{"product_id":"soc-2-compliance-toolkit","title":"SOC 2 Compliance Toolkit (52 Templates)","description":"\u003cp\u003e\u003cstrong\u003eEverything for SOC 2 readiness and for running your controls afterward: 53 files, including 52 editable templates in nine folders.\u003c\/strong\u003e The four individual SOC 2 products cost $286 separately; the toolkit is $249, a saving of $37, and adds five folders of operating templates sold only here.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/soc-2-policy-templates-pack\"\u003eSOC 2 Policy Templates Pack\u003c\/a\u003e\u003c\/strong\u003e (folder 01): 20 policies, criteria map and acknowledgement tracker.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/soc-2-readiness-assessment-control-matrix\"\u003eReadiness Assessment \u0026amp; Control Matrix\u003c\/a\u003e\u003c\/strong\u003e (folder 02): 61 criteria, 148 controls, dashboard and 111-item evidence list.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/soc-2-risk-assessment-vendor-management-kit\"\u003eRisk Assessment \u0026amp; Vendor Management Kit\u003c\/a\u003e\u003c\/strong\u003e (folder 03): procedures, 47-risk register, vendor tiering and 62-question questionnaire.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/soc-2-audit-prep-system-description-kit\"\u003eAudit Prep \u0026amp; System Description Kit\u003c\/a\u003e\u003c\/strong\u003e (folder 04): system description, assertion outline and 12-week readiness plan.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eIncident Response\u003c\/strong\u003e (Word and Excel, folder 05): response plan, six playbooks (phishing, ransomware, lost or stolen laptop, data leak, account takeover, vendor breach), incident log with corrective actions, and a tabletop kit with three scenarios.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eBusiness Continuity\u003c\/strong\u003e (folder 06): BC\/DR plan, business impact analysis with RTO\/RPO gap flags, and DR test report.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAccess and Change\u003c\/strong\u003e (folder 07): change log with self-approval and emergency checks, joiner, mover and leaver checklists, and a quarterly access review with HR cross-check and sign-off.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eGovernance and Training\u003c\/strong\u003e (folder 08): org chart and security roles, Security Committee charter and minutes, a 21-slide awareness deck with speaker notes and a 10-question quiz.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCompliance Calendar\u003c\/strong\u003e (Excel, folder 09): 120 recurring activities by month plus 35 event-driven controls.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here guide\u003c\/strong\u003e (PDF, 7 pages): file map, 90-day path and which file answers which criterion.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eYour first 90 days\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eDays 1 to 30:\u003c\/strong\u003e scope, first pass of the control matrix, org chart and committee charter, adapt policies, risk workshop including fraud, enforce MFA and device management.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDays 31 to 60:\u003c\/strong\u003e approve and communicate policies, training, vendor reviews, first quarterly access review, logging and alerting, incident plan and a tabletop.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDays 61 to 90:\u003c\/strong\u003e BIA and DR test, committee meeting, choose your auditor, draft the system description, collect evidence and run the go\/no-go check.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eSaaS companies of roughly 10 to 200 people preparing for a first Type 1 and moving on to Type 2, and teams on a compliance platform who want complete, company-specific documents and operating templates.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Word (.docx), Excel (.xlsx) and PowerPoint (.pptx), plus PDF. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eCriteria are referenced by number and summarized in our own words; the AICPA criteria are free to download from the AICPA.\u003c\/li\u003e\n\u003cli\u003eSOC 2 is an attestation report by a licensed CPA firm, not a certification. These templates help you prepare; they do not guarantee an unqualified SOC 2 opinion.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603742097602,"sku":"ICC-SOC2-TOOLKIT","price":249.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/soc-2-compliance-toolkit.png?v=1790686224","url":"https:\/\/isocloudconsulting.com\/products\/soc-2-compliance-toolkit","provider":"ISO Cloud Consulting","version":"1.0","type":"link"}