SOC2Prep

SOC 2 policy gap finder

This starts from what you already have rather than from a generic list, and it ranks what is missing by how early in the audit the request arrives.

Last reviewed 2026-09-14Written by Jacob Masse, TrazTech Inc.

There is a difference between a list of policies you ought to have and a list of the ones you are missing. The first is easy to find and easy to ignore. The second is short, specific, and has an order to it, because the audit request list does not arrive all at once. Some documents are asked for in the first week and hold up everything behind them. Others are not asked for until fieldwork, and a few are never asked for at all unless something in your business triggers them.

Tick the policies you already have approved, say what your company actually does, and this returns what is missing, ranked by when the request arrives. It also treats an unapproved draft as missing, because that is how an auditor treats it.

The list appears on this page. Nothing is emailed anywhere unless you ask for it at the end.

Which policies do you already have?

Tick a document only if it exists, has been edited for your company, and carries an approval date. A downloaded template nobody signed does not count here, and it does not count in an audit either.

What does your company actually do?

This decides which of the conditional documents apply. Policies about things you do not do are the fastest way to fail your own controls.

Which Trust Services Criteria are in scope?
What state are the documents you have in?

Have staff acknowledged them?

How many people work there?

When does the observation window open?

Approval is the control, not the document

An auditor testing a policy is not grading the prose. They are checking four things: that it exists, that it was approved by someone with the authority to approve it, that the approval carries a date inside or before the observation window, and that the people it applies to have acknowledged the version in force. A well-written document with no approval record fails all four tests except the first. A plain one with a version history and signatures passes.

That is why a draft counts as missing here. It is also why the cheapest work on most gap lists is not writing anything: it is taking the documents that already exist, putting them through an approval, and collecting the acknowledgements.

The trap in a downloaded set

Template packs are written to be defensible everywhere, which means they commit you to cadences and controls a company of thirty people will not meet. Monthly access reviews, annual penetration tests of every system, a security committee meeting every quarter with minutes. The auditor tests you against what your policy says, not against a general standard, so every sentence you do not intend to perform is an exception you wrote yourself.

Read every cadence, every named role and every retention period before approving. Change them to what you will actually do. A policy saying access is reviewed twice a year and evidence showing twice a year is a clean control. A policy saying quarterly with two reviews in the period is a finding. The policy templates page goes through how to edit a downloaded set safely.

Common questions

How many policies does a first SOC 2 need?

Between twelve and twenty for most companies, depending on scope and on how much you combine. There is no required number and no required set, because SOC 2 publishes criteria rather than a document list. What matters is that every criterion has something written behind it and that the document says what you actually do.

Can we put several topics in one document?

Yes, and below thirty people it usually reads better. One information security policy with clear sections is easier to keep current than fifteen separate files that drift apart. The trade-off is that every change puts the whole document through approval again, and that every person acknowledges all of it. Most teams split out the ones with different audiences: the code of conduct and acceptable use go to everyone, the engineering documents go to engineers.

Who is allowed to approve a policy?

Someone with the authority to commit the company, and the same person should not approve their own work where that can be avoided. In a small company that is usually a founder or an executive. Record the name, the role and the date. An approval by an unnamed committee is the version auditors push back on.

How often do policies have to be reviewed?

Annually is the near-universal answer and the one to write down, plus a review after any material change. The review itself is evidence: a dated record showing the document was looked at and either changed or confirmed. A policy with an approval date two years old is one of the easiest findings an auditor can make, because it takes ten seconds to spot.

Want the missing ones drafted properly

Send the gap list and what your company does, and Canadian firms that do readiness work will write documents that match your actual practice.

Get matched