.
Ensures critical business functions continue during and after disruptions.
Procedures for evaluating, onboarding, and monitoring third-party vendors.
Procedures for inventorying, tracking, and disposing of assets.
Section 3 of SOC 2 Type 2 report — mandatory narrative describing infrastructure, software, people, procedures, and data per AICPA Description Criteria DC 200 (2018 revision).
Section 2 of SOC 2 Type 2 report — formal management attestation of control effectiveness per AICPA AT-C 205.
Procedures for recovering IT infrastructure after catastrophic events.
Procedures for requesting, reviewing, approving, and deploying changes.
Controls for securing network infrastructure and communications.
Encryption standards and key management practices.
Requirements for logging events and maintaining audit trails.
Answer questions about your infrastructure and PoliWriter generates all 22 SOC 2 Type I policies customized to your organization. Audit-ready in hours, not months.
Get Started FreeNo credit card required. 3 documents free.
Service Organization Control 2 - Trust Services Criteria covering Security, Availability, Processing Integrity, Confidentiality, and Privacy. Requires an observation period of 3-12 months demonstrating controls operate effectively over time.
22 templatesGeneral Data Protection Regulation - EU data protection and privacy regulation.
10 templatesHealth Insurance Portability and Accountability Act - US healthcare data protection.
12 templatesInternational standard for information security management systems (ISMS).
11 templatesPayment Card Industry Data Security Standard — security controls for organizations that store, process, or transmit payment cardholder data.
12 templatesCalifornia Consumer Privacy Act / California Privacy Rights Act — grants California consumers rights over their personal information collected by businesses.
8 templatesNIST Cybersecurity Framework — voluntary guidance for managing cybersecurity risk across five core functions: Identify, Protect, Detect, Respond, and Recover.
10 templatesISO/IEC 42001 — International standard for Artificial Intelligence Management Systems (AIMS), covering responsible AI development, deployment, and governance.
8 templatesNIS 2 Directive (EU 2022/2555) — EU-wide cybersecurity legislation requiring essential and important entities to implement comprehensive risk management and incident reporting.
10 templatesNIST SP 800-53 — Comprehensive catalog of security and privacy controls for federal information systems, widely adopted by private sector organizations.
10 templates