{"title":"SOC 2 Templates and Policy Pack","description":"\u003cp\u003eSOC 2 is an attestation report, issued by a licensed CPA firm, that shows customers how a service organization protects their data against the AICPA Trust Services Criteria for security, availability, confidentiality, processing integrity and privacy.\u003c\/p\u003e\u003cp\u003eThese editable Word and Excel templates are for founders, CTOs, first security hires and operations leads at SaaS companies preparing for a first Type 1 or Type 2 report. Start with the \u003ca href=\"\/products\/free-soc-2-readiness-checklist\"\u003efree SOC 2 readiness checklist\u003c\/a\u003e to see how close you are. Then use the \u003ca href=\"\/products\/soc-2-readiness-assessment-control-matrix\"\u003eReadiness Assessment \u0026amp; Control Matrix\u003c\/a\u003e to find gaps, the \u003ca href=\"\/products\/soc-2-starter-bundle\"\u003eStarter Bundle\u003c\/a\u003e for policies, controls, risk and vendor management, or the complete \u003ca href=\"\/products\/soc-2-compliance-toolkit\"\u003eSOC 2 Compliance Toolkit\u003c\/a\u003e.\u003c\/p\u003e\u003cp\u003eNew to SOC 2? Read our \u003ca href=\"\/pages\/soc-2\"\u003eSOC 2 guide\u003c\/a\u003e.\u003c\/p\u003e","products":[{"product_id":"free-soc-2-readiness-checklist","title":"Free SOC 2 Readiness Checklist","description":"\u003cp\u003e\u003cstrong\u003eA 15-minute, honest view of how close your SaaS company is to a SOC 2 audit, before you spend money on auditors or platforms.\u003c\/strong\u003e Answer 30 questions and get a score, results by area and next steps.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eReadiness Checklist\u003c\/strong\u003e (Excel): 30 questions in six areas (scope and governance, policies and people, risk and vendors, access and endpoints, engineering and operations, resilience and response), with Yes \/ Partly \/ No dropdowns, automatic scoring, results by area and a first step for every gap.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePrintable checklist\u003c\/strong\u003e (PDF, 3 pages) with scoring instructions and four readiness bands.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here note\u003c\/strong\u003e (PDF, 1 page).\u003c\/li\u003e\n\u003c\/ul\u003e\u003ch2\u003eHow to use it\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003eSet aside 15 minutes with the people who know your engineering, IT and HR practices.\u003c\/li\u003e\n\u003cli\u003eAnswer every question. When torn between Yes and Partly, choose Partly: auditors need evidence, not intentions.\u003c\/li\u003e\n\u003cli\u003eRead the next steps for your band and repeat in a month to see progress.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWant the full system?\u003c\/h2\u003e\u003cp\u003eThe \u003ca href=\"\/products\/soc-2-readiness-assessment-control-matrix\"\u003eSOC 2 Readiness Assessment \u0026amp; Control Matrix\u003c\/a\u003e ($59) checks all 61 criteria with 148 controls. The \u003ca href=\"\/products\/soc-2-starter-bundle\"\u003eSOC 2 Starter Bundle\u003c\/a\u003e ($199) adds 20 policies and the risk and vendor kit, and the \u003ca href=\"\/products\/soc-2-compliance-toolkit\"\u003eSOC 2 Compliance Toolkit\u003c\/a\u003e ($249) has everything.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eFree instant download. Excel (.xlsx) and PDF; no macros.\u003c\/li\u003e\n\u003cli\u003eCriteria are referenced by number and summarized in our own words; the AICPA criteria are free to download from the AICPA.\u003c\/li\u003e\n\u003cli\u003eA self-assessment for planning. It is not an audit and does not predict an auditor's opinion.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603738820802,"sku":"ICC-FREE-SOC2-CHECK","price":0.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/free-soc-2-readiness-checklist.png?v=1790686081"},{"product_id":"soc-2-policy-templates-pack","title":"SOC 2 Policy Templates Pack (20 Editable Policies)","description":"\u003cp\u003e\u003cstrong\u003eTwenty editable SOC 2 security policies that read like your company, not a generic template.\u003c\/strong\u003e Each one is mapped to the Trust Services Criteria and ends with the evidence auditors usually request.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003e20 policies\u003c\/strong\u003e (Word, 105 pages in total): Information Security, Access Control, Acceptable Use, Asset Management, Change Management, Secure Software Development, Data Classification and Handling, Data Retention and Disposal, Encryption and Key Management, Incident Response, Business Continuity and Disaster Recovery, Backup, Vendor and Third-Party Management, Risk Management, Human Resources Security, Security Awareness and Training, Logging and Monitoring, Vulnerability and Patch Management, Network and Cloud Security, and Code of Conduct.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eConsistent structure\u003c\/strong\u003e in every policy: purpose, scope, roles, numbered policy statements, standards and minimums, exceptions, enforcement, review, related criteria and an evidence table, with blue Guidance notes and [square-bracket] placeholders.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePolicy-to-Criteria Map\u003c\/strong\u003e (Excel): all 20 policies mapped to all 61 criteria, with an automatic coverage check.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAcknowledgement and Review Tracker\u003c\/strong\u003e (Excel): policy approval and review register, staff acknowledgement tracker, review log and dashboard.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here guide\u003c\/strong\u003e (PDF, 4 pages): the order of work, default owners and common mistakes.\u003c\/li\u003e\n\u003c\/ol\u003e\u003cp\u003eAlso included in the \u003ca href=\"\/products\/soc-2-starter-bundle\"\u003eSOC 2 Starter Bundle\u003c\/a\u003e and the \u003ca href=\"\/products\/soc-2-compliance-toolkit\"\u003eSOC 2 Compliance Toolkit\u003c\/a\u003e.\u003c\/p\u003e\u003ch2\u003eHow to use it\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003eRead policy 01 end to end; it sets the governance model the others rely on.\u003c\/li\u003e\n\u003cli\u003eFind and replace your organization name, product name, cloud and identity providers and role titles across all 20.\u003c\/li\u003e\n\u003cli\u003eWork through each policy with its owner, changing every bracketed number to one you will reliably meet.\u003c\/li\u003e\n\u003cli\u003eCheck the coverage map, approve the policies and record dates in the tracker.\u003c\/li\u003e\n\u003cli\u003ePublish, run an acknowledgement campaign and collect evidence from day one.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eFounders, CTOs, first security hires and operations leads at SaaS companies of roughly 10 to 200 people preparing for a first SOC 2 report, including teams on a compliance automation platform who want policies that match how they really work.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Word (.docx) and Excel (.xlsx), plus a PDF guide. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eCriteria are referenced by number and summarized in our own words; the AICPA criteria are free to download from the AICPA.\u003c\/li\u003e\n\u003cli\u003eSOC 2 is an attestation report by a licensed CPA firm, not a certification. These templates help you prepare; they do not guarantee an unqualified SOC 2 opinion.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603738853570,"sku":"ICC-SOC2-POLICIES","price":129.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/soc-2-policy-templates-pack.png?v=1790686101"},{"product_id":"soc-2-readiness-assessment-control-matrix","title":"SOC 2 Readiness Assessment \u0026 Control Matrix (Excel)","description":"\u003cp\u003e\u003cstrong\u003eFind your SOC 2 gaps, assign owners and track evidence before the auditor arrives.\u003c\/strong\u003e One Excel workbook with 148 controls written for a cloud-hosted SaaS company, mapped to all 61 Trust Services Criteria.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eScope sheet\u003c\/strong\u003e (Excel): report type, categories, in-scope systems and subservice organizations such as your cloud host.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCriteria sheet\u003c\/strong\u003e (Excel): all 61 criteria by ID with our own plain-English summaries, switching in or out with your chosen categories.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eControl Matrix\u003c\/strong\u003e (Excel): 148 controls across 18 domains, from governance and access control to privacy, each with the criteria it maps to, the related policy, owner, frequency, status, gap notes and target date.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eReadiness Dashboard\u003c\/strong\u003e (Excel): readiness by criteria series, with a flag for any in-scope series that has no control.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eEvidence Request List\u003c\/strong\u003e (Excel): 111 typical auditor requests (the PBC list), each linked to control IDs and marked for Type 1, Type 2 or both.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eInstructions sheet and Start Here guide\u003c\/strong\u003e (Excel and PDF): key terms in plain English and the order of work.\u003c\/li\u003e\n\u003c\/ol\u003e\u003cp\u003eAlso included in the \u003ca href=\"\/products\/soc-2-starter-bundle\"\u003eSOC 2 Starter Bundle\u003c\/a\u003e and the \u003ca href=\"\/products\/soc-2-compliance-toolkit\"\u003eSOC 2 Compliance Toolkit\u003c\/a\u003e.\u003c\/p\u003e\u003ch2\u003eHow to use it\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003eComplete the Scope sheet: Type 1 or Type 2, categories, systems and vendors (30 to 60 minutes).\u003c\/li\u003e\n\u003cli\u003eWalk each control domain with its owner. Edit descriptions to match reality, set status honestly and mark N\/A with a reason (1 to 2 days).\u003c\/li\u003e\n\u003cli\u003eAdd target dates for everything not yet operating and feed the gaps into your project plan.\u003c\/li\u003e\n\u003cli\u003eReview the dashboard with leadership, then monthly.\u003c\/li\u003e\n\u003cli\u003eAssign owners to the evidence requests and start collecting now, even before you pick an auditor.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eThe person asked to \"get us SOC 2\": a founder, CTO, first security hire or operations lead at a SaaS company. No prior audit experience needed. If you already use a compliance platform, use it to check the platform's control set against your real operations.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Excel (.xlsx) plus a PDF guide. Works in Excel 2016 or later, Microsoft 365, Google Sheets and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eCriteria are referenced by number and summarized in our own words; the AICPA criteria are free to download from the AICPA.\u003c\/li\u003e\n\u003cli\u003eSOC 2 is an attestation report by a licensed CPA firm, not a certification. These templates help you prepare; they do not guarantee an unqualified SOC 2 opinion.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603739082946,"sku":"ICC-SOC2-CONTROL-MATRIX","price":59.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/soc-2-readiness-assessment-control-matrix.png?v=1790686128"},{"product_id":"soc-2-risk-assessment-vendor-management-kit","title":"SOC 2 Risk Assessment \u0026 Vendor Management Kit","description":"\u003cp\u003e\u003cstrong\u003eA credible SOC 2 risk assessment and vendor management program without buying a GRC platform.\u003c\/strong\u003e These are two areas where first-time SOC 2 companies often have thin evidence.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eRisk Assessment Procedure\u003c\/strong\u003e (Word, 6 pages): a step-by-step method for the annual and change-driven risk assessment, including fraud risk (CC3.1 to CC3.4), with a fictional worked example.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eRisk Register\u003c\/strong\u003e (Excel): a 5 x 5 register with 47 pre-written SaaS risks written as cause, event and consequence, inherent and residual scoring, an appetite flag, heat maps and a dashboard.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eVendor Management Procedure\u003c\/strong\u003e (Word, 6 pages): intake, tiering, due diligence by tier, how to review a SOC 2 report and its complementary user entity controls (CUECs), contract terms, monitoring and offboarding (CC9.2).\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eVendor Inventory and Risk Tiering\u003c\/strong\u003e (Excel): automatic tiering from six questions, review due dates, a 14-step SOC report review checklist, review log, CUEC mapping and dashboard.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eVendor Security Questionnaire\u003c\/strong\u003e (Excel): 62 questions in 14 sections with answer dropdowns, weights, critical flags and automatic scoring.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here guide\u003c\/strong\u003e (PDF): the order of work, what good looks like and common mistakes.\u003c\/li\u003e\n\u003c\/ol\u003e\u003cp\u003eAlso included in the \u003ca href=\"\/products\/soc-2-starter-bundle\"\u003eSOC 2 Starter Bundle\u003c\/a\u003e and the \u003ca href=\"\/products\/soc-2-compliance-toolkit\"\u003eSOC 2 Compliance Toolkit\u003c\/a\u003e.\u003c\/p\u003e\u003ch2\u003eHow to use it\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003eRead the procedure and confirm scales and appetite with the CEO.\u003c\/li\u003e\n\u003cli\u003eAdapt the example risks, then run a 60 to 90 minute workshop with your leads, including a fraud discussion.\u003c\/li\u003e\n\u003cli\u003eAgree treatments, get CEO approval and save a dated copy as evidence.\u003c\/li\u003e\n\u003cli\u003eList every vendor (check your identity provider app list, expense reports and cloud marketplace) and let the workbook tier them.\u003c\/li\u003e\n\u003cli\u003eReview SOC reports from Critical and High vendors, map the CUECs, and send the questionnaire to vendors without a report.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eThe person responsible for SOC 2 readiness at a SaaS company, and teams whose platform's built-in risk register feels generic. Auditors want to see real risks, fraud discussed, risk reviewed when things change, and vendor SOC reports actually read.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Word (.docx) and Excel (.xlsx), plus a PDF guide. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eCriteria are referenced by number and summarized in our own words; the AICPA criteria are free to download from the AICPA.\u003c\/li\u003e\n\u003cli\u003eSOC 2 is an attestation report by a licensed CPA firm, not a certification. These templates help you prepare; they do not guarantee an unqualified SOC 2 opinion.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603741343938,"sku":"ICC-SOC2-RISK-VENDOR","price":49.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/soc-2-risk-assessment-vendor-management-kit.png?v=1790686150"},{"product_id":"soc-2-audit-prep-system-description-kit","title":"SOC 2 Audit Prep \u0026 System Description Kit","description":"\u003cp\u003e\u003cstrong\u003eThe system description, management assertion and 12-week plan that take you from SOC 2 readiness to fieldwork.\u003c\/strong\u003e The system description is often the longest single piece of writing in SOC 2 preparation; this kit gives you the structure and worked examples.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eSystem Description Template\u003c\/strong\u003e (Word, 7 pages): management's description organized by the topics of the AICPA description criteria (DC 200), in 11 sections from services and commitments to subservice organizations, CUECs, incidents and changes, with shaded fictional examples and a completion checklist.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eManagement Assertion Template\u003c\/strong\u003e (Word, 3 pages): the structure of the assertion, an outline and a pre-signing checklist. Your auditor provides the final wording.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAudit Readiness Plan\u003c\/strong\u003e (Excel): a 37-task 12-week plan, Type 2 period planner, 12-month evidence calendar for 113 recurring controls, an auditor scorecard with 10 weighted criteria plus a licensed-CPA-firm gate, and a 25-item go\/no-go checklist.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here guide\u003c\/strong\u003e (PDF): how the pieces fit, steps and common mistakes.\u003c\/li\u003e\n\u003c\/ol\u003e\u003cp\u003eAlso included in the \u003ca href=\"\/products\/soc-2-compliance-toolkit\"\u003eSOC 2 Compliance Toolkit\u003c\/a\u003e.\u003c\/p\u003e\u003ch2\u003eHow to use it\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003eEnter your start date in the 12-week plan and assign owners.\u003c\/li\u003e\n\u003cli\u003eScore two to four CPA firms and aim to sign an engagement letter by around week 9.\u003c\/li\u003e\n\u003cli\u003eDraft the system description, starting with services, system components and subservice organizations, which take longest.\u003c\/li\u003e\n\u003cli\u003ePut the evidence calendar into your team calendars.\u003c\/li\u003e\n\u003cli\u003eRun the go\/no-go checklist before confirming a Type 1 date or starting a Type 2 period, then prepare the assertion with your auditor's wording.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eTeams nearly ready for their first SOC 2 audit, or who have picked a Type 1 date and need to organize the last mile: the description, the auditor, the timeline and the evidence.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Word (.docx) and Excel (.xlsx), plus a PDF guide. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eCriteria are referenced by number and summarized in our own words; the AICPA criteria are free to download from the AICPA.\u003c\/li\u003e\n\u003cli\u003eSOC 2 is an attestation report by a licensed CPA firm, not a certification. These templates help you prepare; they do not guarantee an unqualified SOC 2 opinion.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603741933762,"sku":"ICC-SOC2-AUDIT-PREP","price":49.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/soc-2-audit-prep-system-description-kit.png?v=1790686175"},{"product_id":"soc-2-starter-bundle","title":"SOC 2 Starter Bundle (Policies, Control Matrix, Risk \u0026 Vendor)","description":"\u003cp\u003e\u003cstrong\u003eThe SOC 2 foundations auditors test first: policies, controls and evidence, risk assessment and vendor management, with a 4-week plan.\u003c\/strong\u003e Bought separately these cost $237; the bundle is $199, a saving of $38.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/soc-2-policy-templates-pack\"\u003eSOC 2 Policy Templates Pack\u003c\/a\u003e\u003c\/strong\u003e (Word and Excel, $129 on its own): 20 editable policies, a map to all 61 criteria with coverage check, and an approval, review and acknowledgement tracker.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/soc-2-readiness-assessment-control-matrix\"\u003eSOC 2 Readiness Assessment \u0026amp; Control Matrix\u003c\/a\u003e\u003c\/strong\u003e (Excel, $59 on its own): scope, 61 criteria, 148 controls, a readiness dashboard and a 111-item evidence request list.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/soc-2-risk-assessment-vendor-management-kit\"\u003eSOC 2 Risk Assessment \u0026amp; Vendor Management Kit\u003c\/a\u003e\u003c\/strong\u003e (Word and Excel, $49 on its own): risk and vendor procedures, a register with 47 example risks, vendor tiering with CUEC mapping, and a 62-question vendor questionnaire.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eBundle Start Here guide\u003c\/strong\u003e (PDF): how the pieces connect and a 4-week plan. 29 files in total.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eYour first 4 weeks\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eWeek 1, scope and baseline:\u003c\/strong\u003e complete the Scope sheet, make a first pass of the control matrix with owners and status, read policy 01 and replace names and tools across all policies.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eWeek 2, risk and vendors:\u003c\/strong\u003e run the risk workshop including fraud, build the vendor inventory, collect Critical vendor SOC reports and start CUEC mapping, adapt policies 02 to 10.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eWeek 3, policies and controls:\u003c\/strong\u003e adapt policies 11 to 20 with realistic numbers, update the matrix with gaps, dates and N\/A decisions, and send the questionnaire to vendors without a SOC report.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eWeek 4, approve and plan:\u003c\/strong\u003e CEO approves policies and the risk assessment, launch staff acknowledgement, check coverage, assign evidence owners and agree the gap-closure plan.\u003c\/li\u003e\n\u003c\/ol\u003e\u003cp\u003eMost teams then need several more weeks of control operation before a Type 1 date, depending on the size of the gaps.\u003c\/p\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eFounders, first security hires and operations leads at SaaS companies of roughly 10 to 200 people who need to get SOC 2-ready without a large platform budget, or who use a platform and want stronger policies and a clearer view of their controls.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Word (.docx) and Excel (.xlsx), plus PDF guides. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eCriteria are referenced by number and summarized in our own words; the AICPA criteria are free to download from the AICPA.\u003c\/li\u003e\n\u003cli\u003eSOC 2 is an attestation report by a licensed CPA firm, not a certification. These templates help you prepare; they do not guarantee an unqualified SOC 2 opinion.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603742032066,"sku":"ICC-SOC2-STARTER","price":199.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/soc-2-starter-bundle.png?v=1790686196"},{"product_id":"soc-2-compliance-toolkit","title":"SOC 2 Compliance Toolkit (52 Templates)","description":"\u003cp\u003e\u003cstrong\u003eEverything for SOC 2 readiness and for running your controls afterward: 53 files, including 52 editable templates in nine folders.\u003c\/strong\u003e The four individual SOC 2 products cost $286 separately; the toolkit is $249, a saving of $37, and adds five folders of operating templates sold only here.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/soc-2-policy-templates-pack\"\u003eSOC 2 Policy Templates Pack\u003c\/a\u003e\u003c\/strong\u003e (folder 01): 20 policies, criteria map and acknowledgement tracker.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/soc-2-readiness-assessment-control-matrix\"\u003eReadiness Assessment \u0026amp; Control Matrix\u003c\/a\u003e\u003c\/strong\u003e (folder 02): 61 criteria, 148 controls, dashboard and 111-item evidence list.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/soc-2-risk-assessment-vendor-management-kit\"\u003eRisk Assessment \u0026amp; Vendor Management Kit\u003c\/a\u003e\u003c\/strong\u003e (folder 03): procedures, 47-risk register, vendor tiering and 62-question questionnaire.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/soc-2-audit-prep-system-description-kit\"\u003eAudit Prep \u0026amp; System Description Kit\u003c\/a\u003e\u003c\/strong\u003e (folder 04): system description, assertion outline and 12-week readiness plan.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eIncident Response\u003c\/strong\u003e (Word and Excel, folder 05): response plan, six playbooks (phishing, ransomware, lost or stolen laptop, data leak, account takeover, vendor breach), incident log with corrective actions, and a tabletop kit with three scenarios.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eBusiness Continuity\u003c\/strong\u003e (folder 06): BC\/DR plan, business impact analysis with RTO\/RPO gap flags, and DR test report.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAccess and Change\u003c\/strong\u003e (folder 07): change log with self-approval and emergency checks, joiner, mover and leaver checklists, and a quarterly access review with HR cross-check and sign-off.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eGovernance and Training\u003c\/strong\u003e (folder 08): org chart and security roles, Security Committee charter and minutes, a 21-slide awareness deck with speaker notes and a 10-question quiz.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCompliance Calendar\u003c\/strong\u003e (Excel, folder 09): 120 recurring activities by month plus 35 event-driven controls.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here guide\u003c\/strong\u003e (PDF, 7 pages): file map, 90-day path and which file answers which criterion.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eYour first 90 days\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eDays 1 to 30:\u003c\/strong\u003e scope, first pass of the control matrix, org chart and committee charter, adapt policies, risk workshop including fraud, enforce MFA and device management.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDays 31 to 60:\u003c\/strong\u003e approve and communicate policies, training, vendor reviews, first quarterly access review, logging and alerting, incident plan and a tabletop.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDays 61 to 90:\u003c\/strong\u003e BIA and DR test, committee meeting, choose your auditor, draft the system description, collect evidence and run the go\/no-go check.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eSaaS companies of roughly 10 to 200 people preparing for a first Type 1 and moving on to Type 2, and teams on a compliance platform who want complete, company-specific documents and operating templates.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Word (.docx), Excel (.xlsx) and PowerPoint (.pptx), plus PDF. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eCriteria are referenced by number and summarized in our own words; the AICPA criteria are free to download from the AICPA.\u003c\/li\u003e\n\u003cli\u003eSOC 2 is an attestation report by a licensed CPA firm, not a certification. These templates help you prepare; they do not guarantee an unqualified SOC 2 opinion.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603742097602,"sku":"ICC-SOC2-TOOLKIT","price":249.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/soc-2-compliance-toolkit.png?v=1790686224"}],"url":"https:\/\/isocloudconsulting.com\/collections\/soc-2-templates.oembed","provider":"ISO Cloud Consulting","version":"1.0","type":"link"}