Skip to product information
1 of 5

SOC 2 Starter Bundle (Policies, Control Matrix, Risk & Vendor)

SOC 2 Starter Bundle (Policies, Control Matrix, Risk & Vendor)

Regular price $199.00 USD
Regular price $237.00 USD Sale price $199.00 USD
Sale Sold out

Instant download. Editable files. One-organization licence. 5-day fit guarantee.

Upgrade and save

Getting ready for the audit itself? The SOC 2 Compliance Toolkit adds the Audit Prep and System Description Kit, incident response, business continuity, access and change management templates and a compliance calendar for $50 more than this bundle.

See the SOC 2 Compliance Toolkit (52 Templates)

Not ready to buy? Get the free SOC 2 readiness checklist

5-day fit guarantee. If it does not fit your SOC 2 program, ask for a refund within 5 days. Conditions.

The SOC 2 foundations auditors test first: policies, controls and evidence, risk assessment and vendor management, with a 4-week plan. Bought separately these cost $237; the bundle is $199, a saving of $38.

What you get

  1. SOC 2 Policy Templates Pack (Word and Excel, $129 on its own): 20 editable policies, a map to all 61 criteria with coverage check, and an approval, review and acknowledgement tracker.
  2. SOC 2 Readiness Assessment & Control Matrix (Excel, $59 on its own): scope, 61 criteria, 148 controls, a readiness dashboard and a 111-item evidence request list.
  3. SOC 2 Risk Assessment & Vendor Management Kit (Word and Excel, $49 on its own): risk and vendor procedures, a register with 47 example risks, vendor tiering with CUEC mapping, and a 62-question vendor questionnaire.
  4. Bundle Start Here guide (PDF): how the pieces connect and a 4-week plan. 29 files in total.

Your first 4 weeks

  1. Week 1, scope and baseline: complete the Scope sheet, make a first pass of the control matrix with owners and status, read policy 01 and replace names and tools across all policies.
  2. Week 2, risk and vendors: run the risk workshop including fraud, build the vendor inventory, collect Critical vendor SOC reports and start CUEC mapping, adapt policies 02 to 10.
  3. Week 3, policies and controls: adapt policies 11 to 20 with realistic numbers, update the matrix with gaps, dates and N/A decisions, and send the questionnaire to vendors without a SOC report.
  4. Week 4, approve and plan: CEO approves policies and the risk assessment, launch staff acknowledgement, check coverage, assign evidence owners and agree the gap-closure plan.

Most teams then need several more weeks of control operation before a Type 1 date, depending on the size of the gaps.

Who it is for

Founders, first security hires and operations leads at SaaS companies of roughly 10 to 200 people who need to get SOC 2-ready without a large platform budget, or who use a platform and want stronger policies and a clearer view of their controls.

Good to know

  • Instant download. Editable Word (.docx) and Excel (.xlsx), plus PDF guides. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.
  • Licensed for use within one organization.
  • Criteria are referenced by number and summarized in our own words; the AICPA criteria are free to download from the AICPA.
  • SOC 2 is an attestation report by a licensed CPA firm, not a certification. These templates help you prepare; they do not guarantee an unqualified SOC 2 opinion.
  • 5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.
View full details

What every download includes

Instant downloadLink on the confirmation page and by email within minutes.
Fully editableWord (.docx), Excel (.xlsx) and PDF. No macros. Works in Microsoft 365 and Google Workspace.
5-day fit guaranteeIf the files do not fit your SOC 2 program, ask for a refund within 5 days. Conditions apply.
Free updatesRevised files for the current version of the Trust Services Criteria are sent to you at no charge. One-organization licence.

Templates refer to Trust Services Criteria numbers (for example CC6.1) and describe them in our own words; they do not reproduce AICPA text. A SOC 2 report is issued by a licensed CPA firm. Templates help you prepare; they do not guarantee a clean report.

Questions about SOC 2 Starter Bundle (Policies, Control Matrix, Risk & Vendor)

Why start with these three products?

Policies, controls and evidence, risk assessment and vendor management are the foundations auditors test first. The pieces are cross-referenced: each control in the matrix names its related policy and criteria, and risks carry criteria IDs with treatments that become controls. That consistency is what makes a first audit go smoothly.

What is not in the Starter Bundle?

The Audit Prep and System Description Kit, and the operating templates for incident response, business continuity, access reviews, change logs, governance, training and the compliance calendar. All of those are in the SOC 2 Compliance Toolkit, which also includes everything in this bundle.

Will we be audit-ready after four weeks?

You should have approved policies, a control matrix with honest status, an approved risk register and a tiered vendor inventory. Most teams then need several more weeks of running controls and collecting evidence before a Type 1 date, and a Type 2 period only starts once controls are operating.

Is this enough if we already use a compliance platform?

Many platform users buy the bundle for policies that read like their company and a control matrix to sanity-check the platform's generic control set. The platform collects evidence; you still have to decide what your controls are and run them. The bundle helps with that part.

How will I receive the files?

A download button appears on the order confirmation page and the same link is emailed to you within a few minutes. Bundles arrive as one ZIP file.

Can I get a refund?

Yes. With our 5-day fit guarantee, if the files do not fit your SOC 2 program you can ask for a full refund within 5 days of your order. It applies once per customer and organization, covers the whole product, and requires you to confirm you have deleted the files. We also refund non-delivery, defective files, wrong items and duplicate purchases within 30 days. Read the full refund policy.

Can I see the files before I buy?

Yes. The images above show real pages from the files, and the free SOC 2 readiness checklist lets you check where you stand before you buy.

Can I use the templates with more than one company?

Each purchase is licensed to one organization. Consultants and groups need one licence per client or legal entity. See the licence agreement.

Templates that work with this one

Useful next steps when you prepare for a SOC 2 audit.