SOC2Prep

SOC 2 policy checklist generator

Most policy lists on the internet are the same twelve American documents regardless of what you selected. This one changes with your criteria, and it adds the documents Canadian privacy law puts on top.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

SOC 2 does not publish a list of required policies. It publishes criteria, and your auditor decides whether your documents cover them. That is why every list you find is different and why most of them are longer than they need to be: a template vendor with sixteen documents to sell describes sixteen required policies.

This works out which documents your selections actually call for. The list appears on the page with what each document has to contain, and it separates the ones SOC 2 drives from the ones Canadian law drives, because the second group applies whether or not you ever commission an audit.

Which Trust Services Criteria are in scope?

Security is mandatory in every SOC 2. Tick the others only if a customer asked for them or you make a public commitment that needs one. Each additional criterion adds audit fee and evidence.

What data do you hold?

This is where the Canadian obligations come from, and they sit outside SOC 2 rather than inside it.

How do you build and run the product?
How many people work there?

Coverage matters, the file count does not

An auditor tests whether a topic is addressed, approved, current and acknowledged. Nothing requires one topic per file. A ten person company can put access control, acceptable use and password requirements in a single document and be in a better position than a company with three separate files that contradict each other on password length.

Combining is worth doing for a small team, because every separate document is a separate approval to record, a separate version history to maintain and a separate annual review to evidence. What fails is missing a topic entirely, and the topics small companies miss are almost always the same three: vendor management, data retention, and risk assessment.

The part American policy packs leave out

A downloaded American policy set covers the SOC 2 topics and stops. It will not mention that PIPEDA requires you to keep a record of every breach for 24 months whether or not the breach was reportable, that Quebec's Law 25 requires a named person accountable for the protection of personal information and a privacy impact assessment before certain projects, or that provincial health privacy law makes you an agent of the custodian when you hold health information for a clinic. SOC 2 and Law 25 maps the Quebec obligations against the criteria one by one.

Those obligations are law rather than criteria. They apply whether or not you buy an audit, no auditor's opinion discharges them, and a SOC 2 report with no privacy criterion in scope says nothing about them either way.

Common questions

How many policies does SOC 2 require?

None specifically. SOC 2 sets criteria and your auditor judges whether your documentation addresses them. In practice a first audit against the security criterion alone lands at roughly ten to fourteen documents, depending on how much you combine. Adding availability, confidentiality, processing integrity or privacy adds two to four more each.

Can we use free SOC 2 policy templates?

Yes, as a starting structure. The failure is not that templates are bad, it is that people ship them unedited. A template promising quarterly access reviews and annual penetration tests, adopted by a company that does neither, has manufactured two exceptions on its own report. Edit every cadence and every commitment to what you will really do.

Does every policy need to be approved by the board?

No. It needs an approver with the authority to approve it, and the approval has to be recorded with a date. In a company of thirty people that is usually the chief executive or the head of engineering. What auditors reject is a document with no approver, no date and no version, because there is then nothing to test.

Do policies need to be reviewed every year?

If your policy says annually, then yes, and the review has to be evidenced with a date even when nothing changed. This is a common and cheap exception to collect: teams write the policies, get them approved, and then never record the review a year later. Put the review on one named person's calendar at the same time as you approve the set.

Which policies do Canadian companies most often miss?

Vendor and third-party management, data classification and retention, and risk assessment. All three are topics small companies have never been asked about before an audit, and all three take longer than expected because the document is easy and the underlying register or assessment is not.

Not sure your policies match how you operate

Tell us the scope and your target date and we will tell you whether this is a writing job or a control job.

Get matched